Home› Insights› The Air Canada ruling and the frontier labs liability debate show every Australian business what AI governance they need before something goes wrong
AI Governance

The Air Canada ruling and the frontier labs liability debate show every Australian business what AI governance they need before something goes wrong

By QuantalAI Solutions Team · 06/10/2026

Air Canada was held liable for its chatbot's mistakes and frontier labs are losing liability protection bids. What Australian businesses need to know.

AI liability is no longer theoretical for Australian businesses. Two developments have settled that, and together they should change how any business owner or manager thinks about every AI tool running inside their operation, including the ones they didn’t approve.

We work with a mid-tier law firm whose associates had been using a range of AI writing and research tools independently, some firm-approved, some not, before the partners had any formal policy in place. The firm knew AI was being used. It didn’t know exactly where, by whom, or on what. That gap is the same gap the Air Canada case exposed, and it’s the gap that insurers are now asking about directly. The same gap exists in accounting practices, financial planning businesses, real estate agencies, and any other firm where staff have a browser and a credit card.

What the Air Canada case actually decided

Air Canada’s AI chatbot told a passenger he could apply for a bereavement fare after travel and claim a refund retroactively. That was wrong. Air Canada tried to argue the chatbot was a separate entity and the airline wasn’t responsible for what it said. The Civil Resolution Tribunal in British Columbia rejected that argument, holding Air Canada liable for the misinformation its own automated system provided (Air Canada v. Moffatt, Civil Resolution Tribunal, British Columbia, 2024, reported by the BBC).

The ruling didn’t require the passenger to prove Air Canada intended to mislead him. It required only that the airline had deployed a system that gave wrong information, and that he relied on it. That’s a negligence frame, and it maps onto any business that puts AI in front of customers or into a workflow that produces customer-facing output.

The ACCC has published guidance on automated decision-making and the Australian Consumer Law making clear that a business can’t disclaim its way out of liability for an automated system that misleads a consumer. Australian courts have plenty of framework to apply the same analysis the Canadian tribunal did.

The frontier labs are not going to carry this for you

The second development is less reported but equally consequential. Frontier AI labs, including Anthropic and OpenAI, have sought various forms of liability protection for harms caused by their models, on the basis that the lab built the underlying system and the deploying business is downstream of it. Those bids have been declined (as reported by Dean Lee on dev.to, citing the policy debate around what he calls “the sovereign put on frontier liability”).

The position that has held is the one that makes sense: the responsibility sits with the business or person who releases and instantiates the model, not the lab that trained it. A builder who supplies timber isn’t liable for a house that falls down. The builder who constructs the house is. When your business deploys an AI agent, configures its prompts, connects it to your customer data, and puts it in front of your clients, your business is the builder. The lab is the sawmill.

This matters because a number of businesses have been operating on an implicit assumption that a vendor’s terms of service would absorb the liability if something went wrong. That assumption was always questionable. It’s now clearly wrong.

The low-cost subscription problem

The Air Canada chatbot wasn’t an expensive, custom-built enterprise system. It was a customer service tool sitting inside the airline’s public-facing infrastructure. The cost of the tool was never the point. What mattered was that the airline put it in front of customers without adequate oversight of what it said.

The same dynamic plays out inside businesses when staff adopt low-cost AI tools without management knowing. These tools are often genuinely useful. They’re also often running on the business’s client data, producing output that ends up in customer-facing documents, without no formal review requirement attached to them.

A cheap subscription inside a staff member’s workflow isn’t a problem because it’s cheap. It’s a problem because the business probably doesn’t know it’s there, probably hasn’t assessed what it does with customer data under the Australian Privacy Principles (Privacy Act 1988), and probably hasn’t confirmed with its insurer whether AI-assisted work is covered.

The firm we work with found, during the process mapping we did together, that AI tools were active at six distinct points in their matter workflow. Two were known and approved. Four weren’t. None of the four had a documented review step. That ratio is not unusual. It’s roughly what we find when we map AI use in any professional services firm that hasn’t done this exercise before.

What governance actually looks like

The standard advice is to write an AI policy. That’s not wrong, but it’s the end of the process, not the start. A policy written before a business knows where AI is running describes what management wishes were true, not what is.

Process mapping comes first. That means sitting down with staff at every level and asking, plainly, what tools they use and at what point in a workflow. An AI tool used consistently, with a documented review step, is a manageable risk. An AI tool used differently by every person who touches a file, with no review requirement, is not.

Once the business knows where AI sits, the governance questions become concrete. Who reviews AI output before it reaches a customer? What happens when the AI is wrong and the reviewer misses it? Does the business’s insurance cover that scenario? The National Insurance Brokers Association has flagged that AI-specific exclusions are appearing in Australian professional indemnity policies, so the answer to that last question may not be what the business assumes.

The firm we work with set a rule that any AI-assisted output touching a client matter required a named paralegal sign-off before it moved to the supervising partner. That’s a person doing the work the AI can’t yet be trusted to do alone. The part that didn’t resolve cleanly: the firm still doesn’t have a consistent way to log which outputs were AI-assisted, so reconstructing the file trail under a claim would take time. That’s the next problem they’re working on.

What this means for you

AI governance is a process question before it’s a technology question. The Air Canada case didn’t turn on which AI tool the airline used. It turned on whether the airline had adequate oversight of what the tool said on its behalf. The frontier liability debate didn’t turn on how powerful the underlying model was. It turned on who deployed it.

For most businesses, the lowest-risk starting point is internal work that never reaches a customer directly: intake processing, document extraction, and summaries reviewed by a staff member before a manager sees them. That keeps a person accountable for every customer-facing output and creates a documented review trail the business can show an insurer or a regulator.

Find out more about AI strategy for professional services firms and how we approach governance as part of the build. You can also read about the AI agents we use to handle document extraction and intake processing in practice.

Start the AI Roadmap Interview

Frequently asked questions

What did the Air Canada chatbot case decide, and why does it matter to Australian businesses?
A Canadian tribunal held Air Canada liable for incorrect information its AI chatbot gave a customer, ruling that the airline couldn't disclaim responsibility for its own automated systems. The same logic applies to any Australian business that deploys AI in a customer-facing or decision-making role. If the AI gives wrong information and a customer relies on it, the business is likely accountable, regardless of which vendor built the underlying model.
Are the frontier AI labs liable if their model causes harm in my business?
No, and that position is hardening. Frontier labs including Anthropic and OpenAI have sought liability protections for harms caused by their models, and those bids have been declined. The responsibility sits with the business or person who deploys and instantiates the model, not the lab that built it. If your business puts an AI system in front of customers or into a workflow, your business owns the output.
Could a low-cost AI subscription create liability exposure for my business?
Yes. The Air Canada case is the clearest illustration of why. The tool's cost is irrelevant to the liability it can create. What matters is whether your business's output, including documents drafted or decisions made with AI assistance, was wrong and whether a customer or counterparty relied on it. Australian professional indemnity and general liability policies are beginning to include AI-specific exclusions, so businesses need to check their current cover and confirm with their broker whether AI-assisted work is included.
What should a business do first to govern its AI use?
Start with process mapping. Before a business can govern AI, it needs to know where AI is already being used, which is often further into workflows than management realises. Staff frequently adopt low-cost tools independently. Once the business knows where AI sits, it can set clear review requirements, decide which tasks AI may assist with and which it may not, and document that governance so it's visible to insurers and, if needed, to a regulator or court.
How does a business start using AI without taking on unnecessary risk?
The lowest-risk starting point is internal work that never reaches a customer directly, such as intake processing, document extraction, and summaries reviewed by a staff member before a manager sees them. This keeps a person accountable for every customer-facing output while the business builds confidence in the AI's accuracy on its own files. From there, businesses can expand to more customer-adjacent tasks once the review process is proven and the governance is documented.