legal247

AI hallucinations: who is liable when your chatbot promises a customer too much?

In brief

A business is liable for AI hallucinations in its own customer service. The chatbot is not a separate legal person, and what it says counts as the business's own statements. Towards consumers, wrong answers can give rise to claims for non-conformity, and misleading answers can breach Norwegian marketing law. A disclaimer in the chat window helps little.

A customer asks the chatbot on your website whether she can get a refund. The chatbot says yes and refers to a scheme that does not exist. The customer acts in reliance on the answer and later demands her money back. The question is who bears the liability, and the answer is almost always the business.

What are AI hallucinations?

AI hallucinations are incorrect statements that a language model presents as fact, in the same confident tone as its correct answers. They may concern prices, terms, deadlines or rights that are simply wrong. The model does not know that it is mistaken and rarely signals that it is guessing.

The risk is particularly high in customer service, because the chatbot answers on behalf of the business, in real time and without a human seeing the answer before the customer does.

Is the business liable for what the chatbot says?

Yes, as a general rule. The chatbot is a tool the business has itself chosen to use in its customer communication. What it says counts as the business’s own statements, in the same way as text on the website or an answer from an employee.

The best-known case is Moffatt v. Air Canada from February 2024. Air Canada’s chatbot told a customer that he could apply for a bereavement fare after his journey, which the airline’s own rules did not allow. Air Canada argued that the chatbot was a separate legal entity responsible for its own actions. The Civil Resolution Tribunal of British Columbia rejected this and held that the airline was responsible for all information on its website, whether it came from a static page or from a chatbot. The customer was awarded the fare difference.

The chatbot is not a separate legal person. What it says, the business says.

The case is Canadian and was decided under Canadian law. There is, as yet, no equivalent Norwegian decision. The outcome is nevertheless well aligned with Norwegian principles of contract and tort law, and it is hard to see a Norwegian court reaching a different result on similar facts.

Which rules apply when the customer is a consumer?

Towards consumers the legal position is clearest, and the business’s room for manoeuvre is smallest.

Rule What it means for wrong chatbot answers
Consumer Purchases Act § 16(1)(c) The goods are non-conforming if they do not match information the seller has given in marketing or otherwise
Consumer Purchases Act § 3 The rules cannot be derogated from to the consumer’s detriment
Marketing Control Act § 7 Incorrect information about price, characteristics or the consumer’s rights may be a misleading commercial practice
Marketing Control Act § 42 Material breaches can lead to an administrative fine

Information from the chatbot about a product is information the seller has given “otherwise” within the meaning of the Consumer Purchases Act (forbrukerkjøpsloven). If the chatbot promises a characteristic the product does not have, the customer may raise claims for non-conformity, such as repair, a price reduction, termination or damages. The seller escapes liability only if the information was corrected before the purchase in the same or an equivalent manner, or could not have influenced the purchase.

If the chatbot systematically gives wrong information about price, the right of withdrawal or the right to complain, this may also be a misleading commercial practice under the Marketing Control Act (markedsføringsloven). The Norwegian Consumer Authority (Forbrukertilsynet) may then issue a prohibition, coercive fines and an administrative fine under Marketing Control Act § 39.

What applies when the customer is another business?

Between businesses the rules are to a greater extent non-mandatory, but the starting point is the same. Under Sale of Goods Act § 18 in the Sale of Goods Act (kjøpsloven), the rules on non-conformity also apply where the goods do not match information the seller has given in marketing or otherwise, and which may be assumed to have influenced the purchase.

For services and software there is no equivalent statutory rule, but an incorrect chatbot answer may still affect what has been agreed, or give grounds for damages under non-statutory rules. How far liability extends in such cases has not been settled in Norwegian case law.

Does it help to say that the chatbot may be wrong?

Not much, particularly towards consumers. A disclaimer in the chat window cannot deprive consumers of their rights under the Consumer Purchases Act, and it does not change the fact that misleading information can breach the Marketing Control Act. Towards business customers a disclaimer may carry somewhat more weight, but a general exclusion of liability for one’s own statements can be set aside under Contracts Act § 36 in the Contracts Act (avtaleloven) if it would be unreasonable to rely on it.

A disclaimer is not worthless, however. It can reduce the customer’s legitimate reliance on answers about matters the chatbot obviously cannot decide, such as individual arrangements or exceptions from the terms.

What does the AI Act say?

AI Act Art. 50(1) requires providers of AI systems that interact with people to ensure that users are informed that they are communicating with an AI system. The obligation applies in the EU from 2 August 2026.

In Norway the regulation does not yet apply. It must first be incorporated into the EEA Agreement and implemented in Norwegian law. The government intends to hold a new public consultation in autumn 2026 and to present a bill in spring 2027. In any case, the transparency obligation only ensures that customers know they are dealing with a chatbot. It does not relieve the business of liability for what the chatbot says.

How can a business limit the risk of AI hallucinations?

  1. Restrict the knowledge base. Let the chatbot answer from approved sources such as terms, price lists and help pages, not from the model’s general knowledge.
  2. Set clear limits. The chatbot should not promise refunds, discounts, compensation or exceptions from the terms. Such questions should be passed to a human.
  3. Test before launch and on an ongoing basis. Ask the questions customers actually ask, including the difficult ones, and check the answers.
  4. Log the conversations. Logs make it possible to detect errors, correct them and document what was actually said. Remember the data protection rules when logs are stored.
  5. Negotiate the vendor contract. Require quality, testing, notice of changes to the model and liability proportionate to the risk. See what is realistic in the article on limitation of liability in SaaS contracts.
  6. Give one person ownership. Someone in the business must own the chatbot in the same way that someone owns the website. A clear AI policy for employees makes the roles clear, and the board should ask about the controls, see the board’s responsibility for AI.

AI hallucinations cannot be eliminated entirely, but the risk can be managed. Businesses that treat the chatbot as a customer service employee, with training, instructions and supervision, are in a far stronger position than those that treat it as a technical tool without an owner. Read also about vibe lawyering and the risk of AI-drafted contracts and the topic page on artificial intelligence.

Questions and answers

Can we state in the chat window that the answers are not binding?

You can, but it helps little. Towards consumers, the Consumer Purchases Act cannot be derogated from to the consumer's detriment, and a general disclaimer does not change the fact that misleading information can breach the Marketing Control Act. A disclaimer should be combined with technical limits on what the chatbot is able to answer.

Can we recover the loss from the AI vendor?

Only if the contract provides a basis for it. The standard terms of the major vendors usually limit their liability heavily. Requirements on quality, testing, logging and liability must therefore be negotiated before the contract is signed.

Do we have to tell customers that they are talking to a chatbot?

In the EU, the obligation in Article 50 of the AI Act applies from 2 August 2026. In Norway the regulation has not yet been implemented, but transparency is recommended in any event. Giving the impression that the customer is talking to a human may also be misleading under the Marketing Control Act.

Next legal review: 1 April 2027