· LinkedIn post · Updated

Whom do the rules hold?

So I went looking at a narrower question. When something goes wrong, whom do the rules we have actually hold responsible?

Five channels converge at a single point; where the channels meet stands a large pale mass with a small dark figure beside it.

Writing in MIT Technology Review on 20 August 2026, Rumman Chowdhury argues that talking about AI as if it were human sets a legal trap. Give a system legal personhood, she says, and it stops being a product and becomes something the law treats as a being.

So I went looking at a narrower question. When something goes wrong, whom do the rules we have actually hold responsible?

Turkey put its AI action plan into force last week. A presidential circular published in the Official Gazette on 18 August 2026 set it running, coordinated by the Ministry of Industry and Technology. It is not a law. It creates no direct obligation for any company. It requires every public institution to carry out its part. It is still the most recent official text we have on the public side.

In the EU the high-risk obligations under Annex III were due to apply from 2 August 2026. Regulation (EU) 2026/1744 moved part of them to December 2027 and another part to August 2028. It has been in force since 27 July 2026, three days after it was published.

One date did not move: 9 December 2026. From that date the EU's product liability rules will cover all software placed on the market, AI systems included. A victim who is not a company may ask the distributor to name the liable party in the EU. No answer within a month, and the claim can be brought against the distributor itself.

California answers the question from the other side: whom responsibility cannot be laid on. Assembly Bill 316, chaptered in California on 13 October 2025, stops a defendant who developed, modified or used the system from resting on the defence that the AI caused the harm on its own. He may still put in evidence: on causation, on a third party's share of fault, and on foreseeability.

Foreseeability is where the record gets interesting. On 22 August 2026 TechCrunch carried an assessment. The subject was what five leading AI labs have told the public about containing a model. OpenAI described a process: restricting permissions, pausing workloads, limiting how far a model is deployed, or taking it fully offline. Anthropic said that if it detected an attempt to evade oversight it would assess whether containment is the right step. Google and Meta declined to say whether any such plan exists inside the company, and xAI did not respond in time. Google added a note of its own: the assessment does not cover the full scope of its safety and security measures. The legal weight of that is simple. A company that has itself listed the measures it can take cannot later call the situation calling for them unforeseeable.

Turkish law starts at article 20 of the Penal Code. Criminal liability is personal, and no one answers for another person's act. No criminal penalty applies to a legal person, though the security measures the law provides are preserved. Article 60 reaches a private legal person operating under a permit from a public authority. It takes an offence committed intentionally and for that person's benefit, through misuse of the authority the permit confers, with its organs or representatives taking part. On conviction the permit is revoked, and the confiscation rules apply to that legal person too.

So here is my answer, and it is mine rather than any court's. Every rule I could find holds a person. The developer, the modifier, the user, the distributor, the holder of the permit. Not one of them holds the model.

Sources