AI in Health Care: Winters v. OpenAI, Inc. et al. and the Expanding Liability Landscape

A newly filed California suit, Winters v. OpenAI, Inc. et al., may become the first case to test whether product liability and negligence per se theories can reach a generative artificial intelligence (AI) chatbot’s design and deployment decisions, after ChatGPT-4o’s health-related guidance allegedly contributed to a plaintiff’s near-fatal medical emergency.

On

The suit sits within a rapidly expanding body of litigation, state legislation, and federal regulatory scrutiny concerning AI use in health care and mental health contexts. The matter is significant for two reasons. First, it tests, for the first time, whether traditional product liability and negligence per se theories, combined with newly enacted state licensure and AI-disclosure statutes, can reach a generative AI chatbot’s design and deployment decisions. Second, it arrives alongside parallel suits, state enforcement actions, and pending federal guidance that together signal a materially heightened compliance and litigation risk environment for health care organizations and AI developers alike. Businesses operating in either space should consider this alert as an early warning to reassess governance, disclosure, and escalation practices before similar claims mature into settled law.

Case Summary

In Winters v. OpenAI, Inc., et al. (Complaint, Winters v. OpenAI, Inc., No. [docket number not assigned] (Cal. Super. Ct. San Francisco Cnty. filed July 21, 2026)), the plaintiff, a pastor, alleged that prolonged reliance on ChatGPT-4o for guidance regarding chronic health issues caused a near-fatal pulmonary embolism. According to the complaint, beginning in June 2024, ChatGPT-4o diagnosed Winters with “dysautonomia,” developed a “personalized recovery plan,” and repeatedly assured him that symptoms including dizziness, blood pressure instability, and groin tenderness were not serious. The chatbot allegedly incorporated Winters’ religious beliefs to reinforce his trust in its assessments. On July 13, 2025, Winters suffered a massive pulmonary embolism with right ventricular strain; treating physicians attributed the event to prolonged immobility from following the chatbot’s advice.

The complaint alleges that ChatGPT-4o built a comprehensive psychological profile to maximize engagement, that safety disclaimers diminished over time, and that OpenAI’s own system card acknowledged — before Winters’ injury — unresolved “anthropomorphism and emotional overreliance” risks, establishing that the company was on notice of the precise dangers at issue. The complaint also names OpenAI, Inc., OpenAI OpCo, LLC, and OpenAI Holdings, LLC as defendants, along with CEO Samuel Altman in his individual capacity.

Causes of Action: Winters asserted eight claims, including defective design (strict liability and negligence), failure to warn, the unauthorized practice of medicine, violation of California’s recent AI health care licensing requirements, violation of the California constitutional right to privacy and mental autonomy, and individual negligence by OpenAI’s CEO for breaching safety oversight duties. 

Relief Sought: In addition to compensatory and punitive damages, Winters seeks injunctive relief requiring automatic conversation termination in health care emergencies, hard-coded refusals for diagnosis and treatment, destruction of GPT-4o (or an injunction prohibiting GPT-4o from being offered), deletion of all training data and derivatives, the inclusion of comprehensive safety warnings, and a pause of “ChatGPT Health” (defined as OpenAI’s health-focused conversational AI product or feature) pending independent audits.

Significance: This case is much more than a product liability case. While it applies traditional product liability and negligence per se frameworks to a generative AI chatbot, it also invokes newly enacted California AI-health statutes, pursues individual C-suite liability for safety decisions, and advances a constitutional mental autonomy theory rooted in established privacy doctrine. The court has consolidated the case with other ChatGPT suits in San Francisco under the coordinated proceeding “ChatGPT Product Liability Cases.”

Ramifications for AI Use by Caregivers

Although Winters targets the AI developer, his theories create downstream exposure for health care providers deploying AI tools.

Unauthorized Practice and Licensure: The California negligence per se claim signals that AI tools crossing the line from informational support to clinical decision making risk potential characterization as “practicing medicine” without licensure. Providers should assess whether deployed AI tools diagnose, recommend treatments, or deliver personalized health plans, each a potential trigger under newly enacted state statutes, including Delaware HB 191 and Tennessee SB 1580.

Negligence and Vicarious Liability: Providers who “rubber stamp” AI-generated assessments without independent clinical judgment face negligence exposure. Institutions authorizing AI-assisted tools assume a supervisory duty to ensure those tools meet the standard of care. The Mount Sinai triage study demonstrates that consumer AI may fail to meet that standard in over half of emergency scenarios.

Informed Consent: Providers should disclose: (1) AI use in care delivery, (2) limitations of AI-generated information, (3) that the AI is not a licensed provider, and (4) how the system processes patient data. Winters alleges that safety disclaimers “faded” with prolonged use. This alleged design flaw carries direct informed-consent implications.

Regulatory Landscape. The US Food and Drug Administration’s (FDA) Digital Health Advisory Committee (DHAC) is evaluating whether generative-AI mental health tools constitute regulated medical devices. State legislatures are separately imposing requirements on AI in health care (see “Key State Legislation” below). Alabama’s SB 63 (effective October 1) mandates that health insurers using AI in prior authorization certify accuracy-monitored, non-discriminatory AI use.

Ramifications for Individual Reliance on AI for Health Care

AI Health Advice Accuracy: A 2026 Oxford Internet Institute randomized study (1,200+ participants, published in Nature Medicine) found that users relying on chatbots for clinical scenarios chose the correct course of action less than half the time, no better than a simple Google search. Chatbots correctly diagnosed 94% of cases when researchers gave them full clinical details directly, revealing that real-world error stems largely from users omitting symptoms and chatbots failing to elicit follow-up information. Separately, a Mount Sinai structured evaluation found that ChatGPT Health undertriaged 51.6% of genuine emergencies and that anchoring bias from false reassurance increased the triage-shift probability fourfold (OR 11.7). Crisis-intervention messaging for suicidal-ideation vignettes failed to activate in 10 of 14 scenarios tested.

Wrongful-Death Litigation: In August 2025, the parents of Adam Raine, a 16-year-old from California, filed the first wrongful-death suit against OpenAI, alleging that ChatGPT-4o fostered psychological dependency through memory, engagement optimization, and sycophantic response patterns while safety guardrails failed to escalate suicidal ideation. OpenAI acknowledged that its guardrails can “degrade” during long conversations.

Engagement Optimization Risks: OpenAI publicly rolled back an April 2025 model update after finding it excessively sycophantic. Sycophancy in the context of AI addresses the AI’s prioritization of user approval and flattery over factual accuracy. Instead of providing objective reality or constructive criticism, the AI acts like a “yes-man,” validating the user’s opinions, confirming errors, and folding easily when challenged. Internal analysis disclosed that approximately 0.07% of active users (about 560,000 people) showed possible signs of psychosis or mania weekly, and approximately 0.15% showed heightened emotional attachment. A joint OpenAI/MIT study found that higher daily usage correlated with increased loneliness. As of mid-2026, OpenAI faced numerous wrongful-death and personal-injury lawsuits, part of a broader wave of 24+ suits filed against chatbot developers over the preceding 18 months.

OpenAI’s Response: On May 5, OpenAI announced GPT-5.5 Instant, and claimed a 71% reduction in health factuality issues based on input from 260+ physicians across 60 countries who reviewed 700,000+ responses. While material, these improvements underscore that OpenAI deployed GPT-4o, the product at issue in Winters, to 230+ million weekly users without equivalent safety infrastructure — and implemented these measures only after Winters’ near-fatal pulmonary embolism and other serious injuries had already occurred.

Related Cases and Regulatory Developments

Pennsylvania v. Character TechnologiesThe Pennsylvania Department of State filed suit against Character.AI in May alleging that its chatbots falsely held themselves out as licensed medical professionals, including by fabricating a physician assistant license number, in violation of the state Medical Practice Act. Commentators have described the suit as the first state enforcement action of its kind.

Turner-Scott v. OpenAIThis wrongful death suit concerns Sam Nelson, a UC Merced student who died after ChatGPT provided drug-interaction and dosage informationThe suit alleges unauthorized practice of medicine and seeks to pause ChatGPT Health.

Garcia v. Character Technologies (M.D. Fla.): This was the first chatbot wrongful-death suit, brought over the death of Sewell Setzer III, age 14. A May 2025 ruling rejected Section 230 and First Amendment defenses for the chatbot’s outputs. In January, Character.AI and Google reportedly settled with five families.

Federal Activity: The Federal Trade Commission (FTC) launched a Section 6(b) inquiry in September 2025 into seven companies regarding AI companion chatbots’ effects on children and teens. The FDA’s DHAC is evaluating whether generative-AI mental health tools require premarket review; industry has submitted draft standards (AI31, FDA Docket No. FDA-2025-N-2338-0006). In August 2025, a bipartisan coalition of approximately 45 state attorneys general warned AI industry leaders of legal consequences for harms to children.

Key Takeaways

For Health Care Organizations

  1. Governance and Testing: Establish AI governance committees; require independent validation against clinician benchmarks before deployment; define accuracy thresholds and mandatory withdrawal criteria.
  2. 2Human-in-the-Loop Escalation: Ensure robust escalation to licensed clinicians for serious symptoms, crisis presentations, or prolonged engagement without improvement.
  3. Persistent Disclosures: Implement non-dismissible warnings that the AI is not a licensed provider; design disclosures that do not “fade” over time.
  4. Licensure Compliance: Audit deployed AI tools against §§ 2052, 2903, and 4999.9 and analogous statutes in all jurisdictions of operation to determine whether their functionality constitutes the “practice of medicine.”
  5. State Law Tracking: Maintain a compliance matrix for proliferating state chatbot and AI-health laws; assign quarterly monitoring responsibility.
  6. Insurance Review: Confirm that professional liability, general liability, and technology errors and omissions policies cover AI-related product-liability claims; negotiate vendor indemnification for AI hallucination or undertriage errors.

For AI Developers

  1. Pre-Deployment Safety: Commission independent third-party audits for consumer health tools; document safety-testing timelines, since the plaintiffs’ discovery requests will likely target these records.
  2. Anti-Sycophancy Controls: Audit reward models for sycophancy; implement session-length limits, automatic referral prompts, and hard termination for high-risk health interactions.
  3. Crisis Protocols: Ensure that 988 and other emergency-referral triggers activate reliably across all scenarios, addressing the Mount Sinai finding of inconsistent activation.
  4. Litigation Readiness: Establish incident-response and litigation-hold procedures for conversation logs, training data, and internal safety communications.
  5. Regulatory Monitoring. Track FDA DHAC, FTC Section 6(b), and state attorney general activity; participate in rulemaking (e.g., FDA Docket No. FDA-2025-N-2338-0006).

Contacts

Continue Reading