Analysis

Air Canada's chatbot made a promise. A tribunal made the airline keep it.

In November 2022, Jake Moffatt's grandmother died. He went to Air Canada's website to book a flight for the funeral and asked the chatbot about bereavement fares. The bot told him he could book at full price and apply for the bereavement discount within 90 days.

That was wrong. Air Canada's actual policy doesn't allow retroactive bereavement claims. But Moffatt had no reason to doubt the assistant on the airline's own site, so he booked, then applied for the refund. Air Canada refused. He took it to British Columbia's Civil Resolution Tribunal.

Air Canada's defense is the part worth remembering. The airline argued that the chatbot was "a separate legal entity that is responsible for its own actions." The tribunal rejected it flatly. In its February 2024 decision, it wrote that Air Canada is responsible for all the information on its website, "whether the information comes from a static page or a chatbot." The airline was ordered to pay.

The amount was small — a few hundred dollars. The precedent is not. Here is what it says to anyone running a customer-facing assistant:

Your bot's words are your words. "The AI said it, not us" is not a defense. If your assistant states a price, confirms a policy, or makes a commitment, your company is on the hook for it — the same as if it were printed on your website.

Now notice what this case wasn't. No one hacked Air Canada. There was no prompt injection, no jailbreak, no attacker. The bot simply answered a normal question incorrectly, and that was enough to create a liability. That's the floor. The ceiling is what happens when someone is trying to make your assistant say something — talking it into a discount, a refund, a commitment it should never make. Retail bots have been talked into selling cars for a dollar. The mechanism is the same; the intent is worse.

So the practical question for a business that has shipped an assistant isn't "could this happen to us." It's "have we ever watched our own bot get pushed, on purpose, to see what it says." Most companies never have. They read the happy-path transcripts, see it answer well, and ship. The adversarial transcripts — the ones an attacker would generate — they never look at.

That's the gap. You can close it two ways, and they work together. Have someone try to break your assistant, on purpose, under authorization, and show you exactly what came out — that's an audit. And once it's in production, keep a record of what it actually says to real people, so that the day someone screenshots a bad answer, you have the full context and not just the screenshot — that's monitoring.

Air Canada lost a small case and made a large point: an assistant in production speaks for you. Worth knowing what it's prepared to say.

Curious what your assistant says under pressure? A 3-day audit shows you — live.