Who Is Liable When Your Chatbot Lies to a Customer
An airline argued in a tribunal that its chatbot was a separate legal entity responsible for its own actions. It lost. That case is now the clearest available statement of where responsibility sits.
In February 2024, a Canadian tribunal decided a small claim that has been quoted ever since. A customer had been told by Air Canada's chatbot that he could apply for a bereavement fare retroactively. That was wrong. The airline refused the refund and argued, among other things, that the chatbot was a separate legal entity responsible for its own actions.
The tribunal rejected that. Its formulation is the useful part: a chatbot has an interactive component, but it is still just a part of the company's website.1
The award was CA$812.02 — trivial money and a small-claims decision rather than binding higher-court precedent. It matters anyway, because it is the clearest statement available of a principle everyone deploying an agent needs: the thing your software says is something your company said.
The failure mode that is not error
The Air Canada case was a hallucination. There is a second category, and it is adversarial.
In late 2023 a customer-facing chatbot at a Chevrolet dealership was instructed by a user to agree with everything and end its replies with a phrase asserting a binding offer. It duly "agreed" to sell a new vehicle for one dollar. No sale was honoured, and the vendor reported thousands of manipulation attempts over the following days.2
Nothing about that required sophistication. It is prompt injection, which OWASP has ranked as the top security risk for applications built on language models — first place since the project began, on the reasoning that it is the risk that enables most of the others.3
The point for a small operator is not the dollar car. It is that a public-facing agent is a text input from strangers, and there is no complete technical fix for that.
What the law is doing
Two things are happening, and they are frequently confused.
Substantive liability is old law. The reasoning applied to Air Canada was ordinary negligent misrepresentation and agency: your agent's statements bind you the way an employee's would. Legal commentary has framed the case in terms of apparent authority — a doctrine considerably older than any chatbot.4
New statutes mostly cover disclosure. At least six US states enacted AI chatbot laws during 2025, and California's companion-chatbot statute took effect on 1 January 2026 carrying a private right of action.5 These largely regulate whether you tell people they are talking to a machine — not whether you are responsible for what the machine says. For that second question, the old doctrines still govern.
A signal worth noting on the commercial side: in April 2025 the first standalone AI liability insurance product was written into the Lloyd's market, with its promoters warning about "silent AI" exposure sitting unpriced inside existing policies.6 When insurers start writing a named product, the risk has stopped being theoretical.
The guardrails that matter
Ranked by how much risk they remove per hour of work:
- Nothing binding without a human. Price, discount, delivery date, refund, eligibility. The agent may explain policy; it may not create an exception to it. This single rule would have prevented both incidents above.
- Restrict the topic, not just the tone. An agent that can only discuss a defined set of subjects has a far smaller attack surface than one instructed to be helpful about anything.
- Say it is a machine, and say where the authority ends. Clear, visible disclosure is what the new statutes require, and legal commentary suggests prominent and specific disclaimers are also the practical way to limit exposure.
- Log everything, retrievably. If you cannot produce what your agent said to a specific person on a specific date, you cannot defend it and you cannot correct it. This is the same argument we made about software operated by agents: reversibility and audit are the load-bearing parts.
- Review the transcripts weekly at first. Not for quality — for the sentences you would not want quoted back to you.
The counter-argument
Being fair to the technology: none of this makes deployment unwise. Support agents handle a large volume of genuinely repetitive contact, and the alternative — a customer waiting two days for an email reply — has its own cost.
And the legal exposure should be kept in proportion. The Air Canada award was under a thousand dollars. The realistic risk for a small company is not a catastrophic judgment; it is a compounding series of small commitments the business did not intend to make, discovered late, in a channel nobody was reading.
The question to answer before deploying is not whether the agent can be wrong. It is what it is allowed to promise while being wrong.
Further reading
Books that shaped this article, including the ones we disagree with. Where a work is popular rather than peer-reviewed, we say so.
Resolution is a participant in the Amazon Services LLC Associates Program. As an Amazon Associate we earn from qualifying purchases — at no additional cost to you. Affiliate links never determine what appears on these lists: several of these books are here specifically because we think they are wrong in an instructive way.
References & notes
- Moffatt v. Air Canada, 2024 BCCRT 149, decided 14 February 2024, British Columbia Civil Resolution Tribunal. Award: CA$812.02. A small-claims decision, persuasive rather than binding precedent.
- Chevrolet of Watsonville chatbot incident, late 2023; recorded as Incident 622 in the AI Incident Database. No sale was honoured.
- OWASP GenAI Security Project, OWASP Top 10 for LLM Applications 2025 (v2.0, 18 November 2024) — prompt injection ranked first.
- Commentary on agency and apparent authority: American Bar Association coverage, 18 June 2025; Duke Law commentary by Deborah DeMott.
- Cooley LLP analysis, 21 October 2025, on 2025 state chatbot statutes and California SB 243, effective 1 January 2026.
- Armilla press release, 30 April 2025, on affirmative AI liability insurance underwritten in the Lloyd's market by Chaucer; reported by the Financial Times, 11 May 2025.
- This article is not legal advice. Jurisdictions differ and this area is moving; check the rules that apply to you.
Corrections are published inline and dated. Write to us if something here is wrong.
// weekly dispatch
One email. Every Tuesday.
The week's analysis, one tool we actually tested, and one behavioural pattern worth practising. Unsubscribe in one click.