A Californian who gets mangled by a chatbot now has an easier path to court than a Belgian denied a mortgage by one, and that inversion is the whole story of AI liability laws in 2026. Europe spent years drafting the plaintiff-friendly rulebook, then killed it. California, which never wrote a comprehensive one, just passed a law saying a company can no longer stand up in court and blame the algorithm. The continent that talks loudest about protecting people from AI quietly made it harder to sue over AI harm, and the country that talks least about it made it easier. I have been chewing on that contradiction for a week, and it still bothers me.

I parked this whole subject when I wrote up the AI Act hitting its August deadline, and then parked the European half of it again in the piece on the withdrawn liability directive and the standards that do not exist yet. Both times I said the international comparison was its own post. This is that post. The short version of the European mechanics: the Commission tabled an AI Liability Directive in September 2022, spent two years failing to get the member states to agree on it, and formally withdrew it in 2025, leaving a revised Product Liability Directive to cover the consumer cases and twenty-seven national court systems to fight over the rest. If you want the full autopsy, it is in that second piece. What I want here is the map, because Europe did not do this in a vacuum, and the rest of the world is a genuine mess.

The country doing the opposite of what you would expect

The United States has no federal AI liability statute, and on current form it is not getting one soon. There is a bill, the AI LEAD Act, sitting in the Senate as S.2937, which would classify AI systems as products and build a developer-focused liability framework at the federal level. It is a bill on a docket, nothing more, and the federal posture around it is actively hostile to the whole project. The June 2026 executive order pushed to pressure states out of regulating AI at all, and it explicitly did not preempt the state laws already on the books. So the thousand-plus AI bills that have moved through state legislatures over the past two years all still bite.

That state layer is where the real action is, and it is pulling in the exact opposite direction from Brussels. Colorado’s AI Act, live as of the end of June, forces impact assessments, risk-management programs, human oversight and incident reporting on high-risk systems, and it hands consumers a private right of action for algorithmic discrimination. Texas passed its Responsible AI Governance Act, effective at the start of the year, banning manipulative and discriminatory systems and building a sandbox and an advisory council around it. But the one that actually made me sit up is California AB 316, which strips out the defense that the harm was the AI’s fault rather than the company’s. No more “the model did it autonomously, take it up with the machine.” That is precisely the black-box escape hatch the European directive was written to close with a causation presumption, and California closed it with a single statute while the directive built to do the same thing was being buried in the Official Journal.

The courts got there before some of the legislatures did. In the Character Technologies litigation, a federal court let a wrongful-death claim proceed on a theory that treats an AI companion’s outputs as a product, opening the door to strict liability over a chatbot the same way you would sue over a defective brake. Other rulings have pinned employment-discrimination liability directly on the vendors of AI hiring tools. None of this is tidy, and it is being assembled case by case out of ordinary tort and product law rather than a purpose-built regime, which is the American way of doing everything. The irony writes itself: the jurisdiction with the loudest “we do not regulate AI” branding is accidentally building the most plaintiff-friendly AI liability environment in the West, through fifty legislatures and a pile of lawsuits, at the exact moment Europe backed away from doing it on purpose.

Britain is muddling through, which is very on brand

The UK made its choice early and has stuck to it: no AI Act, no dedicated liability law, lean on the common law and the existing regulators. In practice that means judges applying centuries-old negligence and product-liability doctrine to problems those doctrines never anticipated, and it is already showing strain. The Getty Images fight against Stability AI exposed how badly territorial and intellectual-property theories fit a model trained everywhere and deployed nowhere in particular, and the courts have been candid about working without a map.

Two things are moving underneath that hands-off posture, though, and they matter more than the headline suggests. The Data (Use and Access) Act, passed in 2025, tore up the old automated-decision rules and wrote a UK-specific regime in their place, pushing the data regulator toward binding codes of practice on AI. And at the end of July 2025, the Law Commission launched the first full review of Britain’s product liability regime since the Consumer Protection Act of 1987, aimed squarely at whether software and AI count as “products” you can sue over. An initial report is expected sometime in 2026. So the UK is not really doing nothing. It is doing the slow version, updating the plumbing quietly rather than passing a landmark law, and betting that adapted old rules plus regulator codes get it most of the way there without the compliance drag Europe just saddled itself with.

Canada killed its law too, for a completely different reason

Here is the detail that reframes the European withdrawal for me. Brussels was not the only Western capital to kill an AI framework in this window. Canada’s Artificial Intelligence and Data Act, the AIDA, part of the Bill C-27 package, died on the order paper on January 6, 2025 when Parliament was prorogued amid the political chaos around Trudeau’s exit. Same season, second dead framework, and the causes could not be more different. Europe’s collapsed under committee deadlock and a deliberate deregulatory shove, while Canada’s got killed off almost by accident, a bill that ran out of parliamentary runway when the government fell apart. The effect on the ground is identical, though: another G7 country that spent years drafting comprehensive AI rules and now has none, its citizens back to whatever provincial and federal tort law already offered. Two of the West’s most serious attempts at governing AI harm went into the ground within weeks of each other, one shot and one that simply expired, and almost nobody outside the specialist press connected them.

Everyone else is scattered further still. South Korea beat even Europe to a comprehensive national framework, its AI Basic Act taking effect in early 2026, though it leans harder on promoting the industry than on giving victims a cause of action. China shipped its own approach, which I covered in the AI Act piece: mandatory content labeling and a registry that governs generative AI for control rather than for anyone’s right to sue. Line them all up and there is no consensus anywhere. Nobody agrees on whether AI needs its own liability law or who should carry the burden of proof, and they cannot even agree on whether an AI system counts as a “product” to begin with. That last question, which sounds like a footnote, is the hinge the whole thing turns on.

Why “harmonization” is the word doing all the work

The entire European project, the reason the AI Act exists in the form it does, is harmonization: one rulebook for a single market of 450 million people, so a company builds once and sells everywhere and a citizen has the same protection in Lisbon as in Helsinki. It is the same logic that drove the NIS 2 cybersecurity floor and every other continent-wide framework Brussels ships. Withdrawing the liability directive punches a hole straight through that premise, and the Commission’s own defense of the move is where the logic knots up. The commissioner who defended the withdrawal to Parliament argued the directive would have caused fragmented rules across member states. The critics argue that withdrawing it is what causes the fragmentation, because now each of the twenty-seven adapts its own national liability law to AI and the single market splinters into a patchwork. They cannot both be right, and the honest read is that the critics have the better of it: several member states were already drafting their own AI liability rules, and pulling the harmonized instrument guarantees they finish, in twenty-seven incompatible flavors.

There is a second harmonization story sitting underneath the first, and it is the one I promised not to get into last time, so here it is. The AI Act does not tell a company how to comply. It delegates that to harmonized standards, and the international anchor for most of them is ISO/IEC 42001, the AI management-system standard that global companies have been racing to certify against. Britain’s standards body published a European edition of it, BS EN ISO/IEC 42001, in March 2026. You would think holding that certification buys you compliance with the AI Act. It does not. A standard only grants the legal “presumption of conformity,” the safe harbor under Article 40, once the Commission cites it in the Official Journal, and as of this summer, not one AI-specific standard has cleared that step. The closest, a European quality-management standard, has passed committee and is still waiting on its citation. Worse, ISO 42001 was never built to the AI Act’s shape: it is an organization-level governance standard, and it simply does not contain the AI Act’s per-system machinery, the fundamental-rights impact assessment, the CE marking, the serious-incident reporting clock, the registration in the EU database. So the global baseline everyone certified against covers maybe two-thirds of what Brussels actually demands, and the European overlay that would cover the rest is stuck in committee. Companies are running a layered strategy out of necessity: ISO 42001 as the worldwide floor, a gap analysis mapping its clauses onto AI Act Articles 9 through 17, and a stack of bespoke European evidence bolted on top to fill what the international standard misses.

What this actually means if you are a person, or a company

If you are a citizen, the uncomfortable truth is that your ability to get compensation when an AI harms you now depends almost entirely on where you are standing when it happens. A Californian benefits from defenses being stripped out and courts entertaining strict-liability theories. Most Europeans get the revised Product Liability Directive when the harm came from a defective consumer “product,” and national tort law that was never written for opaque models when it did not. Canadians are back to whatever existed before the dead law. The single most predictable consequence of all this is forum shopping: harm gets litigated wherever the plaintiff or the defendant can find the friendliest court, which is exactly the outcome a harmonized regime exists to prevent.

If you are a company, the compliance surface is now a nightmare of overlapping, contradictory obligations. You cannot build once. It means certifying to ISO 42001 for a global baseline, layering European evidence on top for the AI Act market, tracking a Colorado impact-assessment regime and a Texas governance act and a California statute that just deleted your favorite defense, and keeping a weather eye on a UK product-liability review that could reclassify your software as a suable product. The regulatory drag the European withdrawal was supposedly meant to lift did not go anywhere. It moved down a layer and multiplied.

I am leaving the insurance angle alone here, even though it is the thing that will quietly decide most of this, because how the underwriting market prices AI liability when nobody can agree what the standard of care even is deserves its own piece and I am not qualified to fake it. What I will say is that the pattern across all of it is the same one I keep hitting. The two most rights-protective instruments of this whole era, Europe’s liability directive and Canada’s AIDA, are both dead, and the place doing the most to actually let victims sue is the United States, almost by accident, through the least coordinated regulatory process on the planet. That is not how any of the people who designed these frameworks expected it to go. Sovereignty, I keep arguing, comes down to who controls the compute and the off switch, but there is a quieter question underneath it: who pays when the switch fails. Right now the honest answer is that it depends on your postcode, and that Brussels wrote the best answer to it and then talked itself out of shipping it. Ask me at the end of 2026 whether the European standards finally land and whether the Commission floats a replacement directive. On the last two years of evidence, I would bet against both.

Sources

  • European Parliament, “Artificial Intelligence and Civil Liability” (study, 2025): AILD design, presumptions, strict-liability debate
  • AI Act Blog, “AI Liability Directive withdrawn: what applies in 2026”: withdrawal effect, national fragmentation
  • Oxford Business Law Blog, “AI Liability After the AILD Withdrawal: Why EU Law Still Matters”: PLD covers consumer AI, professional-use cases fall to national law
  • IPWatchdog, “EU Commission Confirms SEP Regulation, AI Liability Directive Withdrawal”: Virkkunen’s fragmentation defense before JURI
  • US Congress, S.2937: AI LEAD Act text (federal products-liability framework, pending)
  • AI Standard of Care, “State AI Legislation Tracker 2025” and “AI Litigation Landscape 2025”: Colorado AI Act, Character Technologies, vendor liability rulings
  • Latham & Watkins, “Texas Signs Responsible AI Governance Act Into Law”: TRAIGA scope
  • California AB 316 / SB 53 coverage: removal of the “AI-did-it” defense, frontier-model duties
  • Osborne Clarke / Baker McKenzie: UK Law Commission review of the Consumer Protection Act 1987; Product Regulation and Metrology Act 2025; DUAA automated-decision reform
  • Schwartz Reisman Institute, University of Toronto, “What’s Next After AIDA?”: Canada’s AIDA dies on prorogation, 6 January 2025
  • Stimson Center, “South Korea’s AI Basic Act”: world-first national comprehensive framework, 2026
  • BSI, “BS EN ISO/IEC 42001:2026”: European edition of the AI management-system standard
  • Cloud Security Alliance, “EU AI Act Compliance: prEN 18286 and ISO 42001”: ISO 42001 gaps vs AI Act per-system obligations
  • Freshfields / KLA JTC 21 tracker: harmonized standards status, Official Journal citation as the presumption-of-conformity trigger