AI Security

Is Your Business Liable for What Its AI Chatbot Says?

A B.C. tribunal made Air Canada pay for a refund policy its chatbot made up. What that ruling means for you, plus five behaviors that create legal risk.

By Isaac, Founder, Visione Edge8 min read
A judge's gavel of dark polished wood on a vast empty desk in navy shadow, beside an old telephone handset off its hook, joined by a single taut thread of luminous blue light like a live wire, lit by one clean diagonal of pale ivory moonlight.

Is your business liable for what its AI chatbot says?

In at least one documented case, yes. In Moffatt v. Air Canada, 2024 BCCRT 149, a British Columbia tribunal found the airline liable for negligent misrepresentation after its website chatbot described a refund rule the airline did not actually offer. It ordered Air Canada to pay CA$812.02. This is a single Canadian small-claims decision, not binding law elsewhere. Treat it as a warning and a question for your counsel.

That case is now the most-cited real example of a company paying for its chatbot's words. It is useful precisely because it is fully public, with exact figures and a clean set of reasons. Below we walk through what happened, why the airline's defenses failed, and — as engineers who build and secure these systems — the five behaviors that turn a helpful bot into a liability. Where the question is legal, we say so and send you to your lawyer.

What actually happened in Moffatt v. Air Canada?

A grieving customer asked Air Canada's website chatbot about bereavement fares. The bot told him he could buy a full-price ticket and claim the discount back within 90 days of travel. Air Canada's own bereavement page said the opposite: no refunds after travel. He booked, claimed, was refused, and took the airline to a small-claims tribunal, which sided with him.

Here are the real numbers, all taken from the tribunal's decision. In November 2022, after his grandmother died, Jake Moffatt booked two last-minute one-way flights between Vancouver and Toronto and paid CA$1,630.36 in total (para. 40). He relied on the chatbot, which told him in writing:

If you need to travel immediately or have already travelled and would like to submit your ticket for a reduced bereavement rate, kindly do so within 90 days of the date your ticket was issued by completing our Ticket Refund Application form. (para. 15)

The critical fact is narrow, so read it twice. Air Canada did have a bereavement policy. What the chatbot invented was the retroactive part. The linked "Bereavement travel" webpage said "the bereavement policy does not apply to requests for bereavement consideration after travel has been completed" (para. 17). The bot promised an after-the-fact refund the real policy never allowed.

Moffatt claimed CA$880 (para. 3). The tribunal awarded CA$650.88 in damages — the actual difference between what he paid and the CA$979.48 it found he should have paid (para. 40) — plus CA$36.14 in pre-judgment interest (para. 42) and CA$125 in tribunal fees (para. 43). The order totals CA$812.02 (para. 44).

ItemAmount (CA$)
What Moffatt paid for the two flights1,630.36
What the tribunal found he should have paid979.48
Damages awarded (the difference)650.88
Pre-judgment interest36.14
Tribunal (CRT) fees125.00
Total Air Canada was ordered to pay812.02

The dollar figure is small. The principle is not: a company paid real money because its chatbot stated a policy that did not exist.

Why didn't Air Canada's own terms save it?

Air Canada raised three defenses, and all three failed. It argued the chatbot's words were not its responsibility, that the correct policy was elsewhere on its site, and that its contract terms (its Domestic Tariff) limited liability. The tribunal rejected each — the last one partly because Air Canada never actually filed the tariff it was relying on (paras. 4, 27, 31).

On responsibility, Air Canada's actual position was that it "cannot be held liable for the information provided by the chatbot," including information from "one of its agents, servants, or representatives" (paras. 4, 27). The tribunal characterized that position in its own words, and the phrasing has become famous:

In effect, Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission. While a chatbot has an interactive component, it is still just a part of Air Canada's website. It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot. (para. 27)

To be precise about who said what: "a separate legal entity that is responsible for its own actions" is the tribunal's characterization of Air Canada's argument, not a quote from Air Canada. On the "it was elsewhere on our site" defense, the tribunal added that Air Canada never explained "why customers should have to double-check information found in one part of its website on another part of its website" (para. 28).

Here is our reading of the ruling — our words, not the tribunal's: if the chatbot wears your logo, its promises are your promises. Whether a properly drafted and properly evidenced disclaimer would have changed the result is a different question, and Air Canada's tariff defense failed on evidence, not principle (para. 31). That is exactly where you call counsel.

The pattern is not "the bot was rude." It is "the bot said something a customer reasonably relied on, or something that could harm them, in your name." The highest-risk statements invent policies, contradict your real terms, give regulated advice, or make commitments you cannot honor. Documented public incidents show each failure mode in the wild.

Consider two well-reported examples, neither of which is a liability ruling — they are incidents that show how bots go wrong. New York City launched a "MyCity" chatbot to help business owners. The Markup's 2024 investigation found it telling employers they could take a cut of workers' tips and telling users that landlords need not accept Section 8 housing vouchers — both wrong, and the second a form of source-of-income discrimination. The city took the bot offline in early 2026, with the incoming administration calling it "functionally unusable." Separately, courier firm DPD had to disable part of its bot after a customer coaxed it into swearing and calling DPD "the worst delivery firm in the world." No lawsuit there — just brand damage that traveled the internet in a day.

The lesson from all three: reputational, regulatory, and financial fallout can arrive whether or not a court is ever involved.

Most exposure traces back to five behaviors. The good news is that each has a concrete engineering control you can wire in before launch. This is the checklist we run against any customer-facing bot. Treat the "control" column as the deliverable and the "signal" column as evidence the risk is real, not hypothetical.

#Chatbot behavior that creates exposureReal-world signalEngineering control that prevents it
1Inventing a policy, price, or entitlement that does not existAir Canada's bot invented a retroactive refund; the airline paid CA$812.02Ground every answer in retrieved, approved source text; block free-form policy generation; default to "I'm not sure — here is the official page"
2Contradicting your own published policyThe bot's 90-day claim conflicted with the real "Bereavement travel" pageOne source of truth: the bot quotes and links the canonical policy, never restates it from memory
3Giving regulated advice it is not authorized to giveNYC's MyCity bot told businesses they could pocket workers' tips and refuse Section 8 vouchersScope guardrails plus a hard refusal on legal, medical, tax, and financial questions, with human handoff
4Making binding-sounding commitments it cannot backAny "yes, you'll get that discount/refund/delivery date" the business will not honorNo commitment without a backend check; log every promise; require a confirmation step and plain disclaimers
5Going off-script when a user manipulates itDPD's bot swore and trashed its own employer on commandInput and output filtering, a strict instruction hierarchy, and prompt-injection defenses

Read the table as one sentence per row: the behavior on the left is what regulators, customers, and opposing counsel notice; the control on the right is what your engineers build. Behavior 1 is the Moffatt failure and the reason Air Canada paid CA$812.02. Behavior 5 is where security meets liability, because a bot that can be talked out of its rules can be talked into saying almost anything — our prompt-injection defenses guide covers that layer in depth.

What don't we know, and when should you call a lawyer?

We are engineers, not lawyers, and nothing here is legal advice. We can tell you how a chatbot goes wrong and how to prevent it. We cannot tell you how a court in your jurisdiction would rule, and neither can a blog post. For that, retain qualified counsel where you operate.

The scope of Moffatt matters. It comes from British Columbia's Civil Resolution Tribunal, an online body that handles small claims (para. 7). The claim was negligent misrepresentation under B.C. law (paras. 24–25). A single small-claims tribunal decision does not bind courts in other provinces or countries, and its precedential weight even within Canada is limited. Read it as a vivid illustration of a principle — you are responsible for what your systems tell people — not as settled law for your market.

Several things remain genuinely open. We do not know how U.S., EU, or other courts will treat similar facts. We do not know whether a well-drafted, properly evidenced disclaimer would shift the outcome, since Air Canada's contract defense failed on missing evidence rather than on the merits (para. 31). We do not know how higher-stakes claims — safety, health, money, immigration — would be handled, and those raise the stakes sharply.

So who should not do this alone? If your bot touches regulated ground — legal, medical, financial, tax, housing, or employment — or makes commitments about price, eligibility, or refunds, involve counsel before you launch, not after. And if a bot has already given a customer wrong information, preserve the conversation logs and call your lawyer before you respond. This is the line where engineering hands off to legal, and crossing it without both is how a CA$812.02 problem becomes a much larger one.

Ready to deploy a chatbot that can't promise what you can't deliver?

Before your bot ever talks to a customer, we pressure-test what it is capable of saying, wire in the five controls above, and hand you the logs you will want if anyone ever asks what it said and why. You walk away knowing your real exposure and the specific fixes that close it — mapped on a single page.

Book a working session and we will map your chatbot's exposure and the controls that prevent it.

Sources

  1. Moffatt v. Air Canada, 2024 BCCRT 149 — Civil Resolution Tribunal (British Columbia), via CanLII, 2024-02-14
  2. Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot — McCarthy Tétrault, 2024
  3. NYC's AI Chatbot Tells Businesses to Break the Law — The Markup, 2024-03-29
  4. DPD chatbot goes off the rails at suggestion of customer — The Register, 2024-01-23
  5. Mamdani to kill the NYC AI chatbot we caught telling businesses to break the law — The Markup, 2026-01-30

Book an architecture call — 30 minutes, no pitch