Treadstone Associates
Article · 8 min read

When an AI chatbot promises something

A business is generally bound by what its own automated systems tell a customer. A chatbot is not a separate legal actor with its own excuse — it is a channel the business chose to speak through, and Canadian regulators and at least one tribunal decision have already started treating it accordingly.

Treadstone Associates · Updated 2026

Key takeaways

  • • The Competition Act’s misrepresentation rules cover a representation made “by any means whatever” — a chatbot’s words are the business’s own representation, not a separate statement from an independent actor.
  • • Canadian commentary widely discusses a 2024 decision of British Columbia’s Civil Resolution Tribunal, Moffatt v. Air Canada, 2024 BCCRT 149, in which the airline was held responsible for a bereavement-fare answer its own website chatbot gave a customer.
  • • A terms-of-service document sets rules for the ongoing relationship — jurisdiction, payment, termination — but it is a different thing from, and does not automatically cure, a specific false statement made during a sales interaction.
  • • The safer operational choice is to route anything that reads as a firm commitment — a price, a refund, a guarantee — through a confirmation step before it is treated as final. That is a design recommendation, not a stated legal requirement.

It is tempting to think of a chatbot’s mistake as somehow different from a human employee’s mistake — as though the automation itself creates a gap in responsibility. Canadian law and at least one Canadian tribunal have not treated it that way.

Whose promise is it?

The Competition Act’s core misrepresentation rule does not carve out an exception for who, or what, delivers the words. It reaches a person who, “for the purpose of promoting, directly or indirectly, the supply or use of a product or for the purpose of promoting, directly or indirectly, any business interest, by any means whatever,” makes a representation that is false or misleading in a material respect. (Competition Act, s.74.01(1)) A chatbot answering a customer question on a company’s own website is squarely inside that phrase — it is the business speaking, through a channel the business built and deployed, and the Bureau’s own plain-language description of the same rule confirms the point applies to “any marketing material, including online and in-store advertisements… and endorsements, among other things.” (Competition Bureau, misleading representations and deceptive marketing practices)

A live example most people have heard of

Canadian legal commentary widely discusses a 2024 decision of British Columbia’s Civil Resolution Tribunal, Moffatt v. Air Canada, 2024 BCCRT 149: a customer relied on a bereavement-fare answer the airline’s own website chatbot gave him, which turned out to be wrong, and the tribunal held the airline responsible for the inaccurate information — reasoning, as the commentary describes it, that the chatbot was simply another part of the airline’s own website and the airline was responsible for what appeared on it. The decision itself is indexed on CanLII, which is not reachable to quote directly from this hub — treat the case as a real, well-documented example worth verifying independently rather than as a quoted holding.

Does a terms-of-service disclaimer fix this?

A terms-of-service document does real work for a business — setting the governing law, describing payment and refund terms, and defining when an account can be terminated. (Treadstone Law, terms of service for online businesses) What it is not built to do is retroactively erase a specific false statement made to a specific customer during an interaction. A general disclaimer sitting in a linked policy page is a different thing, in the eyes of the general impression test, from what was actually said to the customer in the moment they relied on it.

A practical design point, not a legal requirement

Nothing in Canadian law requires a specific technical safeguard here, but the exposure above points toward an obvious operational choice: route anything that reads as a firm commitment — a specific price, a refund amount, a guarantee, an exception to a stated policy — through a confirmation step, rather than letting a generative system state it as settled fact in the flow of a conversation. That is a governance recommendation drawn from the legal exposure above, not a rule stated anywhere in the Competition Act.

Monitoring after deployment is already a named federal expectation

This design point is not an invention of caution for its own sake — it echoes a measure ISED’s own Voluntary Code asks managers of a public-facing generative system to commit to: “Monitor the operation of the system for harmful uses or impacts after it is made available… including through the use of third-party feedback channels,” updating the system as needed to address risks that materialise. (ISED, Voluntary Code of Conduct) A confirmation step for firm commitments is one concrete way to act on that expectation, rather than discovering the same failure repeatedly through customer complaints.

Giving a customer somewhere to go when the system got it wrong

Canada’s privacy commissioners frame this from the individual’s side rather than the business’s: organisations should “ensure that impacted individuals are provided with an effective challenge mechanism for any administrative or otherwise significant decision made about them… and allowing them the opportunity to request human review and/or re-consideration of the decision.” (OPC, generative AI principles) A chatbot promise is not usually framed as an “administrative decision,” but the same underlying idea applies well beyond that category: a customer who was told something wrong needs an accessible, human way to have it corrected, not just a policy page saying the bot might be inaccurate.

A worked example

A service business’s chatbot tells a customer, mid-conversation, that a loyalty discount will automatically apply to their next invoice. It does not. “The bot said it” is not a defence under the general impression test, which asks what the representation conveyed, not which internal system produced it — the same reasoning that held Air Canada responsible for its chatbot’s bereavement-fare answer applies just as directly here. What limits the damage afterward is exactly the two design points above: a confirmation step that would have caught the promise before it was made, and an easy path for the customer to have it corrected once it was not.

Related: disclosing that a customer is talking to an AI system, and why language models make things up.

How a business puts a confirmation step around AI-driven customer conversations is covered on the AI growth and marketing hub.

Common questions

Can a business avoid liability with a disclaimer that chatbot answers may be inaccurate?

Not reliably. A general disclaimer sitting elsewhere in a policy page does not necessarily cure a specific representation made directly to a customer in the conversation itself — this remains a fact-specific question, and no primary Canadian source sets an exact threshold for how much disclaimer language is enough.

Does this only apply to chatbots, or to any AI system that talks to customers?

The same “by any means whatever” language applies regardless of the specific channel — a voice agent, an email autoresponder, and a chat widget all sit inside the same rule, because the rule is about the representation, not the technology that delivered it.

Is monitoring a chatbot after launch actually expected, or just good practice?

It is named directly as an expected measure in ISED’s Voluntary Code for managers of a public-facing generative system — monitoring for harmful impacts after deployment, including through third-party feedback channels. The code itself is voluntary and binds only its signatories, but it describes the standard a business would want to be able to point to if a chatbot promise were ever challenged.

Does it matter whether the customer could tell they were talking to an automated system?

It can matter to the overall general impression, but it does not remove the underlying exposure — the representation still came from the business’s own channel either way. Disclosing that a system is automated is covered separately in the companion piece on this hub, and is best treated as its own, additional safeguard rather than a substitute for the confirmation step described above.

Find out where a firm commitment could slip through unchecked.

A short call is enough to walk through a specific chat, voice or email flow against the exposure above.