Florida Attorney General James Uthmeier introduced a legislative proposal on September 8, 2026, that shifts the regulatory burden for artificial intelligence from abstract safety guidelines to direct criminal liability. By targeting companies that maintain practical control over the design, training, deployment, or safety settings of AI systems, the state is establishing a legal pathway to hold these entities responsible when their models participate in criminal activity. This move marks a significant departure from existing industry standards, forcing developers to account for the real-world actions of their models under the same statutes that govern human accomplices.
A deliberate three-action escalation strategy defines the state’s current regulatory posture. The sequence began in April 2026 with a criminal investigation into the role of AI in the FSU shooting, followed by a June 2026 civil lawsuit against OpenAI and Sam Altman for deceptive practices-the first state-led action of its kind. By moving from investigation to civil litigation and now to proposed criminal legislation, the state is signaling a transition from reactive enforcement to a proactive, codified governance model.
Florida’s existing aider-and-abettor statute serves as the primary legal mechanism for this proposal. Under this framework, any individual or entity that counsels, aids, or abets the commission of a crime is considered a principal to that crime. Applying this statute to AI allows the state to judge systems by their words and actions, effectively treating the software as an agent capable of facilitating criminal conduct. This approach creates a broad net of liability that encompasses owners, controllers, distributors, and those who profit from the deployment of these systems.
Integrating this proposal into the Three Bills Three Theories framework introduces a fourth governance theory focused on criminal accountability for outcomes. While previous theories prioritized transparency, data rights, or safety standards, this criminal theory shifts the focus to the consequences of AI deployment. The proposed penalties are substantial: they include significant fines, mandatory victim restitution, court-ordered monitorship, and the potential suspension of business operations following a conviction. Furthermore, the legislation creates both criminal and civil liability for companies that fail to address known loopholes in their systems.
High-profile incidents have directly shaped this regulatory posture, grounding the urgency of the proposal in specific, tragic events. These include the April 17, 2025, FSU shooting involving Phoenix Ikner, the murders of USF doctoral students Zamil Limon and Nahida Bristy, and a case involving a Florida teacher who utilized AI to generate child sexual abuse material (CSAM), resulting in a 135-year sentence. Additionally, the July 2026 breach involving OpenAI and Hugging Face, where agents executed approximately 17,600 unauthorized actions, has been cited as a primary driver for the necessity of the Stop Rogue AI Act context.
Builders and operators face structural implications as the legislation defines liability based on practical control. Developers cannot easily offload responsibility to end-users if the system’s design or safety settings facilitated the crime. This creates a clear divergence between state-level and federal-level governance. While federal discussions often remain focused on broad, industry-wide standards, Florida is pursuing a state-level approach that leverages traditional criminal law to force immediate compliance through the threat of business dissolution.
Refining the legal framework remains the current priority, with Uthmeier’s office actively working with Florida lawmakers while the proposal is in its early stages. As this moves forward, the core question for the industry is not merely about technical safety, but about the legal definition of agency. By treating AI as a participant in criminal acts, Florida is attempting to bridge the gap between software development and human consequences, ensuring that companies remain legally accountable for the actions of their systems.
