The model hallucinated. The vendor built it. The chatbot “said it.” The agent acted on its own.
If your organization deploys the system, you still own the outcome.
The chatbot is still the company’s voice
That principle was unmistakable in Moffatt v. Air Canada (2024 BCCRT 149). A customer relied on the airline’s website chatbot for bereavement-fare guidance. The chatbot was wrong. Air Canada argued, in effect, that the chatbot was a separate legal entity responsible for its own actions. The British Columbia Civil Resolution Tribunal called that “a remarkable submission” and held the airline liable.
A chatbot on a company website is still the company’s voice.
The same logic has hardened
California’s AB 316, effective January 1, 2026, blocks defendants who developed, modified, or used an AI system from claiming the AI autonomously caused the harm as if it were a separate legal actor. Other defenses (causation, foreseeability, comparative fault) can still be raised. “The AI did it by itself” cannot.
A U.S. federal court made a similar point in 2026 in American Council of Learned Societies v. National Endowment for the Humanities (S.D.N.Y.). The court rejected the idea that an institution could “scapegoat ChatGPT” after using it as a chosen instrument without adequate human review. The tool does not absorb the responsibility. The organization that chose it does.
The pattern across professions
Lawyers have been sanctioned for filing AI-generated fake citations. In a 2026 Mississippi federal case, attorneys on both sides were removed from a lawsuit after AI hallucinations appeared in filings. The professional duty did not change because software was involved. The human who submitted the work remained accountable.
Customer-facing chatbots have produced the same result. In May 2026, Germany’s Higher Regional Court of Hamm held a medical company liable for misleading chatbot answers about physician qualifications, treating the error as the company’s commercial statement — not the model’s independent act. That court allowed appeal; the operational lesson does not depend on the last appeal.
Harder cases involving frontier chatbots and alleged personal harm are still fact-specific. What is not unsettled for leaders is the operational rule: if your company uses AI to inform customers, employees, or decisions, “the model made a mistake” is not a governance strategy.
Regulation is moving the same way
The EU AI Act splits responsibility between providers, who design and place systems on the market, and deployers, who use those systems under their authority. Deployers of high-risk systems must assign human oversight to people with the competence, training, and authority to intervene. They must monitor operation, retain logs, and escalate serious incidents.
Human oversight is supposed to be real, not ceremonial. People must be able to understand the system’s limits, detect anomalies, resist automation bias, and stop the system if needed.
That is the leadership issue inside the legal language. Accountability fails when ownership is shared so widely that nobody owns the outcome.
So who should be accountable?
In practice, responsibility sits in layers:
- The organization that puts the system in front of customers or employees
- The leader who approved the use case
- The operator assigned to monitor it
- The provider or vendor, when design, safety, or documentation failures contribute to harm
- The human reviewer, when they accept an output they should have checked
The mistake is pretending one of those layers can disappear. Vendors matter. Models matter. The company that deployed the system still has a duty of care.
This gets more urgent as organizations move from chatbots to agents that can take actions — send a message, change a record, file a claim, trigger a workflow. If no one can explain what it did, why it did it, and who had authority to stop it, accountability is already broken.
What strong AI leadership looks like
Do not wait for a lawsuit to invent a process. Build accountability before the first production mistake.
- Name an owner. Every production AI system needs a human accountable for outcomes, not just a project team.
- Classify the risk. A writing assistant and a claims engine should not have the same controls.
- Verify before high-stakes use. If the output affects money, rights, safety, reputation, or legal positions, a competent human must review it.
- Design a stop button. Oversight that cannot interrupt the system is not oversight.
- Log the trail. Who used the system, what it produced, what was accepted, and what was overridden.
- Train the people in the loop. Untrained review is rubber-stamping.
- Own the communication. When AI is wrong, the organization explains, corrects, and remediates. It does not hide behind the model.
Teams copy what leaders model. If leaders treat AI errors as the technology’s problem, people will ship faster and check less. If leaders treat AI as a powerful tool that still requires judgment, people will build systems that can survive contact with reality.
AI will make mistakes. That is not the scandal. The scandal is having no one responsible when it does.
The companies that scale AI well will not be the ones that never fail. They will be the ones that can answer, quickly and clearly: Who owned this, what went wrong, and what changes now?
This article is for general information. It is not legal advice.