Who is liable when AI makes a mistake?
Your chatbot promises a customer something that is not true. Who pays? In almost every case, you do. What the law says now, what arrives on 9 December 2026, and the six things to settle before your AI sends anything out.
TerenceYour customer service assistant tells a client there is a two-year warranty when there is only one. Or your AI drops a zero in a quote that goes out automatically. Who is liable when AI makes a mistake: you, your customer, or the company that built the system? The honest answer is that you are first in line. And on 9 December 2026 that only shifts in one direction. This article covers what the law says today, what is coming, and the six things to settle before you let AI send anything out.
The short answer: you are first in line
There is no separate law that says: this was the AI, so the supplier pays. Whoever suffers damage knocks on the door of the business they dealt with. That is you. Whether your customer holds you to a promise you broke or to carelessness on your part makes little difference to your wallet.
The reasoning is simple and hard to argue with: you decided to deploy the system, you decided how much room it gets, and you benefit when it works. Your AI is not a legal party. It is a tool. Scaffolding that collapses is not liable for itself either.
That does not mean you have no case against your supplier. But that is a second conversation, and it only starts after you have already compensated your customer. Recovering from someone else takes months. Your customer is on the phone tomorrow.
The case that makes this clearest
The best-known ruling comes from Canada. In November 2022, Jake Moffatt asked the chatbot on Air Canada's website about bereavement fares. The chatbot told him he could claim the discount after travelling. That was wrong: the actual policy required applying in advance. Air Canada refused to pay.
On 14 February 2024 the Civil Resolution Tribunal in British Columbia disagreed (Moffatt v. Air Canada, 2024 BCCRT 149). Among other things, Air Canada argued that the chatbot was responsible for its own statements. That argument failed. The airline should reasonably have made sure the information on its own website was accurate, and had to pay roughly 650 Canadian dollars.
The sum is small. The principle is not. Everything your system says to a customer, your company says. There is no difference between an employee who gets it wrong and an assistant who gets it wrong, except that the assistant can do it a hundred times a day before anyone notices.
Your chatbot is not a separate party you can blame afterwards. What it promises, you promised. Which is the best possible reason to decide in advance what it may and may not say.
What changes on 9 December 2026
There is a new European product liability directive: Directive (EU) 2024/2853. It entered into force on 8 December 2024 and must be part of Dutch law by 9 December 2026 at the latest. The key change for you: software, apps, updates and AI systems count as products from that date. Until now, product liability was about things you could physically hold.
the date software and AI systems fall under product liability
The Netherlands is not finished yet. The bill transposing the directive (number 36906) was submitted to parliament on 2 March 2026 and, in early August 2026, is still with the justice committee awaiting the minister's response to its report. That changes nothing about the deadline: it is set at European level.
Two things to know. First, the new rules only apply to products placed on the market or put into service on or after 9 December 2026. What is already running falls under the old regime. Second, and most articles skip this: the regime protects natural persons. It covers injury, damage to items someone uses privately, and now also the destruction of private files such as your photo archive. The 500 euro threshold that used to apply has been scrapped, so small damage counts too.
What it does not cover is the commercial loss of your business customer. If a client loses revenue because your system quoted the wrong lead time, product liability does not help them. That comes down to your contract and to what they could reasonably expect. For most small and mid-sized firms, that is the scenario that actually occurs.
And that special AI liability law? It is not coming
Brussels spent years working on a separate directive on AI liability. It would have made suing an AI supplier easier. That proposal has been withdrawn: the European Commission announced it in February 2025 and the withdrawal was published in the Official Journal on 6 October 2025. No agreement was reached.
For you that means no special rules, no special protection and no special escape route. Just ordinary Dutch law, the same law that applies when an employee says something wrong or a machine breaks. That is less dramatic than the headlines suggest, and it makes the question practical rather than legal: how much room do you give a system that occasionally makes things up?
Three situations from practice
1. Your assistant promises something that is not true
A customer asks whether they can still exchange a product. The assistant says yes, the policy says no. Rule of thumb: if the customer could reasonably rely on it, you are bound. With a consumer, certainly. The more confidently your system states it, the stronger that reliance. A system that hands over to a human when unsure costs you a few minutes. A system that guesses when unsure costs you the promise.
2. A quote goes out with the wrong amount
This turns on whether the other party should have spotted the error. If it says 450 euro where 4,500 belongs, you will probably get out of it, because that is an obvious slip. If it says 4,150 euro where 4,500 belongs, the customer is entitled to rely on it. Which is exactly why this is the process where you put a human in the loop: not because AI is bad at arithmetic, but because the mistake is no longer reversible once the email is gone.
3. Your supplier's system does something strange
You can try to recover your loss. In practice, standard software terms get in the way: many contracts cap liability at what you paid in a year. On a 40 euro monthly subscription that is 480 euro. That is not cover, it is a gesture. If you want this to mean anything, arrange it up front. Afterwards you negotiate empty-handed.
The six things to settle before go-live
You do not limit liability by avoiding AI. You limit it by deciding in advance what the system does and does not get to handle. This is the list we work through on every project, and one you can run yourself.
- Write down what the system may do on its own. Not in general terms but per action: answering a question about opening hours, yes. Making commitments about warranty, price or lead time, no.
- Apply the reversibility rule. Anything you can undo within five minutes, the system may do itself. Anything that leaves the building or touches money goes past a human.
- Log what happens. Which question came in, which answer went out, at what time. Without that you cannot reconstruct what was said when a complaint lands, and you cannot show you were careful.
- Disclose that it is AI. Since 2 August 2026 that is required when someone is interacting with an AI system. One line in the first message is enough, but it has to be there.
- Put in the contract with your builder who covers what: who fixes an error, within what time, and what the ceiling is. Do that before you sign, not after the first incident.
- Ask your insurer in writing whether your business liability policy covers damage caused by an automated answer. Not verbally through the broker. In writing, with the question put as concretely as possible.
The reversibility rule is the cheapest protection available. A wrong answer you can correct within an hour is an inconvenience. A wrong quote your customer has accepted is an obligation.
Three questions for anyone building this for you
Whether you talk to us or to someone else, these questions tell you within ten minutes whether they have thought about it.
- Which actions can this system take that I cannot undo? If the answer is vague, so is the design.
- Where is it written down what the system may not say? A good builder has a list, not a feeling.
- What happens when the system does not know? The right answer is: it gives no answer and a human picks it up. Not: it does its best.
That last one is where most of the trouble starts. A system doing its best on a question it does not understand sounds exactly as convincing as a system that knows. That difference should be built in, not hoped for.
What does it cost to get this right?
I start with a free introductory conversation. We discuss what takes time, which systems you use and where automation could help. You then receive a proposal with automation opportunities, integrations, a schedule and costs.
If we build it afterwards, a small project of one to two weeks runs between 300 and 5,000 euro, and a mid-sized project of three to six weeks between 5,000 and 12,000 euro. Maintenance is monthly, from 100 euro, cancellable each month. Scoping and logging are not extras with us. They are part of the design, because without them we cannot explain what the system does.
And if the answer is that you are better off keeping this process manual, we say so. With liability that happens more often than you would think: some decisions are simply too expensive to get wrong.
What you can do today
Take one AI application already running in your business and ask yourself three questions. Can this send something out without anyone looking? Can I find out what it said to a customer yesterday? Do I know what my supplier covers when it goes wrong? Three noes is not a disaster, but it is worth an afternoon.
Ready to get started?
Request a free consultation. We look together at where you are losing time.
Schedule free call