Who Is Responsible When An AI Gets It Wrong?

If this thing gets something wrong, where does that leave me? A straight answer rather than reassurance, from the build side.

Every conversation about AI risk eventually arrives at the same question, usually phrased carefully because nobody wants to sound like they are looking for trouble. If this thing gets something wrong, where does that leave me?

It is a fair question and it deserves a straight answer rather than reassurance. The short version is that responsibility sits with you far more than most people assume when they adopt a tool. The longer version is worth understanding, because the exposure is manageable once you can see its shape.

I build these systems, I do not advise on liability. Nothing here is legal advice and I would not want it treated as any. What follows is the practical picture as it looks from the build side, and the point at which you should be talking to someone qualified.

The customer blames you, and they are not being unreasonable

Start with the non-legal reality, because it governs most outcomes. If a bot on your website tells somebody the wrong thing, that customer experienced your business getting it wrong. They did not enter into a relationship with a model provider. They asked your website a question and your website answered.

"The AI said it, not us" is not a distinction anybody outside the industry recognises, and it reads badly in a review whether or not it is technically defensible.

What this means for you

Treat anything your AI says in public as something you said. That single reframe answers most of the decisions further down this page, and it is the standard your customers are already applying.

Wrong prices and mistaken commitments

The scenario people worry about most is a bot quoting a figure you would never have agreed to.

Whether a mistaken price binds you is genuinely fact-specific. It turns on things like how the offer was presented, whether the customer knew or ought to have realised it was an error, and how obviously wrong it was. An automated system can form a contract, so "a computer said it" is not by itself a defence. Equally, a customer trying to hold you to something plainly absurd is on weaker ground.

What I can tell you without qualification is that this is a bad question to be researching after the fact, and an easy one to design out beforehand.

What this means for you

Do not let a public bot state prices, confirm bookings or agree deadlines. Let it gather and let a person commit. That one rule removes almost the whole category, and it costs you seconds rather than the time saving you were after.

Consumer rules apply to whatever generated it

The rules about not misleading consumers apply to what your website says. They do not carve out text that was generated rather than written. If a bot describes a product inaccurately or invents a guarantee, that is your published claim.

The same goes for accessibility, advertising standards, and anything sector-specific you already have to comply with. Regulated trades in particular should assume their existing obligations follow them into anything automated, because those rules were written about the business, not about the technology.

What your supplier's contract almost certainly says

It is worth actually reading the terms of any AI product you build on, because the pattern is consistent and it surprises people.

Providers generally disclaim responsibility for output accuracy, cap their liability at something modest, and place the obligation to check outputs on you. Several make you responsible for how the output is used and require you not to present it as authoritative in contexts where that would be inappropriate.

That is not sharp practice, it is the only position a general-purpose tool provider can take. But it does mean the commercial risk of a wrong answer has already been allocated, and it has been allocated to whoever deploys it.

What this means for you

If you buy an AI build from a developer, that is a separate contract from the model provider's, and it is the one where you have room to negotiate. Ask what they warrant, what happens if the thing misbehaves, and who fixes it. A supplier who has thought about this will have an answer.

Data protection is the one with a regulator attached

Most AI mistakes cost you an awkward conversation. Data protection failures can cost more than that, because there is a regulator and a complaints route that does not depend on anyone suing you.

If personal data is involved, the responsibility is clearly yours as controller. The provider processing it on your behalf does not inherit that. The full shape of that question is in can I use AI on customer data, and it is the area where I would push hardest for proper advice if you handle anything sensitive.

Check whether your insurance follows you

This one gets missed almost universally. If you carry professional indemnity or cyber cover, it is worth asking your broker directly whether claims arising from AI-generated output are covered, and whether anything in your policy assumes work is produced by a person.

I am not suggesting there is a problem waiting. I am suggesting it is a five-minute question with a definite answer, and a bad thing to discover the answer to during a claim.

What actually reduces the exposure

None of this argues against using AI. It argues for a handful of specific controls, all of which are cheap:

  1. A person commits, the AI gathers. Prices, bookings, deadlines and agreements go through a human.
  2. Say it is a bot, and make the route to a person obvious. Managing expectations is itself a control.
  3. Keep the conversations. If somebody claims your bot promised them something, a log is the difference between a discussion and a guess.
  4. Publish terms that cover it. Website terms that address automated responses give you something to point at.
  5. Narrow what it can reach. It cannot get a customer record wrong if it cannot see customer records.
  6. Have a complaints route that works. Most situations resolve at the point somebody can reach a person who can fix it.

Do those and the realistic worst case for a small business bot moves from a genuine problem to an apology and a correction.

Keeping it in proportion

I would rather you adopted AI carefully than not at all, and the businesses that get hurt by this are not the cautious ones. They are the ones that let something make commitments unsupervised because nobody asked what it could do, only what it could say.

Ask the second question early and most of this stops being a risk register and becomes a design decision. The controls above are in what a chatbot should and should not be allowed to do, the staff-facing half is in how to write an AI policy your team will actually follow, and the whole picture is in my guide to using AI safely in a small business.

More In This Series

← All posts

Want A Second Opinion On Your Own Setup?

Get in touch and your message comes straight to me. I reply within 48 hours, usually sooner.

Contact Us