The Air Canada Ruling: You Are Liable for What Your AI Says

What happened

Air Canada’s website chatbot gave a customer incorrect information about the airline’s bereavement fare policy. The customer, dealing with a death in the family, relied on what the chatbot told him, booked accordingly, and later applied for the fare adjustment the bot had described. The airline refused, pointing out that its actual policy, published elsewhere on the same website, said something different. The dispute went to a tribunal.

Air Canada’s defense was remarkable, and it is the reason this case matters to every business. The airline argued the chatbot was a separate legal entity responsible for its own statements. In other words: the bot said it, not us.

The tribunal rejected that completely. The ruling was blunt: a company is responsible for all the information on its website, whether it comes from a static page or a chatbot. It made no difference that the correct policy existed elsewhere on the site. A customer should not have to cross-examine a company’s own website to figure out which part of it is telling the truth. Air Canada was held liable and ordered to compensate the customer.

Why this matters far beyond airlines

The dollar amount in this case was small. The precedent is not. This ruling sets the frame for every business deploying AI on customer-facing channels, and the logic extends cleanly.

Your AI chatbot quoting the wrong price is your quote. Your AI answering a policy question incorrectly is your policy statement. Your AI-generated service page making a claim your business cannot back is your claim. Your automated email response promising a turnaround you do not offer is your promise. “The AI said it, not us” is not a defense. A tribunal has already said so, in writing, and the reasoning is exactly what any future court would reach for.

The three exposure points most businesses have not mapped

Chatbots. The most direct exposure, because the bot converses in real time with no human in the loop. Every hallucinated policy, invented discount, or wrong compliance answer is a statement your company just made to a customer who may act on it.

AI-generated content. Service pages, blog posts, and product descriptions written by AI and published without review carry the same liability as anything your team wrote deliberately. If an AI-written page claims a capability, a certification, or a result you cannot substantiate, that claim is yours the moment it goes live.

Automated communications. AI-drafted email replies, quote generators, and scheduling assistants all speak for the company. The more of the customer conversation you automate, the more statements you are making that no human has verified.

For MSPs and compliance-focused firms, the stakes escalate further. Wrong information about compliance requirements, security capabilities, or coverage scope is not just embarrassing. It is potential legal exposure with clients whose own contracts and audits depend on that information being right. In a business built on trust and precision, an unsupervised AI speaking for you is a liability multiplier.

The governance answer

None of this means rip out your chatbot or ban AI content. It means treat AI output the way you treat employee output, because legally, that is what it is.

You would not let a brand-new hire answer customer questions with zero training, zero constraints, and zero review. Apply the same standard to the tools. Constrain what the chatbot is allowed to answer, and give it explicit escalation paths to a human for anything involving pricing, policy, or compliance. Review AI-generated content before it publishes, with special attention to claims, numbers, and promises. Keep the source material the AI references current, because a bot reasoning from last year’s policy produces this year’s liability. And assign a named human owner for every AI touchpoint, because accountability that belongs to everyone belongs to no one.

Run one exercise this month: list every place AI currently speaks for your company, and next to each, write the name of the person who reviews it. Blank spaces on that list are your exposure map.

The standard we build to

This is the standard behind every site and system we deliver: humans make the decisions, humans own the outcomes, and nothing speaks for the business that a person has not verified. AI accelerates the work. It does not get to sign the company’s name.

[Internal link: Web Development page on “build” / AI + Search page on “AI”]

FAQ

Is a business legally responsible for its AI chatbot?

Yes. In the Air Canada case, a tribunal ruled the company was responsible for all information on its website, including chatbot responses. The airline’s argument that the chatbot was a separate entity was rejected. AI output carries the same liability as any company statement.

How can businesses reduce AI chatbot liability?

Treat AI output like employee output. Constrain what the chatbot is allowed to answer, review AI-generated content before publishing, keep policies it references current, and assign a human owner accountable for accuracy. Deploying AI without review is publishing unverified statements under your company’s name.

Running AI on your site without a review process? Book a free audit before it costs you.

Check Out Our Other Blogs