Category: Regulation
California Assembly Bill 316 took effect January 1, 2026. It prohibits the use of AI autonomy as a defense in civil litigation. An organization that deploys an AI agent cannot argue in a California court that the agent acted on its own and therefore the organization bears no responsibility for the outcome.
The liability lands on the deployer regardless of how autonomous the agent was, regardless of whether the deploying organization intended the agent's actions, and regardless of whether the agent behaved within its design parameters.
The Case Law Foundation
The legal foundation for AB 316 was already being built before the statute passed. In Moffatt v. Air Canada, a court held that an organization was liable for commitments made by an autonomous agent even when those commitments directly contradicted the organization's internal policy. The agent promised a bereavement fare discount. The policy said no such discount existed. The court ruled Air Canada responsible for the promise its agent made regardless of the agent's autonomy.
The principle: organizations are accountable for what their agents commit to on their behalf. AB 316 made that principle statutory in California.
The Evidentiary Dimension
In February 2026, the Southern District of New York ruled in United States v. Heppner that written exchanges between a defendant and Claude are not protected by attorney-client privilege. The first ruling of its kind nationwide. The implication extends beyond privilege. If AI interactions are discoverable in litigation, every organization needs to know exactly what their agents produced, what instructions they were operating under, and what actions they took.
The audit trail is not just a compliance requirement. It is litigation preparation.
What Deployers Now Own
Under AB 316 combined with the Moffatt precedent, California deployers own the full liability surface of their agents. Every commitment an agent makes on behalf of the organization. Every action it takes in a customer interaction. Every decision it reaches in an automated workflow. The legal shield of AI autonomy is gone.
What remains is the organization's ability to demonstrate that the agent was operating within a defined, documented, and verifiable scope of authority when the relevant action occurred. That demonstration requires records that most organizations do not currently maintain: a signed per-agent authorization record showing exactly what the agent was allowed to do, produced at execution time, not reconstructed from logs afterward.
The National Direction
California tends to lead on liability law. AB 316 is unlikely to remain California-only. The June 2 White House Executive Order on criminal enforcement, the Moffatt precedent, and the global trend toward deployer liability in AI governance frameworks all point in the same direction. The AI autonomy defense is being dismantled systematically.
Organizations building deployer liability documentation into their agent infrastructure now are building for the legal environment that is coming everywhere, not just California.
Sources: California AB 316 Analysis and Harvard Law Review on United States v. Heppner