“Autonomy describes how the contact was executed. Walden asks whose contact it was.”
An autonomous agent negotiates a price, moves money, and closes a transaction with someone in Los Angeles. The transaction goes wrong. The person in Los Angeles wants to sue.
They cannot sue the agent. An AI agent is not a legal person, holds nothing, and cannot be served. The defendant has to be a company—the one that built the agent, the one that deployed it, or both—and that company may have no office, no employee, and no server in California. Whether a California court can hear the case at all is therefore the first question in the dispute, and often the only one that gets decided.
For twenty years the answer usually favored the defendant. That has changed.
Key Takeaways
- The uniformity defense is gone in the Ninth Circuit. After Briskin v. Shopify,1 express aiming no longer requires that a defendant single out the forum state. A platform that operates the same way everywhere can still be subject to jurisdiction where its conduct lands.
- The defendant is the operator, not the agent. Jurisdiction analysis runs against the legal person who deployed the system. That makes the deployment decision—not the agent’s output—the conduct a court examines.
- Autonomy is unlikely to work as a jurisdictional shield. A company that deploys an agent to transact with whoever appears has made a choice about where it is willing to do business. Arguing that the agent picked the counterparty concedes that the company built something to pick counterparties.
- The open seam is targeting. Where an operator genuinely restricts an agent by geography and the restriction fails, the analysis is materially different from one where no restriction existed.
- The record is built before the dispute. Geographic controls, terms presentment, and logs of what the agent knew about its counterparty are jurisdictional facts. They exist or they do not by the time a motion is filed.
What Briskin and Gelasio Actually Changed
Specific personal jurisdiction over an online defendant runs through the express-aiming element of the effects test:2 the defendant must have done something purposefully directed at the forum. For two decades, defendants won by arguing that a website available everywhere is directed nowhere in particular, and that anything less than forum-specific targeting could not satisfy the test.
The Ninth Circuit’s en banc decision in Briskin v. Shopify rejected that framing. A platform that operates identically in every state does not thereby escape every state. In Gelasio v. Zafar, the same rule reached a foreign operation alleged3 that took a California resident’s money through an offshore entity.
One discipline point before going further. Gelasio is a memorandum disposition, unpublished and not precedent under Ninth Circuit Rule 36-3.4 Briskin is the binding authority. Gelasio’s value here is evidentiary rather than precedential: it shows a panel applying the en banc rule to a foreign operator, which is useful for predicting outcomes and useless for compelling one.
The doctrinal shift is narrow but consequential: uniform conduct is no longer self-exculpating. What matters is where the defendant’s conduct was aimed in substance, not whether the defendant drew a circle around one state.
That is the environment an AI agent operator now litigates in.
The Guardrail That Decides This: Walden v. Fiore
Briskin loosened express aiming; it did not repeal the constitutional floor beneath it. Walden v. Fiore holds that the contacts supporting specific jurisdiction must arise from the defendant’s own conduct connecting it to the forum.5 Judge Callahan’s Briskin dissent put the objection directly: by resting jurisdiction on the fact that the plaintiff “used his iPhone while ‘located in California,’” the majority “departs from the longstanding principle that jurisdiction turns on ‘the defendant’s contacts with the forum State itself, not the defendant’s contacts with persons who reside there.’”6
That guardrail is where the AI-agent question actually lives. If an agent transacts with a Californian only because a Californian happened to reach it, the operator’s forum contact looks like the plaintiff’s residence wearing a costume, and Walden is a real defense. If the operator deployed a system configured to find and transact with counterparties wherever they are, the contact is the operator’s own conduct and Walden does not save it.
The practical test is therefore not whether the agent acted autonomously. It is whether the operator’s own configuration choices, made before any plaintiff existed, reach into the forum. Autonomy describes how the contact was executed. Walden asks whose contact it was.
Why the Agent Cannot Be the Defendant
It is worth being precise about who is in the caption, because the analysis depends on it.
An AI agent has no legal personality. It cannot be sued, cannot be served, holds no assets, and cannot satisfy a judgment. Every theory of recovery therefore runs to a person—a developer, a deployer, sometimes both, and occasionally the user who directed it.
This matters for jurisdiction because the conduct a court evaluates is the company’s conduct. The relevant acts are deploying the agent, defining its scope of authority, deciding which counterparties it may transact with, and choosing what disclosures it makes. Those are corporate decisions made at a desk, and they are the contacts a court will weigh.
Framed that way, “the agent did it autonomously” is not the defense it sounds like. It relocates the inquiry to the decision to deploy an autonomous system, which is a decision the company made deliberately.
Three Fact Patterns
The unrestricted agent. An operator deploys an agent that transacts with any counterparty that reaches it. It has no geographic limits, no residence screening, and no jurisdictional terms. A Californian transacts; a dispute follows.
This is the hardest posture for the operator. The company chose to accept business from anywhere, and after Briskin the fact that it treated California no differently than anywhere else does not carry the argument. The agent’s counterparty selection is the direct product of a configuration the company chose.
The restricted agent that overran its limits. The operator excluded California by design—geographic controls, residence attestation, a refusal path—and the agent transacted with a Californian anyway, whether through a technical failure, a misrepresentation by the counterparty, or a prompt-injection attack.
This is a genuinely different case, and it is where the doctrine still has room. The company can point to an actual, contemporaneous decision not to do business in the forum. Whether that survives depends on evidence: what the control was, whether it was enforced or aspirational, and what the operator did after the first failure. An unenforced policy is not a jurisdictional defense.
The agent acting for the plaintiff. The Californian’s own agent initiated the transaction with a foreign operator that never sought California business at all. Here the operator’s contacts with the forum may be genuinely attenuated, and the better analysis may be that the resident reached out rather than that the operator reached in.
The Question Nobody Has Answered
No court has held that an AI agent’s autonomous selection of a counterparty is or is not the operator’s express aiming at that counterparty’s forum. Everything above is an application of existing doctrine to facts the doctrine did not contemplate, and practitioners should treat it that way.
Two framings will compete. On one, the agent is an instrumentality: what it does, the operator did, and deploying it without limits is purposeful availment of every market it can reach. On the other, express aiming requires an intention about a place, and a system that selects counterparties on non-geographic criteria cannot supply it.
The instrumentality framing is the more likely winner, and a Ninth Circuit judge has already stated it. Concurring in Briskin, Judge Collins treated automated conduct as the company’s own: these “automated torts,” so to speak, are for minimum-contacts purposes Defendants’ conduct in California, and such conduct “is attributable to those persons who deliberately intended that such systems reach into that State and operate in that manner when they do so.”7
decision immunize the business that automated it. But it is not decided, and a defendant with a real targeting record has a real argument.
What to Do Now
If you deploy agents. Decide where you are willing to do business and make the agent enforce it, rather than stating it in terms nobody implements. Log what the agent knew about each counterparty’s location and what it did with that information. Present terms in a way that produces evidence of assent. Treat the first control failure as the moment the record starts, because that is how it will be read later.
If you were harmed by one. The jurisdictional facts are largely in the operator’s systems, and jurisdictional discovery is the mechanism for reaching them. The configuration—what the agent was permitted to do, and whether any geographic limit existed—is usually more probative than the transaction itself.
Either way. These disputes are decided on records created long before anyone files. The authorization architecture that answers the liability question, which we have written about in deployer liability and in who is liable when an AI agent loses money, is the same record that answers the jurisdictional one.
Work with Astraea Counsel
Astraea Counsel litigates disputes arising from AI systems, including the jurisdictional fights that decide them before the merits are reached. See our AI litigation attorney page, or contact us to discuss a dispute.
Footnotes
-
Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc). ↩
-
Calder v. Jones, 465 U.S. 783 (1984) (effects test); see Schwarzenegger v. Fred Martin Motor Co., 374 F.3d 797 (9th Cir. 2004) (three-part specific-jurisdiction framework). ↩
-
Gelasio v. Zafar, No. 24-7277 (9th Cir. Apr. 29, 2026) (mem.) (reversing dismissal for lack of personal jurisdiction). ↩
-
9th Cir. R. 36-3 (unpublished dispositions are not precedent except under law of the case or claim or issue preclusion; citable per Fed. R. App. P. 32.1). ↩
-
Walden v. Fiore, 571 U.S. 277 (2014). ↩
-
Briskin, 135 F.4th 739 (Callahan, J., dissenting) (first quoting the majority opinion; then quoting Walden, 571 U.S. at 285); id. (majority op.) (answering that the dissent “overreads Walden”). ↩
-
Briskin, 135 F.4th 739 (Collins, J., concurring in the judgment). ↩
