Addaly is in open beta. Things will change, and AI answers can be wrong — check anything that matters.

AI, Safety and What Goes Wrong

The failure modes of AI, stated plainly, with the numbers.

Lesson 8 of 738 min

Who is responsible when it is wrong

The chatbot that cost an airline money

In 2022 a man whose grandmother had died asked Air Canada's website chatbot about bereavement fares. The chatbot told him he could book at full price and apply for a discount within ninety days. That was not the airline's policy. When he applied, the airline refused, and argued — in front of British Columbia's Civil Resolution Tribunal — that the chatbot was a separate legal entity responsible for its own actions.

The tribunal rejected that in February 2024, in language worth remembering: the chatbot is part of the company's website, the company is responsible for all the information on it, and it makes no difference whether the information comes from a static page or a chatbot. The award was small, a few hundred dollars. The principle is not.

That case is the cleanest available answer to the most common question about AI harms: who is responsible? The answer, in most jurisdictions and most of the time, is the same person who would have been responsible if a member of staff had said it.

The chain, and where it breaks

For any deployed system there is a chain: the model provider, the company that built a product on it, the organisation that deployed it, the professional who used the output, and the person affected. Responsibility is contested along that chain and the details differ by country, but a few patterns hold.

Professional duties do not transfer to tools. A lawyer who files a brief citing invented cases is sanctioned as a lawyer. A doctor who follows a bad recommendation is judged by the medical standard of care. A structural engineer who stamps a drawing owns the stamp. "The software said so" has not, so far, worked as a defence in any of these fields, and the courts that have addressed it have said the duty to check is exactly the duty that was already there.

Consumer-facing statements bind the business. The Air Canada reasoning generalises: a company that puts an interface in front of customers owns what it says. Regulators in several countries have said the same about advertising claims, pricing and eligibility information.

Model providers disclaim heavily. Read a provider's terms and you will find output disclaimed as-is, warranties excluded, and liability capped at something like the fees paid in the past twelve months. Some now offer copyright indemnities to business customers for specific claims — which is informative in itself, since a company only indemnifies risks it has priced.

Product liability law is being extended. The EU's revised Product Liability Directive, agreed in 2024, brings software including AI within the product liability regime and adjusts the burden of proof where a claimant cannot reasonably be expected to explain a complex system. The separate AI Liability Directive was withdrawn in 2025, so the picture in Europe is a general product regime plus the AI Act's safety obligations rather than a bespoke liability statute. Elsewhere, most claims still run through ordinary negligence, contract and consumer protection law.

What this means for you, in practice

If you use these tools in work that affects other people, three things follow.

You are the last human in the chain, and the chain usually stops there. The output you send under your name is yours. This is not a moral position, it is how the cases have gone.

Contracts matter more than model quality. Before an organisation depends on a vendor, the questions are: what is warranted, what is the liability cap, who indemnifies whom, and what happens when the underlying model changes. Teams routinely spend three months evaluating accuracy and forty minutes on this.

Keep the record. If a system's output contributed to a decision, keep the input, the output, the version and the date. When something is disputed a year later, the absence of a record does not protect you; it just means the reconstruction happens without your evidence in it.

The gap that is not yet closed

Be honest about the unresolved part. When a general-purpose model produces a harmful output through no obvious fault of the deployer, in a use nobody anticipated, the law in most countries does not yet allocate that cleanly. Suing a model provider over a text output faces causation problems that ordinary product cases do not. Several jurisdictions are actively legislating and the answers will differ between them.

What you should not conclude is that responsibility is therefore floating free. Almost every actual harm so far has landed on somebody who had a duty they already had, and the tool did not remove it.

The one thing to keep

Deploying a system does not move responsibility onto it: professional duties, consumer law and product liability keep landing on the human or business that used or presented the output.

Before you move on

A clinic's booking assistant tells a patient a treatment is covered by their insurer, which is untrue, and the patient incurs a large bill. On the pattern of decided cases, where does responsibility most likely sit?

Pick the one you would defend. Nobody sees your answer.

No ads. No data sale. No public scores on people. Ever.

© 2026 Addaly