Is Your Business Liable for What Your AI Chatbot Tells Customers? featured image

Is Your Business Liable for What Your AI Chatbot Tells Customers?

by John DiGiacomo

Partner

Revision Legal

When an AI chatbot speaks to your customers, it is speaking on your business’s behalf. If it gets something wrong — inventing a return policy, promising capabilities a product does not have, quoting an incorrect price, or providing inaccurate information about a service — saying “the AI made a mistake” is unlikely to protect you. Customers who reasonably rely on those statements have recourse under consumer protection law, and courts and regulators have begun making clear that deploying an AI tool does not transfer legal responsibility away from the business that deployed it.

AI Is Not a Legal Shield

Businesses are deploying AI chatbots across customer service, sales, support, and product recommendation functions at a rapid pace. The appeal is obvious: AI can handle high volumes of customer interactions at low cost. But the legal framework governing those interactions has not changed. When a chatbot operates through your website, your app, or your customer service system, customers reasonably understand its responses as information coming from your business. Courts treat this no differently than they would treat a misleading statement from a human employee acting within the scope of their role.

The Federal Trade Commission has been explicit on this point. The FTC Act, 15 U.S.C. § 45, prohibits unfair or deceptive acts or practices in commerce. In 2025, the FTC finalized a consent order requiring DoNotPay to cease making deceptive claims that its AI service could substitute for a licensed human attorney — a case that illustrates the Commission’s willingness to hold AI businesses to the same standards as any other commercial actor. The FTC has separately issued guidance making clear that AI does not create an exception to consumer protection law, and that automation does not relieve a business of responsibility for the claims it makes to consumers.

The Legal Exposure Comes From Ordinary Statements

The risk does not require sophisticated AI-generated legal advice or medical recommendations. Consumer protection liability can arise from simple, routine chatbot responses. Consider the exposure that exists when a chatbot tells a customer any of the following:

  • “Your order is fully refundable.”
  • “This product is safe for use with [specific condition or context].”
  • “There are no additional fees.”
  • “The item is in stock and will ship within 24 hours.”
  • “You qualify for our premium tier.”
  • “Our products are entirely made in the United States.”

If any of these statements is false, misleading, or unsupported, the fact that a language model generated it does not automatically shield the business from liability under the FTC Act, state Unfair, Deceptive, or Abusive Acts or Practices (UDAP) statutes, express warranty claims under the Uniform Commercial Code, or the Magnuson-Moss Warranty Act, 15 U.S.C. § 2301 et seq., which governs written warranties on consumer products.

The Air Canada Case: A Cautionary Precedent

The most widely cited illustration of AI chatbot liability is Moffatt v. Air Canada (2024), decided by the British Columbia Civil Resolution Tribunal. A passenger asked Air Canada’s chatbot about bereavement fares following a family member’s death. The chatbot told him he could purchase a full-fare ticket and apply for a discounted bereavement rate retroactively. That information was wrong — Air Canada’s actual policy required the bereavement rate request to be made before the flight. When the passenger sought the discount after travel, Air Canada refused, arguing that the chatbot was a separate legal entity responsible for its own outputs.

The tribunal rejected that argument. It held that Air Canada was responsible for all information on its website, including information provided by its chatbot, and that the passenger’s reliance on the chatbot’s statement was reasonable. Air Canada was ordered to compensate the passenger for the difference between what he paid and the bereavement rate. While this decision came from a Canadian tribunal, U.S. courts are watching these precedents, and domestic consumer protection law provides multiple pathways for plaintiffs to bring analogous claims.

Privacy Obligations Add Another Layer of Risk

Beyond consumer protection, AI chatbots that collect information from customers during conversations create privacy obligations. Customer-facing chatbots typically gather names, contact information, account details, and descriptions of customer problems. Depending on your state privacy law obligations — including CCPA/CPRA for California-based customers — that data collection may need to be disclosed in your privacy policy, and customers may have rights to access or delete the information gathered during chatbot interactions.

The FTC has specifically warned businesses about privacy obligations arising from AI systems that interact with consumers. If your chatbot uses customer conversation data to train or improve an AI model, or shares that data with third-party AI providers, additional disclosure obligations may apply. Learn more about how our internet law attorneys help businesses navigate AI compliance obligations.

How to Reduce Your Legal Exposure

Businesses can continue using AI chatbots while meaningfully reducing their legal risk by taking the following steps:

Connect the chatbot to verified, current information. A chatbot that draws from a controlled, up-to-date knowledge base of your actual policies, product specifications, and service terms is far less likely to generate false statements than one allowed to generate responses freely. Retrieval-augmented generation (RAG) architectures, which ground AI responses in specific curated documents, reduce hallucination risk substantially.

Test and monitor responses systematically. Run regular adversarial tests in which testers ask the chatbot questions likely to produce inaccurate answers — edge cases, policy details, product comparisons, eligibility questions. Document what the chatbot says and correct the underlying knowledge base when errors appear.

Limit the chatbot’s authority. A chatbot should not be able to change contracts, issue refunds, promise upgrades, make service-level commitments, or bind the business to anything beyond strictly informational responses. Any request involving a transaction, a complaint escalation, a legal question, or a sensitive matter should route to a human employee.

Do not rely on disclaimers alone. A disclaimer stating that “AI-generated responses may contain errors” is not a defense to a consumer protection claim if the chatbot continues to make materially false statements that customers rely on. Disclaimers may be relevant context, but they do not excuse ongoing inaccuracy.

Limit what personal data the chatbot collects. Collect only the information necessary for the chatbot to perform its function. Ensure your privacy policy accurately describes how chatbot interaction data is stored, used, and shared. If the chatbot passes data to a third-party AI provider, review that provider’s data processing terms carefully.

Contact the Internet Law Attorneys at Revision Legal

If your business uses AI chatbots or is considering deploying AI in customer-facing functions, the experienced internet law attorneys at Revision Legal can help you understand your legal obligations and structure your AI use to reduce exposure. Contact us through the form on this page or call (855) 473-8474.

Extra, Extra!
Related Posts

What to Look for When Buying an Existing E-Commerce Business

What to Look for When Buying an Existing E-Commerce Business

Revision Legal

Buying an existing e-commerce business can look like a shortcut to an established brand, a proven customer base, and immediate revenue. But what you are actually buying is a bundle of legal assets and obligations — trademarks, copyrights, domain names, software licenses, customer data, supplier contracts, and platform accounts — and if any of those […]

Read more about What to Look for When Buying an Existing E-Commerce Business

Can Your Business Be Fined for Not Having a Cookie Consent Banner?

Can Your Business Be Fined for Not Having a Cookie Consent Banner?

Revision Legal

Many business owners treat a cookie consent banner as a formality — a pop-up visitors click through before getting on with whatever brought them to the site. From a legal standpoint, that framing gets it backwards. The banner is a symptom. The real issue is whether your website is activating non-essential tracking technologies before obtaining […]

Read more about Can Your Business Be Fined for Not Having a Cookie Consent Banner?

5 Essential Laws Every E-Commerce Business Must Comply With

5 Essential Laws Every E-Commerce Business Must Comply With

Revision Legal

Running an e-commerce business involves far more than selecting products and setting up a checkout flow. Every online store operating in the United States has legal obligations that govern how it collects customer data, advertises products, handles email marketing, and designs its website. Ignoring these obligations — even unintentionally — can result in regulatory fines, […]

Read more about 5 Essential Laws Every E-Commerce Business Must Comply With

Put Revision Legal on your side