Yes. In Canada, a business is liable for what its AI chatbot tells a customer. A British Columbia tribunal rejected the argument that a chatbot is a separate legal entity responsible for its own actions, and held the company to what the bot promised. There is no federal AI statute doing this work. Ordinary negligence, contract and advertising law already cover it.
By Cody Wise, founder, Wise Media. Last updated 28 September 2026. This article explains how existing Canadian law applies to customer-facing AI. It is not legal advice, and it is not a substitute for advice from counsel on your specific deployment.

Summary
- In Moffatt v. Air Canada, 2024 BCCRT 149, the airline’s chatbot told a customer he could apply for a bereavement fare after travelling. The published policy said the opposite. The tribunal found negligent misrepresentation and ordered Air Canada to pay.
- Air Canada argued the chatbot was a separate legal entity responsible for its own actions. The tribunal rejected it, treating the chatbot as part of the website like any other page.
- Canada has no AI Act in force. What binds a customer-facing chatbot is negligent misrepresentation, contract, the Competition Act’s misleading representation provisions, privacy law, and accessibility obligations.
- Quebec adds a specific requirement where a decision is rendered exclusively by automated processing of personal information: the individual has to be told.
- The technical failure mode is predictable. A bot with access to a stale policy page, no retrieval boundary and no escalation path will eventually assert something the business does not honour.
- The controls that matter are narrow scope, grounded retrieval from one current source, a hard refusal boundary, visible AI disclosure, logged transcripts, and a fast human escalation path.
Table of contents
- The case that settled it in Canada
- Why “the AI said it, not us” is not a defence
- The four bodies of law that actually bind a Canadian business chatbot
- Where chatbots actually go wrong
- The chatbot governance checklist
- Should you even have one? A decision framework
- Common mistakes
- FAQ
The case that settled it in Canada
Jake Moffatt needed to fly after a death in the family. He asked the chatbot on Air Canada’s website about bereavement fares. The bot told him there was a discount for travel because of a death in the family, and that he could submit his ticket within ninety days of issuance to claim the reduced rate. He booked, then applied afterwards. Air Canada refused, because its actual bereavement policy did not allow requests after travel was completed. The correct rule was on a different page of the same website, which the bot linked to.
Moffatt took it to British Columbia’s Civil Resolution Tribunal. The decision came down on 14 February 2024. The tribunal found Air Canada liable in negligent misrepresentation and ordered it to pay damages representing the difference between the fare he paid and the bereavement fare, plus pre-judgment interest and his tribunal fees.
The amount was trivial. The holding was not. This is a small claims style forum, not an appellate court, so it does not bind other courts. It is nonetheless the clearest Canadian statement available on the question every business with a chat widget eventually asks, and it has been cited well outside Canada ever since.
Why “the AI said it, not us” is not a defence
Air Canada’s central argument was that the chatbot was a separate legal entity responsible for its own actions. The tribunal treated the chatbot as part of the website, no different from a static page, and reasoned that it should be obvious to Air Canada that it is responsible for all the information on its website, whether that information comes from a static page or a chatbot.
The second half of the argument was that a customer should have checked the correct page, which the bot had linked. The tribunal was not persuaded. A customer has no way to know that one part of a company’s website is reliable and another part is not, and nothing warned Moffatt that the chat answer was less trustworthy than the policy page.
The test being applied
Negligent misrepresentation in Canada turns on a familiar set of elements: a duty of care arising from the relationship, an untrue or misleading representation, negligence in making it, reasonable reliance by the other party, and resulting loss. Applied to a chatbot, each element lands somewhere a business can actually control.
| Element | What it means for a chatbot |
|---|---|
| Duty of care | You put the widget on your site to answer customer questions. That relationship is the duty. |
| Untrue representation | The model asserted something your policy does not support. Confidence of tone is irrelevant. |
| Negligence in making it | You deployed without grounding, testing or a refusal boundary. This is the element you engineer against. |
| Reasonable reliance | The bot sits on your domain, in your brand. Reliance is reasonable unless you make it unreasonable, clearly and prominently. |
| Damages | The customer acted and lost money. |
Notice that “we used a third party vendor” appears nowhere. Your vendor’s contract may allocate risk between you and them. It does not change your customer’s rights against you.
The four bodies of law that actually bind a Canadian business chatbot
Start with what is not true. There is no Canadian AI Act in force. The Artificial Intelligence and Data Act formed part of Bill C-27, which did not become law. A great deal of published advice discusses AIDA obligations as though they were live requirements. They are not.
That absence is not relief. Four existing bodies of law already reach a customer-facing chatbot, and they were enforceable before anyone shipped one.
1. Negligent misrepresentation and contract
This is the Moffatt route, and it is the most likely one for a small business. A bot states a policy, price, availability, warranty term or eligibility rule incorrectly. The customer acts on it. The business is on the hook for the gap.
There is a related contract risk that gets less attention. A bot that quotes a price, confirms a booking or accepts terms may be doing something a customer can reasonably read as the business making an offer or accepting one. If your chatbot can quote, it should quote from a source of truth rather than generate.
2. The Competition Act
Paragraph 74.01(1)(a) covers making a representation to the public that is false or misleading in a material respect. A chatbot answer given to the public, on your website, about your product, is a representation. Nothing in the provision requires a human to have written it, and the civil provisions do not require intent.
Practically, the higher-risk answers are the ones about price, performance claims, availability and refund entitlements. If your bot can improvise on price, it can improvise you into a misleading representation, which is the same exposure covered in our guide to fixing incorrect information about your business in AI answers, except this time the model is one you deployed. It also runs straight into the display rules we covered in drip pricing rules for Canadian websites, because a bot that quotes an unattainable price has made the same representation your pricing page would have.
3. Privacy law
Chatbots collect personal information, usually more than the business expects, because customers paste order numbers, addresses, account details and sometimes health or financial context into a free text box. Federal and provincial privacy law applies to that collection exactly as it does to a web form.
The Office of the Privacy Commissioner of Canada published principles for responsible, trustworthy and privacy-protective generative AI technologies on 7 December 2023. Two lines matter most for a chat widget. Where a generative AI tool is public-facing, the OPC says to ensure that individuals interacting with the tool are aware that they are interacting with a generative AI tool. It also says to ensure that outputs which could have a significant impact on an individual or group are meaningfully identified as being created by a generative AI tool. Those are guidance rather than statute, but they are the regulator’s stated expectation, and they are cheap to meet.
The practical consequences: name the bot as a bot in the widget header, say in your privacy policy what chat transcripts are used for and how long they are kept, do not send transcripts to a model provider that trains on them unless you have said so, and make sure your consent banner actually covers the chat widget, which is frequently loaded before consent.
4. Quebec’s automated decision rule, and its real scope
Quebec’s private sector privacy statute goes further than the rest of Canada. Section 12.1 provides that a person carrying on an enterprise who uses personal information to render a decision based exclusively on an automated processing of that information must inform the person concerned no later than when it informs them of the decision. On request, the individual must also be told the personal information used, the reasons and the principal factors and parameters that led to the decision, and their right to have the information corrected. They must also be given the chance to submit observations to a member of staff who can review the decision.
Read the scope carefully, because it is routinely overstated. The section is about decisions rendered exclusively by automated processing. A chatbot that answers questions about shipping times is not rendering a decision. A system that automatically approves or refuses an application, a refund, a rate or an eligibility claim, with no human in the loop, is. If you serve Quebec and your automation decides rather than informs, that is the provision to hand your counsel.
A fifth, quieter one: accessibility
Chat widgets are among the worst offenders in accessibility audits. Focus traps, no keyboard escape, messages that never reach a screen reader because the live region is not announced, and contrast that fails on the brand colour. If you are federally regulated or otherwise bound, that is exposure on top of everything above, and it interacts with the Canadian accessibility obligations that already apply to the rest of your site.
Where chatbots actually go wrong
The failures are not exotic. Across deployments they cluster into five patterns, and each has a specific engineering answer.
| Failure pattern | What it looks like | The fix |
|---|---|---|
| Stale grounding | The bot answers from a policy page updated eighteen months ago, or from a cached index nobody refreshes. | Ground retrieval in one current source of truth, and rebuild the index on publish rather than on a schedule. |
| Conflicting sources | Two pages say different things. The model picks one, usually the more helpful one. | Resolve the conflict in the content, not in the prompt. Deduplicate before you deploy. |
| Improvised specifics | Asked for a number the source does not contain, the model supplies a plausible one. | A hard refusal boundary. No source, no answer, escalate instead. |
| Long conversation drift | Ten turns in, the bot is negotiating an exception the business never authorised. | Cap turns, re-inject the scope on every turn, and end sessions that go off scope. |
| Wrong confidence register | The bot states a guess in the same tone it states a fact. | Require the answer to name its source, or say it does not know. |
Moffatt is the first row plus the third. There was a correct policy page. The bot did not answer from it, and nothing stopped it from answering anyway.

The chatbot governance checklist
Ten items. None of them are expensive, and together they are both the risk control and the evidence that you exercised care.
- Write the scope down. One page listing what the bot may answer and what it must refuse. If it is not on the list, it is out of scope.
- Ground every answer. Retrieval from a defined, current corpus. No free generation about policy, price, eligibility or availability.
- Set a refusal boundary. When retrieval returns nothing relevant, the bot says it does not know and hands off. Silence is a feature.
- Ban the high-risk categories outright. Legal, medical, tax, immigration, safety, and anything that looks like a binding quote or a contractual commitment.
- Disclose that it is AI, in the widget header where it is visible before the first message, not in a tooltip.
- Give a one click human escalation that is visible on every turn, not only after the bot fails twice.
- Log every transcript with a retention period you have written down and disclosed. You cannot review what you did not keep, and you cannot keep it indefinitely without saying so.
- Review a sample weekly. Twenty conversations. Look for answers with no source and for anything that reads like a commitment.
- Re-test after every content change. A policy page edit changes what the bot will say. Treat content releases as deployments.
- Keep the record. Dated scope document, test results, review logs. If a dispute ever arises, that file is the difference between a defensible process and a shrug.
Item 10 is the one that gets skipped and the one that pays. Care you cannot evidence looks identical to care you did not take.
Should you even have one? A decision framework
A chatbot is worth deploying when your support volume is high, your answers are stable and documented, and the cost of a wrong answer is low. It is a bad idea in the reverse case, and most small businesses that regret one were in the reverse case.
| Signal | Deploy | Do not deploy yet |
|---|---|---|
| Question volume | Hundreds of repetitive questions a month | A handful a week that you answer personally |
| Answer stability | Policies documented and rarely change | Pricing negotiated case by case |
| Cost of a wrong answer | Low. Shipping times, hours, locations | High. Eligibility, quotes, regulated advice |
| Content quality | One current source of truth | Conflicting pages nobody has reconciled |
| Escalation capacity | Someone can pick up a handoff same day | Nobody is monitoring the inbox |
Pros and cons, stated plainly
- Pro. Deflects repetitive questions at any hour, which is real margin on a support-heavy business.
- Pro. Forces you to document policies properly, because grounding requires a source. Several clients have got more value from the content cleanup than from the bot.
- Pro. Captures intent data on what customers are actually confused about, which is a free roadmap for your site.
- Con. You own every word it says, without having read any of them in advance.
- Con. It needs maintenance. A bot grounded in stale content degrades quietly, and nobody notices until a customer does.
- Con. It adds a privacy surface, an accessibility surface and a performance cost to every page it loads on.
The cheaper alternative is usually underrated. A well structured FAQ, current policy pages and clear contact routing solve most of what a chatbot is bought to solve, with none of the liability surface. That is the same calculation behind choosing between an AI website builder and an agency build: automation is worth it where the work is repetitive and the downside is small, and expensive where it is neither.
Common mistakes
- Relying on a disclaimer to fix everything. A small-print line saying answers may be inaccurate does not make reliance unreasonable when the widget sits on your domain in your brand and is presented as the way to get help.
- Pointing at the vendor. Your contract with a vendor allocates risk between the two of you. Your customer’s claim is against the business they dealt with.
- Letting the bot quote prices. The single highest-risk capability, and the one most often switched on by default.
- Shipping it and never reading the transcripts. You cannot govern what you never look at, and a weekly sample takes twenty minutes.
- Grounding in the whole website. Your site contains outdated blog posts, old promotions and superseded policies. Ground in a curated corpus, not a crawl.
- Loading the widget before consent. Third party chat scripts frequently set storage on load, which undercuts the consent banner sitting right beside them.
- No escalation path. A bot that cannot hand off converts an ordinary question into a complaint.
Frequently asked questions
Is my business legally responsible if my AI chatbot gives a customer wrong information?
In Canada, treat the answer as yes. A British Columbia tribunal held a company liable in negligent misrepresentation for what its website chatbot told a customer, rejecting the argument that the chatbot was a separate legal entity. The decision does not bind other courts, but no Canadian authority points the other way.
Does a disclaimer saying the AI may be inaccurate protect me?
It helps at the margin and it does not immunise you. Reliance has to be unreasonable for the defence to work, and a prominent, specific warning shown before the conversation starts is far stronger than a line in your terms. It is worth having. It is not a substitute for the bot being right.
Do I have to tell customers they are talking to an AI?
There is no general federal statute compelling it. The Office of the Privacy Commissioner’s guidance says public-facing generative AI tools should ensure individuals know they are interacting with one, and disclosure also strengthens any argument about what reliance was reasonable. Treat it as standard practice rather than an open question.
Is my chatbot vendor liable instead of me?
Not to your customer. Your vendor agreement may give you indemnities and it is worth reading what it actually covers, but the customer dealt with your business on your website. Air Canada’s chatbot was not built in house either.
Can a chatbot form a binding contract on my behalf?
It can create a real argument that one was formed, which is why price quotes, booking confirmations and acceptance of terms should never be generated. If the bot needs to quote, have it retrieve a quote your system produced rather than compose one.
Should a small business use an AI chatbot at all?
Only where the volume justifies it and the answers are documented and stable. If you field a few questions a week, or your pricing is negotiated case by case, a clear FAQ and fast human replies will outperform a bot and carry none of the exposure.
The takeaway
Canada did not need an AI statute to answer this question. A chatbot is part of your website, and a business is responsible for what its website says. The absence of a dedicated AI law removes a compliance checklist, not the liability.
Which makes this an engineering problem with a legal consequence. Scope it narrowly, ground it in one current source, give it a refusal boundary and a human escalation path, log what it says, and read a sample of it every week. Do that and the bot is an asset. Skip it and you have published an unreviewed spokesperson.
Deploying AI on your site without deploying the liability
Wise Media builds AI features into Canadian business websites with the grounding, refusal boundaries, disclosure and escalation paths in place from the start, and audits existing deployments that went live without them. If you are running a chatbot now, or planning one, send us the details through the intake form and we will tell you what needs to change. Builds run through our website packages, and ongoing maintenance and review through website growth packages.