xAI sues Minnesota: AI tool makers, not users, are liable
Minnesota's HF 1606 puts strict liability on the operator of an AI image tool, not the user. xAI is suing. If you ship AI features, this is your problem too.
xAI sued Minnesota Attorney General Keith Ellison in federal court this week, days before HF 1606 takes effect. Strip out the subject matter and what's left is the part that should worry anyone shipping AI features: Minnesota wrote a law that holds the operator of the AI tool liable for what a user does with it, with no safe harbor for good-faith compliance. That's a different liability model than the deepfake laws that came before it, and it's the one other states will copy if it survives.
What actually happened
Per AP coverage, the statute targets the companies that make the tools available rather than the people who use them, with civil penalties reported at $500,000 per violation. xAI's complaint argues the law is an overbroad, content-based restriction under the First Amendment, that its definitions sweep in ordinary images like swimwear and shirtless photos, and that it offers no safe harbor for a company that prohibits the misuse and enforces against it.
xAI's practical response is the tell. Rather than litigate and keep operating, the company says it has already implemented technical measures restricting image editing of real people in revealing clothing, and is prepared to geoblock the feature for Minnesota. Ellison defended the law on the record. Worth noting for anyone handicapping the outcome: Minnesota's earlier deepfake law survived a 2025 court challenge, while California's election deepfake law was blocked on First Amendment grounds. This is genuinely unsettled.
Why operator liability matters for your business
Two concrete exposures, and neither requires you to run a model.
First, you may be the operator. If your app wraps an image API — AI headshots, product photo cleanup, a customer-facing "generate a mockup" button — a law aimed at "owners and operators of AI platforms" plausibly describes you, not just OpenAI. Strict liability with no safe harbor means your acceptable-use policy and your moderation filter don't get you out of it. That's the same structural problem as Article 50's labeling duties and New York's synthetic performer disclosure: the obligation lands on whoever ships the feature.
Second, your vendor's geoblock is your outage. When a frontier lab decides one state isn't worth the risk, the feature you built a workflow around stops working for those users — quietly, on the vendor's timeline. If you can't answer "which states are my users in?" from your own data, you can't scope that blast radius.
So: capture user jurisdiction at signup, put every AI-generated feature behind a region-aware flag you control, and read your vendor's terms for who indemnifies whom and what geographic availability they actually promise. Usually: nobody, and none.
Key takeaways
- xAI sued Minnesota's AG in federal court over HF 1606, days before it takes effect
- The law assigns liability to the maker of the AI tool, not the user — reportedly $500K per violation
- xAI's complaint argues there is no safe harbor for good-faith enforcement, and the definitions are overbroad
- xAI plans to geoblock rather than absorb the risk — meaning AI features can vanish per-state without warning
- Operator move: capture user jurisdiction, region-flag every AI feature, and check your vendor's indemnity terms
We ship AI features behind flags you control, not switches your vendor owns. Region-aware gating, jurisdiction captured in your own data, and a fallback path when a provider pulls a capability. See how we build it or have us review your AI feature exposure.
Sources: AP via ClickOnDetroit, CBS Minnesota.
- #ai-regulation
- #compliance
- #vendor-risk
- #image-generation
- #liability
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Pacing the Frontier letter: model supply is a policy dial
Over 1,200 employees at OpenAI, Anthropic, Google and Meta asked Washington for tools to pace frontier AI. What the Pacing the Frontier letter means for your stack.
Read itMicrosoft hits 30M Copilot seats: measure outcome per seat
Microsoft 365 Copilot crossed 30 million paid seats and Azure passed $100B a year. The number your business should track instead of the seat count.
Read it