Why "The AI Did It" Is No Longer a Defense
In May 2026, a federal court quoted the comedian Flip Wilson to reject the government's argument that an AI system made a decision independently. "That excuse did not work for Geraldine Jones, and it does not work for the Government," the court wrote.
The legal landscape has shifted. Courts in the US, Germany, and the Netherlands have held deployers liable for AI-generated harm. California has eliminated the autonomous-harm defense entirely. Colorado requires impact assessments and risk management programs. The EU AI Act mandates tamper-evident logging for high-risk systems. The direction is consistent across jurisdictions: deploying an AI agent does not transfer responsibility. It concentrates it.
For organizations building and deploying AI agents, the question is no longer whether they are liable. It is whether they can demonstrate the oversight that the law now requires.
The autonomous-harm defense is dead
California's AB 316, effective January 1, 2026, adds Civil Code section 1714.46, which provides that in any civil action against a defendant who "developed, modified, or used" an AI system alleged to have caused harm, the defendant may not assert as a defense that "the artificial intelligence autonomously caused the harm."
The law preserves traditional defenses, causation, foreseeability, comparative fault. It does not create strict liability. What it removes is the specific argument that the AI acted on its own, beyond the developer's or deployer's control.
The legislative history cites Moffatt v. Air Canada (2024), where Air Canada argued its chatbot was a "separate legal entity." The tribunal rejected this and held the airline liable for the chatbot's inaccurate bereavement fare information. California codified the principle: if computers cannot be accountable, and they are nonetheless making decisions, accountability shifts to those who built, modified, or deployed them.
AB 316 applies across the supply chain, to anyone who "developed, modified, or used" the system. A foundation model developer, a fine-tuner, an integrator, and a deployer are all within scope. The defense is unavailable to all of them.
What deployers must actually show
If "the AI did it" is unavailable, deployers need affirmative evidence of responsible oversight. The documentation requirements are specific and escalating.
California
AB 2013 (effective January 1, 2026) requires entities that design, build, or substantially modify generative AI systems to publish a high-level summary of training data on their website. The summary must cover data sources, volume, collection methods, intellectual property status, and whether personal information was included. "Substantial modification" includes retraining or fine-tuning that materially changes functionality. Enforceable through California's Unfair Competition Law, with potential for private litigation.
AB 331 (Automated Decision Tools) requires deployers to perform impact assessments for automated decision tools by January 1, 2025, and annually thereafter. Private right of action for algorithmic discrimination starting January 1, 2026. Penalties up to $10,000 per violation.
Colorado
Colorado's original AI Act (SB24-205) required deployers of high-risk AI systems to implement risk management programs, complete impact assessments before deployment and at least annually, retain records for three years, and notify the attorney general within 90 days of discovering algorithmic discrimination. Governor Polis signed SB 189 on May 14, 2026, delaying the effective date to January 1, 2027 and narrowing the requirements to focus on transparency and disclosure. Deployers must provide pre-use consumer notices and adverse outcome explanations within 30 days. Developers must provide deployers with intended uses, harmful uses, training data summaries, and oversight instructions.
The revised law allocates liability: deployers are liable when they deploy automated decision-making technology in a manner not intended, documented, or marketed by the developer.
European Union
The EU AI Act's Article 12 requires high-risk AI systems to technically allow for automatic event logging over the lifetime of the system. Logging capabilities must enable recording of events relevant to identifying risks, facilitating post-market monitoring, and monitoring system operation. For remote biometric identification systems, minimum logging must include the period of each use, the reference database, the input data that led to a match, and the identification of natural persons involved.
Article 19 requires providers to keep logs for at least six months. Deployers must keep logs under their control for the same period. Article 18 requires static compliance documentation retained for ten years.
The practical logging standard, as interpreted by legal analysts: logs must capture timestamps, session and user IDs, model identifiers and versions, input hashes, outputs, model parameters, downstream actions, and retention classes. "Technically allow" rules out a logging policy that depends on operators remembering to enable it. "Over the lifetime" extends past initial deployment through every update and retraining.
The EU Revised Product Liability Directive (December 2024) classifies AI as a "product" and reverses causation burdens. If plaintiffs show AI caused harm and could not access information to prove defect, defendants must prove the system was not defective.
Singapore
Singapore's Model AI Governance Framework for Agentic AI, launched in January 2026, establishes four governance dimensions. Assess and bound risks upfront. Ensure meaningful human accountability. Implement technical controls and processes. Enable end-user responsibility. The framework requires organizations to evaluate system linkages, data sensitivity, autonomy, and cascading effects before deployment. Human oversight must remain central, with clear allocation of responsibilities and approval checkpoints before high-risk actions.
The framework is voluntary. Its influence is not.
Courts are already deciding
The case law is accelerating. Courts are consistently rejecting the defense that AI systems act independently, and they are holding deployers to specific standards of oversight.
In American Council of Learned Societies v. NEH (SDNY, May 2026), the government suggested that a viewpoint-based classification was ChatGPT's doing, rather than the government's. The court rejected this. Personnel "did not examine any of the applications or underlying materials." There was "not a scintilla of evidence" of meaningful review of AI-generated rationales. The absence of a single example where a human disagreed with AI output was noted.
In Garcia v. Character Technologies (M.D. Fla., May 2025), the court held a chatbot is a "product" for strict products liability purposes and rejected the First Amendment defense. Design defect and failure-to-warn claims were allowed to proceed.
In Mobley v. Workday (N.D. Cal., 2024-2025), the court held Workday liable as an "agent" even without a direct employment relationship, rejecting the defense that Workday was "just a software vendor." The court found that Workday's software was "participating in the decision-making process," not simply implementing criteria set by employers.
In OLG Hamm (Germany, May 2026), a business was held fully liable for false statements by its AI chatbot under unfair competition law. The court ruled that "generative models produce false outputs even from correct input data; hallucination is a property of the generation process, not a data error." Even proving the system was fed only correct data did not relieve liability.
In the Amsterdam District Court (March 2026), X Corp. was held directly responsible for harmful outputs generated by Grok. The court rejected the defense that "users are the ones prompting the AI," stating: "The entity that designs and controls the system remains the 'designated responsible party.'" A binding injunction required safeguards with a penalty of 100,000 euros per day for non-compliance.
In Munich (May 2026), Google was held liable for defamatory content in AI Overview search results. The court ruled Google is responsible and must remove the comments and prevent repetition.
The documentation gap
The regulations and case law converge on a common requirement: deployers must demonstrate responsible oversight through documented evidence. Not after the fact. Before deployment and throughout the system's lifetime.
Clifford Chance identified the core problem in a February 2026 briefing: legacy technology agreements designed for software that operates under human direction say little about a customer's ability to understand or control an AI agent's behavior. Yet when something goes wrong, it is the customer who must justify that behavior to regulators, auditors, customers, and courts. The agent acts. The human answers. Without a mandate record, the human has nothing to answer with.
A legal finance analysis from February 2026 put it directly: "The 'black box' argument is dead. The 'trade secret, can't disclose' defense is dead. Plaintiffs' counsel are targeting AI Act compliance documentation. Without it, defendants walk into court with no defense."
The documentation required is not a monitoring dashboard or a logging policy. It is a record of what was authorized, by whom, within what bounds, subject to what regulations, and whether the agent stayed within those bounds for every action taken. Courts and regulators need a document they can examine. Logs are not that document.
What this means for deployers
The trajectory is clear. Across US state law, EU regulation, Singapore guidance, and court decisions in multiple jurisdictions, the same four requirements are emerging: human oversight, traceability, bias prevention, and demonstrable accountability.
The question courts ask is no longer whether an AI agent caused harm. It is whether the deployer can prove they exercised responsible control. As one legal analyst told Computerworld: "Once the AI is the author, the company is the publisher."
Deployers need named humans at accountability nodes, verification gates before AI output ships, and audit trails that survive discovery. "The model recommended it" is a legally empty sentence.
The infrastructure to support this does not yet exist in most organizations. It needs to be built, not as a compliance exercise, but as the operational layer that makes AI deployment defensible.
Truss records mandate boundaries before execution and creates a verifiable chain of custody for every agent action. When a court asks whether an action was authorized, the answer is a record. When a regulator asks whether the deployer exercised oversight, the answer is a record. When a counterparty asks whether the agent stayed within its scope, the answer is a record.
The law is written. The obligations are in force. The infrastructure to meet them is what we are building.