Florida has sued OpenAI and Sam Altman personally. Europe's version of that risk arrives in December.
Florida is the first US state to sue OpenAI, and it has named the chief executive as a defendant. The case treats ChatGPT as a consumer product with safety defects. In the EU, new product liability rules will soon treat AI software the same way, and they apply to every company that ships it.
On June 1 Florida’s attorney general, James Uthmeier, sued OpenAI and its chief executive Sam Altman in state court, accusing them of deceptive and unfair trade practices. It is the first lawsuit by a US state against the company. The complaint says OpenAI marketed ChatGPT as safe, including to children, while ignoring internal and external warnings about its risks. Uthmeier said the penalties could reach billions of dollars. Naming the chief executive personally is the part other AI companies will notice first.
What Florida alleges
The claims are brought under Florida’s consumer protection law, which is designed for companies that mislead customers about what they are buying. According to the attorney general’s announcement, the state alleges that OpenAI put speed to market ahead of safety, marketed ChatGPT to children, collected data from minors without meaningful parental consent, and played down dangerous errors. It also alleges harms including dependency, self-harm and violence. The suit follows a criminal investigation into how the man charged with the April 2025 shooting at Florida State University used ChatGPT.
OpenAI’s response, quoted by NPR, is that it has industry-leading protections for young users, including age prediction, a separate experience for minors and parental controls, and that it agrees minors need significant protection. NPR counts more than 20 lawsuits already filed against OpenAI over shootings and suicides, and notes that Google and Character.AI face similar claims.
A consumer protection case, with a CEO in it
Most AI lawsuits so far have been private suits by families or rights holders. A state attorney general has more tools: investigative powers, civil penalties per violation, and no need to prove what happened to one specific user. Consumer protection law also avoids the harder questions about whether an AI company is responsible for what a user decides to do. The state only has to show that OpenAI said one thing about safety and knew another.
Naming Altman personally raises the stakes. Executives are sometimes named in consumer protection cases when the state argues they directed the conduct. Whether it survives in court is another question, but it turns a corporate risk into a personal one for the people who decide how fast a product ships.
There is also a political side. Florida’s government is Republican and generally close to the Trump administration, which has spent the past six months trying to stop states from regulating AI. Child safety laws were explicitly exempted from that push. Florida has found the part of AI regulation that the federal campaign against state rules leaves open, and it will not be the last state to use it.
My view is that the case is stronger on its general theory than on some of its specific allegations. Tying a chatbot to a shooting is legally difficult, and OpenAI will fight it hard. The broader argument, that a company selling a product to children has to be able to show its safety claims were true, is one most people would accept and many courts will too.
Europe treats AI software as a product
European companies should not see this as an American curiosity. The EU’s revised Product Liability Directive, which member states must turn into national law by 9 December 2026, explicitly classifies software and AI as products, whether delivered on a device, from the cloud or as a subscription service. Liability is strict: an injured person does not have to prove negligence, only that the product was defective and caused the harm.
According to Freshfields’ analysis, two features make it bite for AI. A product is defective when it does not provide the safety people are entitled to expect or that the law requires, which ties liability directly to compliance with the AI Act. And courts can presume a defect when a company breaches mandatory safety requirements, when the technology is too complex for a claimant to prove the fault, or when the company does not disclose evidence it is ordered to hand over. Because software keeps changing after release, the manufacturer’s responsibility runs for as long as it controls the updates.
That applies to any company that puts an AI product on the European market, including one built on another company’s model.
What to do before December
Check what you say about safety. Florida’s case rests on the gap between OpenAI’s marketing and its internal knowledge. Look at how your company describes its AI features on its website, in sales material and in contracts, and make sure you can back up every claim about accuracy and safety.
Find out whether children can use your product. If they can, even when they are not the intended users, you need age-appropriate safeguards and a record of why you chose them. The AI Act already bans AI practices that exploit the vulnerabilities of children, and the Digital Services Act requires online platforms that minors use to protect their privacy and safety.
Keep the evidence. Under the new directive, a company that cannot show how its AI was tested, what risks it found and what it did about them may be presumed at fault. The documentation the AI Act asks for doubles as a defence in a liability claim.
And review your contracts with model providers. If you build on a model from OpenAI, Anthropic, Google or Mistral and sell the result in Europe, you are likely to be treated as the manufacturer. Ask what your supplier will cover if its model causes the defect.
