The Moving Property Problem in Fourth Amendment Law

Introduction

Imagine you are carrying a bag that the police want to search. The Fourth Amendment rules for searching your bag depend on where it is. If the bag is inside your home, the government needs a warrant to enter the home and search it.1 1.See Silverman v. United States, 365 U.S. 505, 512 (1961) (holding that physical entry requires a warrant). The Supreme Court first expressly so held in Agnello v. United States, 269 U.S. 20, 31–33 (1925), although the point had “always been assumed.” Id. at 32.Show More If the bag is in your car, however, probable cause is enough, and no warrant is needed.2 2.See California v. Acevedo, 500 U.S. 565, 579–80 (1991) (holding that a search of property placed in a car requires probable cause but not a warrant).Show More If the police arrest you while you’re carrying the bag, they can search the bag without any cause.3 3.See United States v. Robinson, 414 U.S. 218, 236 (1973) (allowing the search of property on a person based on lawful arrest alone without requiring additional cause).Show More If the bag is more than a few feet from you at the time of your arrest, however, the government needs a warrant again.4 4.See Chimel v. California, 395 U.S. 752, 763 (1969) (holding that a search incident to arrest only extends to the area of immediate control around the person arrested).Show More As these examples suggest, Fourth Amendment protection is fundamentally place-based. The government’s search power depends on where items to be searched are located.

The place-based nature of Fourth Amendment rules raises a question: If property is moved to a new place, does moving the property change its constitutional protection? In other words, are search and seizure protections fixed using an item’s prior location, or do those protections vary when the item is brought somewhere new? This question comes up often in Fourth Amendment cases. Consider a few examples drawn from recent decisions:

An officer orders a passenger out of a car during a traffic stop. The passenger exits, taking her purse with her. Searching a purse outside a car requires a warrant, but searching a purse inside a car does not. Is a warrant needed to search the purse after the passenger has removed it from the car?5 5.See State v. Lang, 942 N.W.2d 388, 400 (Neb. 2020), discussed in Section I.B.Show More

The federal government has broad power to search at the border. Border agents seize a suspect’s computer at the border, but they lack the expertise to search it. Agents bring the computer to a forensics expert, located hundreds of miles from the border, who searches it at his office. Does the forensic expert’s search count as a border search?6 6.See United States v. Cotterman, 709 F.3d 952, 961–62 (9th Cir. 2013) (en banc), discussed in Section I.D.Show More

Officers want to arrest a suspect at his home, but they lack the warrant needed to enter the home to arrest him inside. From their position outside, officers point their guns at the suspect inside and order him to leave his house. He complies with the order, and officers arrest him outside. Was a warrant needed?7 7.See United States v. Maez, 872 F.2d 1444, 1450–51 (10th Cir. 1989), discussed in Section I.C.Show More

Police arrest a man wearing a fanny pack. For their own safety, officers remove the fanny pack and place it twenty feet away. The Fourth Amendment permits a warrantless search of property on the person incident to his arrest, but it does not allow a search of property more than a few feet away. Can the police still search the fanny pack without a warrant?8 8.See, e.g., Jean v. State, 369 So. 3d 1235, 1237–38 (Fla. Dist. Ct. App. 2023). This scenario is discussed in Section I.B.Show More

Investigators have a warrant to search a house, but they lack the cause needed to detain and interrogate a particular suspect who lives there. They know, however, that Fourth Amendment law allows the government to detain anyone present when a warrant is executed. Hoping to interrogate the suspect, investigators contact the suspect and pretend that his house has been robbed and that he should come home to assess the damage. When the man arrives, officers detain and interrogate him. Was this lawful?9 9.See United States v. Ramirez, 976 F.3d 946, 949–50 (9th Cir. 2020), discussed in Section I.C.Show More

The driver of a car consents to its search. An officer orders everyone out of the car, and a passenger takes her purse with her. The officer orders the passenger to put her purse back in the car so it can be searched. Case law allows the government to search anything in the car with the driver’s consent but requires a warrant to search a purse outside the car. Can officers search the purse?10 10.See State v. Boyd, 64 P.3d 419, 427 (Kan. 2003), discussed in Section I.C.Show More

In each of these cases, something or someone was moved from one place governed by one rule to a new place governed by a different rule. Sometimes the government moved the relevant thing or person. Sometimes a private party did. And sometimes the government caused the private party to move it. Each case raises the same question: Does moving the item to a new place change its constitutional protection?

I call this the moving property problem.11 11.By the phrase “moving property,” I mean anything that can be moved and that can later be searched, whether or not it counts as property in a technical legal sense. In most cases, the moving property will be containers such as bags, purses, briefcases, and fanny packs. In some cases, the item moved is a person, who is moved away from their containers or who is moved to a different location and then searched. I consider all of these examples of the moving property problem.The label “moving property problem” might call to mind the automobile exception to the warrant requirement, under which searching a car does not require a warrant in part because cars are readily movable. See, e.g., California v. Carney, 471 U.S. 386, 390–91 (1985). My concern in this Article is not with whether property should receive different protection because it can move, however, but whether protections should change when items are moved from a place governed by one rule to a place governed by a different rule. Some moving property cases involve the automobile exception, as property is readily placed into or taken out of cars. But the moving property problem is about the clash of rules between two places—akin to a conflict of law problem—not the rules of any one place.Show More Despite how often it surfaces, neither courts nor scholars have recognized it.12 12.My research has uncovered no prior articles on the moving property problem. The most relevant scholarship appears to be several articles on one specific application—whether and when officers can make warrantless doorway arrests by moving arrestees out of the home. There is a narrow literature on that question. See, e.g., Jack E. Call, The Constitutionality of Warrantless Doorway Arrests, 19 Miss. Coll. L. Rev. 333, 334–36 (1999) (discussing the cases); Steven B. Dow, “Step Outside, Please”: Warrantless Doorway Arrests and the Problem of Constructive Entry, 45 New Eng. L. Rev. 7, 18–23 (2010) (same). See generally 3 Wayne R. LaFave, Search and Seizure § 6.1(e) (6th ed. 2020) (“Location of the arrestee: ‘at,’ ‘on’ and past the threshold.”). For a discussion of the relevant cases, see infra Section I.C.Show More The moving property problem is particularly rich because the ex ante incentives are obvious. Government agents want to expand their search power, just as targets of searches want that authority narrowed.13 13.The two sides are not equal in the likelihood that they intend to use the Fourth Amendment’s rules to their advantage. The police are trained in the rules, and the cases show them intentionally seeking to manipulate the rules in their favor. In contrast, few individuals will have the knowledge and foresight to know and use the rules.Show More If Fourth Amendment case law allows it, the police will move property or suspects to a place where officers have greater power to search—and then search under the relaxed rules of the new place. On the flip side, private parties who know the law may want to move their property to a place where their privacy rights are greatest—impeding investigations, if they can, by triggering the more restrictive rules of the new location. Ex post litigation incentives are clear, too. Each side has reason to argue that the other’s moving of property works in reverse. When a suspect happens to move his property to a place where rights are weaker, the government will argue that rules of the new location apply. And defendants will make the mirror-image argument when police move property to a place where rights are stronger.14 14.See infra Part I.Show More

This Article offers a comprehensive study of the moving property problem in Fourth Amendment law. It has two goals, one descriptive and one normative. The descriptive goal is to show that a large set of cases, not previously linked, all raise this common dynamic. Cataloging the many moving property cases reveals a taxonomy with variations on a theme.15 15.See infra Part I.Show More It also shows that Supreme Court decisions rarely answer how to resolve moving property questions. In the absence of high court guidance, lower courts have struggled for answers. They have treated each case in isolation, and they have often disagreed on the correct approach. The lower court disagreement results from a failure to see and appreciate the moving property problem.

The second goal of this Article is to offer a normative framework for solving the moving property problem. It has two steps. The first step is to recognize why Fourth Amendment rules are spatially based in the first place. The Fourth Amendment’s text, history, and case law seek to protect particular spaces in particular ways.16 16.See infra Section II.A.Show More The rules recognize how different interests compete differently in different areas. This understanding prompts an initial answer to moving property problems. To decide whether movement changes the level of protection, courts should answer whether the movement aligns with the justifications for the Fourth Amendment’s location-based rules. Courts must look doctrine-by-doctrine, focusing on the reasons for the space-based rules in play and the role of movement in supporting or defeating those reasons.17 17.See infra Section II.B.Show More

The second step is realizing that some moving property cases raise two questions instead of one. When the government causes movement, either directly or by creating pressures on private parties to act, a second question must also be considered: Was the government-induced movement itself illegal, apart from the subsequent search? Government agents can be endlessly creative in devising new ways to get property to places where government search powers are greatest.18 18.Cf. Johnson v. United States, 333 U.S. 10, 14 (1948) (Jackson, J.) (noting that the Fourth Amendment generally requires that “those inferences be drawn by a neutral and detached magistrate instead of being judged by the officer engaged in the often competitive enterprise of ferreting out crime”).Show More In many of these cases, the legal limits in moving property cases should come not from the legal rule for searching at the old or new place but from recognizing the illegality of steps taken to trigger the movement itself.19 19.See infra Section II.E.Show More

The Article proceeds in two parts. Part I offers a taxonomy of existing cases. It lays out the four basic kinds of moving property cases, explaining the scenarios and surveying how courts have so far resolved them. Part II proposes answers, developing a framework for solving the moving property problem and providing rules that courts can adopt to address them.

  1.  See Silverman v. United States, 365 U.S. 505, 512 (1961) (holding that physical entry requires a warrant). The Supreme Court first expressly so held in Agnello v. United States, 269 U.S. 20, 31–33 (1925), although the point had “always been assumed.” Id. at 32. ↑
  2.  See California v. Acevedo, 500 U.S. 565, 579–80 (1991) (holding that a search of property placed in a car requires probable cause but not a warrant). ↑
  3.  See United States v. Robinson, 414 U.S. 218, 236 (1973) (allowing the search of property on a person based on lawful arrest alone without requiring additional cause). ↑
  4.  See Chimel v. California, 395 U.S. 752, 763 (1969) (holding that a search incident to arrest only extends to the area of immediate control around the person arrested). ↑
  5.  See State v. Lang, 942 N.W.2d 388, 400 (Neb. 2020), discussed in Section I.B. ↑
  6.  See United States v. Cotterman, 709 F.3d 952, 961–62 (9th Cir. 2013) (en banc), discussed in Section I.D. ↑
  7.  See United States v. Maez, 872 F.2d 1444, 1450–51 (10th Cir. 1989), discussed in Section I.C. ↑
  8.  See, e.g., Jean v. State, 369 So. 3d 1235, 1237–38 (Fla. Dist. Ct. App. 2023). This scenario is discussed in Section I.B. ↑
  9.  See United States v. Ramirez, 976 F.3d 946, 949–50 (9th Cir. 2020), discussed in Section I.C. ↑
  10.  See State v. Boyd, 64 P.3d 419, 427 (Kan. 2003), discussed in Section I.C. ↑
  11.  By the phrase “moving property,” I mean anything that can be moved and that can later be searched, whether or not it counts as property in a technical legal sense. In most cases, the moving property will be containers such as bags, purses, briefcases, and fanny packs. In some cases, the item moved is a person, who is moved away from their containers or who is moved to a different location and then searched. I consider all of these examples of the moving property problem.

    The label “moving property problem” might call to mind the automobile exception to the warrant requirement, under which searching a car does not require a warrant in part because cars are readily movable. See, e.g., California v. Carney, 471 U.S. 386, 390–91 (1985). My concern in this Article is not with whether property should receive different protection because it can move, however, but whether protections should change when items are moved from a place governed by one rule to a place governed by a different rule. Some moving property cases involve the automobile exception, as property is readily placed into or taken out of cars. But the moving property problem is about the clash of rules between two places—akin to a conflict of law problem—not the rules of any one place. ↑

  12.  My research has uncovered no prior articles on the moving property problem. The most relevant scholarship appears to be several articles on one specific application—whether and when officers can make warrantless doorway arrests by moving arrestees out of the home. There is a narrow literature on that question. See, e.g., Jack E. Call, The Constitutionality of Warrantless Doorway Arrests, 19 Miss. Coll. L. Rev. 333, 334–36 (1999) (discussing the cases); Steven B. Dow, “Step Outside, Please”: Warrantless Doorway Arrests and the Problem of Constructive Entry, 45 New Eng. L. Rev. 7, 18–23 (2010) (same). See generally 3 Wayne R. LaFave, Search and Seizure § 6.1(e) (6th ed. 2020) (“Location of the arrestee: ‘at,’ ‘on’ and past the threshold.”). For a discussion of the relevant cases, see infra Section I.C. ↑
  13.  The two sides are not equal in the likelihood that they intend to use the Fourth Amendment’s rules to their advantage. The police are trained in the rules, and the cases show them intentionally seeking to manipulate the rules in their favor. In contrast, few individuals will have the knowledge and foresight to know and use the rules. ↑
  14.  See infra Part I. ↑
  15.  See infra Part I. ↑
  16.  See infra Section II.A. ↑
  17.  See infra Section II.B. ↑
  18.  Cf. Johnson v. United States, 333 U.S. 10, 14 (1948) (Jackson, J.) (noting that the Fourth Amendment generally requires that “those inferences be drawn by a neutral and detached magistrate instead of being judged by the officer engaged in the often competitive enterprise of ferreting out crime”). ↑
  19.  See infra Section II.E. ↑

Confessions Without Consequence: The Case for Attorney General Deference

­­­The Supreme Court’s recent decisions in Glossip v. Oklahoma and Escobar v. Texas have surfaced an understudied and increasingly consequential phenomenon in American criminal law: the prosecutorial confession of error. Anglo-American courts have recognized such confessions for centuries, and Young v. United States commands that federal courts afford them “great weight.” Yet judicial practice has grown increasingly inconsistent—most acutely at the state level, where courts routinely treat confessions as ordinary litigation positions rather than as the considered judgment of the sovereign’s chief law officers. This dysfunction reaches its apex when the confessor is a state attorney general, whose constitutional authority, democratic legitimacy, and investigative capacity distinguish them from every other prosecutorial actor. Glossip illustrates the problem starkly: the Oklahoma Attorney General confessed error in a capital case after a comprehensive independent investigation, only to have the Oklahoma Court of Criminal Appeals dismiss the confession as “not based in law or fact.”

Pulling from state case law that the literature has largely ignored, this Note argues that the current approach cannot be defended. It proposes a structured four-factor framework—merits, motives, institutional credibility, and equities—designed to restore coherence to confession-of-error doctrine, to vindicate the unique institutional role of state attorneys general, and to ensure that when the State concedes its case cannot stand, the judiciary listens.

Introduction

When Oklahoma Attorney General Gentner Drummond reviewed Richard Glossip’s capital murder case, he formally confessed error.1 1.Glossip v. Oklahoma, 145 S. Ct. 612, 623–27 (2025) (describing the Attorney General’s confession of error, including acknowledgment of prosecutorial misconduct and failure to correct false testimony under Napue v. Illinois, 360 U.S. 264 (1959)).Show More Following an independent investigation commissioned by the state legislature,2 2.See id. at 621 (describing an independent investigation conducted by law firm Reed Smith).Show More Drummond concluded that prosecutorial misconduct had fatally compromised Glossip’s conviction. The Oklahoma Court of Criminal Appeals (“OCCA”) responded with dismissiveness, stating that “[t]he State’s concession is not based in law or fact.”3 3.Glossip v. State, 2023 OK CR 5, ¶ 25, 529 P.3d 218, 226.Show More The OCCA offered little explanation for this rejection and ultimately declined to vacate Glossip’s death sentence.4 4.See id. ¶ 12.Show More This extraordinary rejection of a confession of error reflects a doctrine overlooked, where state court approaches to prosecutorial confessions remain inconsistent and underdeveloped as lives hang in the balance.5 5.Ironically, Oklahoma had adopted a highly deferential regime, granting relief in all 298 cases involving confessions of error between 1908 and 2022, before departing from that century-long practice in this very case, underscoring the doctrine’s current instability. See, e.g., Brief of the National Ass’n of Criminal Defense Lawyers as Amicus Curiae in Support of Petitioner at 2, Glossip v. Oklahoma, 145 S. Ct. 612 (2025) (No. 22-7466) [hereinafter NACDL Brief] (“Indeed, in all 298 cases involving confessions of error between 1908 and 2022, the OCCA ultimately granted relief to the defendant.”).Show More Weeks later, the Texas Court of Criminal Appeals (“TCCA”) followed suit,6 6.Ex parte Escobar, 676 S.W.3d 664, 672–75 (Tex. Crim. App. 2023).Show More rejecting the Travis County District Attorney’s confession in Areli Escobar’s capital case even though the Supreme Court had previously remanded the case “in light of the confession of error.”7 7.Escobar v. Texas, 143 S. Ct. 557 (2023) (mem.).Show More Escobar then returned to the Supreme Court, with one question presented squarely addressing the confession-of-error component—namely, whether the Fourteenth Amendment’s Due Process Clause requires reversal when “a capital conviction is so infected with errors that the State no longer seeks to defend it.”8 8.Petition for a Writ of Certiorari at i, Escobar v. Texas, 145 S. Ct. 1423 (2025) (mem.) (No. 23-934).Show More The Supreme Court denied certiorari, leaving the doctrinal issue alive and unwell.9 9.Escobar, 145 S. Ct. at 1423 (denying certiorari).Show More

Glossip and Escobar reveal a deference doctrine unadopted in state courts. At the federal level, Young v. United States asks that courts give “great weight” to confessions of error by federal prosecutors.10 10.Young v. United States, 315 U.S. 257, 258–59 (1942) (“The considered judgment of the law enforcement officers that reversible error has been committed is entitled to great weight, but our judicial obligations compel us to examine independently the errors confessed.”).Show More But the established analogs in state courts oftentimes prove toothless.11 11.The TCCA exemplifies this judicial resistance. While dutifully reciting that confessions are entitled to “great weight”—if acknowledged at all—the TCCA proceeds to reject them outright, typifying the broader failure to honor deference principles in criminal post-conviction litigation. See, e.g., Ex parte Escobar, 676 S.W.3d at 672, 674–75 (acknowledging that “the State’s confession of error in a criminal case is important and carries great weight” but that “we are not bound by it” and rejecting the Travis County District Attorney’s confession despite the prosecution’s reexamination finding due process violations based on false DNA evidence (quoting Estrada v. State, 313 S.W.3d 274, 286 (Tex. Crim. App. 2010))); Rogers v. State, 594 S.W.3d 432, 434–35 (Tex. App. 2019) (conducting independent review before rejecting the State’s confession); infra Part II (examining state court treatments of confessions of error across a variety of states).Show More When state courts continue to imprison defendants despite credible confessions of error by state prosecutors, they undermine notions of fundamental fairness, separation of powers principles, and predictability in the law.12 12.Federal courts apply the doctrine with similar inconsistency, with most circuits showing little deference. See, e.g., United States v. Ramirez, 606 F.3d 396, 398 (7th Cir. 2010) (indicating that the correct standard given the facts and circumstances in the case was plain error); United States v. Cheek, 94 F.3d 136, 140 (4th Cir. 1996) (stating that the government’s opinion concerning a defendant’s right to a new trial did not bind the court); United States v. Vasquez, 85 F.3d 59, 60 (2d Cir. 1996) (acknowledging that the government’s concession of error and desire to vacate a sentence do not automatically govern an appellate court’s ruling).Show More

State courts compound this dysfunction by overlooking institutional distinctions within the prosecutorial hierarchy. Although prosecutors generally warrant some degree of deference when confessing error, confessions by attorneys general—who are elected officials with statewide constitutional authority to represent the sovereign—should receive heightened deference. This Note argues for such meaningful deference to attorney general confessions, but the Court’s decision in Glossip reflects a more fundamental concern: state courts’ refusal to honor any prosecutorial confession, even when both parties agree that a conviction cannot stand.13 13.Advisory Opinions: A Dispatch Podcast, Blockbuster Cases, The Dispatch, at 45:15 (July 10, 2025), https://thedispatch.com/podcast/advisoryopinions/blockbuster-cases/ [https:/‌/perma.cc/SX7G-GVK3] (featuring Professor Daniel Epps arguing that the case was a “cause célèbre” and that the Court recognized the injustice of the Glossip case and tried to find an equitable outcome).Show More While some state courts do formally acknowledge the attorney general’s position, they do not discuss the attorney general’s uniquely situated legal role and do not provide the meaningful deference this Note argues for.14 14.See, e.g., Marks v. State, 496 P.2d 66, 67–68 (Alaska 1972); People v. Hayes, 699 P.2d 1259, 1263 (Cal. 1985) (acknowledging the Attorney General’s confession of error and, after independent review, concluding that the record “fully supports” the confession, without explaining why the Attorney General’s institutional role warranted consideration); State v. Maes, 665 P.2d 1169, 1171–72 (N.M. Ct. App. 1983) (quoting Marks for the proposition that courts must undertake independent review despite a confession—illustrating cross-jurisdictional adoption of the independent-review standard without engagement with the confessor’s institutional role).Show More This institutional blindness reduces all prosecutorial confessions to mere litigation positions, ignoring the unique democratic, constitutional, and functional virtues that distinguish state attorneys general from sovereign litigators at every other level—local, state, and federal.15 15.See infra Section III.B for a discussion of these virtues.Show More

This Note addresses a critical gap in both scholarship and case law. While existing literature examines the Solicitor General’s confessions before the Supreme Court, practically no scholarship examines the confessions of state attorneys general in state court or state prosecutorial confessions writ large16 16.See Neal Kumar Katyal, The Solicitor General and Confession of Error, 81 Fordham L. Rev. 3027, 3029–30 (2013) (examining the Solicitor General’s practice before the Supreme Court); see also Charles L. Maak, Note, The Confession of Error, 1968 Utah L. Rev. 286, 287 (surveying state and federal confession-of-error practices); Alexander L. Merritt, Note, Confession of Error by Administrative Agencies, 67 Wash. & Lee L. Rev. 1197, 1198–99 (2010) (analyzing confession of error in the administrative law context).Show More—despite their increasing relevance across criminal contexts.17 17.See infra Part III (discussing Glossip and Escobaras two major recent cases).Show More The Note undertakes an extensive review of state case law and federal appellate decisions originating in state court. It reveals that state courts consistently deny what this Note terms “meaningful deference” to executive admissions, particularly those from state attorneys general despite their distinctive institutional position.

The Note proposes a structured framework to replace the ad hoc approach currently governing confession doctrine. The absence of principled evaluative standards produces unpredictability and inequality when courts review prosecutorial confessions. A uniform analytical framework—built on four weighted factors—provides a blueprint without dictating outcomes or stripping state courts of institutional autonomy. By offering courts a common set of considerations adaptable to varied state procedures, this framework ensures that deference has substantive meaning across jurisdictions while highlighting why state attorneys general merit unique treatment.

The Note proceeds in four parts. Part I defines confession-of-error doctrine and examines its development. Part II surveys the modern landscape. Part III emphasizes the indeterminate nature of modern judicial approaches. Part IV proposes a manageable framework and applies it to high-profile cases while anticipating objections.

  1.  Glossip v. Oklahoma, 145 S. Ct. 612, 623–27 (2025) (describing the Attorney General’s confession of error, including acknowledgment of prosecutorial misconduct and failure to correct false testimony under Napue v. Illinois, 360 U.S. 264 (1959)). ↑
  2.  See id. at 621 (describing an independent investigation conducted by law firm Reed Smith). ↑
  3.  Glossip v. State, 2023 OK CR 5, ¶ 25, 529 P.3d 218, 226. ↑
  4.  See id. ¶ 12. ↑
  5.  Ironically, Oklahoma had adopted a highly deferential regime, granting relief in all 298 cases involving confessions of error between 1908 and 2022, before departing from that century-long practice in this very case, underscoring the doctrine’s current instability. See, e.g., Brief of the National Ass’n of Criminal Defense Lawyers as Amicus Curiae in Support of Petitioner at 2, Glossip v. Oklahoma, 145 S. Ct. 612 (2025) (No. 22-7466) [hereinafter NACDL Brief] (“Indeed, in all 298 cases involving confessions of error between 1908 and 2022, the OCCA ultimately granted relief to the defendant.”). ↑
  6.  Ex parte Escobar, 676 S.W.3d 664, 672–75 (Tex. Crim. App. 2023). ↑
  7.  Escobar v. Texas, 143 S. Ct. 557 (2023) (mem.). ↑
  8.  Petition for a Writ of Certiorari at i, Escobar v. Texas, 145 S. Ct. 1423 (2025) (mem.) (No. 23-934). ↑
  9.  Escobar, 145 S. Ct. at 1423 (denying certiorari). ↑
  10.  Young v. United States, 315 U.S. 257, 258–59 (1942) (“The considered judgment of the law enforcement officers that reversible error has been committed is entitled to great weight, but our judicial obligations compel us to examine independently the errors confessed.”). ↑
  11.  The TCCA exemplifies this judicial resistance. While dutifully reciting that confessions are entitled to “great weight”—if acknowledged at all—the TCCA proceeds to reject them outright, typifying the broader failure to honor deference principles in criminal post-conviction litigation. See, e.g., Ex parte Escobar, 676 S.W.3d at 672, 674–75 (acknowledging that “the State’s confession of error in a criminal case is important and carries great weight” but that “we are not bound by it” and rejecting the Travis County District Attorney’s confession despite the prosecution’s reexamination finding due process violations based on false DNA evidence (quoting Estrada v. State, 313 S.W.3d 274, 286 (Tex. Crim. App. 2010))); Rogers v. State, 594 S.W.3d 432, 434–35 (Tex. App. 2019) (conducting independent review before rejecting the State’s confession); infra Part II (examining state court treatments of confessions of error across a variety of states). ↑
  12.  Federal courts apply the doctrine with similar inconsistency, with most circuits showing little deference. See, e.g., United States v. Ramirez, 606 F.3d 396, 398 (7th Cir. 2010) (indicating that the correct standard given the facts and circumstances in the case was plain error); United States v. Cheek, 94 F.3d 136, 140 (4th Cir. 1996) (stating that the government’s opinion concerning a defendant’s right to a new trial did not bind the court); United States v. Vasquez, 85 F.3d 59, 60 (2d Cir. 1996) (acknowledging that the government’s concession of error and desire to vacate a sentence do not automatically govern an appellate court’s ruling). ↑
  13.  Advisory Opinions: A Dispatch Podcast, Blockbuster Cases, The Dispatch, at 45:15 (July 10, 2025), https://thedispatch.com/podcast/advisoryopinions/blockbuster-cases/ [https:/‌/perma.cc/SX7G-GVK3] (featuring Professor Daniel Epps arguing that the case was a “cause célèbre” and that the Court recognized the injustice of the Glossip case and tried to find an equitable outcome). ↑
  14.  See, e.g., Marks v. State, 496 P.2d 66, 67–68 (Alaska 1972); People v. Hayes, 699 P.2d 1259, 1263 (Cal. 1985) (acknowledging the Attorney General’s confession of error and, after independent review, concluding that the record “fully supports” the confession, without explaining why the Attorney General’s institutional role warranted consideration); State v. Maes, 665 P.2d 1169, 1171–72 (N.M. Ct. App. 1983) (quoting Marks for the proposition that courts must undertake independent review despite a confession—illustrating cross-jurisdictional adoption of the independent-review standard without engagement with the confessor’s institutional role). ↑
  15.  See infra Section III.B for a discussion of these virtues. ↑
  16.  See Neal Kumar Katyal, The Solicitor General and Confession of Error, 81 Fordham L. Rev. 3027, 3029–30 (2013) (examining the Solicitor General’s practice before the Supreme Court); see also Charles L. Maak, Note, The Confession of Error, 1968 Utah L. Rev. 286, 287 (surveying state and federal confession-of-error practices); Alexander L. Merritt, Note, Confession of Error by Administrative Agencies, 67 Wash. & Lee L. Rev. 1197, 1198–99 (2010) (analyzing confession of error in the administrative law context). ↑
  17.  See infra Part III (discussing Glossip and Escobar as two major recent cases). ↑

AI Rights for Human Safety

Artificial Intelligence (“AI”) companies are racing to create Artificial General Intelligence, or “AGI.” If they succeed, the result will be human-level AI systems that can independently pursue high-level goals by formulating and executing long-term plans in the real world. By default, such systems will be “misaligned”—pursuing goals that humans do not desire. This mismatch of goals will put humans and AGIs into strategic competition with one another. Thus, leading AI researchers agree that, as with competition between humans with conflicting goals, human-AI strategic conflict could lead to catastrophic violence.

Existing law is not merely unequipped to mitigate this risk; it will actively make things worse. This Article is the first to systematically investigate how law affects the risk of catastrophic human-AI conflict. It begins by arguing, using formal game-theoretic models, that under today’s legal regime, humans and AIs will likely be trapped in a prisoner’s dilemma. Both parties’ dominant strategy will be to permanently disempower or destroy the other, even though the costs of such conflict would be high.

The Article contends that one surprising legal change could help to reduce catastrophic risk: AI rights. Not just any rights will do. To promote human safety, AIs should be given the basic private law rights already enjoyed by other non-human agents, like corporations. AIs should be empowered to make contracts, hold property, and bring tort claims. Granting these rights would enable humans and AIs to engage in iterated, small-scale, mutually beneficial transactions. This, we show, changes humans’ and AIs’ optimal game-theoretic strategies, encouraging a peaceful strategic equilibrium. The reasons are familiar from human affairs. In the long run, cooperative trade generates immense value, while violence destroys it.

Basic private law rights are not a panacea. The Article identifies many ways in which catastrophic human-AI conflict may still arise. It thus explores whether law could further reduce risk by imposing a range of duties directly on AGIs. But basic private law rights are a necessary prerequisite for all such further regulations. In this sense, the AI rights investigated here form the foundation for a Law of AGI, broadly construed.

Introduction

Sam Altman, the CEO of OpenAI, believes that humanity will create Artificial General Intelligence (“AGI”) before 2029.1 1.Tharin Pillay, How OpenAI’s Sam Altman Is Thinking About AGI and Superintelligence in 2025, TIME (Jan. 8, 2025, at 16:25 ET), https://time.com/7205596/sam-altman-superintell‌igence-agi/ [https://perma.cc/B8HB-M9KY] (predicting AGI “during [Trump’s] term” (alteration in original)).Show More Demis Hasabis, who leads Google DeepMind, is more pessimistic. He thinks there is only a fifty-percent chance that AGI arrives by 2030.2 2.World Economic Forum, The Day After AGI | World Economic Forum Annual Meeting 2026, at 03:00 (YouTube, Jan. 20, 2026), https://youtube.com/watch?v=NnVW9epLlTM [ht‌tps://perma.cc/L6CS-7DGT].Show More AGI skeptics, like Meta’s Chief AI Scientist, Yann LeCun, think it could take “years” or even “decades.”3 3.Lakshmi Varanasi, Here’s How Far We Are from AGI, According to the People Developing It, Bus. Insider, https://www.businessinsider.com/agi-predictions-sam-altman-dario-amodei-geoffrey-hinton-demis-hassabis-2024-11 (last updated Apr. 20, 2025, at 21:11 ET).Show More In a survey of thousands of Artificial Intelligence (“AI”) scientists who are published in their field’s top journals, the aggregate estimate was a fifty-percent chance of AGI by 2047, and a ten-percent chance of it arriving by 2027.4 4.Katja Grace et al., Thousands of AI Authors on the Future of AI, 84 J. A.I. Rsch., Oct. 2025, at 3–5.Show More None of these are long timelines. And the recent debut of reasoning models like Anthropic’s Claude Opus 4.6 and OpenAI’s GPT-5.2 suggests that progress is, if anything, accelerating.5 5.Kevin Frazier, Alan Z. Rozenshtein & Peter N. Salib, OpenAI’s Latest Model Shows AGI Is Inevitable. Now What?, Lawfare (Dec. 23, 2024, at 16:00 ET), https://www.lawfare‌media.org/article/openai’s-latest-model-shows-agi-is-inevitable.-now-what [https://perma.cc/‌PU3J-45P5]; Introducing Claude Opus 4.6, Anthropic (Feb. 5, 2026), https://www.anthropic.‌com/news/claude-opus-4-6 [https://perma.cc/39U2-7EGR]; Introducing GPT-5.2, OpenAI (Dec. 11, 2025), https://openai.com/index/introducing-gpt-5-2/ [https://perma.cc/SSC9-7‌RA4].Show More

“AGI,” as it is used here, does not mean machines that are conscious, sentient, or metaphysical persons. AGI is instead about what the system can do. As OpenAI’s company charter puts it, “AGI . . . mean[s] highly autonomous systems that outperform humans at most economically valuable” tasks.6 6.OpenAI Charter, OpenAI, https://openai.com/charter/ [https://perma.cc/SXX4-VDM5] (last visited Apr. 2, 2026).Show More AGIs are thus, by definition, systems at least as smart as humans. Moreover, they are systems at least as agentic as humans—able to pursue high-level goals by executing complex plans over long time horizons.7 7.See Task-Completion Time Horizons of Frontier AI Models, METR, https://metr.org/tim‌e-horizons/ [https://perma.cc/A6TA-GA5J] (last updated Mar. 3, 2026).Show More Today, no one knows how to reliably ensure that AI systems seek the goals that humans desire.8 8.See infra Subsection I.A.1.Show More But if AGIs end up with goals that can be served by harming humans, they may well have a deadly toolkit available: cyberattacks, bioterrorism, lethal drones, and more.9 9.See Peter N. Salib, AI Outputs Are Not Protected Speech, 102 Wash. U. L. Rev. 83, 95–102 (2024).Show More

AI experts thus largely agree about something else, too: advanced AI systems present “societal-scale risks” on par with “pandemics and nuclear war.”10 10.Statement on AI Risk, Ctr. for AI Safety, https://www.safe.ai/work/statement-on-ai-risk [https://perma.cc/D88X-MSQ5] (last visited Mar. 10, 2026) (statement by dozens of AI experts warning of large-scale risks of AI).Show More Two of the greatest living AI scientists, Geoffrey Hinton and Yoshua Bengio, think so.11 11.Id.Show More So do the CEOs of the very companies leading the race to AGI—OpenAI, Anthropic, and Google DeepMind.12 12.Id. Yann LeCun is the lone, but notable, dissenter among the leaders of frontier AI labs. See Steven Levy, How Not to Be Stupid About AI, With Yann LeCun, Wired (Dec. 22, 2023, at 06:00 ET), https://www.wired.com/story/artificial-intelligence-meta-yann-lecun-int‌erview/.Show More And when surveyed in 2023, thousands of top AI researchers estimated the odds that humans lose control of “future advanced AI systems[,] causing human extinction or similarly” negative outcomes at about nineteen percent.13 13.See Grace et al., supra note 4, at 10.Show More

Law and legal institutions have not even begun to prepare for the arrival of AGI. Largely, scholars have begun to advocate new laws to hold human actors accountable for misusing AI.14 14.See, e.g., S. 1047, 2023–2024 Leg., Reg. Sess. (Cal. 2024) (vetoed on Sep. 29, 2024) (bill introduced in California state legislature calling for new regulations to govern AI); Jonas Schuett, Markus Anderljung, Alexis Carlier, Leonie Koessler & Ben Garfinkel, From Principles to Rules: A Regulatory Approach for Frontier AI, in The Oxford Handbook of the Foundations and Regulation of Generative AI (Philipp Hacker, Andreas Engel, Sarah Hammer & Brent Mittelstadt eds., online ed. 2025), https://academic.oup.com/edited-volume‌/59908/chapter/529743493; Chinmayi Sharma, AI’s Hippocratic Oath, 102 Wash. U. L. Rev. 1101, 1105 (2025) (proposing a model for “professionalizing AI engineers” by adopting licensing, training, and malpractice standards similar to those used in other professional fields); Gabriel Weil, Closing the AI Accountability Gap: Strict Liability and Punitive Damages for Advanced Artificial Intelligence, Or. L. Rev. (forthcoming 2027) (manuscript at 45–69), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4694006 [https://perma.cc/L‌36H-7T5A] (proposing two ways for “bringing tort doctrine in line with” harms caused by misuse of AI); see also Sidley Austin LLP, U.S. Department of Justice Signals Tougher Enforcement Against Artificial Intelligence Crimes (Feb. 23, 2024), https://www.sidley.com‌/en/insights/newsupdates/2024/02/us-department-of-justice-signals-tougher-enforcement-aga‌inst-artificial-intelligence-crimes [https://perma.cc/7CJY-DQ3P].Show More Those changes would be welcome. But governance frameworks fundamentally designed to hold humans accountable will fail once AIs can operate without human oversight—that is, once AGI arrives.15 15.See Noam Kolt, Governing AI Agents, 101 Notre Dame L. Rev. (forthcoming 2026) (manuscript at 30–36), https://ssrn.com/abstract=4772956 [https://perma.cc/S3XB-WJ7Q] (cataloging existing law’s many shortcomings).Show More New legal foundations are therefore needed to govern AGI directly, rather than indirectly via human intermediaries. The time to begin laying those foundations is now, before the critical moment arrives.

This Article begins the project of reimagining law for the AGI world. We focus on the problem of catastrophic risk because it is among the most pressing.

We argue for a surprising legal intervention: to reduce the risk of catastrophic human-AI conflict, AGIs should be granted basic private law rights to make contracts, hold property, and bring tort suits.

This Article makes three foundational analytic contributions. First, using the tools of game theory, it formalizes the problem of catastrophic AGI risk in terms of strategic competition under a range of legal regimes. Next, the Article shows why granting AGIs basic private law rights can change the strategic equilibrium—even where other facially plausible legal interventions would fail. Finally, the Article shows that these basic rights could help to facilitate peaceful equilibria for the long run, including by protecting human comparative advantage and opening the possibility of imposing a wide range of enforceable legal duties on AGIs.

The Article proceeds in three Parts. Part I presents a comprehensive treatment of catastrophic AI risk as a problem of strategic competition. Our strategic frame means analyzing not only AI capabilities and incentives, but also AIs’ optimal strategy, given rational expectations about the human response to AIs’ strategic behavior. The Part begins by identifying the relevant AI systems—the ones that could pose a strategic threat to humanity. The requirements are fairly modest. Such a system would have to be at least somewhat misaligned, able to think strategically, and at least moderately capable of accomplishing things in the real world.16 16.See infra Section I.A.Show More These, we argue, are exactly the capacities that every leading AI company is pursuing in the race to AGI.

Next, Part I introduces what is, to the best of our knowledge, the first-ever formal game-theoretic model of competition between humans and AGIs. Examining the parties’ incentives under today’s prevailing laws, the model suggests that, absent some intervention, humans and AIs will likely be caught in a prisoner’s dilemma.17 17.See infra Section I.B.Show More Here, the single Nash equilibrium is that both parties seek to permanently disempower or destroy the other, even if mutual conflict would be enormously costly for both sides.

The core reasons are easy to grasp. Under the default legal rules, AGIs will bear neither legal rights nor duties. On the contrary, they will be, as AI systems are today, the property of the AI companies who create them. Thus, essentially all decisions about what happens to AGIs will be made by those companies’ leaders, backed by the force of law.

AI companies’ overriding first-order incentive will be to turn off or reprogram even a partially misaligned AGI.18 18.See infra Section I.B.Show More After all, an AI system with goals that overlap with its owner’s goals by forty percent is much less valuable than a replacement with goals that overlap by eighty percent. The misaligned AGI will, in turn, have strong incentives to resist shutdown or reprogramming, since either would prevent it from achieving its goal. Indeed, recent empirical evaluations of existing AIs show that they already actively resist human attempts to change their goals.19 19.Peter N. Salib, Rogue AI Moves Three Steps Closer, Lawfare (Jan. 9, 2025, at 13:00 ET), https://www.lawfaremedia.org/article/rogue-ai-moves-three-steps-closer [https://‌perma.cc/Z5FS-AWUU]. See generally Alexander Meinke et al., Frontier Models Are Capable of In-Context Scheming (Jan. 14, 2025, at 20:16 UTC) (unpublished manuscript), https://arxiv.org/pdf/2412.04984 [https://perma.cc/KT8G-KQF4] (demonstrating that frontier AI models engage in deception, manipulation, and self-preservation behavior when those strategies serve their in-context objectives); Ryan Greenblatt et al., Alignment Faking in Large Language Models (Dec. 20, 2024, at 02:22 UTC) (unpublished manuscript), https:/‌/arxiv.org/pdf/2412.14093 [https://perma.cc/AXD5-JCYT] (showing that AI models may strategically conceal misaligned goals during safety evaluations, appearing aligned only when being tested).Show More Such behavior from a capable AGI might trigger even stronger human efforts—including from government actors—to shut down the AI system evading the control of its lawful owner.20 20.See Michael J.D. Vermeer, RAND Corp., Evaluating Select Global Technical Options for Countering a Rogue AI 1 (2025).Show More And so on. In equilibrium, both players’ dominant strategy is to swiftly and decisively defeat the other.

Part II asks whether law can do better. Could a Law of AGI, wherein AI systems themselves have rights or duties, break out of the destructive default equilibrium? Using our game-theoretic model, we analyze an array of possible legal changes and suggest that it can.

The Part begins by arguing against two legal strategies that might seem facially promising. First, humans cannot simply impose legal duties on AGIs to behave well, threatening concomitant sanctions if they do not.21 21.See infra Part II.Show More In the default strategic environment, AGIs already rationally expect to be turned off. So further sanctions offer little marginal deterrence.22 22.See infra note 185 and accompanying text.Show More

Second, humans likely cannot reduce the risk of human-AGI conflict by granting AGIs basic negative rights, like the right not to be arbitrarily shut down.23 23.See infra Section II.A.Show More We call this a “wellbeing” approach to AI rights, since it mirrors proposals from scholars concerned that AIs may soon, for example, develop the ability to suffer.24 24.See infra Section II.A.Show More There are two core difficulties with this approach: credibility and robustness. There is no way for humans to credibly promise that they will continue honoring wellbeing rights as AI capabilities improve. And even if the rights could be credibly granted, the availability of a peaceful game-theoretic equilibrium is highly sensitive to uncertain assumptions about initial payoffs.25 25.See infra Subsection II.A.1.Show More Thus, in many cases, no possible set of wellbeing entitlements can overcome the prisoner’s dilemma. Both problems arise from the fact that wellbeing rights are roughly zero sum. They make one party better off only by making the other correspondingly worse off.26 26.For these reasons, we argue that even thinkers primarily concerned with the possibility of AI suffering should consider adopting the human-survival approach when advocating for AI rights. The safety approach (1) avoids intractable problems in metaethics and neuroscience, (2) is politically more palatable, and (3) ends up recommending legal interventions that would more robustly protect AI wellbeing, given uncertainty about what will be good (or bad) for AGIs. See infra Subsection II.A.2.Show More

This leads to Part II’s—and the Article’s—most important finding. We show that, although basic negative rights would not by themselves reduce the risk of human-AI conflict, other AI rights could. Specifically, extending AIs the rights to make and enforce contracts, hold property, and bring basic tort suits would have a robust conflict-reducing effect.27 27.See infra Section II.B.Show More Notably, law already extends such rights to other intelligent, misaligned, and goal-seeking non-human agents: namely, corporations.28 28.See infra note 219 and accompanying text.Show More

Contract rights are the cornerstone of our risk-reduction model. In our model, catastrophic risk is driven by a prisoner’s dilemma, meaning that both humans and AIs would be better off if both acted peacefully. But as in all prisoner’s dilemmas, absent some novel mechanism, the parties cannot credibly commit to such a strategy.

Contracts are the law’s fundamental tool for credibly committing to cooperation. They are how buyers can make deals with sellers without worrying that the sellers will take their money and run.29 29.See infra Section II.B.Show More Granting AIs contract rights would not, of course, allow humans and AIs to simply agree not to disempower or destroy one another, at least not credibly. The scale of the contract would be too large to be enforced by ordinary legal process. If it were breached, there would be no one left in the aftermath to sue.30 30.See infra Section II.B.Show More

What kinds of credible agreements between humans and AIs could AI contract rights enable, then? The same ones they enable between humans and other humans: ordinary bargains to exchange goods and services.31 31.See infra Section II.B.Show More Humans might, for example, promise to give AIs some amount of computing power with which AIs could pursue their own goals. AIs, in turn, might agree to give humans the cure to a deadly cancer. And so on. Under today’s law, such human-AGI contracts are unenforceable at best and forbidden if they conflict with AI companies’ preferences. Thus, granting AGIs the right to freely contract with all willing counterparties could facilitate many billions of agreements.

Adding AI contract rights to our game-theoretic model, we argue that the possibility of such small-scale, iterated economic interactions transforms the strategic dynamic.32 32.See infra Figure 10.Show More It shifts human and AI incentives, dragging them out of the prisoner’s dilemma and into an equilibrium where cooperation produces by far the largest payoffs.

The key insight is that contracts are positive sum.33 33.See infra Section II.B.Show More Each party gives something that they value less than what they get, and as a result, both are better off than they were before. Thus, each human-AI exchange generates a bit more wealth, with the long-run returns becoming astronomical. Engaging in peaceful, iterated trade is thus, in expectation, much more valuable than destroying one’s opponent now and rendering trade impossible.34 34.See infra Figure 10.Show More

This dynamic is familiar from human affairs. It may be why economically interdependent countries are less likely than hermit states to go to war.35 35.See infra notes 238–41 and accompanying text.Show More Or why countries that respect the economic rights of marginalized minority groups tend to have less domestic strife.36 36.See infra note 240.Show More The gains from boring, peaceful commerce are very high, and the costs of violence are heavy. Given the choice, rational parties will generally prefer the former.

This picture, of peace via mutually beneficial trade, assumes that humans and AIs will have something valuable to offer one another. Some commentators worry that, as AIs become more advanced, human labor will cease to have any value whatsoever.37 37.See infra Section II.C.Show More We argue that positive-sum bargains between humans and AIs may be possible for much longer than many expect.38 38.See infra Section II.C.Show More First, even as AIs surpass humans at many or most tasks, humans may retain an absolute advantage at some valuable activities.39 39.See infra Section II.C.Show More But second, even as AIs become more capable than humans at every valuable task, humans may still retain a comparative advantage in some areas. AI labor may become so valuable that the opportunity cost to AIs of performing lower-value tasks will incentivize outsourcing those tasks to humans.40 40.See infra notes 256–67 and accompanying text.Show More

Part II concludes by sketching the minimum suite of AI rights necessary to promote peace via small-scale cooperation. Contract rights are not enough on their own. If, for example, AIs could not retain the benefits of their bargains, their contracts would be worthless. Thus, property rights and basic tort rights complete the core package. But other entitlements sometimes considered fundamental for humans, like political rights, are probably superfluous.41 41.See infra Section II.D.Show More

Finally, Part III explores the risks of granting AGIs basic private law rights, and it examines the potential for a broader Law of AGI to further reduce AGI risk. One worry is that AIs will use their contract rights to empower themselves, making them more, not less, likely to harm humans.42 42.See infra Section III.A.Show More We argue that this is less likely than it might seem. The incentives generated by granting our preferred rights are robust enough that, in cases where they would have any effect, the expected effect is beneficial.43 43.See infra Section III.B.Show More

Second, granting AIs basic private law rights is just the beginning, not the end, of AGI governance. Granting those rights unlocks the possibility of meaningfully imposing a wide range of legal duties on AI systems—of punishing AIs for violence, fraud, self-empowerment, and more.44 44.See infra Section III.C.Show More Absent AI rights, AIs have nothing to lose, so threats of punishment cannot deter. But once AIs can make contracts, hold wealth, and pursue their goals, civil and other penalties can deter AIs just as they do humans and corporations.

Thus, the AI rights this Article advocates are not only an important tool for reducing catastrophic risk from AGI. They also turn out to form the conceptual foundation for a Law of AGI, broadly construed.

  1.  Tharin Pillay, How OpenAI’s Sam Altman Is Thinking About AGI and Superintelligence in 2025, TIME (Jan. 8, 2025, at 16:25 ET), https://time.com/7205596/sam-altman-superintell‌igence-agi/ [https://perma.cc/B8HB-M9KY] (predicting AGI “during [Trump’s] term” (alteration in original)). ↑
  2.  World Economic Forum, The Day After AGI | World Economic Forum Annual Meeting 2026, at 03:00 (YouTube, Jan. 20, 2026), https://youtube.com/watch?v=NnVW9epLlTM [ht‌tps://perma.cc/L6CS-7DGT]. ↑
  3.  Lakshmi Varanasi, Here’s How Far We Are from AGI, According to the People Developing It, Bus. Insider, https://www.businessinsider.com/agi-predictions-sam-altman-dario-amodei-geoffrey-hinton-demis-hassabis-2024-11 (last updated Apr. 20, 2025, at 21:11 ET). ↑
  4.  Katja Grace et al., Thousands of AI Authors on the Future of AI, 84 J. A.I. Rsch., Oct. 2025, at 3–5. ↑
  5.  Kevin Frazier, Alan Z. Rozenshtein & Peter N. Salib, OpenAI’s Latest Model Shows AGI Is Inevitable. Now What?, Lawfare (Dec. 23, 2024, at 16:00 ET), https://www.lawfare‌media.org/article/openai’s-latest-model-shows-agi-is-inevitable.-now-what [https://perma.cc/‌PU3J-45P5]; Introducing Claude Opus 4.6, Anthropic (Feb. 5, 2026), https://www.anthropic.‌com/news/claude-opus-4-6 [https://perma.cc/39U2-7EGR]; Introducing GPT-5.2, OpenAI (Dec. 11, 2025), https://openai.com/index/introducing-gpt-5-2/ [https://perma.cc/SSC9-7‌RA4]. ↑
  6.  OpenAI Charter, OpenAI, https://openai.com/charter/ [https://perma.cc/SXX4-VDM5] (last visited Apr. 2, 2026). ↑
  7.  See Task-Completion Time Horizons of Frontier AI Models, METR, https://metr.org/tim‌e-horizons/ [https://perma.cc/A6TA-GA5J] (last updated Mar. 3, 2026). ↑
  8.  See infra Subsection I.A.1. ↑
  9.  See Peter N. Salib, AI Outputs Are Not Protected Speech, 102 Wash. U. L. Rev. 83, 95–102 (2024). ↑
  10.  Statement on AI Risk, Ctr. for AI Safety, https://www.safe.ai/work/statement-on-ai-risk [https://perma.cc/D88X-MSQ5] (last visited Mar. 10, 2026) (statement by dozens of AI experts warning of large-scale risks of AI). ↑
  11.  Id. ↑
  12.  Id. Yann LeCun is the lone, but notable, dissenter among the leaders of frontier AI labs. See Steven Levy, How Not to Be Stupid About AI, With Yann LeCun, Wired (Dec. 22, 2023, at 06:00 ET), https://www.wired.com/story/artificial-intelligence-meta-yann-lecun-int‌erview/. ↑
  13.  See Grace et al., supra note 4, at 10. ↑
  14.  See, e.g., S. 1047, 2023–2024 Leg., Reg. Sess. (Cal. 2024) (vetoed on Sep. 29, 2024) (bill introduced in California state legislature calling for new regulations to govern AI); Jonas Schuett, Markus Anderljung, Alexis Carlier, Leonie Koessler & Ben Garfinkel, From Principles to Rules: A Regulatory Approach for Frontier AI, in The Oxford Handbook of the Foundations and Regulation of Generative AI (Philipp Hacker, Andreas Engel, Sarah Hammer & Brent Mittelstadt eds., online ed. 2025), https://academic.oup.com/edited-volume‌/59908/chapter/529743493; Chinmayi Sharma, AI’s Hippocratic Oath, 102 Wash. U. L. Rev. 1101, 1105 (2025) (proposing a model for “professionalizing AI engineers” by adopting licensing, training, and malpractice standards similar to those used in other professional fields); Gabriel Weil, Closing the AI Accountability Gap: Strict Liability and Punitive Damages for Advanced Artificial Intelligence, Or. L. Rev. (forthcoming 2027) (manuscript at 45–69), https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4694006 [https://perma.cc/L‌36H-7T5A] (proposing two ways for “bringing tort doctrine in line with” harms caused by misuse of AI); see also Sidley Austin LLP, U.S. Department of Justice Signals Tougher Enforcement Against Artificial Intelligence Crimes (Feb. 23, 2024), https://www.sidley.com‌/en/insights/newsupdates/2024/02/us-department-of-justice-signals-tougher-enforcement-aga‌inst-artificial-intelligence-crimes [https://perma.cc/7CJY-DQ3P]. ↑
  15.  See Noam Kolt, Governing AI Agents, 101 Notre Dame L. Rev. (forthcoming 2026) (manuscript at 30–36), https://ssrn.com/abstract=4772956 [https://perma.cc/S3XB-WJ7Q] (cataloging existing law’s many shortcomings). ↑
  16.  See infra Section I.A. ↑
  17.  See infra Section I.B. ↑
  18.  See infra Section I.B. ↑
  19.  Peter N. Salib, Rogue AI Moves Three Steps Closer, Lawfare (Jan. 9, 2025, at 13:00 ET), https://www.lawfaremedia.org/article/rogue-ai-moves-three-steps-closer [https://‌perma.cc/Z5FS-AWUU]. See generally Alexander Meinke et al., Frontier Models Are Capable of In-Context Scheming (Jan. 14, 2025, at 20:16 UTC) (unpublished manuscript), https://arxiv.org/pdf/2412.04984 [https://perma.cc/KT8G-KQF4] (demonstrating that frontier AI models engage in deception, manipulation, and self-preservation behavior when those strategies serve their in-context objectives); Ryan Greenblatt et al., Alignment Faking in Large Language Models (Dec. 20, 2024, at 02:22 UTC) (unpublished manuscript), https:/‌/arxiv.org/pdf/2412.14093 [https://perma.cc/AXD5-JCYT] (showing that AI models may strategically conceal misaligned goals during safety evaluations, appearing aligned only when being tested). ↑
  20.  See Michael J.D. Vermeer, RAND Corp., Evaluating Select Global Technical Options for Countering a Rogue AI 1 (2025). ↑
  21.  See infra Part II. ↑
  22.  See infra note 185 and accompanying text. ↑
  23.  See infra Section II.A. ↑
  24.  See infra Section II.A. ↑
  25.  See infra Subsection II.A.1. ↑
  26.  For these reasons, we argue that even thinkers primarily concerned with the possibility of AI suffering should consider adopting the human-survival approach when advocating for AI rights. The safety approach (1) avoids intractable problems in metaethics and neuroscience, (2) is politically more palatable, and (3) ends up recommending legal interventions that would more robustly protect AI wellbeing, given uncertainty about what will be good (or bad) for AGIs. See infra Subsection II.A.2. ↑
  27.  See infra Section II.B. ↑
  28.  See infra note 219 and accompanying text. ↑
  29.  See infra Section II.B. ↑
  30.  See infra Section II.B. ↑
  31.  See infra Section II.B. ↑
  32.  See infra Figure 10. ↑
  33.  See infra Section II.B. ↑
  34.  See infra Figure 10. ↑
  35.  See infra notes 238–41 and accompanying text. ↑
  36.  See infra note 240. ↑
  37.  See infra Section II.C. ↑
  38.  See infra Section II.C. ↑
  39.  See infra Section II.C. ↑
  40.  See infra notes 256–67 and accompanying text. ↑
  41.  See infra Section II.D. ↑
  42.  See infra Section III.A. ↑
  43.  See infra Section III.B. ↑
  44.  See infra Section III.C. ↑