"The chatbot promised the customer a discount that didn't exist. The tribunal ruled: the company is liable."
Air Canada argued the chatbot was a "separate legal entity responsible for its own actions." The argument was rejected. A business is liable for whatever its AI says — even when it makes things up.
If your AI gives prices, promises or instructions to customers, this affects you today — before we even get to the AI Act.
"A customer talked a dealership chatbot into 'selling' him a brand-new car for $1 — and declaring the deal legally binding."
The bot was set up with no limits on what it could promise. A few clever prompts later, the conversation was viral and the dealership was in the headlines.
AI in a sales role with no boundaries = promises you don't control. Scope and a non-binding disclaimer aren't a luxury — they're the first line of defence.
"A customer got a courier company's chatbot to swear during the conversation — and write a poem about how 'useless' the company itself is."
After an update, the guardrails slipped. A frustrated customer needed only a few minutes to get the bot to mock its own employer — in public.
The damage isn't always legal; often it's reputational. Behavioural testing before production and oversight after — not "we shipped it, we're done."
"Employees pasted confidential code into ChatGPT 'to get some help.' The company found out — and banned all AI tools."
Three leak incidents in a few weeks: source code and internal meeting notes ended up in an external system, beyond the company's control.
Your staff already use AI — with or without permission. A usage policy and training (also required by Article 4) cost very little next to a leak.
"An executive approved a $25M transfer after a video call with the 'CFO.' Everyone on the call was a deepfake."
The fraud didn't exploit a gap in the systems — it exploited trust in what we see and hear.
AI isn't only your own risk; it's also a weapon in others' hands. Payment approval and identity-verification processes need hardening against synthetic content.