AI Security, Privacy and ComplianceCustomer Service Automation

Is Your Business Legally Responsible for What Your AI Chatbot Tells Customers?

Last updated 22 July 2026 · 7 min read

Direct Answer

Yes — an Australian business is responsible for what its customer-facing AI chatbot tells a customer, in the same way it's responsible for what a human employee says on its behalf. Under the Australian Consumer Law (section 18), a business engages in misleading or deceptive conduct if it makes a false representation to a customer, and it's the business, not the tool, that made the representation regardless of who or what generated the words. A widely cited overseas illustration is Moffatt v. Air Canada (2024), where a Canadian tribunal held the airline liable after its chatbot gave incorrect fare information, rejecting the argument that the chatbot was a separate responsible entity. Design accordingly: scope the chatbot to verified information, keep records of what it said, and route anything policy- or price-specific to a human.

Detailed Explanation

A customer asks a business's AI chatbot a policy question — a return window, a fare rule, a warranty term — and the chatbot gives a confident, specific, and wrong answer. The customer relies on it, and it costs them money or a missed opportunity. Who's responsible?

For an Australian business, the starting point is the Australian Consumer Law (ACL). Section 18 prohibits a business from engaging in conduct, in trade or commerce, that is misleading or deceptive or likely to mislead or deceive — and it's the business making the representation to the customer, not the tool that generated the words. There's nothing in the ACL that carves out an exception for a statement a chatbot produced rather than a human employee; a false statement about a fare rule, a return window, or a warranty term exposes the business the same way it would if a staff member had said it.

A widely cited overseas illustration of the same underlying idea is Moffatt v. Air Canada, decided by British Columbia's Civil Resolution Tribunal in February 2024. A customer used Air Canada's website chatbot to ask about bereavement fares after a family member's death; the chatbot told him he could apply for the reduced fare retroactively, which was incorrect under Air Canada's actual policy. When the airline refused to honour the chatbot's answer, the customer brought a claim. The tribunal found Air Canada liable for negligent misrepresentation and ordered it to pay damages — and specifically rejected Air Canada's argument that the chatbot was "a separate legal entity that is responsible for its own actions," holding instead that a company is responsible for all the information on its website, regardless of whether a static page or an interactive chatbot produced it. It's a Canadian decision, not Australian law, but it reflects the same principle Australian courts and the ACCC apply under the ACL: a business doesn't get to disclaim responsibility for its own tools simply because a human didn't type the specific words in the moment.

The same logic that makes a business responsible for a sign in its store, a clause in its terms of service, or an employee's verbal promise to a customer extends naturally to a chatbot the business built, deployed, and presented as speaking for it.

This is a different question from whether a business has to tell customers they're talking to an AI, which covers a disclosure obligation that exists independently of whether the chatbot says anything wrong. It's also distinct from how do you stop AI assistants from hallucinating, which covers the technical mitigation — this page covers what happens legally when that mitigation fails and a customer is affected by it.

What This Means in Practice

Treat chatbot output as a business representation, not a disclaimed suggestion. The Air Canada ruling suggests that a general disclaimer telling users to "verify important information" is unlikely to fully protect a business against a specific, confident, incorrect answer the chatbot gave — a customer's reasonable reliance on what looks like an authoritative answer from a company's own tool carries real weight.

Scope the chatbot to what it can answer reliably. A chatbot grounded in your actual help docs and policies is far less likely to invent an incorrect policy than one answering from general knowledge — the single biggest practical risk reduction is keeping the chatbot's source material accurate and current, and having it decline or escalate questions its source material doesn't clearly answer.

Build a real escalation path for high-stakes questions. Pricing exceptions, refund eligibility, legal or safety-related questions, and anything involving a specific customer's account or circumstances are exactly the categories where a wrong chatbot answer carries the most cost — route these to a human rather than letting the chatbot improvise a confident-sounding answer.

Keep records of what the chatbot actually said. Conversation logs matter if a dispute arises — a business that can't reconstruct what its chatbot told a specific customer is in a weaker position than one that can show the exchange and address it directly.

Consumer-protection rules add a second layer beyond ordinary misrepresentation. In Australia, a chatbot systematically giving customers misleading information about pricing, availability, or terms can also draw ACCC scrutiny and enforcement action under the ACL's misleading-conduct and false-representation provisions, independent of any individual customer's claim — the same principle that underlies the site's coverage of selective review solicitation and other consumer-facing automated communications.

Things to Consider

  • This is a developing area of law, and outcomes vary by jurisdiction. The Air Canada case is a Canadian tribunal decision, not Australian authority, though the ACL's misleading and deceptive conduct provisions in Australia point the same direction. Equivalent principles are actively being tested and applied in courts and regulators worldwide, and specifics of contract, consumer-protection, and misrepresentation law differ by region. Treat "a business is responsible for its chatbot's statements" as the safe operating assumption under Australian law, not a universally settled point of law everywhere.
  • The stakes scale with what the chatbot is allowed to talk about. A chatbot scoped narrowly to general product information carries less liability exposure than one answering open-ended questions about pricing, policy exceptions, or legal terms — the scoping decision covered on how do you build a chatbot from your help docs is also a risk-management decision, not just a quality one.
  • A wrong answer that's caught and corrected quickly is a very different situation from one a business stands behind. How a business responds once it learns its chatbot gave incorrect information — promptly honouring what a reasonable customer relied on, versus disputing it — affects both the immediate outcome and the broader reputational exposure.
  • This risk sits alongside, not instead of, the general reliability problem. Why does your chatbot give wrong answers covers the technical diagnosis and fixes; this page covers what's at stake if a wrong answer reaches a customer before that gets fixed.

Common Mistakes

  • Assuming a "for informational purposes only" disclaimer fully shields the business. A general disclaimer is a reasonable practice but is unlikely on its own to fully offset a customer's reasonable reliance on a specific, confident answer — see the Air Canada case, where a disclaimer reportedly existed and the airline was still found liable.
  • Letting the chatbot answer questions its source material doesn't actually cover. A chatbot that improvises a plausible-sounding policy answer rather than declining or escalating is the exact failure mode behind the Air Canada case — the fix is scoping and escalation rules, not hoping the model doesn't guess.
  • Treating a chatbot dispute the same as any other customer complaint, with no distinct review process. Because a wrong chatbot answer can create real legal exposure beyond reputational cost, a business benefits from a clear internal process for reviewing and responding to chatbot-related disputes specifically, not folding them into a generic complaints queue.
  • Not keeping conversation logs. Without a record of the actual exchange, a business is arguing from memory or the customer's account alone if a dispute reaches a formal claim.

Frequently Asked Questions

What actually happened in the Air Canada chatbot case?
In 2022, a customer used Air Canada's website chatbot while researching a bereavement fare after a family member's death. The chatbot told him he could apply for the reduced fare retroactively, after booking — which was incorrect; Air Canada's actual policy required the request before travel. When Air Canada refused the retroactive discount, the customer took the airline to British Columbia's Civil Resolution Tribunal. In February 2024, the tribunal ruled in the customer's favour, finding Air Canada liable for negligent misrepresentation and ordering it to pay damages. Air Canada had argued the chatbot was a separate legal entity responsible for its own words — the tribunal rejected that argument outright, holding Air Canada responsible for all information on its website, whether from a static page or a chatbot.
Does this mean every chatbot mistake creates legal liability?
Not automatically — liability generally still depends on the specifics (whether the statement was false, whether the customer reasonably relied on it, and whether that reliance caused a loss), the same factors that would apply to a human employee's mistaken representation. What the Air Canada case establishes is that 'the chatbot said it, not us' is not a viable defense on its own — a business can't disclaim responsibility for its own customer-facing tool's statements simply because no human typed them in the moment.
Does having an AI usage disclaimer on the chatbot protect the business?
A disclaimer alone is unlikely to fully protect a business, though it may help. In the Air Canada case, the chatbot interface reportedly included a general disclaimer about verifying important information, and the tribunal still found the airline liable — a customer's reasonable reliance on a specific, confident answer from a company-deployed tool is difficult to fully disclaim away. The safer mitigation is scoping the chatbot to information it can answer reliably and routing higher-stakes questions to a human, not relying on disclaimer language to absorb the risk.

References

Related Questions