The startup DoNotPay is facing a class action lawsuit alleging that its AI-powered 'robot lawyer' provided substandard, inaccurate legal documents and practiced law without a license.
DoNotPay was alleged in a class action lawsuit misleading customers and misrepresenting its product as an AI-powered "robot lawyer," citing such as that the product has no law degree, or is supervised by any lawyer.
Risk classification
- Primary risk domain: 7 AI system safety, failures, & limitations
- Primary risk subdomain: 7.3 Lack of capability or robustness
The AI system failed to perform reliably, generating inaccurate legal documents, blank pages, and failing to respond to court summons, resulting in legal and financial penalties for users.
Additional risk subdomains
- 4.3 Fraud, scams, and targeted manipulation: The company marketed the product as a 'robot lawyer' and misled customers into believing they were receiving competent legal services from an entity authorized to practice law.
Causal factors
- Entity: AI
- Intent: Unintentional
- Timing: Post-deployment
The incident was caused by the AI system generating substandard and inaccurate legal documents, which was an unintended failure of the deployed product.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The system operates as an automated chatbot and document generator, which carries transparency obligations to ensure users know they are interacting with an AI.
AI system and alleged parties
- AI system: ChatGPT
- AI purpose: Writing Assistant; Chatbot
- Behaviour type: Assistant
- Alleged developer: DoNotPay
- Alleged deployer: DoNotPay
- Alleged harmed parties: Jonathan Faridian, DoNotPay customers
Harm severity
Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Minor, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Epistemic
Reported: Yes, the report describes DoNotPay generating inaccurate and poorly drafted legal documents, and misleading customers about its AI capabilities.
Directly caused: The AI generated inaccurate legal documents, such as an agency agreement with incorrectly printed names and a blank demand letter, misleading users into believing they had valid legal filings.
Indirectly caused: N/A
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 4
- People reportedly exposed: 4
Potential causes
Management
- Misrepresentation of Product: Management marketed a simple template generator as a 'robot lawyer'.
- Prioritizing Hype Over Safety: Company pushed courtroom stunts over ensuring basic document accuracy.
Technology
- Substandard Document Generation: AI generated poorly drafted, inaccurate templates or blank legal documents.
- Flawed Automation Logic: System changed user pleas or failed to send summons responses correctly.
Data Inputs
- Ad-Lib Template Filling: AI relied on simple user inputs to fill basic, unverified templates.
Human Factors
- Overreliance on AI Claims: Customers trusted AI to provide competent legal services without oversight.
- Misleading Founder Hype: CEO promoted unrealistic AI capabilities, like courtroom representation.
Process and Methods
- Lack of Human Legal Review: AI-generated documents were not supervised or reviewed by licensed lawyers.
- Inadequate Delivery Tracking: System failed to deliver generated demand letters to intended recipients.
Regulatory Environment
- Unauthorized Practice of Law: AI service operated without necessary legal licenses or state bar approval.
- FTC Crackdown on AI Hype: Regulatory scrutiny over unsubstantiated and false product efficacy claims.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide clear details about the lawsuits, the specific complaints of the plaintiffs, and the nature of DoNotPay's services. The facts regarding the substandard documents and the legal allegations are consistent across both sources.
- Ambiguities identified: The exact technical integration of ChatGPT versus their legacy template-based system is not fully detailed.
A class-action lawsuit against DoNotPay for its failed 'robot lawyer' AI system represents a consumer protection and regulatory compliance issue rather than a national security threat. The incident has negligible impact on physical security, intelligence, sovereignty, strategic economics, or societal stability.
- Overall national security impact: Negligible
- Response level: Minor
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: DoNotPay
Threat characteristics
- Imminence: Long-term. The incident is a localized consumer lawsuit with no imminent threat to national security.
- Autonomy: Human-controlled. The AI system assists with drafting documents, but users must ultimately review, sign, and submit them to courts.
- Novelty: Evolved capability. Represents an evolution of existing document template tools through the integration of large language models like ChatGPT.
Impact by dimension
- Physical security: Negligible. No physical security, critical infrastructure, or kinetic threat is indicated in the incident reports.
- Information security: Negligible. The incident involves consumer legal assistance and does not compromise intelligence capabilities or involve state-sponsored information warfare.
- Sovereignty: Negligible. The incident involves private consumer legal disputes and does not impact sovereign government operations, border control, or constitutional processes.
- Economic security: Negligible. Financial losses are limited to individual consumer subscriptions and minor court fines, with no threat to strategic industries or national economic stability.
- Societal stability: Negligible. The incident is a consumer-level commercial dispute and does not involve mass surveillance, systematic discrimination, or large-scale civil unrest.