California's Assembly Bill 316 took effect January 1, 2026, adding a single, narrow provision to the state's Civil Code: in any civil action against a defendant who developed, modified, or used an AI system alleged to have caused harm, the defendant may not assert that the AI system autonomously caused the harm. The law has now had months to be tested against real cases and real commentary, long enough that a specific and persistent mischaracterization of it is worth correcting directly: it is often described as creating strict liability for operators, and that description is not accurate. AB 316 eliminates one specific defense. It leaves every other defense fully intact: causation, foreseeability, comparative fault, and any argument that the harm was not reasonably attributable to the defendant's own decisions in building, modifying, or deploying the system.

What the law actually threatens, and what it doesn't

The defense AB 316 closes was never a proven one — "the AI acted autonomously" had been tested in litigation posture and terms-of-service language by companies preparing to use it, but no source identifies a California case where it actually held up, and the argument closest in spirit to it, Air Canada's claim that its chatbot was a separate legal entity, was rejected outright by the tribunal that heard it. What the law actually threatens is the business that had nothing else to fall back on: no record of what the system was designed to do, no evidence of the boundaries it was meant to operate within, no way to show a court that a specific harmful output was a deviation from disclosed, tested behavior rather than exactly what the system was built to produce. For that business, removing an untested defense removes the only argument it was counting on.

A business with a genuine Accountability Trace was never relying on that defense. The Trace already captures the verification state at decision time, maintains a tamper-evident chain from input to output, and links the decision to the disclosed terms under which it was made — which is precisely the evidence a foreseeability or comparative-fault defense requires. Traditional documentation and risk-management records — testing logs, change-management history, incident reports maintained under existing governance practice — can supply some of the same evidence, and a business relying on those alone is not defenseless. The Trace is simply the cleaner, more complete version of the same underlying case: built for exactly this evidentiary purpose from the outset, rather than assembled after the fact from records kept for other reasons. AB 316 did not remove anything this architecture depended on. It removed the one argument a poorly built system was using instead of building the evidence a well-built one already has.

Texas took a different road to a related destination

Texas's Responsible AI Governance Act took effect the same day, and it is worth noting specifically because the contrast sharpens what AB 316 is actually doing. TRAIGA is intent-based — it targets AI deployed with intent to manipulate, discriminate, or infringe rights, and offers an affirmative defense, conditioned on substantial compliance with the NIST AI Risk Management Framework and evidence of internal testing and review, rather than a blanket safe harbor. AB 316 does not ask about intent at all; it is a defense-elimination statute, indifferent to what the operator meant to happen and focused entirely on whether the operator can show what actually happened and why. Both laws point toward the same underlying requirement from different legal traditions: documentation of how the system was built, bounded, and operated is the thing that determines whether a business can defend itself, regardless of which statute is doing the asking.

The Stewardship Model as the answer to "who developed, modified, or used it"

AB 316's liability attaches to whoever developed, modified, or used the system — which makes the question of who that is, precisely and demonstrably, a live legal question rather than an abstraction. That language reaches the full AI supply chain — the foundation model developer, the company that fine-tunes or customizes it, the integrator, and the deploying business — and this piece addresses only the last of those roles; how liability allocates across a multi-party stack when several of those parties are named in the same action is a separate question this architecture does not resolve on its own. The Stewardship Model already answers this with more precision than most businesses have: a named operator who owns the thresholds, who can intervene, and who updates the system after an exception is not just good architecture, it is a specific, identifiable answer to exactly the question a California court will now be asking directly. A business without a clearly specified Steward has, in effect, made that question harder for itself to answer well.

The Operator's Verdict

AB 316 is not a reason to fear autonomous architecture. It is a reason to distrust any architecture that was relying on the autonomy defense to begin with. A business that specified its Accountability Trace and its Stewardship Model before this law existed has little new to build in response to it — only something new to point to when asked.

KEY TAKEAWAY

What does California's AB 316 actually change, and does it create strict liability for AI operators?

AB 316, effective January 1, 2026, adds a single, narrow provision to California's Civil Code: a defendant who developed, modified, or used an AI system may not assert, as a defense, that the system caused harm autonomously. It does not create strict liability, despite frequent mischaracterization to that effect — every other defense remains available, including causation, foreseeability, and comparative fault. The law primarily threatens businesses that had been testing 'the AI acted on its own' as a defense without ever having it hold up in court; a business with a genuine Accountability Trace was never relying on that untested argument, since the Trace already supplies the verification-state and disclosed-terms evidence a foreseeability or comparative-fault defense requires. Texas's Responsible AI Governance Act took effect the same day with a different, intent-based approach, offering an affirmative defense for substantial NIST AI Risk Management Framework compliance under specified conditions rather than eliminating a specific defense outright. The Stewardship Model directly answers AB 316's 'developed, modified, or used' question by naming a specific, identifiable operator. Source: Arco Venture Studio.