PREDICTIVE TREND INSIGHT
Corporate legal liability for ungoverned decisions made by AI agents Illustration

Corporate legal liability for ungoverned decisions made by AI agents

Direct Summary:

A company is legally responsible for the decisions its AI agents make in front of customers or counterparties, in essentially the same way it's responsible for what its employees say and do. This isn't speculative — a tribunal already ruled on it. In Moffatt v. Air Canada (2024), Air Canada argued its website chatbot was "a separate legal entity" responsible for its own mistakes; the tribunal rejected that and held the company liable for negligent misrepresentation. Deploying an AI agent doesn't create a liability shield; it creates a new channel through which the same underlying legal duties apply.

"You don't have to be great to start, but you have to start to be great."

— Zig Ziglar

Key Insights

  • "The AI decided, not us" is not a defense: the Air Canada tribunal explicitly rejected the argument that a company's own deployed chatbot is a separate entity it isn't responsible for.
  • The legal theory is usually familiar, not novel: negligent misrepresentation, breach of contract, and ordinary agency/vicarious-liability doctrine already cover most "the AI agent did it" scenarios — courts are applying existing law, not waiting for AI-specific statutes.
  • Some jurisdictions are closing the remaining gap anyway: California has enacted a statute specifying that a defendant cannot use an AI system's autonomous operation as a defense to liability, and Colorado's AI Act (effective June 2026) requires deployers of high-risk systems to run impact assessments and maintain active risk-management programs.

"What happens legally when an AI agent makes a bad decision on the company's behalf" sounds like a novel question, but the emerging answer is mostly a familiar one: the company is on the hook, the same as it would be for a human employee or a printed policy document. The clearest precedent for this is a small-dollar Canadian tribunal case that's become the reference point for the whole issue.

The precedent: Moffatt v. Air Canada

In late 2022, Jake Moffatt asked Air Canada's website chatbot about bereavement fares after a family death. The chatbot told him he could book a full-fare ticket and claim the bereavement discount retroactively — which was wrong; Air Canada's actual policy required the discount to be requested before travel. When Moffatt tried to claim it afterward, Air Canada refused, and the case went to the British Columbia Civil Resolution Tribunal.

Air Canada's defense was, in effect, an ungoverned-agent argument: it claimed the chatbot was "a separate legal entity that is responsible for its own actions." The tribunal rejected this outright in February 2024, finding Air Canada liable for negligent misrepresentation and ordering it to pay damages. The tribunal's reasoning was blunt: a company is responsible for all information it puts in front of customers, whether that information comes from a static web page, a human agent, or an automated system. This is now the standard reference point cited across legal commentary on AI agent liability, because it's a clean, decided case rather than a hypothetical.

Why this isn't really a new legal problem

Legal analysts tracking agentic AI liability generally frame it through existing doctrine rather than treating it as legally novel. Under ordinary vicarious liability principles, an organization can be responsible for an AI agent's actions similarly to how an employer is responsible for an employee acting within the scope of their role — the AI doesn't need to be a "person" for the company to own the consequences of deploying it. Legal commentators tracking this space note that jurisdictions are increasingly converging on a "reasonable oversight" standard: the deploying organization is liable for an agent's bad decision unless it can demonstrate it had genuine monitoring, auditing, and safety controls in place — not just a policy document saying it should.

Some jurisdictions are also moving to close any residual ambiguity by statute rather than relying purely on case law. California has enacted a law that specifically bars defendants from arguing that an AI system's autonomous operation is itself a defense against liability. Colorado's AI Act, effective June 2026, goes further procedurally: it requires deployers of high-risk AI systems to conduct regular impact assessments and maintain active risk-management programs — turning "we didn't have adequate oversight" from a liability argument into a compliance violation in its own right.

What this means for governance in practice

The practical takeaway from Air Canada isn't "don't use AI agents" — it's that deploying one doesn't change who's accountable for its output. Treat an AI agent's customer-facing statements and decisions the same way you'd treat statements from a human employee: they need to be accurate, the company needs a way to catch and correct mistakes quickly, and "the system said something wrong" needs to trigger the same kind of remediation a human error would, not get treated as a technical curiosity outside the company's responsibility.

Practical Challenge

Read the tribunal's actual reasoning in Moffatt v. Air Canada (linked below) and identify the specific argument Air Canada made to try to avoid liability — then write one sentence on why that argument failed.

Concept Check

What legal argument did Air Canada make in its defense, and how did the tribunal respond?
Correct! The tribunal explicitly rejected the "separate entity" argument, ruling that a company is responsible for all information on its website regardless of whether a human or a chatbot produced it.
Incorrect. Try again! Hint: Air Canada's defense centered on trying to disclaim responsibility for its own deployed tool, not on disputing the facts.

Sources & Further Reading

Previous Guide Dashboard Next Guide