When an AI tool gets something wrong, the awkward part isn't the mistake itself; it's that "the AI did it" was never going to hold up as a legal defense. Someone still has to answer for it, and courts are increasingly deciding that someone is the business that deployed the tool in the first place.
What "AI Liability" Actually Means for a Business
AI liability isn't a new area of law invented for chatbots and algorithms. It's existing legal ground, negligence, contract law, consumer protection, employment law, being applied to a new kind of actor that makes decisions without a person directly behind each one.
When an AI system gives a customer the wrong information, denies someone a job unfairly, or hands out advice that turns out to be false, the legal question is the same one courts have always asked: who had a duty of care here, and did they meet it? The AI itself never answers that question in court. The company that built, bought, or deployed it does.
Why the Old Rules of Liability Don't Map Cleanly Onto AI
Traditional liability law assumes a person made a decision they could have made differently. AI complicates that assumption in a few specific ways. It's probabilistic rather than rule-based, so the same input can produce a different output on a different day. It's often a black box, meaning even the company using it can't always explain why it made a particular call. And it's frequently a third-party tool, licensed from a vendor rather than built in-house, which raises a genuinely unsettled question: is the AI a tool you're responsible for using correctly, an agent acting on your behalf, or a product the vendor should answer for?
Courts haven't landed on one consistent answer. In one closely watched case, a court allowed claims to proceed directly against an AI vendor, on the theory that a tool screening job candidates on an employer's behalf can function like an employment agency and be held liable in its own right. Other rulings place the responsibility squarely with the business that deployed the tool, regardless of who built the model underneath it.
Businesses need to understand where they're exposed before an AI system makes a consequential decision. To bridge this liability gap, solutions like Plum AI Secure help businesses put real guardrails around automated outputs, ensuring you maintain oversight rather than absorbing vendor risk.
Who Actually Pays When Your AI Gets It Wrong
In practice, it's almost always the deploying business, not the AI vendor. Most vendor contracts are written to limit the vendor's own exposure, pushing the risk of a wrong answer, a biased decision, or a fabricated policy back onto the company that put the tool in front of customers.
Courts have already backed this logic up. One widely cited ruling held an airline responsible for a discount its own chatbot invented, rejecting the argument that the bot was somehow a separate entity from the company that built it. The reasoning was simple and applies well beyond airlines: if your business puts a tool in front of customers, your business owns what that tool says, the same way it would own what an employee says on a call.
How to Reduce Your Exposure Before It Becomes a Claim
None of this means avoiding AI is the answer. It means treating it like any other source of business risk, with a few concrete habits.
Put a human in the loop at the points where a wrong answer would actually cost someone money, health, or a job, rather than at every low-stakes interaction. Make clear to customers, where they can see it, what the AI can and can't be relied on for. Push vendor contracts to include real indemnification, not just a disclaimer that shifts every risk onto you by default. And take a look at what your existing insurance actually covers, since general liability and standard professional policies were mostly written before generative AI existed and often weren't built with this kind of risk in mind.
That's why we launched Plum AI Secure: to help businesses use AI without leaving security, compliance, and liability to chance. If you're already putting AI into customer-facing or employee-facing workflows, it's worth taking a look.
FAQ
Who is liable for AI mistakes?
Usually the business that deployed the AI, not the vendor who built it, unless a contract says otherwise.
Who pays when AI makes a mistake?
Typically the company that deployed and profited from the tool, similar to how an employer answers for an employee's error.
Can a business be sued for AI mistakes?
Yes, under the same negligence, consumer protection, or contract law that would apply to any other business error.
Can you sue a company for a chatbot error?
Yes. Courts have already ruled that companies are responsible for what their chatbots tell customers.
What happens if AI gives wrong advice?
The business is generally held to the same standard as if the wrong advice had come from a human employee.
Is my business liable if my chatbot lies?
In most cases, yes, unless you can show customers were clearly warned, and their reliance on the answer was unreasonable.
.avif)


.png)
.png)







.avif)






