Control and its limits
Who is liable when an AI system causes harm, or an agent acts?
Short answerThe people and organizations behind the system. California now says so in statute: a party that developed, modified, or used an AI system cannot defend itself by saying the system caused the harm on its own. With agents, the hard part is a record showing who stood behind the action.
What California changed
California AB 316, in effect since January 1, 2026, bars a defendant who developed, modified, or used an AI system from asserting that the system autonomously caused the harm. It leaves causation, foreseeability, and comparative fault intact. What it removes is one argument: the machine did it.
Its definition is worth noticing. AB 316 reaches a system that can "infer from the input it receives how to generate outputs," the same functional test the EU AI Act uses in Article 3(1). Two jurisdictions with little in common arrived at the same line independently, and the line is whether a system infers, whatever it is built from. More on that line in what people mean by AI.
Developer or operator
Two models for allocating responsibility are in play, and they place the exposure differently.
- Developer liability. Responsibility runs to whoever designed and trained the system, by analogy to product liability.
- Operator liability. Responsibility runs to the organization that deployed it, whoever built it.
In financial services this is already concrete. A bank that deploys a third-party model is an operator; the lab that trained the model is a developer. Which model prevails decides who carries the risk.
Agents and the identity gap
With an agent, the liable parties are the same. What changes is the evidence. When a person acts inside a system, the record says who they were. When an autonomous agent acts, in most deployments today, the record says "service account": no agent, no authority, no instruction. A rule can assign liability before that gap closes. Enforcing it takes a record that names someone, which is why attribution is far from administrative detail.
Where standards are heading
- NIST opened an AI Agent Standards Initiative in February 2026, explicitly addressing agents run without dedicated identity, authorization, or accountability controls.
- Singapore published the first comprehensive governance framework for agentic AI in January 2026, requiring each agent to carry a verifiable identity and an audit trail of which agent acted under whose authority.
- The EU AI Act applies Articles 14 and 15, on human oversight and on system reliability, to autonomous agents in high-risk settings.
The NIST and Singapore items come from secondary reporting. Read the primary documents before relying on their detail.
What to check
- List every agent with standing authority to act in your systems, and the identity each one runs under.
- For each, confirm the record can show which agent acted, under whose authority, and on what instruction.
- For each third-party model you deploy, find what the contract says about who carries the risk, and have counsel read it with AB 316 in mind.
Sources
- California Assembly Bill 316 (Krell), Artificial intelligence: defenses, chaptered October 13, 2025, effective January 1, 2026. Bars the autonomy defense; leaves causation, foreseeability, and comparative fault intact. Defines AI by whether it infers from input how to generate outputs. Read the section itself before relying on any summary of it.
- European Union, Artificial Intelligence Act, Article 3(1); Articles 14 and 15.
- Baker McKenzie, United States: Legal Accountability for AI Agents, June 2026. Developer and operator liability models; California AB 316. Law-firm analysis.
- Berkeley Technology Law Journal, Multi-Agent AI is Outpacing the Liability Frameworks Built for Single-Agent Systems, June 2026.
- NIST Center for AI Standards and Innovation, AI Agent Standards Initiative, February 2026; Singapore IMDA, Model AI Governance Framework for Agentic AI, January 2026. Agent identity and authorization. Reached via secondary reporting; primaries not yet retrieved.
Reviewed