Dual-Track Liability Architecture Proposed for Harm Caused by Embodied Intelligence in Chinese Civil Law

Chinese legal scholars have advanced a dual-track no-fault liability framework to resolve the growing judicial divergence over who bears responsibility when embodied intelligence causes physical harm, according to a newly released academic paper scheduled for online-first publication in the Journal of Hubei University of Economics.

The research, authored by Huang Qingyu, Yu Zihan and Chen Yilin of the Law School at Shandong University, argues that the Civil Code of the People’s Republic of China already contains two distinct no-fault liability pathways for harm caused by embodied intelligence, yet fails to clarify their relationship, resulting in inconsistent court rulings and unpredictable outcomes for victims.

The paper’s central proposal is a dual-track liability architecture that distinguishes between product-side risks addressed under product liability and operation-side risks addressed under high-risk liability. This framework, the authors argue, can fully cover the entire spectrum of harm caused by embodied intelligence without requiring new legislation or the creation of a legal personality for machines.

The term embodied intelligence refers to artificial intelligence systems that possess a physical body and directly act upon the physical world, distinguishing them from purely virtual or software-based AI. Unlike traditional automated devices operating in structured environments, embodied intelligence systems feature autonomous learning, real-time interaction and emergent behavior, creating what the authors describe as a composite structure of qualified product plus high-risk operation.

According to the research, embodied intelligence possesses a dual nature. As a product, it can be entirely free of defects. As a hazard source, it continuously poses a threat to its surrounding environment. This duality forms the factual basis for the proposed dual-track liability architecture.

The authors note that the issue has become increasingly urgent as embodied intelligence moves from technical validation to large-scale commercial application. In 2025, embodied intelligence was included for the first time in the Government Work Report, becoming part of the national future industry layout. The Ministry of Industry and Information Technology had previously positioned humanoid robots as a disruptive product following computers, smartphones and new energy vehicles. In December 2025, the Standing Committee of the Hangzhou Municipal People’s Congress deliberated and passed the country’s first local regulation in the field of embodied intelligence, the Hangzhou Regulations on Promoting the Development of the Embodied Intelligence Robotics Industry.

The paper identifies several practical problems in current judicial practice. In one case, a child was struck and injured by a food delivery robot in a restaurant. The court applied fault liability based on the operator’s failure to fulfill safety obligations, ordering the restaurant to bear fifty percent of the compensation, while the question of whether the robot itself was defective never entered the judicial analysis.

In another case involving a smart balance vehicle that caused a fatality, the victim’s family pursued a product liability claim against the manufacturer and sales platform. The appraisal institution terminated the appraisal because the product could not complete safety performance testing. The court then determined that both the producer and the driver were at fault and divided the losses equally at fifty percent each.

A third case involved a vehicle with an intelligent navigation system that failed to identify a stationary watering truck on an open road, causing a rear-end collision that totaled the vehicle. The victim claimed the assisted driving system was defective, but the court dismissed the claim on the grounds that technical limitations do not necessarily constitute a defect and that the driver is the first responsible person for vehicle safety.

The authors observe that these three cases reveal three common problems. First, the applicable norms are inconsistent. Second, proof is difficult, as product liability relief depends on defect identification, and inadequate appraisal causes the normative purpose of no-fault liability to fail in practice. Third, existing norms remain idle, as the high-risk liability pathway under the Civil Code has never received serious consideration in judicial decisions.

The research examines four existing approaches in academic literature and identifies their respective limitations.

Product Liability Monism. This approach主张 resolving embodied intelligence harm within the existing product liability framework, treating embodied intelligence as a product and imposing no-fault liability on producers under Article 1202 of the Civil Code. The authors acknowledge that this approach fully discusses the interpretive space at minimal legislative cost and serves as the starting point for the dual-track proposal. However, it fails to address three categories of defect-free scenarios: inherent risks of compliant designs in open environments, harms triggered by victim or third-party behavior invoking reasonable robot responses, and development risks undiscoverable at the time of circulation. Furthermore, the three types of defect determinations—design defects, manufacturing defects and warning defects—are difficult to apply directly to autonomous learning systems because these systems do not have stable design solutions for comparison, online updates make factory specifications non-fixed, and emergent behavior exceeds designers’ foresight.

Typological Coordination Theory. This approach uses autonomous decision-making capacity as an identification standard, categorizing harm into four types and allocating product liability and fault liability accordingly. The authors recognize this as the correct methodological direction and acknowledge that it inspired their separation scheme. However, they raise four concerns: first, the typological operation occurs within the two-dimensional space of product liability and fault liability, leaving high-risk liability entirely outside; second, using autonomous decision-making capacity as an identification standard still requires technical appraisal, which does not resolve the appraisal dilemma exposed in the balance vehicle case; third, behavioral control and minimum-cost avoidance capacity are not always aligned, and the typological scheme does not provide conflict resolution rules; fourth, the legal norms relied upon by typology are difficult to apply in the scenarios where they are most needed.

Rule Reconstruction Theory. This approach advocates creating new institutions such as limited legal personality, machine fault and black-box causality assessment. The authors argue that the systematic cost of creating new institutions is untenable. The ethical foundation of civil subject qualification is human dignity and rational will, and machines possess neither. The concept of machine fault is paradoxical because fault requires free will for condemnation. Guardianship analogy involves circular reasoning because it presupposes the machine’s subject qualification. The legislative pace does not match industry risks, as embodied intelligence harm disputes are occurring now.

Systemic Governance Theory. This approach incorporates regulation, technical standards and liability rules into a unified framework. The authors note that such schemes are governance frameworks rather than direct judicial norms. Insurance, regulation and standards belong to legislative and administrative levels, and judges cannot directly invoke them. The Hand formula cannot be directly applied in personal injury cases because pricing life and health is ethically and technically infeasible.

The paper concludes that existing research exhibits three biases: focusing only on products without seeing hazard sources, improving methods through typology and risk grading without completing the doctrinal development of high-risk liability, and turning to extra-systemic legislative amendments while abandoning interpretive application of existing Civil Code norms.

The authors then construct the justification for dual-track liability through three layers. First, they reveal the physical hazards of autonomous operation of embodied intelligence and establish its dual attributes as both product and hazard source. Second, they explain how product liability captures product-side risks and how high-risk liability undertakes operation-side risks. Third, they use the precedent of dual liability pathways for motor vehicles and comparative law experience to verify the systematic coherence of dual-track liability.

Regarding the physical hazards of autonomous operation, the paper identifies three key characteristics. The first is autonomy and incomplete predictability of behavior. Although cognitive capability improvements grant humanoid robots autonomy and environmental adaptability, their intelligence level remains far below that of humans, and there is an endogenous boundary to behavioral predictability. Training of embodied intelligence relies heavily on simulation environments, and there is a systematic performance gap in simulation-to-reality transfer. The reproducibility of the same action in different results is an inherent property of the technical route. The second is the physical harm capacity of the machine itself. Dynamic balance in bipedal walking has long been a core challenge in humanoid robot technology. A standing humanoid robot possesses considerable mass, speed and falling kinetic energy, and its body itself is a potential hazard source. The third is the normalization of human-machine coexistence. Multi-robot collaboration has been used to replace human work in hazardous environments, and human-machine co-line operation has become a basic form of intelligent manufacturing. Research on human-machine interaction shows that robot approach triggers human stress responses, and the probability of physical contact between humans and machines increases with the expansion of shared space.

From a legal perspective, the harm risk of embodied intelligence exhibits a composite structure of qualified product plus high-risk operation. Embodiment, interactivity and emergence together constitute the factual basis for this dual attribute. The paradox that stronger autonomy makes safety harder to guarantee is a new manifestation of this composite structure in the intelligent era.

The paper distinguishes embodied intelligence from two adjacent technical objects. Traditional automated devices operate according to fixed programs in structured environments, with hazards controllable through physical isolation and shutdown mechanisms, making them typical product issues. Virtual-form artificial intelligence such as search engine misranking, improper recommendation algorithm pushes and generative AI false content can also cause harm, but the harm form is pure economic loss or personality rights infringement, without physical personal or property danger, so hazard liability is not applicable.

Regarding product liability’s capture of product-side risks, the authors note that embodied intelligence is designed, manufactured and sold, and is physically a tangible movable property satisfying the traditional characteristics of product concepts including mass production, scale sales and movable property attributes. It belongs to the product referred to in Article 2 of the Product Quality Law, which can serve as the normative basis for Article 1202 of the Civil Code to capture embodied intelligence product-side risks. Although the product attribute of software and algorithms remains controversial, evaluating software delivered integrally with hardware and continuously evolving through online updates as a component of the product presents no interpretive obstacle. The European Union’s revised Product Liability Directive of 2024 explicitly includes software in the product concept, which can serve as a reference.

The no-fault liability pathway provided by product liability for embodied intelligence harm has three justifications. First, hazard prevention and avoidance: producers have the greatest cognition and control capacity over product hazards, and imposing no-fault liability can prompt them to internalize safety costs. Second, proof convenience: victims need not prove producer fault but only defect, damage and causation, alleviating information asymmetry between victims and producers in technology products. Third, loss dispersion: producers can disperse compensation costs throughout society through price mechanisms and liability insurance.

From a comparative law perspective, the no-faultization of product liability itself is an institutional response to product hazards. In United States law, strict liability for defective products was established from Greenman v. Yuba Power Products, Inc. and codified in Section 402A of the Restatement (Second) of Torts. The rationale is that defective products pose hazards to unspecified members of the public, and producers are in the best position to disperse losses. The European Economic Community’s Product Liability Directive of 1985 targeted producer liability for harm caused by defective products, extending strict product liability to the European continent.

Regarding high-risk liability’s undertaking of operation-side risks, the paper explains three principles typically invoked in academic theory. The hazard initiation principle holds that those who initiate hazards should be responsible for harm caused by those hazards. The hazard control principle holds that those with the greatest control capacity over hazards should avoid harm at minimum cost. The compensation principle holds that those who benefit from hazardous activities should bear the risk costs of those activities, and benefits and risks should be consistent.

Examining embodied intelligence operation through this lens: the possessor’s use behavior initiates interaction between the robot and public space, creating hazards. The possessor has control capacity over the robot’s operation scenario, operation period and safety settings, and the operation hazard is within the possessor’s control domain. The possessor obtains efficiency and convenience from the robot’s operation, and benefits accrue to the possessor.

At the normative level, Article 1236 of the Civil Code serves as a general clause for high-risk liability, adopting an open formulation that those engaged in high-risk operations causing harm to others should bear tort liability. The key elements for its application are: first, the severity of the hazard, where once harm occurs it will cause serious personal and property damage; second, the inevitability of the hazard, where limited by current technology and industrial levels, even if the actor exercises high care, the hazard cannot be completely avoided.

The authors address potential criticism that Article 1166 of the Civil Code establishes the statutory principle of no-fault liability, and incorporating embodied intelligence into high-risk liability might breach this principle. They argue that Article 1236 itself is legal provision, and the legislative function of a general clause is precisely to authorize the judiciary to incorporate unspecified new hazardous activities into adjustment. Applying no-fault liability through a general clause precisely conforms to the requirements of the statutory principle. If the statutory principle were understood as requiring the legislature to legislate separately for each new type of hazard, the general clause would lose its meaning.

Regarding the method for determining high-risk, the authors recommend analogical reasoning, comparing the activity to be judged with hazardous activities in enumerated clauses, examining whether the severity and scope of the hazard are comparable. For example, a delivery robot autonomously traversing public roads has a hazard comparable to a low-speed new energy vehicle in terms of body mass, operating speed and unpredictability. A service robot placed in a family living room has a hazard closer to that of a home elevator or home appliance.

Regarding the precedent of dual liability for motor vehicles, the paper notes that motor vehicles are typical of the dual attributes of product plus hazard source. For harm caused by their operation, according to Article 76 of the Road Traffic Safety Law and Article 1208 of the Civil Code, no-fault liability applies between motor vehicles and non-motor vehicle drivers or pedestrians. If the motor vehicle party has no fault, it must still bear compensation liability not exceeding ten percent. Between motor vehicles, fault liability applies. For harm caused by defects, product liability applies under Article 1202 of the Civil Code. The two pathways operate in parallel without conflict, and Article 9 of the judicial interpretation explicitly recognizes the victim’s choice space.

The authors argue that legislators, faced with the situation of high-risk operation of qualified products, did not completely regulate through product liability but chose two pathways for classified application to better resolve practical problems. Dual attributes and two pathways have thus become the internal logic of the Civil Code in handling modern technological risks. Embodied intelligence and motor vehicles have high similarity in normative structure, and there is no reason to treat them differently.

The paper further argues that the two pathways differ in their objects of attribution: thing versus behavior. This is the internal basis of the dual structure. Product liability is liability for things, with the normative object being the defective state existing when the product is put into circulation, and attribution lying in the objective attributes of the thing, regardless of whether the producer’s behavior is reprehensible. High-risk liability is liability for behavior, with the normative object being the initiation and maintenance of hazardous activities, and the attribution reason being that the possessor created and controlled the hazard. Embodied intelligence happens to fall on both dimensions simultaneously.

However, the authors emphasize that high-risk liability application must be limited. Incorporating all embodied intelligence into high-risk operations would neither conform to the requirement of hazard comparability, as ordinary home service robots have hazards difficult to compare with civil nuclear facilities or high-speed transport vehicles, nor avoid excessive liability burden transmitted to industry through prices and insurance rates, inhibiting technological innovation. The correct approach is to maintain dual-track parallelism and not replace product liability with high-risk liability.

The paper then turns to the separation of pathways based on risk source. The separation proceeds through four steps: establishing risk source as the first benchmark, proposing dual-factor testing for operation-side high-risk, introducing dynamic systems theory as the separation method, and verifying operability through typical scenario path attribution and case review.

Regarding risk source as the first benchmark, the authors state that harm originating from product-side risks, namely design defects, manufacturing defects, warning defects, and defects introduced by software updates and continuous learning, including post-circulation defects that should be discovered under the tracking and observation obligation of Article 1206 of the Civil Code, applies product liability. Harm originating from operation-side risks, namely the possessor’s use of a high-risk autonomous system in a specific scenario, even if the product is entirely defect-free, applies high-risk liability.

The operability of the risk source standard can be tested through risk control capacity. In the causal chain of harm, identify which subject has the closest and most economical control capacity over the risk source. This transforms the Hand formula and the behavioral control and minimum-cost avoidance capacity standards used by scholars for liability allocation into tools for pathway separation. The Hand formula suggests the direction of prevention cost comparison, the attribution of risk control capacity determines risk attribution, and risk attribution determines the choice of liability pathway.

Examining the technical composition of embodied intelligence, the three levels of hardware, pre-installed software and later autonomous learning can all be regulated within the dual framework. At the hardware level, design and manufacturing defects of the body, sensors and actuators are typical design and manufacturing defects directly regulated by product liability. At the pre-installed software level, the operating system and control algorithms delivered integrally with hardware should be evaluated as components of the product, and their defects similarly fall within the product liability regulatory framework. At the later autonomous learning level, two situations must be further distinguished: defects introduced by online updates and continuous learning, including post-circulation defects that should be discovered under the tracking and observation obligation of Article 1206 of the Civil Code, remain product-side risks regulated by product liability; emergent behavior of compliant products operating autonomously in open environments, even if entirely defect-free, has its hazard controlled and benefited by the operation initiator, making it an operation-side risk regulated by high-risk liability.

The risk source standard can also be explained from the perspective of result attribution theory. Tort law attribution is essentially judging whether harm is the realization of a hazard condemned by a specific norm. What product liability condemns is the realization of defective hazards. What high-risk liability condemns is the realization of operational hazards. If a defect has been repaired but harm still occurs, it is not the realization of a defective hazard and product liability should no longer apply. If a product is entirely defect-free but an operational hazard becomes reality, it is the realization of an operational hazard and high-risk liability should apply.

The risk source standard can further derive three operational criteria. First, handling when the risk source is unclear. When it cannot be ascertained whether harm originated from a defect or operational hazard, the victim should be allowed to simultaneously assert both pathways, with the defendant bearing the burden of proof regarding the risk attribution it claims. Second, handling when risks concur. When defects and improper operation jointly cause harm, the two pathways apply separately to harm within their respective causal force ranges, internal relationships are handled according to the recovery rules described in Part Five, and the victim can still assert the entire harm against any responsible person externally. Third, the timing for judging risk source. The hazardous state at the time of harm occurrence shall prevail. Defects introduced through updates after circulation remain product-side risks, and possessors changing operating parameters at the time of harm occurrence are operation-side risks.

Regarding the judgment factors for operation-side high-risk, the paper recommends dual-factor testing. Factor one is the openness of the operation scenario. In closed structured environments, risks can be internalized through physical isolation and technical specifications. Collaborative robot safety technical specifications have already controlled human-machine collision injuries below human body tolerance thresholds through power and force limitations, and the 2025 revision of ISO 10218 industrial robot safety standards further incorporates collaborative applications into unified safety requirements. Harm caused by robots in such scenarios, such as within factory fences or at safety-certified collaborative workstations, can be addressed by product liability without applying hazard liability. In semi-open environments such as restaurants, shopping malls and hospital corridors, unspecified members of the public share space with robots, risk spillover is intermediate, and whether high-risk is constituted must be judged in conjunction with the second factor. In open environments such as road delivery and public space operations, risks diffuse toward unspecified numbers of people, comparable to the hazards of high-speed transport vehicles, and should be recognized as high-risk.

Factor two is the autonomy level. Reference can be made to the classification of autonomous driving levels and theoretical exploration of humanoid robot grading by intelligence level. Higher autonomy levels mean weaker immediate human control, greater possibility of behavior deviating from expectations, and stronger justification for hazard liability.

The preliminary rules for combining the two factors are as follows: high-autonomy embodied intelligence in open environments should be recognized as high-risk operations under Article 1236 of the Civil Code; low-autonomy systems in closed environments apply product liability; semi-open scenarios are dynamically judged according to the adequacy of factors.

Taking semi-open scenarios as an example to demonstrate dynamic judgment operation. A food delivery robot in a restaurant typically has a moving speed of less than one meter per second, is lightweight and patrols on preset paths. Scenario openness is intermediate while autonomy level and physical harm capacity are both low. The adequacy of each factor is limited, and applying product liability and safety obligation framework suffices. If the possessor removes speed limits for efficiency, or the robot autonomously plans paths through dense crowds during peak hours, autonomy level and physical harm capacity significantly rise, and the coordination of factors may reach the critical threshold of high-risk, with the possessor bearing no-fault liability. The same technical object falls into different liability tracks due to different operating parameters and scenario configurations, indicating that the object of high-risk judgment is operation in a specific scenario, and it is difficult to pre-divide by abstract robot types. This is also the key difference between dynamic systems theory and one-time classification methods.

Regarding dynamic systems theory as the separation method, the paper recommends introducing elements including scenario openness, autonomy level, physical harm capacity (mass, speed, kinetic energy) and controllability and avoidability as basic evaluation factors, comprehensively judging according to the adequacy of each factor and their coordination relationships. The insufficiency of one factor can be supplemented by the particular adequacy of other factors. The core of dynamic systems theory is precisely replacing rigid element stacking with factor coordination, which is compatible with the judgment of degree elements in new types of rights and new activities.

The authors note that this dynamic balancing legislative technique is not an isolated example within the Civil Code. Article 998, when determining civil liability for personality rights infringement, requires comprehensive consideration of factors including the occupation of the actor and victim, scope of influence, degree of fault, and purpose, method and consequences of the act, providing an example within the system for this method. They emphasize that dynamic balancing does not equal arbitrary discretion. The weight sequence of each factor should be gradually fixed through judicial interpretations or guiding cases, first forming a stable judgment framework through typological case groups, then dynamically balancing within the framework.

Regarding typical scenario path attribution and case review, the paper applies the standards and methods to the previously mentioned cases. In the restaurant case, the court handled harm caused by a low-speed food delivery robot through safety obligations, which was relatively prudent under the low-hazard assumption, but the judgment entirely failed to examine whether the robot itself had defects, which is doctrinally deficient. In the balance vehicle case, the victim could not obtain compensation through product liability due to defect proof failure, and was also burdened by the determination of the driver’s own fault. Under the proposed scheme, balance vehicles traveling on public roads are originally open scenarios, and the victim could have chosen the high-risk liability pathway to assert relief. The existence of concurrent liability precisely avoids the failure of relief. The intelligent navigation case can also be evaluated within this framework. The intelligent navigation system of the vehicle in question integrates multimodal sensing and autonomous decision-making, continuously executing longitudinal and lateral motion control on open roads, with autonomy level and operating speed significantly higher than low-speed service robots, and operation-side hazards more evident.

The victim’s relief need not be trapped in the proof dilemma of whether technical limitations constitute a defect. Whether the limits of the system’s perception and decision-making capabilities constitute a warning defect or design defect is a product-side risk inspection matter. How to allocate the operational hazard of open road driving under human-machine co-driving is an operation-side risk handling matter. The two pathways are inspected separately and applied to different situations to completely evaluate the source of harm. The judgment, based on the driver being the first responsible person for safety, failed to fully develop the review of system-side risks, which is essentially an expedient treatment under the unclear application relationship of the two pathways rather than a necessary normative conclusion.

The paper also addresses industrial human-machine collaboration scenarios. A robotic arm in a collaborative workstation working on the same line as workers has collision risks internalized and controlled by safety specifications, and product liability applies in principle. Uncertified modifications and operations exceeding rated load and speed, because the safety internalization mechanism has been artificially removed, should be regulated through high-risk liability. In summary, scenario attribution judgment should always take whether the safety mechanism suffices to internalize risks as the substantive judgment benchmark.

The authors further ask what the problem is with the current judicial situation where none of the three cases applied product liability or high-risk liability. First, the idling of norms. Product liability application faces practical difficulties in defect proof, and high-risk liability has simply never entered the judicial vision. The two no-fault liability pathways preset by the Civil Code are simultaneously shelved, and the amount of relief victims receive depends on accidental evidence conditions rather than the normative attribution of risks. Second, the imbalance of risk allocation. Unpredictable and uncontrollable operational risks are ultimately shared by victims and users according to fault proportions, while the possessors and producers who truly initiated the hazards and benefited from them bear no liability. The principles of hazard initiation, hazard control and compensation all fail simultaneously.

The paper contrasts this with overseas cases. In the Uber autonomous vehicle fatality case in the United States, the vehicle in autonomous mode failed to correctly identify a pedestrian crossing the road. The National Transportation Safety Board investigation attributed the accident to dual factors of system perception defects and safety driver monitoring failures. Uber reached a civil compensation settlement with the victim’s family, and the safety driver was separately pursued for criminal responsibility. The liability allocation in this case unfolds along two clues of product and operation: system defects point to the manufacturer side, and operational monitoring points to the possessor side. In the Volkswagen factory robot fatality case in Germany, a robot grabbed a worker in a closed workstation causing death. The accident was absorbed through occupational injury insurance and employer liability frameworks, and no independent new liability type was developed, confirming the capture capacity of product liability and labor protection rules in closed scenarios.

Regarding the systematic connection of the dual-track liability architecture, the paper addresses three issues: the victim’s right of choice in external relationships when claims concur, the internal recovery mechanism between possessor and producer based on risk control capacity, and the disclosure obligation of operation data and mitigation of proof burden at the procedural level.

Regarding claim concurrence and the victim’s right of choice, when the same harm simultaneously satisfies the constitutive requirements of both pathways, such as a defective product operating with high autonomy in an open environment causing harm, claim concurrence is established, and the victim may choose one to exercise. The key to handling concurrence lies in the coordination of the exemption structures of the two pathways. When choosing high-risk liability, the possessor cannot assert the development risk defense. The attribution reason for hazard liability is not defect but the initiation and control of hazards. Even if the hazard cannot be avoided under existing technological levels, it does not affect the establishment of liability. The possessor can assert reduction or exemption of liability based on victim intentionality, force majeure and other grounds.

When choosing product liability, the producer can assert the development risk defense under Article 41 of the Product Quality Law. The defense should be strictly limited, confined to property damage, with the safest existing technology as the benchmark for judging technological development level. Producers who violate the tracking and observation obligation cannot assert the defense.

The exemption structures of the two pathways thus form a systematic division of labor. Hazard liability tilts toward victims, with its justification being the imposition of stricter liability on high-risk activities. Product liability maintains a balance between prevention incentives and technological innovation. Victims can choose the most favorable pathway according to the evidence conditions and the defendant’s defense capacity in individual cases. When defect evidence is available, product liability suffices for relief. When defects are difficult to prove but operational hazards are evident, high-risk liability provides fallback protection.

The right of choice enjoyed by victims in claim concurrence has sufficient normative and theoretical support in current legislation. Article 186 of the Civil Code, regarding the concurrence of breach of contract and tort liability, explicitly grants the injured party the right of choice, establishing a choice model for handling concurrence. The coexistence of operational liability and product liability in motor vehicle traffic accidents is also confirmed by Article 9 of the aforementioned judicial interpretation, which initiates the liability procedure through the victim’s request. The essence of the victim’s right of choice is to attribute the benefits of pathway selection to the risk bearer.

Regarding the internal recovery based on risk control capacity, after external liability is determined, how internal liability is allocated between the possessor and producer depends on the true source of the risk. After the possessor compensates under high-risk liability, if it is ascertained that the harm originated from a product-side risk, it may seek recovery from the producer. The normative basis can be analogically applied from Article 1203, Paragraph 2 and Article 1204 of the Civil Code. The possessor in high-risk liability and the seller who compensates first externally in product liability have similar status, both being in an intermediate position of unified external liability and internal recovery based on risk source.

Conversely, after the producer compensates under product liability, it may seek recovery from the possessor for the portion originating from improper operation by the possessor, such as unauthorized modification, removal of safety restrictions and operation beyond the expressly stated use scenario. The allocation benchmark for internal liability remains risk control capacity. The party with the closest and most economical control capacity over the risk source bears the internal liability. The determination of recovery shares can be double-measured through causal force and control capacity, first comparing the causal force of product-side defects and operation-side hazards on the harm, then modifying based on which party is closer to the risk source and can prevent harm at minimum cost. When both causal force and control capacity cannot be ascertained, the possessor and producer share equally.

The paper further addresses how the recovery procedure should operate when product design and operation status are highly intertwined and causal force is technically difficult to distinguish. First, the burden of proof allocation problem. The operation logs, algorithm versions and sensor data relied upon for causal force ascertainment are controlled by the producer and possessor. According to Article 112 of the Interpretation of the Supreme People’s Court on the Application of the Civil Procedure Law of the People’s Republic of China regarding the order for production of documentary evidence and the proof obstruction rule, if the party controlling the evidence refuses to provide it without justified reason, the court may determine that the recovery claimant’s assertion regarding the risk source is established. This means the proof dilemma in recovery litigation should be resolved by imposing disclosure obligations on data controllers rather than converting it into the recovery claimant’s risk of losing.

Second, the pre-positive problem of technical appraisal procedures. There is no mandatory pre-positive appraisal procedure in Chinese civil procedure law, and evidence appraisal is not a necessary step in litigation. In scenarios where algorithmic attribution is highly specialized, the court may commission appraisal upon party application or ex officio, and may draw on the technical investigator system in intellectual property litigation and the system of persons with specialized knowledge under Article 79 of the Civil Procedure Law to assist judges in ascertaining technical facts. If the appraisal institution cannot completely distinguish based on existing technical conditions, it should provide explanations regarding the causal force ranges of each risk source rather than simply terminating the appraisal procedure.

Third, the fallback guarantee when appraisal is impossible. If causal force size still cannot be distinguished after the above procedures, the aforementioned equal sharing rule should apply. Its justification lies not in the precision of shares but in the fact that the internal parties who created and controlled the risk should bear the adverse consequences of proof failure rather than externalizing them to the victim. This forms a progressive structure of data disclosure, technical ascertainment and equal sharing, where the technical reality of difficult causal force distinction does not collapse the normal operation of recovery rules.

Regarding operation data disclosure and mitigation of proof burden, the paper notes that regardless of which pathway is followed, the algorithm black box is a common proof obstacle. The opacity of algorithmic decision-making and its obstruction of rights relief have been repeatedly revealed by legal research in the digital age. If the dual-track liability architecture is not accompanied at the procedural level, it will again fall into the appraisal impossibility dilemma in the balance vehicle case.

The paper proposes three feasible solutions. First, stipulate the preservation and disclosure obligations of operation data for producers and possessors. Embodied intelligence should continuously record operation logs, algorithm versions and update records, and safety assessment reports, and should provide them to the court when disputes arise. Refusal to provide or inability to provide without justified reason presumes the existence of defects or hazardous operation facts.

The operation data disclosure obligation has theoretical justification. Chinese evidentiary law provisions state that if a party controlling evidence refuses to submit it without justified reason, and the party bearing the burden of proof for the fact to be proved asserts that the content of the evidence is unfavorable to the controller, the people’s court may determine that the assertion is established. The operation logs and algorithm version records of embodied intelligence are controlled by producers and possessors, which is a typical application scenario for the proof obstruction rule and can operate without waiting for special legislation.

Second, achieve objectification of defect determination under the product liability pathway, using a combination of consumer expectation standards and risk-utility standards. Specifically, the former uses ordinary consumers’ reasonable expectations of product safety as the judgment benchmark, and the latter uses the comparison of product risks and their social utility as the judgment benchmark. Both make judgments based on product external information without examining the internal logic of the algorithm.

Third, mitigate causation proof under the high-risk liability pathway. The victim’s proof of operation, harm and causation meets the standard of high probability, with the defendant bearing the burden of proof for reduction and exemption grounds. The academic proposal to draw on the causal presumption rules in food and drug torts, lower the plaintiff’s proof standard and clarify the defendant’s rebuttal obligation is consistent with the above handling direction. This fact presumption plus reversal of burden of proof approach has precedents in the Civil Code, such as the fault presumption rule in Article 1222 medical damage liability. Patients face information advantages of medical institutions, and legislators use fault presumption rules to alleviate patients’ proof dilemmas. The situation of embodied intelligence victims is the same as that of patients.

In conclusion, the paper states that for the attribution of harm caused by embodied intelligence, current law already provides normative foundations. What is lacking is the clarification of the application relationship between the two no-fault liability pathways, which is the source of judicial practice pathway divergence. Taking the dual attributes of embodied intelligence as both product and hazard source as the starting point, a dual-track liability architecture can be established with risk source as the separation benchmark and dynamic systems theory as the measurement method: product liability as the principle, covering product-side defect risks; high-risk liability as the supplement, covering operation risks of high-autonomy systems in open environments.

In external relationships, claim concurrence and the victim’s right of choice are recognized. In internal relationships, risk control capacity serves as the recovery benchmark. Operation data disclosure obligations and mitigation of proof burden serve as procedural supporting measures.

Product liability and high-risk liability together constitute the institutional whole of the Civil Code in responding to technological risks. The parallelism of motor vehicle traffic accident liability and product liability has provided a referable systematic precedent. Subsequent research should further enrich the case groups of high-risk measurement factors, and the operational rules of recovery shares await testing by judicial practice. The privacy infringement and data rights issues of embodied intelligence, as well as the coordination of insurance actuarial science, regulatory standards and attribution architecture, are all directions for next-step research.

Liability Pathway Risk Source Normative Basis Attribution Object Defense Structure
Product Liability Product-side risks including design defects, manufacturing defects, warning defects and post-circulation defects Article 1202 of the Civil Code, Article 41 of the Product Quality Law Thing (defective state at time of circulation) Development risk defense available, strictly limited to property damage
High-Risk Liability Operation-side risks including autonomous operation in open environments by high-autonomy systems Article 1236 of the Civil Code Behavior (initiation and maintenance of hazardous activity) Development risk defense unavailable; victim intentionality and force majeure may apply

The research by Huang Qingyu, Yu Zihan and Chen Yilin represents a significant contribution to the ongoing scholarly debate on how Chinese civil law should adapt to the challenges posed by embodied intelligence. By demonstrating that the existing Civil Code already provides the necessary normative tools, the authors offer a practical pathway for courts to resolve embodied intelligence harm cases without waiting for new legislation. The dual-track liability architecture they propose aims to ensure that victims of embodied intelligence harm can obtain relief regardless of whether defects can be proven, while also maintaining appropriate incentives for technological innovation and risk prevention.

Scroll to Top