Your Chatbot Lied to a Customer. Now Who Pays?

AI chatbot lawsuits are mounting in 2026. The legal risk for every business isn't the headline case -- it's the Air Canada line. How to limit your exposure.

Cover Image for Your Chatbot Lied to a Customer. Now Who Pays?

On May 22, 2026, Northeastern University ran a piece with a blunt headline: ChatGPT faces a lawsuit onslaught. As of March, at least 11 suits had been filed against OpenAI alone, plus more against Character.AI and Google. The theories are escalating fast -- wrongful death, product design defect, failure to warn. In January, the landmark Setzer case settled after a court did something no court had done before: it classified an AI chatbot's output as a "product" rather than protected speech.

If you run a chatbot on your website, it's tempting to read those headlines and relax. Those are suits against the labs that build the models, over tragic edge cases involving companion AI. You just answer shipping questions. None of it applies to you.

That's the wrong conclusion. The lawsuits making headlines are about foundation-model makers and catastrophic harm. The legal exposure that applies to your business is older, quieter, and far more settled. It has a name most people in support already know: the Air Canada line.

The case every business chatbot owner should have memorized

In February 2024, a Canadian tribunal ruled on a dispute that looked trivial. A grieving customer had asked Air Canada's website chatbot about bereavement fares. The bot told him he could book now and apply for a refund within 90 days. That policy did not exist. The bot made it up.

When the customer asked for the refund, Air Canada refused and argued, in writing, that the chatbot was "a separate legal entity that is responsible for its own actions." The tribunal rejected that outright. Its ruling is the sentence to tape to your monitor:

"It makes no difference whether the information comes from a static page or a chatbot."

Air Canada was ordered to honor the invented policy and pay damages, interest, and fees. The dollar amount was small. The principle was not. A regulator looked at a hallucinating bot and said: this is the company speaking. You are bound by what it says.

That principle has only hardened since. The Setzer settlement's "product" framing means chatbot output can be evaluated like any other thing a company ships -- subject to product-liability theories when it's defective. US courts imposed over $145,000 in AI hallucination sanctions in Q1 2026, including a record $110,000 penalty in Oregon and a first-of-its-kind professional license suspension in Nebraska. The headline suits may take years and may not reshape the industry, as Northeastern's John Wihbey cautioned -- proving a specific technology harmed a specific person is hard. But the Air Canada line needs no novel legal theory. It already works, in small-claims tribunals and consumer-protection complaints, today.

This post is about that everyday exposure, not the headline litigation. None of it is legal advice -- talk to a lawyer about your situation. The goal here is narrower and more useful: understand exactly how a website chatbot creates liability, and what controls actually reduce it.

The seven ways a support bot gets you sued

"Hallucination" is a single word for at least seven distinct failure modes, and each carries a different kind of business risk. A bot that invents a refund window is a different problem from one that fabricates a safety instruction.

Hallucination typeWhat the bot doesLiability it creates
PolicyInvents a return, refund, or warranty termYou may be bound to honor it (the Air Canada line)
PricingQuotes a price, discount, or fee that doesn't existDeceptive-pricing and consumer-protection exposure
Account-specificStates a wrong fact about this customer's order or balanceBreach of contract, misrepresentation
ActionClaims it did something ("your order is cancelled") that didn't happenFailure to deliver; reliance damages
CitationCites a source, statute, or document that doesn't existSanctions in regulated contexts; loss of trust
CapabilityPromises something the product can't doFalse advertising
SafetyGives a wrong instruction with physical consequencesNegligence, product liability, the most serious tier

The throughline: the law doesn't care that an AI generated the statement. The FTC and state consumer-protection statutes prohibit unfair or deceptive practices regardless of whether a human or a model produced them. As one liability analysis put it, if your AI acts as an agent of your business, you bear responsibility for what it communicates.

Why a raw LLM is a liability machine

Here's the uncomfortable engineering fact behind all of this. A large language model is optimized to produce fluent, plausible, confident text. It is not optimized to produce true text. Those two goals overlap most of the time, which is exactly what makes the failures dangerous -- the wrong answer arrives in the same calm, authoritative tone as the right one. There's no tremor in its voice when it invents your refund policy.

People assume retrieval fixes this. It helps enormously, but it isn't a guarantee. A 2025 Stanford study of retrieval-heavy legal research tools found the best one was correct and grounded on only 65% of queries; competitors landed at 41% and 19%. These are expensive, purpose-built products with the model pointed at a curated corpus, and they still hallucinated on a third of questions. Bolting a general-purpose model onto your website with a system prompt that says "be helpful" is not in the same universe of safety.

The lesson is not "don't use a chatbot." Plenty of businesses resolve the majority of their support volume with AI and never face a problem, because they constrained the bot correctly. The lesson is that the safety lives in the architecture around the model, not in the model itself. A chatbot is only as defensible as the controls you put between the language model and your customer.

The controls that actually reduce exposure

Map each control to the risk it addresses. This is the part that matters, and it's where platform choice stops being cosmetic.

ControlWhat it doesRisk it cuts
Retrieval groundingAnswers only from your training content, not the model's memoryPolicy, pricing, capability hallucinations
Authoritative Q&A pairsExact, hand-written answers that override everything elseThe high-stakes questions you can't get wrong
Source citationShows which document an answer came fromCitation hallucinations; makes review possible
Real-time actionsLooks up live order/account data via API instead of guessingAccount-specific hallucinations
Confidence-based handoffRoutes uncertain or high-risk intents to a humanAction and safety hallucinations
Output guardrailsBlocks invented discounts, fake URLs, unconfirmed claimsPricing and action hallucinations
Conversation logsA reviewable record of every answer the bot gaveEvidence, auditing, fast correction

A few of these deserve detail, because they're where most teams under-invest.

Grounding is the floor, not the ceiling. Training your chatbot on your own website, documents, and help center is the difference between a bot that answers from your reality and one that answers from the internet's average. In Agentkit, that's the default: a chatbot answers from the content you train it on -- crawled pages, uploaded PDFs and docs, and text snippets. The model is instructed to work from that corpus rather than improvise. For document-heavy support, chatting with your own documents keeps answers tethered to the actual policy file, not a paraphrase of it.

Q&A pairs are your seatbelt for the questions that cannot be wrong. Grounding reduces invention but doesn't eliminate it. For the handful of questions where a wrong answer is a lawsuit -- your refund window, your cancellation terms, a safety-critical instruction -- you want a hard-coded answer, not a generated one. Agentkit's Q&A pairs do exactly this: an exact, human-written answer that takes priority over every other source. The model doesn't get a vote on whether your return policy is 30 days. You wrote it down; the bot reads it back. Identify your ten highest-liability questions and lock them as Q&A pairs before you ship.

Real-time actions replace guessing with looking up. Account-specific hallucinations -- "your order shipped yesterday" when it didn't -- come from a bot answering questions it has no data for. The fix is to give it data. Custom API actions let the chatbot call your order system, CRM, or inventory in real time and answer from the actual record. If the data isn't available, a well-built bot says so instead of inventing a status.

Handoff is a liability control, not a UX nicety. The single most important architectural decision is what the bot does when it's unsure. A defensible chatbot escalates low-confidence answers and high-risk intents -- refunds, billing, cancellations, anything safety-adjacent -- to a person. Designing that boundary well is its own discipline; we covered it in depth in AI human handoff design. The bot that says "let me get a teammate" on a refund dispute is the bot that never invents a refund policy.

Instructions and guardrails set the bot's defaults. Your system prompt should tell the bot to refuse to speculate, to never invent prices or discounts, to admit when it doesn't know, and to stay strictly within your domain. Good prompt engineering turns "be helpful" into "be helpful, but never make up a policy, and escalate anything you're not certain about." Pair that with domain restrictions so the widget only runs on your own pages, and rate limiting so a single user can't probe it into misbehaving the way DPD's chatbot was famously goaded into swearing at customers in 2024.

Logs are your evidence and your early-warning system. Every Agentkit conversation is logged. That record does two jobs: it lets you review what the bot actually told people (and correct a bad pattern before it becomes a complaint), and it's the documentation you'll want if a customer ever claims the bot promised something. Review the grounded-answer rate and the questions that triggered handoff weekly. The bot that's quietly drifting will show up in the logs long before it shows up in a tribunal.

One more, easy to miss: keep the knowledge base current. Half of liability comes not from invention but from confidently stating a policy that used to be true. Auto-retrain (on Standard plans and above) re-crawls your content on a schedule so the bot isn't citing last quarter's pricing page.

A pre-launch liability checklist

Before you embed a chatbot on a page where customers make decisions, walk this list:

  1. Is it grounded? The bot answers from your content, not the open model. Verify by asking it something not in your docs -- it should decline, not improvise.
  2. Are the high-stakes answers locked? Refund, cancellation, warranty, pricing, and any safety-critical instruction are Q&A pairs, not generated text.
  3. Does it look things up instead of guessing? Account- and order-specific questions hit a live API or get handed off -- never answered from thin air.
  4. Does it escalate when unsure? Low-confidence and high-risk intents route to a human. You've tested that the boundary actually fires.
  5. Is it scoped? Domain restrictions limit it to your site; rate limiting blocks abuse; instructions forbid invented prices and promises.
  6. Can you review it? Conversation logs are on, and someone looks at them on a cadence.
  7. Is the knowledge current? Stale-but-confident is its own failure mode. Auto-retrain or a manual refresh schedule keeps content live.

Embedding is the easy part once the controls are in place:

<script
  src="https://cdn.agentkit.ai/widget.js"
  data-chatbot="your-chatbot-id"
  async>
</script>

A note on scope: this is about civil liability for what your bot says -- distinct from the wave of AI-specific regulation moving through statehouses, which we covered separately in the 2026 chatbot laws guide. You need to think about both. A bot can be fully compliant with disclosure laws and still bind you to an invented refund policy.

The takeaway

The lawsuits against OpenAI and Character.AI will be litigated for years, and most businesses running a support bot will never be a party to anything like them. But every one of those businesses lives under the Air Canada line: your chatbot speaks for you, and you own what it says. That's not a reason to avoid AI support. Companies are resolving most of their support volume with chatbots and saving real money doing it -- the economics are not in dispute. It's a reason to treat the bot as what it legally is: an agent of your business, deployed with the same care you'd give a human one.

The difference between a liability and an asset is the architecture around the model. Ground it in your content. Lock your high-stakes answers. Hand off when it's unsure. Log everything. A chatbot built that way doesn't just avoid the courtroom -- it's the one customers actually trust, because it tells them the truth or tells them it doesn't know.

Build your chatbot for free →

No credit card required.

Get started freeNo credit card required