Technology Intelligence
Cyber Security

What the Air Canada Chatbot Case Means for Your Website

10 minutes read4 August 2026
What the Air Canada Chatbot Case Means for Your Website

Moffatt v Air Canada held a business liable for inaccurate advice given by its website chatbot. It is a Canadian tribunal decision, not a UK precedent, but the underlying principle — that customers can rely on what your systems tell them — fits UK consumer-protection thinking. UK businesses should treat a customer-facing chatbot as their own voice: constrain it to verified content, keep a route to a human, keep logs, and check that supplier liability caps do not leave the gap on the business.

A customer visits your website, opens the chat window and asks a simple question. The bot answers confidently. The answer is wrong. The customer relies on it, acts on it and loses money. When they complain, can your business say "that was the chatbot, not us"?

In 2024, an airline tried exactly that argument in front of a Canadian tribunal — and lost. The decision is short, readable and widely cited, and it has become the reference point for a question every business adding a chatbot now has to answer: who is responsible when the bot gets it wrong?

A chatbot is part of your website. To a customer, it speaks with your voice — and the law tends to see it the same way.

The Quick Answer

In Moffatt v Air Canada (2024 BCCRT 149), a British Columbia tribunal held that Air Canada was liable for inaccurate advice its website chatbot gave a customer. The tribunal rejected the airline's suggestion that the chatbot was a separate entity responsible for its own actions, describing that submission as "remarkable".

This is important, but read it carefully:

  • It is a Canadian small-claims tribunal decision, not a UK court judgment — it is not binding in the United Kingdom.
  • It turned on negligent misrepresentation under Canadian law, not on UK consumer regulations.
  • The sums were small (the airline was ordered to pay CA$812.02 in total), but the reasoning is what matters.
  • The principle it illustrates — customers can rely on what your systems tell them — is consistent with how UK consumer law tends to treat misleading information.

For a UK small business, the practical takeaway is not the ruling itself but the working assumption behind it: plan on the basis that your business owns what its chatbot says. Constrain it to verified content, keep a route to a human, and keep records.

This article is general information, not legal advice. Named cases and statutes are summarised, not quoted as advice. Take specific advice before relying on any point for your own situation.

Last checked: 4 August 2026. Case law, consumer-protection rules and regulator guidance change. Verify the current position before acting.

What actually happened in Moffatt v Air Canada

In November 2022, following the death of his grandmother, Jake Moffatt visited Air Canada's website to book flights and to find out about the airline's bereavement fares. While researching, he used a support chatbot on the site.

According to the tribunal's decision, the chatbot told Mr Moffatt that he could apply for bereavement fares retroactively — that is, after the flight had been booked. He booked, then later learned from Air Canada staff that the airline did not in fact allow retroactive bereavement-fare claims. The chatbot's answer had been wrong, and it conflicted with the airline's own "Bereavement travel" web page.

Mr Moffatt asked for a partial refund reflecting the difference between the fare he paid and the bereavement fare he had been led to expect. Air Canada refused, and the dispute went to the Civil Resolution Tribunal in British Columbia.

DetailWhat the decision recorded
CaseMoffatt v Air Canada, 2024 BCCRT 149
TribunalCivil Resolution Tribunal of British Columbia (a small-claims body)
Decided14 February 2024
Legal basisNegligent misrepresentation
The wrong informationThe chatbot said bereavement fares could be claimed retroactively; they could not
OutcomeClaim mostly allowed; airline ordered to pay CA$812.02 in total (including CA$650.88 in damages)

The argument the airline lost

The part of the decision that made headlines was Air Canada's defence. The airline argued, in effect, that it could not be held responsible for information provided by its chatbot — suggesting the chatbot was a separate entity accountable for its own actions.

The tribunal member described this as a "remarkable" submission. The reasoning was blunt: while a chatbot has an interactive component, it is still just part of Air Canada's website, and a business is responsible for all the information on its website. It made no difference, the tribunal held, whether the information came from a static page or a chatbot.

The tribunal also rejected the idea that customers should have to cross-check a chatbot's answer against another page on the same site. Air Canada could not explain why its "Bereavement travel" page was inherently more trustworthy than its own chatbot. If a business puts information in front of customers, it cannot expect them to guess which parts are reliable.

"The chatbot said it, not us" is not a defence you want to be running. It failed in Moffatt, and it sits badly with how UK consumer law treats misleading information.

What this case is — and what it is not

It is easy to over-read a case like this. So before drawing any lessons, it is worth being precise about its limits.

  • It is not a UK precedent. The Civil Resolution Tribunal is a Canadian body, and the decision is not binding on any UK court or regulator.
  • It is a small-claims decision, not a higher-court judgment setting down principle for others to follow.
  • It was decided on negligent misrepresentation under Canadian law — a different framework from the UK's consumer-protection regime.
  • The financial award was modest. Its influence comes from the reasoning and the timing, not the size of the damages.

What it is, is a clear and quotable illustration of a principle that UK businesses should already be planning around: a customer is generally entitled to rely on what your business tells them, and an automated channel does not change who is doing the telling.

How this maps onto UK consumer protection

UK consumer law does not need the Air Canada case to reach a similar destination. For years, the Consumer Protection from Unfair Trading Regulations 2008 prohibited "misleading actions" — broadly, giving consumers false or deceptive information that causes, or is likely to cause, them to take a decision they would not otherwise have taken.

That framework has since been strengthened. On 6 April 2025, the unfair commercial practices provisions of the Digital Markets, Competition and Consumers Act 2024 came into force, giving the Competition and Markets Authority a broader consumer-enforcement role. The prohibition on misleading consumers remains central, with a particular focus on online activity.

The key point for chatbots is that this framing does not generally ask who — or what — produced the misleading statement. If your business puts information in front of a consumer through your website, and that information is misleading and affects their decision, the fact that an automated assistant generated it is unlikely to be the answer to the problem.

The principle, in one line

Responsibility tends to follow the business that presented the information to the customer — not the tool that generated it. Whether the words came from a person, a page or a bot, the customer was dealing with you.

None of this means a chatbot is uniquely dangerous. Staff give wrong answers too. What changes with a chatbot is scale and confidence: a bot can give the same wrong answer to hundreds of customers, quickly, in a tone that sounds authoritative. The exposure that used to be one awkward phone call can become a pattern.

The supplier gap: who actually carries the risk

Many small businesses do not build their own chatbot. They buy one — a plug-in, a hosted assistant, or an AI feature bundled into their website platform or helpdesk. It is natural to assume the provider stands behind what the tool says. Usually, it does not.

AI and software providers typically disclaim warranties about accuracy and cap their liability to you, often at a low figure such as the fees you have paid. Meanwhile, your customer's expectation is unchanged: they dealt with your business, so they look to your business to put things right. The gap between what your customer can claim from you and what you can recover from your supplier is carried by you.

WhoWhat they typically expect or offer
Your customerTo rely on the answer and hold your business to it
Your AI/chatbot supplierTo disclaim accuracy and cap its liability, often at the fees paid
Your businessLeft carrying the gap between the two — unless you have planned for it

This is why supplier assessment matters before you switch a chatbot on. Read the liability and indemnity clauses. Understand what the provider does and does not stand behind. For higher-consequence uses — anything touching price, entitlements, safety, refunds or legal rights — that gap may be the reason to keep a human in the loop rather than let the bot answer alone.

Who Is Liable When AI Gets It Wrong? — our guide to chatbots, promises and supplier liability caps

Do disclaimers fix this?

A disclaimer — "this chatbot may make mistakes" — has some value, but it is a mitigation, not a shield. Consumer rights generally cannot be excluded by small print, and unfair terms can be unenforceable. Clear, honest signposting still helps: it sets expectations, and it can reduce the harm when the bot does slip.

But relying on wording alone where the consequences of an error are serious is a weak position. In Moffatt, the tribunal was unimpressed by the idea that a customer should have hunted for the "real" answer elsewhere on the site. A notice that quietly points customers away from the answer they were just given is unlikely to carry much weight.

Treat disclaimers as a way to set expectations and offer a human route — not as a substitute for making the chatbot right in the first place.

Practical constraints for a customer-facing bot

If the working assumption is that your business owns what its chatbot says, the design question becomes simple: how do we make the bot safe to speak for us? For a small business, a handful of controls do most of the work.

1. Constrain it to verified content

The single most effective control is to limit what the bot can say. A chatbot that answers freely from a general model can invent policies, prices and entitlements that your business has never offered. A chatbot grounded in your own approved, current content — and told to say "I'm not sure, let me connect you" when a question falls outside it — is far less likely to make a promise you cannot keep.

  • Feed it from a single, maintained source of truth — the same pages your staff would rely on.
  • Keep prices, policies and entitlements out of free-text generation where you can; link to the authoritative page instead.
  • Design it to decline and escalate on anything it is not confident about, rather than guessing.
  • Review its content on the same cycle you review the underlying policies — a bot trained on last year's refund policy is a liability.

2. Keep an easy route to a human

Every customer-facing bot should offer a visible, quick way to reach a person — especially for complaints, money, entitlements and anything time-sensitive. A human route is both good service and a genuine risk control: it catches the cases where a wrong answer would cause real harm before the customer acts on it.

3. Keep logs

If a customer says "your website told me X", you want to know whether it did. Keeping a record of chatbot conversations (within your data-protection obligations) lets you check what was actually said, spot patterns of wrong answers early, and correct the source rather than firefighting one complaint at a time. Logs turn a dispute about memory into a question of fact.

4. Match the control to the consequence

Not every chatbot answer carries the same risk. A bot that suggests opening hours is not the bot that quotes a price or confirms a refund entitlement. Decide in advance which topics the bot may handle end-to-end, which it must hand to a human, and which it should not touch at all. The higher the consequence of being wrong, the tighter the leash.

A short, fictional worst case (clearly fictional)

The following scenario is invented to illustrate the point. It does not describe any real business or event.

A small UK retailer adds an off-the-shelf chatbot to its website to reduce support emails. To sound helpful, it is left free to answer from a general model. Over one busy weekend, it confidently tells dozens of customers that a discontinued product carries a 60-day money-back guarantee. The retailer has never offered that. The supplier's terms cap its liability at the monthly subscription fee. The retailer is left honouring — or arguing about — a promise it never made, across many customers at once.

Every control above would have blunted it: verified content only, escalation on refund questions, logs to catch the pattern on day one, and a supplier assessment that flagged the liability cap before launch.

If a chatbot does get it wrong

Mistakes happen even with good controls. What separates a manageable slip from a spreading problem is how quickly you notice and record it. Capturing what happened — what was said, to whom, what was affected and what you changed — lets you fix the source, treat customers consistently, and show you took it seriously.

A simple, repeatable record does this without ceremony. Our AI Incident Record is a one-page structure for exactly that: what happened, what was exposed, who was told and what changed afterwards.

Download the AI Incident Record (PDF)

The bottom line

Moffatt v Air Canada is not UK law, and it should not be cited as though it were. But it captures a principle that UK consumer-protection thinking already supports: customers are entitled to rely on what your systems tell them, and an automated channel does not shift responsibility away from the business behind it.

The safe way to plan is to assume your business owns what its chatbot says. Constrain the bot to verified content, keep a human within easy reach, keep logs, and check that your supplier's liability cap has not quietly left the whole risk with you. Do that, and a chatbot is a genuine asset rather than a promise-making machine you cannot control.

Explore the AI Governance hub — practical guidance for small businesses using AI

Sources and further reading

The following sources were reviewed on 4 August 2026. Legal and regulatory positions change; verify the current position before relying on any point.

Moffatt v Air Canada, 2024 BCCRT 149 — full decision (Civil Resolution Tribunal of British Columbia)

The Consumer Protection from Unfair Trading Regulations 2008, regulation 5 (misleading actions) — legislation.gov.uk

Digital Markets, Competition and Consumers Act 2024 — legislation.gov.uk

CMA — Unfair commercial practices guidance (CMA207)

Cooley — New UK Consumer Law Regime Comes Into Force (DMCC Act, 6 April 2025)

Plain-English Takeaway

Treat your website chatbot as your own voice, not a third party you can disown. The safest working assumption is that your business owns what its AI tells customers, so constrain the bot to verified content, keep an easy route to a human, and keep logs of what was said. This is not legal advice, and every situation differs — but planning on the basis of responsibility is far cheaper than arguing about it after a customer has relied on a wrong answer.

Related Articles

Cyber Security

The Free AI Account That Cost a Client Relationship

A free AI account feels private because it sits behind your own login, and because the settings screen offers a switch that promises to keep your conversations out of the model's training data. But confidentiality obligations do not check your training-data toggle. When a business holds information under a non-disclosure agreement or a client contract, the risk is not only what a model might remember — it is that the information left the business at all, and reached an outside service that was never approved to hold it. This article walks through a fictional but realistic scenario, explains why "training is off" answers only part of the question, and sets out the placeholder-and-redaction workflow that lets the work still get done.

Read article
Cyber Security

Is Your Business Ready for the Vulnerability Patch Wave?

AI-assisted security tools can search large codebases and identify possible software vulnerabilities much faster than traditional manual research alone. This may create a Vulnerability Patch Wave — a sustained increase in security advisories, emergency fixes and updates that organisations must assess, test and deploy faster than before. This article explains what the wave is, why discovery is accelerating, why fixing remains slower and what businesses should do.

Read article
Cyber Security

Is Temporary Chat Safe for Sensitive Business Discussions?

ChatGPT Temporary Chat does not appear in normal chat history, does not use or create saved memories and is not used to improve OpenAI's models. However, OpenAI may retain a copy for up to 30 days for safety purposes, Custom Instructions may still apply and the information is still transmitted to and processed by an external service. This article explains what Temporary Chat actually protects and why confidential business information still requires care.

Read article

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor