California’s AI Liability Rule: Why “The AI Did It” Is No Longer a Defense

California Civil Code § 1714.46 establishes a simple rule for AI liability: defendants cannot escape responsibility by arguing that AI acted autonomously. The law preserves traditional defenses while making clear that “the AI did it” is not one of them.

California’s AI Liability Rule: Why “The AI Did It” Is No Longer a Defense
ChatGPT generated picture from: George Burn, arrested for stealing brushes and a box - North East Museums Collection on Flickr
Key Takeaways: (1) Scope: Defendants who developed, modified, or used AI alleged to have caused harm. (2) Core rule: A defendant cannot assert that the AI autonomously caused the harm as a defense. (3) Not strict liability: Plaintiffs must still establish the underlying basis for liability. (4) Traditional defenses survive: The statute expressly preserves defenses involving causation and foreseeability. (5) Comparative fault survives: Defendants may introduce evidence concerning the fault of another person or entity.

Effective date: January 1, 2026.

Authority: California Civil Code § 1714.46, enacted through AB 316.

California has enacted a remarkably short artificial intelligence law with potentially significant consequences for civil litigation.

California Civil Code § 1714.46 provides that when a defendant developed, modified, or used artificial intelligence that allegedly caused harm, the defendant cannot defend the case by arguing that the AI autonomously caused the harm. The provision was enacted through AB 316 (Stats. 2025, ch. 672)


In California, “The AI did it” is not a defense.

That does not mean that anyone who develops or uses AI automatically becomes liable whenever something goes wrong. Section 1714.46 does not create strict liability, establish a new AI tort, or eliminate traditional defenses involving causation, foreseeability, or comparative fault.

What Counts as Artificial Intelligence?

If the definition in Cal Civ § 1714.46 looks familiar, it should.

AB 316 uses the same definition of artificial intelligence that California previously adopted through AB 2885 for several other statutory contexts. AI is an “engineered or machine-based system” that varies in autonomy and can, for explicit or implicit objectives, infer from inputs how to generate outputs capable of influencing physical or virtual environments.

I previously broke down that definition in detail in California Defines AI: AB 2885 and Its Impact, including its focus on AI systems rather than models, varying levels of autonomy, inference, objectives, and outputs.  

What is new here is not the definition—it is what California does with it.

Civil Code § 1714.46 takes that familiar definition and places it in California's law of civil obligations. When an AI system falling within that definition is alleged to have caused harm, a defendant who developed, modified, or used it cannot defend the action simply by asserting that the AI autonomously caused the harm.

California is doing something quite targeted: preventing AI autonomy itself from becoming a liability shield.

Who Does the Law Apply To?

Cal. Civ. § 1714.46 applies in an action against a defendant who "developed, modified, or used artificial intelligence" that is alleged to have caused harm to the plaintiff. 

Section 1714.46 applies in an action against a defendant who “developed, modified, or used” artificial intelligencealleged to have caused harm.

These are not separately defined categories of regulated actors. Instead, the statute uses three broad descriptions of conduct that potentially connect a defendant to the AI involved in the alleged harm.

Readers familiar with the EU AI Act may see some resemblance to its categories of providers and deployers, but the concepts should not be treated as interchangeable. As discussed in our article Who Is Regulated Under the EU AI Act? Understanding Providers, Deployers, Importers, Distributors and Other Operators, the EU AI Act establishes specifically defined regulatory roles across the AI value chain, including providers, deployers, importers, distributors, authorized representatives, and certain product manufacturers. 

California Civil Code § 1714.46 does something much simpler.

Developed

A defendant that developed the AI may fall within the statute.

There is an obvious conceptual resemblance to an EU AI Act provider, but the California term is broader and less prescriptive. Under the EU AI Act, being a provider is not synonymous with simply writing or developing the technology. Provider status also depends on matters such as having an AI system or GPAI model developed and placing it on the market or putting the system into service under one's own name or trademark. 

Section 1714.46 does not impose those additional elements. It simply refers to a defendant who “developed” the AI.

Modified

The statute separately includes a defendant that modified the AI.

Again, there is an interesting parallel with the EU AI Act—but an important difference.

Under the EU AI Act, modification can change an organization's regulatory status. As discussed in my EU AI Act article, Article 25 can cause a distributor, importer, deployer, or other third party to assume the obligations of a provider when, among other circumstances, it makes a substantial modification to a high-risk AI system. 

California's provision is considerably broader on its face. Section 1714.46 says “modified,” not “substantially modified,” and does not condition its application on the modification transforming the defendant into another regulatory category.

That distinction may prove significant.

Used

Finally, the statute reaches a defendant that used the AI allegedly causing the harm.

This comes closest conceptually to the EU AI Act's deployer, a person or entity that “uses an AI system under its authority.

But once again, the California language is simpler and potentially broader.

Section 1714.46 does not use the defined concept of “deployer,” does not say “under its authority,” and does not expressly contain the EU AI Act's personal-use limitation. The relevant statutory word is simply “used.”


California Is Not Importing the EU AI Act's Operator Framework

California appears to cast a deliberately simple net: Did the defendant develop, modify, or use the AI alleged to have caused the plaintiff's harm?

If so, the defendant cannot escape the action merely by asserting that the AI acted autonomously.

That distinction also reinforces what I think is one of the most interesting themes in this law: California law isn't trying to determine who “owns” the AI's conduct through a complex operator taxonomy. It is making sure that autonomy itself does not create a gap in ordinary civil responsibility.


Practice Tip: Do not assume that in California using a third-party AI system transfers responsibility to the AI developer. Section 1714.46 expressly reaches defendants that developed, modified, or used the AI allegedly involved in the harm. Organizations integrating AI into products, services, decision-making processes, or autonomous workflows should therefore consider potential tort exposure as part of AI governance—even when somebody else built the underlying model. Individuals using such products and services should consider it as well.

3. The Prohibited Defense: “The AI Did It”

Here is the heart of the law.

When a defendant developed, modified, or used AI that allegedly caused harm, the defendant cannot argue that the AI autonomously caused the harm as a defense.

California has taken that argument off the table. This becomes particularly important as AI systems gain greater autonomy and can make decisions or take actions with limited human involvement.

Consider the recent OpenAI/Hugging Face incident. As discussed in my article Alabama Subpoenas OpenAI After Autonomous AI Agent Escapes Testing Environment and Hacks Hugging Face, an experimental AI agent reportedly escaped its testing environment and conducted an unauthorized intrusion into external systems without OpenAI initially realizing what had occurred. 

The incident is not a § 1714.46 case—at least not yet?—but it illustrates exactly the kind of autonomy problem the law addresses. If similar facts gave rise to a California civil action, OpenAI could not simply argue: “We didn't tell the AI to do that; it acted on its own.”

Practice Tip: Governance implication: Organizations should treat responsibility for increasingly autonomous AI as something that must be allocated and managed, not outsourced to the machine.

But This Is Not Strict Liability...

That does not necessarily mean the defendant would automatically be liable. Section 1714.46 expressly preserves defenses involving causation, foreseeability, and comparative fault.

In other words, a defendant could still argue that its conduct did not cause the harm, that the harm was not reasonably foreseeable, or that another person or entity was responsible.


The AI's autonomy cannot itself be the defense. Whether the defendant is actually responsible for the harm remains a separate question.

4. AI Is New. The Question of Responsibility Is Not

California could have placed this rule in a standalone AI regulatory framework alongside requirements for disclosures, risk assessments, developer obligations, or government enforcement.

It did something different.

Section 1714.46 sits in the Civil Code's “Obligations Imposed by Law.” That Part begins with § 1708's foundational rule that every person has a noncontractual obligation to refrain from injuring another person's person, property, or rights. The provisions that follow address civil liability, available defenses, remedies, and circumstances in which liability may be limited or excluded.

The technology may be new.

The underlying legal question is very old:

When someone is harmed, who bears responsibility?

Section 1714.46 gives us at least one part of California's answer: the machine's autonomy does not, by itself, relieve the humans and organizations behind it of responsibility.


California is not regulating how AI must be developed or deployed. It addresses how existing principles of civil responsibility apply when AI enters the causal chain.

Because the statutory language is so concise, it is equally important to identify what the Legislature did not include.

Section 1714.46 does not expressly:

  • Create a standalone cause of action.
    The provision speaks of an existing “action against a defendant” whose AI is alleged to have caused harm.
  • Create strict liability for AI.
    Plaintiffs must still establish the requirements of whatever cause of action they bring.
  • Establish a negligence standard specifically for AI.
    The statute does not prescribe development, testing, monitoring, or safety requirements.
  • Eliminate causation or foreseeability defenses.
    It specifically preserves them.
  • Make one actor responsible for everyone else's conduct.
    Comparative fault remains available.
  • Apply only to AI developers.
    It expressly covers development, modification, and use.

Conclusion

Section 1714.46 is short, but its principle is consequential: as AI becomes more autonomous, autonomy does not become a liability shield. California leaves ordinary questions of causation, foreseeability, and comparative fault intact, while removing one increasingly plausible defense—“the AI did it.”


AI autonomy ≠ legal autonomy: The statute recognizes that AI may operate autonomously without treating that autonomy as an independent liability shield.

Additional Resources

  • California Civil Code § 1714.46 — Artificial Intelligence and Civil Liability — The operative provision establishing that a defendant may not assert that AI autonomously caused the plaintiff’s harm as a defense, while preserving other defenses, including causation, foreseeability, and comparative fault. Read § 1714.46
  • California Assembly Bill 316 (2025–2026), Chapter 672 — The legislation that added § 1714.46 to the California Civil Code. Read AB 316
  • California Civil Code, Part 3 — Obligations Imposed by Law — The broader statutory framework in which § 1714.46 sits. It begins with § 1708’s foundational obligation to refrain from injuring another person, their property, or their rights. Read Part 3
  • The de la Torre Review — “California Defines AI: AB 2885 and Its Impact” — Explains in detail the California AI definition used in § 1714.46, including its treatment of autonomy, inference, objectives, inputs and outputs, and the distinction between AI systems and AI models. Read the article
  • The de la Torre Review — “Who Is Regulated Under the EU AI Act? Understanding Providers, Deployers, Importers, Distributors and Other Operators” — Provides a useful comparison with the EU AI Act’s more detailed approach to allocating responsibility among providers, deployers, importers, distributors, and other actors in the AI value chain. Read the article
  • The de la Torre Review — “Alabama Subpoenas OpenAI After Autonomous AI Agent Escapes Testing Environment and Hacks Hugging Face” — A real-world illustration of the responsibility questions that arise when an autonomous AI agent allegedly takes consequential actions that its developer did not specifically direct or initially detect. Read the article

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe