Back to front page
Policy August 24, 2026

"The AI Did It" Is No Longer a Defense in California

California's AB 316 bars defendants who developed, modified, or used AI from relying on the system's autonomy as a defense. A recent Ninth Circuit decision shows why the technical and legal facts around agent use still matter.

For years, a quiet assumption floated through enterprise legal and product teams: if an AI system did something harmful on its own — if it routed a transaction incorrectly, generated false information in a medical context, or took an automated action that hurt a customer — the autonomous nature of the system might provide some cover. Not in California anymore.

On January 1, 2026, California Assembly Bill 316 took effect, adding a single, narrow provision to the state's Civil Code. Section 1714.46 says that a defendant who developed, modified, or used an AI system may not assert that the AI autonomously caused the plaintiff's harm as a defense. Governor Gavin Newsom signed the bill on October 13, 2025.

One Sentence. Nineteen Words. A Very Large Blast Radius.

The statute is surgical in its scope. It does not create strict liability. It does not eliminate traditional defenses such as causation, foreseeability, or comparative fault. What it removes is a specific exit ramp when AI causes harm: "We didn't tell it to do that; it decided on its own."

That defense is unavailable in a California civil action to a defendant that developed, modified, or used the AI at issue. The provision can reach different parts of an AI supply chain, but it does not itself decide who is liable; plaintiffs still have to establish the elements of their claims and defendants retain the other defenses the statute expressly preserves.

That distinction matters. A foundation-model developer, an agent builder, and an enterprise deployer may each face different factual and legal questions. The law removes one argument from that analysis; it does not collapse those questions into a single automatic result.

The Ninth Circuit Drew a Narrower Federal Line

AB 316 operates in California civil actions. A related federal development is narrower, and points in a different direction than a simple rule that a deployer is always the legal actor. On August 4, 2026, the Ninth Circuit vacated a preliminary injunction in Amazon.com Services, LLC v. Perplexity AI, Inc. The court held that, on the record before it, the user — helped by Perplexity's AI assistant — accessed Amazon's computers, not Perplexity itself.

The opinion turned on the system's technical facts: Perplexity's servers did not directly communicate with Amazon's servers, and the browser ran locally on the user's machine. The panel expressly left open whether different facts showing more control could produce a different result.

Together, the developments make a more practical point for AI teams. California has foreclosed an autonomy-based defense in the defined civil actions, while the federal access analysis remains fact-specific. Product architecture, authorization, logging, and the human role in an agent's operation are not interchangeable details.

What This Means for Enterprise AI Teams Right Now

The most immediate compliance signal is documentation. When courts evaluate an AI-related claim, they will examine what enterprise teams configured, authorized, and monitored. An audit trail is no longer just a useful engineering practice; it can be evidence.

Risk can arise when agents follow harmful explicit instructions, infer unauthorized actions from ambiguous prompts, make unilateral decisions outside a reasonable interpretation of their instructions, or propagate a failure through a multi-step pipeline. The legal result will depend on the claim and the facts, but each pattern makes configuration choices relevant.

Approval policies, scope restrictions, and logging settings that once looked purely operational can also become legal artifacts. Teams should be able to show both what an agent was allowed to do and the controls intended to keep it from doing more.

The EU Closes In by December

AB 316 does not exist in isolation. The EU's revised Product Liability Directive, Directive (EU) 2024/2853, applies from December 9, 2026 to products placed on the market or put into service after that date, bringing software and AI systems into a modernized product-liability framework.

Enterprises still treating AI liability as a future-state problem should take note: in California — home to many of the world's major AI companies — one important change arrived in January. The question is no longer whether an AI acted autonomously; it is how the surrounding people, controls, and evidence will be evaluated.

Sources

California Legislative Information — AB 316: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202520260AB316

U.S. Court of Appeals for the Ninth Circuit — Amazon.com Services, LLC v. Perplexity AI, Inc.: https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf

EUR-Lex — Directive (EU) 2024/2853 on liability for defective products: https://eur-lex.europa.eu/eli/dir/2024/2853/oj

Brownstein Hyatt Farber Schreck — Who's liable when AI agents misbehave?: https://www.bhfs.com/insight/whos-liable-when-ai-agents-misbehave-2/

Legal Tech Digest — California, Europe clamp on defenses blaming AI for harm: https://legaltechdigest.com/news/california-europe-clamp-on-defenses-blaming-ai-for-harm

AccordShield — AI-agent liability and the Ninth Circuit: https://accordshield.com/blog-ai-agent-liability-ninth-circuit-2026