All articles

AI support chatbots: what actually happens when yours promises something you never agreed to

10 min read

Most directories add a chat widget for the same reason: support tickets arrive at two in the morning, an advertiser wants to know why a payment failed or why a photo got rejected, and nobody wants to pay a night shift to answer the same five questions. An AI assistant trained on the help pages looks like the obvious fix. It never sleeps, it never gets short with a difficult advertiser, and it costs a fraction of a support hire.

What gets missed in that calculation is what happens the first time the assistant gets it wrong. Not a typo, not a broken link, but a wrong answer stated with full confidence: yes, that refund is approved, yes, you can skip re-verification this time, yes, that photo is within the rules. The instinct is to treat this the way you would treat a software bug: patch it, apologise, move on. Several courts have already ruled that this instinct is mistaken, and the reasoning they used applies just as cleanly to a classifieds directory as it did to the businesses that were actually sued.

A chatbot is not a separate legal entity

The clearest statement of the principle came out of a small claims style tribunal in British Columbia, in a case that had nothing to do with adult content. A traveller named Jake Moffatt asked Air Canada's website chatbot about bereavement fares after a family death, and the chatbot told him he could apply for the discount after booking, within ninety days. That was wrong. A separate page on the same site said the discount had to be requested before travel, and Air Canada refused to honour the difference once Moffatt pointed out what its own chatbot had told him.

Air Canada's defence was that the chatbot should be treated as a separate entity responsible for its own words, not the airline. The tribunal rejected that argument in terms worth repeating to anyone building a support bot: "Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission. While a chatbot has an interactive component, it is still just a part of Air Canada's website. It makes no difference whether the information comes from a static page or a chatbot." Air Canada did try a second defence, pointing to clauses in its own published tariff, but lost that argument too because it never produced the actual tariff text as evidence, only a description of what it supposedly said.

The money involved was small: about 650 Canadian dollars in damages plus interest and tribunal fees, because this was a low value claims process, not a jury trial. That is exactly the detail worth sitting with. The legal principle that decided the case did not depend on the amount, and it would apply identically to a chatbot that quoted an advertiser a wrong renewal price, or confirmed a refund a billing team never approved. This was also a British Columbia tribunal, not a binding precedent anywhere else and certainly not American law, but the reasoning mirrors ordinary negligent misrepresentation doctrine that exists across most common law jurisdictions, including the ones a US-based operator actually answers to.

American courts reached the same place decades earlier

This is not a new problem invented by generative AI. In 1972, a United States appeals court decided State Farm Mutual Automobile Insurance Co. v. Bockhorst, a case about a much older kind of automation: a mainframe that generated a policy reinstatement notice using outdated information a human employee had failed to update first. The court held the insurer bound by what its own computer had sent out, writing that "a computer operates only in accordance with the information and directions supplied by its human programmers. If the computer does not think like a man, it is man's fault."

The legal mechanism in that case is not identical to Moffatt's, and it would be a stretch to present them as the same test: Bockhorst turned on what the law treats as the insurer's own knowledge through its employees, while Moffatt turned on a duty to represent facts accurately to a consumer. What the two cases share is the conclusion an operator actually needs: neither court let the business point at its own machine and walk away. A support bot is not a loophole, and it was never going to be one, because the doctrine that closes that loophole predates the chatbot by half a century.

Two different ways this bites, and a directory risks both

There are two separate exposures hiding inside the same chat widget, and they call for different fixes. The first is what the bot tells one specific advertiser in a private conversation, the Moffatt and Bockhorst situation: a wrong promise that the advertiser relied on and that cost them money. The second is what you claim, in marketing copy or on the site itself, about what the bot or the systems behind it actually do, which is a question of truth in advertising rather than contract law.

The second exposure has its own enforcement history. In September 2024 the US Federal Trade Commission opened five cases under what it called Operation AI Comply, against companies it said oversold what their AI products could actually deliver. One of them, DoNotPay, had marketed itself as offering the "world's first robot lawyer" and claimed its tool could let a user sue for assault without a lawyer and produce legally valid documents, while never once testing its output against a human lawyer's standard or employing any lawyer at all. The company settled for 193,000 dollars and a ban on claiming its service can substitute for professional advice without evidence. FTC Chair Lina Khan's comment at the time was blunt: "Using AI tools to trick, mislead, or defraud people is illegal," and there is "no AI exemption from the laws on the books."

Those five cases were all against companies selling an AI product with inflated claims, not against a business that simply deployed a chatbot for its own customer support, so treat the connection as a strong warning rather than a ruling against this exact scenario. The statute behind it, Section 5 of the FTC Act, bans unfair or deceptive practices generally, with no carve out for who wrote the sentence making the claim. A directory that tells advertisers "our AI verifies every profile automatically" when the process is really a human spot check with software assistance is making exactly the kind of claim that statute exists to catch, which is worth reading alongside what actually has to be true before a listing is printed as verified.

The specific promises a support bot is most likely to make

Picture the questions an advertiser actually types into a directory's chat widget, because that is where the risk concentrates. Billing questions produce the most dangerous answers: a bot trained to be helpful will lean toward confirming a refund, a proration, or a cancellation an advertiser is asking for, because that is the response that ends the conversation fastest. Every one of those answers is a commitment the finance side never signed off on, and it undercuts the deliberate, slower refund process built to keep a dispute from turning into a chargeback.

Verification questions are worse, because the stakes are regulatory rather than just financial. An advertiser who does not want to resend an ID document will phrase the question to make skipping it sound reasonable, and a bot optimising for a short, satisfying answer can agree that the existing record is fine when it is not current or was never actually checked. The same risk shows up around moderation: an advertiser appealing a rejected photo or a taken down listing will ask the bot directly whether the content is allowed, and a confident wrong answer here contradicts a decision a moderator already made for a reason the bot cannot see.

None of this requires a dramatic failure to become expensive. A single advertiser who can show a screenshot of the bot promising something the business will not honour already has the basic elements of a complaint, and a pattern of similar promises across many advertisers turns one awkward refund into a pattern a regulator or a plaintiff's lawyer can point to. The 2026 case of a Toronto car dealership whose bot, nicknamed Quinn, texted a customer an offer to buy back his car for over 27,000 Canadian dollars illustrates the business cost well even though it never reached a court: the dealership revoked the offer as an AI error, then honoured it in full only after a national news outlet called for comment, and it changed its process afterward so that buyback offers now come from a person. Nothing about that outcome depended on a judge, which is the part worth noticing: the expensive part was the retraction and the story, not a verdict.

What to actually do, in order

Start by deciding what the bot is never allowed to resolve on its own. Refund amounts, verification exceptions, and any ruling on whether specific content is allowed should trigger a fixed response that hands the conversation to a person, rather than an answer generated on the spot, because these are exactly the categories that turn one wrong sentence into a binding promise or a compliance gap.

Keep whatever the bot was trained or instructed on in lockstep with the actual, current policy pages, and treat a policy change as incomplete until the bot's source material is updated the same day, not the same week. A bot answering from a refund policy that was replaced a month ago is not a hypothetical risk, it is the single most common way this goes wrong in practice.

Log every conversation in full and keep the logs somewhere a support lead actually reads on a regular schedule, not just somewhere they are stored. A weekly pass through a sample of transcripts catches a bad pattern while it is still one advertiser's problem rather than a hundred advertisers' problem, and the same logs are what lets you show, if it ever comes to that, that the business was taking reasonable care rather than ignoring the tool once it was switched on.

Do not treat a disclaimer line as a liability shield on its own. A warning that AI responses may be inaccurate is still worth having, because it is evidence that the business took some care, but Air Canada lost its case over the accuracy of what the bot said, not over the absence of a disclaimer, and the tribunal's objection was that nobody checked the chatbot's answer against the real policy before it was published to customers. A disclaimer that sits next to answers nobody ever audits does little.

Finally, ask your insurer directly, in writing, whether your current policy responds to a claim arising from something an AI support tool told a customer, in the same conversation where you are already confirming what the content exclusions on a standard policy actually leave uncovered. Most general liability policies were written before any of this existed, and the honest answer from a broker who has not been asked the direct question is usually a guess rather than a fact.

The common thread across all of this is simple enough to repeat to anyone on the team who thinks the bot is a separate problem from the business: every court that has looked at this question so far has treated the chatbot as the company talking, in the company's own voice, through a different interface. Build the guardrails, the logging, and the review habit as if a new, slightly overconfident employee had just started answering every ticket overnight, because legally, that is close to what happened.

Try the DEMO

Escort directory software, ready to go