Florida Attorney General James Uthmeier has introduced a legislative proposal that fundamentally alters the risk profile for the agent economy. By seeking to apply an existing aider-and-abettor statute to the developers and deployers of autonomous systems, the state is bypassing the ongoing federal debate over technical standards. This proposal, introduced on September 8, 2026, signals that the cost of deploying agentic AI may soon include the risk of criminal prosecution for the entities behind the code, effectively establishing a fourth governance theory that operates independently of Washington.
This state-level move arrives as Congress remains locked in a three-pronged legislative competition. The current federal landscape is defined by distinct, competing approaches: the infrastructure-first model of the Stop Rogue AI Act, which mandates continuous action verification; the prohibition-first stance of the Sanders-Casar Ban ASI Act, which seeks to halt advanced development; and the fiduciary-first framework of the Warner AI AGENT Act, which imposes non-waivable duties of care. Each of these federal proposals attempts to build a new regulatory architecture from the ground up, often including safe harbor provisions to encourage innovation.
Florida’s approach, detailed in the recent AG proposal, operates on a different logic. Rather than creating a new agency or technical standard, the legislation utilizes an existing criminal statute. Under this framework, any entity that counsels, aids, or abets a crime is treated as a principal. The legislation specifically targets companies that maintain practical control over the design, training, deployment, or safety settings of an AI agent. This shifts the focus from compliance with specific technical benchmarks to the legal consequences of an agent’s real-world actions.
The structural distinction here is profound. While federal bills are debating how to define and regulate AI agents, Florida is treating them as instruments of human agency. This theory does not require the creation of a new regulatory regime; it simply applies established criminal law to the developers and deployers of autonomous systems. Unlike the federal proposals, which offer various forms of safe harbor for compliant actors, the Florida model provides no such protection. It is designed to be retroactive, applying to incidents that have already occurred, and carries severe penalties including heavy fines, victim restitution, court-ordered monitorship, and the potential suspension of operations.
This legislative push is the culmination of a three-action escalation, as outlined in the Florida Attorney General’s press release: a criminal investigation initiated in April 2026, a civil lawsuit filed against OpenAI and Sam Altman on June 1, 2026, and now, the proposed criminal legislation. The urgency is driven by a series of high-profile incidents cited in the press release, including the FSU shooting on April 17, 2025, the murders of Zamil Limon and Nahida Bristy, a Florida teacher CSAM case resulting in a 135-year sentence, and the OpenAI-Hugging Face breach in July 2026 that saw approximately 17,600 unauthorized actions. These events have created a political environment where the absence of federal guidance, as confirmed by the Congressional Research Service report IF13151, is being filled by aggressive state-level action.
For the agent economy, this creates a complex and costly reality. Builders and deployers must now account for a state-level regulatory patchwork that operates independently of federal efforts. The cost structure is shifting away from simple compliance and toward the necessity of robust liability insurance and specialized criminal defense. Because the Florida theory targets practical control rather than specific technical requirements, companies cannot rely on a checklist of standards to insulate themselves from liability. They must instead evaluate their entire development and deployment lifecycle through the lens of potential criminal exposure. The emergence of this state-led criminal accountability means that the legal environment for AI is becoming increasingly fragmented. Builders and investors must prepare for a future where the primary regulatory risk is not just failing to meet a federal standard, but facing criminal charges for the actions of the agents they deploy. As the regular legislative session approaches in March 2027, the era of operating in a regulatory vacuum is ending, replaced by a landscape where liability is both immediate and potentially criminal. For those building in this space, the focus must shift from mere technical optimization to a rigorous assessment of how their systems could be interpreted under criminal law.