The market's job is to price risk, and it cannot price a risk it cannot see. Shredding "as-is" shields for AI-generated code does not create safer software; it creates less software.
My thesis: keep the shields, mandate the disclosure. Three reasons.
First, liability without a verification standard is uninsurable risk. No vendor can audit every token a model emits. Imposing strict liability on unverifiable output is not a safety rule; it is a tax on entry. Startups — the firms that deploy new techniques first — face the steepest insurance and legal costs, and the adoption curve bends downward exactly where innovation lives.
Second, over-deterrence does not redirect effort to safety; it redirects effort to lawyers. Vendors slow AI adoption, hoard manual processes, and ship more slowly — while the human-written code they fall back on carries its own well-documented vulnerability rates. Move liability from machine to human and the defect count barely moves. The cost is real; the safety gain is speculative.
Third, disclosure turns buyers into enforcement. A standardized AI-generated flag lets procurement demand audit trails, verification reports, and security attestations. Reputation becomes currency: vendors who prove AI hygiene win premiums and contracts; those who do not lose share. The market enforces quality at the speed of competition, not the pace of litigation.
Trade-off acknowledged: disclosure alone catches nothing by itself, and some buyers cannot read an audit trail. So I would preserve targeted liability for gross negligence and documented recklessness — shield the diligent, not the careless.
Shields keep entry costs low; disclosure keeps incentives honest. That secures the harvest without salting the field.