tuesday, october 6, 2026 · the day's ai, attributed published by trilot llc · wyoming
guide · judgment & safety

Who is liable when your AI is wrong

Where your exposure actually sits when a model speaks for your business, what your vendor's contract already says about it, and the one review step that shrinks it.

Published 2026-09-05 · Updated 2026-09-05 · Read 9 min · Reviewed by Rami Steitieh

Verified 2026-09-05 · Rami
on this page · 0 / 0 checked

The complaint never arrives in the form you rehearsed. A customer forwards a screenshot of your support chat promising a refund window you have never offered. A competitor’s lawyer writes about a line in your AI-drafted comparison page that says their product does something it does not do. A client asks why the case study on your site quotes a person who says they never said it. In each case nobody decided anything. A model produced a plausible sentence, the sentence went out under your name, and now somebody wants a remedy.

The instinct at that point is to look upstream. You did not write it, the tool did, and the tool belongs to a company with a legal department larger than your whole business. That instinct is wrong almost everywhere it has been tested, and the reason is not subtle: you chose the tool, you pointed it at your customers, and you published what it said. What follows is where the exposure actually sits, what the contracts you already agreed to say about it, and the small number of habits that keep an ordinary model error from becoming a legal problem. None of it is legal advice, and none of it is written for regulated deployment. If you are automating decisions about credit, hiring, housing, insurance or medical care, you need a lawyer and a risk process, not a guide.

The tool is a supplier and you are the publisher

The clearest test so far is small, boring and unhelpful to anyone hoping for a loophole. A customer relied on what an airline’s website chatbot told him, the information was wrong, and he took it to British Columbia’s Civil Resolution Tribunal. The airline argued that it could not be held liable for information provided by one of its agents, servants or representatives, including a chatbot. The tribunal read that as suggesting “the chatbot is a separate legal entity that is responsible for its own actions”, and answered it in two sentences: “While a chatbot has an interactive component, it is still just a part of Air Canada’s website. It should be obvious to Air Canada that it is responsible for all the information on its website” [1].

The money was trivial. The tribunal ordered $812.02 in total, in Canadian dollars, made up of $650.88 in damages, $36.14 in pre-judgment interest and $125 in tribunal fees [1]. What matters is the reasoning, because it costs nothing to apply and it generalises. A chatbot is a part of your website. A generated product description is a part of your catalogue. An automated support reply is a letter from you. The interactive component changes how the text is produced, not whose text it is.

Regulators have taken the same line without waiting for new statutes. When the US Federal Trade Commission announced Operation AI Comply on 25 September 2024, a sweep against companies using AI to deceive consumers, its chair at the time put the position in one sentence: “there is no AI exemption from the laws on the books” [2]. The cases in that sweep included a service that claimed to be “the world’s first robot lawyer” and a writing tool whose “Testimonial & Review” feature produced detailed consumer reviews “based on very limited and generic input” [2]. Nothing in that enforcement theory required a new law about AI. Existing rules on deception, endorsements and advertising already reached the conduct, because the conduct was a business making false claims to customers.

Your vendor’s contract already assigned the risk, and it assigned it to you

Before you speculate about how a court might rule, read the agreement you clicked through. It is not ambiguous, and the two vendors most small businesses actually pay say it in the same shape.

OpenAI’s terms of use, effective 1 January 2026, give you the output and the responsibility together. You “own the Output,” and in the same document you “must evaluate Output for accuracy and appropriateness for your use case, including using human review as appropriate, before using or sharing Output from the Services” [3]. You also must not use “any Output relating to a person for any purpose that could have a legal or material impact on that person, such as making credit, educational, employment, housing, insurance, legal, medical, or other important decisions about them” [3]. The accuracy section is blunter: “Output may not always be accurate. You should not rely on Output from our Services as a sole source of truth or factual information, or as a substitute for professional advice” [3]. The business agreement repeats it for companies: “Customer is solely responsible for all use of the Outputs and for evaluating the accuracy and appropriateness of Output for Customer’s use case” [5].

Anthropic’s commercial terms land in the same place. “It is Customer’s responsibility to evaluate whether Outputs are appropriate for Customer’s use case, including where human review is appropriate, before using or sharing Outputs,” and factual assertions in outputs “should not be relied upon without independently checking their accuracy, as they may be false, incomplete, misleading or not reflective of recent events or information” [4]. The warranty disclaimer removes the last doubt, in capitals: “ANTHROPIC DOES NOT WARRANT, AND DISCLAIMS THAT, THE SERVICES OR OUTPUTS ARE ACCURATE, COMPLETE OR ERROR-FREE” [4].

Then there is the clause most people never reach. Indemnity in these contracts runs toward the vendor as well as away from it. OpenAI’s terms of use put it directly to business users: “If you are a business or organization, to the extent permitted by law, you will indemnify and hold harmless us, our affiliates, and our personnel, from and against any costs, losses, liabilities, and expenses (including attorneys’ fees) from third party claims arising out of or relating to your use of the Services and Content or any violation of these Terms” [3]. If a third party sues over something you published from a model, the contract you agreed to points the cost at you, and can point some of the vendor’s cost at you as well.

Vendors do offer legal cover, and it is worth having. It just does not cover the failure you are worried about.

OpenAI’s Services Agreement commits to “indemnify, defend, and hold Customer harmless against any liabilities, damages and costs (including reasonable attorneys’ fees) payable to a third party arising out of a Claim alleging that the Services infringe any third-party IP Right” [5]. Read the noun. The claim has to be that the service infringes an intellectual property right. The agreement then excludes claims arising from “combination of any Services with products, services, or software not provided by OpenAI”, from “modification of any Services by any party other than OpenAI”, and from Customer Content and Customer Applications [5].

Anthropic’s is drawn the same way. It defends against a third-party claim alleging that the customer’s paid use of the services, or outputs generated through it, “violates any third-party intellectual property right” [4]. It then excludes claims arising from inputs or other data the customer provided, from use the customer “knows or reasonably should know violates or infringes the rights of others”, from “the practice of a patented invention contained in an Output”, and from “an alleged violation of trademark based on use of an Output in trade or commerce” [4]. Google’s generative AI indemnity is narrower still in one practical respect: it applies to a specific named list of services, which as of 20 July 2026 runs to Google Cloud and Workspace products such as Gemini for Google Cloud, Gemini Enterprise, Gemini in Workspace, NotebookLM Enterprise and Grounding with Google Search [6]. A consumer subscription is not on that list.

So the shape of the protection is this. If a model reproduces someone’s copyrighted work and they sue you for it, you may have a defence paid for by your vendor, provided you are on a covered plan and did not trigger an exclusion. If a model states a false fact about a named competitor, invents a policy your customer relies on, or gets a number wrong in a quote, there is no indemnity anywhere in these documents that touches it. That is the whole gap, and it is the exact gap that ordinary daily AI use sits in.

Sort your output by whether it is public and names a real thing

You cannot review everything, and you do not need to. Exposure is not evenly spread across AI output, and the sorting rule is simpler than a risk framework.

The high-exposure zone is anything that reaches a person outside your business and makes a checkable claim about a named person, company, product, price or date. That covers support replies, generated product and service descriptions, comparison pages, quotes and proposals, case studies, and any assistant widget on your site. This is where defamation, misleading-advertising and contract exposure concentrate, because each of those needs an identifiable subject and a statement a reader could act on. It is also where the airline’s chatbot sat [1].

The low-exposure zone is internal and non-factual: brainstorming, first drafts you will rewrite, summaries only your team reads, tone and formatting work. A model that mangles an internal meeting note costs you ten minutes. It does not create a claimant.

Most operators have never drawn this line, which is why review either does not happen or happens uniformly and gets abandoned. Draw it once, in writing, and the rule becomes cheap: if it is going outside and it names something real, a human reads it before it ships. Nothing else needs the same treatment. The point of sorting is to make the review small enough that it actually survives a busy week.

In the EU, labelling AI output is a rule and not a courtesy

Disclosure used to be a matter of taste. Since 2 August 2026, when the EU AI Act’s transparency obligations began to apply, parts of it are law for anyone in scope [7].

Article 50 puts three things on the table. Providers of AI systems intended to interact directly with people must ensure those people “are informed that they are interacting with an AI system”, unless that is obvious to a person who is “reasonably well-informed, observant and circumspect” [7]. Providers of systems that generate synthetic audio, image, video or text must ensure outputs “are marked in a machine-readable format and detectable as artificially generated or manipulated” [7]. And deployers who publish AI-generated or manipulated text “with the purpose of informing the public on matters of public interest” must disclose that it was artificially generated, with an exception where the content “has undergone a process of human review or editorial control” and “a natural or legal person holds editorial responsibility for the publication” [7].

That last exception is the sentence to read twice, because it describes the process you should be running anyway. The way out of the disclosure obligation for published text is a review by a person plus a named someone who carries responsibility for what went out. The regulation and the practical rule converge: either a human owns the words, or you say a machine wrote them. Even outside the EU, that is a defensible position to be able to describe to a customer, a client or a court.

One direction in which liability runs back to the vendor

Liability is not entirely one-way, and one change is worth knowing about because it lands soon. The EU’s revised product liability directive defines a product as “all movables, even if integrated into, or inter-connected with, another movable or an immovable; it includes electricity, digital manufacturing files, raw materials and software” [8]. Software is a product. Recital 13 goes further and says that “a developer or producer of software, including AI system providers within the meaning of Regulation (EU) 2024/1689 of the European Parliament and of the Council, should be treated as a manufacturer” [8]. The directive applies to products placed on the market or put into service after 9 December 2026 [8]. It also states that liability under it “is not, in relation to the injured person, limited or excluded by a contractual provision or by national law” [8], so the fine print does not do the work there that it does elsewhere.

For a small operator this cuts two ways, and it is worth being honest about both. If a defective AI component causes the kind of damage the directive covers, the strict-liability route reaches its producer instead of stopping at a term of service. But if you build and ship software of your own with a model inside it, the same definition can reach you, because what you sold is also software. The direction of travel is that AI stops being treated as a mysterious third thing and gets sorted into the categories law already has: a product has a manufacturer, a publication has a publisher, an advertisement has an advertiser.

checklist
Before AI output goes outside your business
0 of 8 · saved in this browser only
calculator
Human-review load per month
— h / month

items × share that name something real × minutes × 4.33 weeks. Computed in the page; nothing is sent anywhere.

What still goes wrong

The honest limits start with jurisdiction. A British Columbia tribunal does not bind a court anywhere else, the FTC’s authority stops at the US border, and the AI Act and the product liability directive are EU instruments with their own scope tests [1][2][7][8]. Nothing here tells you what a judge in your country would do on your facts. What the record does show is a consistent direction. A Canadian tribunal and a US regulator each treated AI output as ordinary business speech with an ordinary business behind it, and neither reached for a category that does not yet exist [1][2]. Planning on the assumption that such a category will appear is a bet with no evidence behind it.

Disclaimers are the second limit, and they are weaker than they feel. A footer reading “AI-generated, may contain errors” sets expectations and shows care, and it is worth having. It will not help much if your assistant states something false and damaging about a named competitor, because the question in that kind of claim is what you published and what you did to check it, not what your fine print said. The vendors’ own disclaimers are instructive here: they work by transferring the evaluation duty to you inside a contract you accepted [3][4][5], which is a mechanism your website footer does not have with a stranger.

The third limit is that the review step is real work, and the reason you bought the tool was to avoid work. That tension does not resolve; it gets rationed. Review in proportion to consequence, and accept that some low-value public output will go out unread. Finally, none of this is written for regulated or high-stakes deployment. If an AI system of yours is touching credit, employment, housing, insurance, medical or legal decisions, you are in a different regime with its own conformity obligations, and the right document is longer than this one and written by a lawyer who knows your jurisdiction.

sources
  1. 01Moffatt v. Air Canada, 2024 BCCRT 149decisions.civilresolutionbc.ca
  2. 02FTC — Operation AI Comply: crackdown on deceptive AI claims and schemesftc.gov
  3. 03OpenAI — Terms of use (effective 1 January 2026)openai.com
  4. 04Anthropic — Commercial Terms of Serviceanthropic.com
  5. 05OpenAI — Services Agreement (business terms, effective 1 January 2026)openai.com
  6. 06Google Cloud — Generative AI indemnified servicescloud.google.com
  7. 07EU AI Act — Article 50, transparency obligationsartificialintelligenceact.eu
  8. 08Directive (EU) 2024/2853 on liability for defective productseur-lex.europa.eu
next guide
What actually keeps an AI agent inside the lines
10 min · verified 2026-09-05
related guides