In most cases, your business. The best-known ruling on this treated a chatbot on a company's website as part of the company, not a separate party, so its answers were judged like any other information the business gave. AI vendors' contracts usually leave responsibility for outputs with you. You can limit the risk but not hand it to the software.
That ruling was Moffatt v. Air Canada, decided in February 2024. The airline's chatbot wrongly told a bereaved customer he could claim a bereavement fare after booking; the airline argued, in effect, that the bot was responsible for its own words. The tribunal disagreed, found the airline hadn't taken reasonable care to make the bot accurate, and ordered it to pay the fare difference. This isn't legal advice, and the rules vary between legal systems, but "the AI said it" hasn't worked as a defence.
Why "the bot said it, not us" fails
The tribunal's reasoning is worth reading closely, because it's exactly the argument a small business might be tempted to make. The airline pointed out that the correct bereavement policy was published on another page of its website. The tribunal was unimpressed: it said the airline didn't explain why the policy page was more trustworthy than its chatbot, or "why customers should have to double-check information found in one part of its website on another part of its website". The standard it applied was simple: a company has to take reasonable care that what it tells customers is accurate, and a chatbot is one of the ways it tells them.
A second real case shows the commercial cost even where no court is involved. In April 2025, the AI support bot for Cursor, a popular coding tool, told users who were being logged out unexpectedly that this was expected under a one-device-per-subscription policy. No such policy existed; the logouts came from a bug. Users who believed the bot, which signed its emails with a human-sounding name, posted about cancelling their subscriptions. The company's co-founder apologised publicly, refunded the affected user, and said AI replies in email support would be clearly labelled from then on.
Put the two together and the pattern is clear. Customers reasonably treat your chatbot as speaking for you. When it invents a policy, a price or a promise, you carry the fallout, whether that's a tribunal order, refunds or lost customers.
Where a small firm's chatbot can create liability
Most small-business bots answer routine questions, and most of those answers are harmless even when imperfect. The risk concentrates in a few kinds of answer:
| Kind of answer | Illustrative wrong answer | Why it matters |
|---|---|---|
| Prices and quotes | "A two-bedroom move is $650, all in." | Customers book on the figure and dispute the real invoice |
| Policies | "You can cancel for free up to 24 hours before." | An invented policy is still your statement |
| Guarantees and warranties | "All our installations carry a ten-year guarantee." | Creates an expectation you may be held to |
| Availability and timing | "An engineer can be with you within two hours." | Emergency customers act on the promise |
| Safety advice | "A faint gas smell near the boiler is usually normal." | Physical harm, the worst category of all |
| Security details | "Leave the key under the mat and we'll let ourselves in." | Advice that exposes a customer to crime |
The last two rows deserve the hardest limits. A bot that gives safety or security advice is doing something no small firm should delegate to software, whatever its accuracy rate.
An HVAC installer's chatbot, set up to limit what it can promise
Take an installer with eight engineers (an illustrative firm) whose website chatbot handles about 900 conversations a month: service bookings, breakdown enquiries, questions about new systems and the odd complaint. Before a relaunch, the owner reviewed 200 past conversations and sorted the bot's answers:
- About 150 were routine and correct: opening hours, which areas the firm covers, booking links.
- About 35 were correct but risky in principle: prices, lead times and warranty questions answered from the website's own pages.
- About 12 were wrong or invented: two made-up discounts, a warranty length the firm doesn't offer, and several confident arrival times.
- Three were safety-related, including a customer describing a gas smell, which the bot answered with troubleshooting tips instead of emergency instructions.
Twelve wrong answers in 200 is six per cent. At 900 conversations a month, that rate would mean around 54 wrong answers a month reaching customers, and the three safety conversations were the ones that kept the owner awake. The relaunch changed four things:
- Safety first. Any mention of gas, carbon monoxide, burning smells, water near electrics or a child or vulnerable person without heating triggers a fixed message with emergency instructions and the out-of-hours number. The AI doesn't compose that reply; it's a template.
- No invented numbers. The bot can only state prices, lead times and warranty terms that appear word for word in a short fact sheet. Anything else gets "I'll ask the team to confirm that".
- Clear disclosure at the start of every chat, and a visible "talk to a person" option.
- A weekly review of 50 conversations, logged on a simple sheet (below).
In the first month after relaunch, the weekly samples turned up two wrong answers in 200, both small, and no safety failures. The review takes about 40 minutes a week. That time is also the firm's evidence of reasonable care if an answer is ever challenged. The detail of writing those limits is covered in chatbot guardrails that stop AI promising what you don't offer, and the handoff design in when an AI chatbot should hand over to a human.
Instructions that stop a bot making promises
Most chatbot platforms let you write standing instructions that shape every answer. The wording matters. The set below, written for a locksmith's booking bot, is illustrative and closes off the risky answers above:
You answer questions for [business name], a locksmith.
You MAY: explain our services, share opening hours, take
booking details, and quote ONLY the prices listed in the
price sheet below, word for word.
You MUST NOT:
- quote any price, discount or fee not in the price sheet
- promise arrival times; say "the team will confirm a time"
- give security advice about specific homes, alarms or keys
- ask for or repeat alarm codes, key numbers or safe codes
- describe any policy not in the policy sheet below
If someone is locked out with a child, pet or vulnerable
person inside, or reports a break-in in progress, reply only
with: [emergency template].
If you don't know, say: "I'll ask the team and they'll
reply within [time]." Never guess.
The difference shows up in the answers. Before instructions like these, a question such as "how much to change the locks on a front door tonight?" got a confident invented figure (illustrative): "Usually around $85, and we can be there in 30 minutes!" After them, the same question gets: "Our listed price for a standard front door lock change is on our price sheet at [price]. Out-of-hours visits cost more, and the team will confirm the total and an arrival time before anyone sets off." It's less exciting and far safer. Instructions aren't a guarantee, because models can still slip, which is why the review routine exists, but they sharply reduce how often the bot improvises.
Telling customers they're talking to a bot
Disclosure is both a legal duty in some places and plain good practice. If you sell to customers in the EU, the AI Act's transparency rules, which have applied since 2 August 2026, require people to be told when they're interacting with a chatbot unless it's obvious. Cursor's experience shows the commercial side: users took an invented policy as official partly because the bot seemed human.
A cleaning company's opening message might read (illustrative): "Hi, I'm the [business name] assistant, an AI. I can answer questions about our services and take booking requests. For quotes, complaints or anything urgent, tap 'talk to a person' and a member of the team will reply during working hours." That's two sentences, it sets expectations, and it gives an exit. Placement and wording options are covered in more depth in what to tell customers at the start of a chat.
Logs and a weekly review: your evidence of reasonable care
The Air Canada reasoning turned on reasonable care. If a customer ever disputes something your bot said, the most useful thing you can show is that you took care: accurate source material, limits on what it could say, a way to reach a person, and a record of checking. Keep transcripts for a sensible period (long enough to cover disputes, short enough to respect privacy), and keep a review log like this one (illustrative, filled in for a roofing contractor):
CHATBOT REVIEW LOG Week of: [date]
Conversations in week: 214 Sampled: 50
# Issue found Action Done
1 Bot said "most repairs same day" Removed phrase Yes
(not our policy) from site copy
2 Quoted gutter clean price from Updated price Yes
old page ($120, now $140) sheet; old page
taken down
3 Customer asked about storm damage Called customer; Yes
insurance claim; bot gave general added rule: no
advice on what insurers cover insurance advice
Safety or security conversations: 0
Customers contacted to correct an answer: 1
Reviewed by: [first name]
Item 2 is the most common real-world cause of wrong answers: the bot faithfully repeats an out-of-date page. When the bot's source is wrong, the fix is the source, not the bot. If you need a fuller method for tracing and fixing those errors, see how to stop an AI chatbot giving customers wrong answers.
When a wrong answer has already gone out
Mistakes will happen, so decide in advance how you'll handle one. An illustrative removals firm found that its bot had quoted $650 for a two-bedroom local move to three customers over a fortnight, using a price from the previous year; the real price was $780. The owner's approach, which works for most small errors:
- Fix the source the same day, so no fourth customer gets the figure.
- Contact each affected customer before they chase you, explain plainly, and apologise.
- Decide on a fair remedy. The firm honoured the $650 for all three, a cost of $390 in total, and judged that cheaper than three disputes and three bad reviews.
- Record what happened and what changed, in the review log.
For larger or obviously mistaken figures, a different remedy may be fair, and that's the point to take advice. Either way, speed and honesty count for more than the exact outcome.
Answers a chatbot shouldn't give at all
Some questions carry risk because of what they are, not how well the bot answers them. Legal, medical, financial and insurance questions sit in that group, and the model vendors say so themselves: OpenAI's usage policies, updated on 29 October 2025, rule out providing tailored advice that needs a licence, such as legal or medical advice, without a licensed professional involved. A trades business meets these questions more often than you'd expect. A roofing customer asks whether storm damage will be covered by their insurer; a boiler customer asks whether a fault makes their home unsafe for a newborn; a tenant asks whether their landlord or they should pay for a new lock.
The safe pattern is the same for all of them. The bot acknowledges the question, says plainly that it can't advise on it, and points to the right person: "I can't advise on what your insurer will cover. Your insurer or broker can confirm that, and our team can provide a written damage report to support a claim." Write those deflections into the bot's instructions for each topic, test them, and include them in the weekly review sample.
Who else can share the responsibility
Liability rarely sits with one party alone, and knowing where it might be shared helps you decide where to spend effort:
- The customer. The Air Canada tribunal asked whether the customer's reliance on the bot was reasonable, and found it was. A customer who asked an ordinary question and acted on the answer is in a strong position. One who spent twenty minutes tricking a bot into offering a 95% discount is in a much weaker one, although you'd still rather the bot never said it.
- The chatbot vendor. If a platform fault, rather than your content or settings, caused a wrong answer, you may have a claim under your contract with the vendor. In practice, liability caps in those contracts are usually low, so this is a backstop, not a plan.
- Your own content. In the review log above, the most common cause of wrong answers was an out-of-date page. When the bot faithfully repeats your own mistake, the responsibility is plainly yours, and so is the fix.
- Staff who configured it. Inside the business, the person who owns the chatbot should own the weekly review. Liability to customers stays with the business, but a named owner is what keeps the reasonable-care routine alive.
The practical takeaway is that the controls you control, accurate content, limits and review, are also the ones that matter most if anyone ever asks whether you took reasonable care.
What your vendor's contract says about wrong answers
If you assumed the chatbot company would share the risk, read its terms. The pattern across the industry is that the customer (you) is responsible for how outputs are used. OpenAI's Services Agreement, for example, says the customer "is solely responsible for all use of the Outputs and for evaluating the accuracy and appropriateness of Output for Customer's use case". Chatbot platforms built on these models generally pass the same responsibility on in their own terms, and their liability caps are usually small relative to a serious claim.
Three questions to put to any chatbot vendor, in writing: How long are full transcripts kept, and can we export them? Can we restrict answers to our own approved content? What happens, contractually, if the bot states something untrue about our prices or policies? The answers tell you how much of the care you'll need to supply yourself, which is usually most of it.
Your own customer terms can help set expectations, but they aren't a shield. An illustrative line: "Our website assistant uses AI to answer general questions. Quotes, prices and bookings are confirmed in writing by our team, and that written confirmation is what we'll rely on." Have a solicitor check wording like that against the consumer rules where you trade, and don't expect it to excuse a bot that invents a policy. Finally, tell your insurer what your chatbot does; whether wrong advice from it is covered is set out in whether your business insurance covers AI mistakes.
Chatbot liability: common follow-ups
Will a disclaimer protect me if my chatbot gets something wrong?
It helps set expectations but is unlikely to be a complete answer. In the Air Canada case the correct policy was on the airline's own website, and the tribunal still said customers shouldn't have to double-check one part of a site against another. Consumer protection rules in many places also limit what small print can exclude. Treat disclaimers as one layer alongside accurate content, limits and escalation.
Do I have to honour a price my chatbot quoted by mistake?
It depends on the facts and the law where you trade, so take advice on any significant amount. Practically, many firms honour small errors to protect goodwill and correct the bot the same day. For large or obviously mistaken figures, contact the customer quickly, explain, apologise and offer a fair remedy, and keep the chat log. Prevention is simpler: don't let the bot quote prices it can't look up.
Does my insurance cover mistakes made by a chatbot?
Possibly, but don't assume it. Professional indemnity, public liability and cyber policies each treat AI differently, and some insurers now ask specific questions about AI use. Tell your broker what your chatbot does, ask in writing whether wrong advice or promises it makes are covered, and check any exclusions for automated systems before you rely on it.
Further reads
- What to Do When AI Gets Something Wrong With a Customer — The customer-facing recovery steps once a mistake has happened.
- How to Test a Customer Chatbot Before It Goes Live — Find wrong answers before customers do.
- What to Ask an AI Chatbot Vendor Before You Sign Up — Ask about logs, limits and liability before you sign.
- How to Train an AI Chatbot on Your FAQs, Policies, and Prices — Give the bot accurate policies so it has less to invent.
- What Is Prompt Injection and Should a Small Business Worry? — How customers can trick a bot into promises you never made.
- How to Measure Whether Your AI Chatbot Is Actually Working — Track accuracy over time, not just chat volume.
- What an AI Consultant Can't Do for You, and What You Must Own — Seven responsibilities that stay with the business when you hire AI help, an ownership card for every automation, and promises no consultant should make.
- How to Write an AI Disclosure Statement for Your Website — An AI-use inventory, the five parts of a good statement, a fill-in template, a picture framer's example and wording to avoid.
- AI Compliance Checklist for Small Businesses: What Applies to You — Map each AI use to the rules it triggers, work through data-protection and EU AI Act checks, and see a language school's uses mapped end to end.
- Customer-Facing or Back-Office: Where Should AI Go First? — A side-by-side comparison of customer-facing and back-office AI as a first move, with a scoring sheet, the middle route, and two worked decisions.
- What to Do When an AI Receptionist Gets a Booking Wrong — A step-by-step response for AI receptionist booking errors: the callback script, a cause-finding table, who absorbs the cost and an incident log.
- Can an AI Chatbot Handle Order Tracking and Returns? — What an order-tracking chatbot needs to see, which return decisions it can safely make, and where a person still has to step in.
- Should an AI Chatbot Answer Allergen Questions for Your Restaurant? — Which allergen questions a restaurant chatbot may answer, which must go to a person, and how to stop it guessing from general knowledge.
- Should a Small Business Let AI Answer Customer Messages? — Sort your last 100 messages, pick the right level of AI involvement, set red lines by business type, and know what each channel costs per reply.
- Can AI Handle Customer Complaints Without Making Them Worse? — Where AI speeds up complaint handling, the five ways its replies inflame customers, and one hotel complaint followed from angry email to resolved.
- How to Protect a Customer-Facing Chatbot From Misuse — Stop visitors tricking your website chatbot: least-power setup, secret-free instructions, spending caps, attack tests and a weekly log check.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Moffatt v. Air Canada, 2024 BCCRT 149, as summarised by McCarthy Tetrault (February 2024); The Register on Cursor's support bot (April 2025); OpenAI Services Agreement (effective 1 Jan 2026); EU AI Act Article 50 transparency duties. Checked September 2026. Not legal advice.