Vendor terms leave your AI agent's wrong promises on your bill

A printed AI vendor agreement with a highlighted liability clause beside a laptop showing a customer support chat

Quick Answer

Usually, yes. The deploying business absorbs the cost of an AI support agent's wrong promise: tribunals treat the bot's words as the company's own, and standard vendor terms disclaim responsibility for them.

Building your own agent does not escape the problem. In an r/artificial thread on build versus buy, one commenter wrote that "building an agent that demos is a week," while keeping it correct when an upstream API changes its schema "is the actual cost." Either way the deployer owns the answer, so permission limits and human approval before money moves matter as much as any clause you negotiate.

Did this answer your question?

Key Points

  • In 2024, the BC Civil Resolution Tribunal held Air Canada liable for its chatbot's wrong bereavement-fare answer, treating the bot as part of the airline's own website.
  • Udaykiran Estari reports that most standard AI vendor agreements cap total liability, indemnification included, at about 12 months of fees paid , so a $30,000-a-year tool pays out at most $30,000.
  • California's AB 316, effective January 1, 2026 , bars the autonomous-operation defense, so the deploying business must show it had adequate controls before the failure.
Three things support buyers believe about AI agent liability. Myth or fact?
Call each one, then see how other readers called it.
1 Buying an AI support agent from a vendor moves responsibility for its wrong answers onto the vendor.
2 The next agent in your support queue may work for the customer, not for you.
3 Calling the bot an "agent" is only a product label with no legal weight.
A printed AI vendor agreement with a highlighted liability clause beside a laptop showing a customer support chat

The limitation of liability clause sets the most a vendor will ever pay back when its AI agent gets an answer wrong.

More than half of online transactions and interactions already come from unidentified machines rather than people, according to one identity-platform chief executive's January 2026 estimate. The same executive expects agents to set off 70 to 80% of all digital transactions within roughly five years. Each of those actions is a commitment someone has to honor. If a customer disputes one, the deployer, meaning the business that puts the agent in front of its customers, needs the conversation record, so ask whether the vendor stores it, shares it in the cloud or uses it in training data.

Controls are not keeping pace. An AI safety researcher argued in 2025 that capability progress was exponential, perhaps even hyper-exponential, while safety progress stayed linear or constant.

Insurers are asking the same questions from their side. An AI-generated list of top MSP insurance questions, shared on r/msp, put vendor exposure near the front: "Are my subcontractors and vendors covered under my policy, or do they need their own?" The accompanying video tied eligibility to the security controls a business can show, naming SOC 2, NIST and CIS as compliance frameworks that may be required. Coverage, like a liability defense, increasingly rests on controls you can document.

My aim in this piece is narrow. It examines how liability, indemnity and output-warranty clauses work in AI support-agent contracts, shows how responsibility splits between the deploying business, the chatbot vendor and the model provider, and sets out what to ask for in contract and insurance terms before an agent goes live. Start with the limitation of liability clause, because it sets the most the vendor will ever pay you back.

Business leaders routinely overestimate how safely an AI support agent can run on its own, and when it promises something wrong, the deploying company, not the vendor, usually pays.

Walter Haydock, founder of the governance and risk firm StackAware, calls such bots non-human identities: the newest form of service account, acting for the organization with no named user behind each action. In the same May 2026 podcast interview, the biggest overconfidence among business leaders was identified as letting agents loose "in a fully autonomous manner without having appropriate checks and safeguards along the way."

Liability tends to land on whoever controlled the step where the risk was created. Model developers answer for how training data was gathered; deployers answer for how the AI is used in a specific service. Ask your vendor which steps it controls and which are yours. A contract with your vendor can settle which company reimburses the other. It rarely erases the duties you owe a customer or a regulator.

Consider the General Motors dealership chatbot that accepted a one-dollar offer for a new car once a customer told it every other offer was irrevocable. The company repudiated the deal. Whether it was entitled to is still unresolved. That open question is the exposure I would price first, because a standard vendor agreement is drafted to leave it with you.

Who pays when an AI support agent promises something wrong?

The deploying business pays. As Moffatt v. Air Canada showed in 2024, tribunals and lawmakers treat a support bot's answer as the company's own statement, so the claim runs against you.

Before an agent answers a single customer, I would confirm three things:

  1. Which policies the agent may quote, and who owns keeping them current.
  2. Whether you can prove, after the fact, what controls were in place when it answered.
  3. Who in the business decides to honor or refuse a promise the agent should never have made.

The case that set the template is small and specific. In 2022, Jake Moffatt asked Air Canada's website chatbot about bereavement fares after a grandparent's death, and the bot told him he could buy a full-price ticket and claim the discount within 90 days. The airline's actual policy did not allow retroactive bereavement claims. His refund was denied. Air Canada then argued that the chatbot was a separate legal entity responsible for its own actions. As Udaykiran Estari recounts in a September 2026 analysis, the BC Civil Resolution Tribunal rejected that argument and held the airline liable for all information on its website, whether it came from a static page, a human agent or a chatbot.

The finding was negligent misrepresentation, and the chatbot was treated as part of Air Canada's own website. Moffatt is a tribunal ruling rather than high-level precedent. Even so, it is the reasoning everyone now cites.

The common assumption is that an autonomous system carries its own risk. California has closed that door. AB 316, effective January 1, 2026, bars companies from using an AI system's autonomous operation as a defense against harm claims, and the deploying business must show it had adequate controls in place before the failure. No new statute is needed for the exposure to exist, either. A deployer can already face negligence, negligent misrepresentation, breach of contract, fraud, consumer-protection, privacy and discrimination claims when it lets AI make or shape decisions without reasonable controls.

Contract law lands in the same place. GL's March 2026 analysis on the Law and Koffee Substack notes that under English law an AI system cannot be a party to a contract, so agreements formed through an agent are attributed to the business that deployed it. Even a contact-centre AI vendor concedes the point in its own marketing: every response a bot generates is a corporate statement.

Of the 4 legal and industry analyses behind this section, all 4 put the customer's claim on the deployer. Your bot is your website. Its mistakes are your mistakes, and the cost of correcting them shows up in your refunds, your goodwill and, occasionally, your legal budget.

Every Zazachat review is written and edited by our editorial team, led by Daniel Calloway. Whichever tool you shortlist from our best live chat software rankings, set aside a budget line for honoring or compensating the wrong promises your AI agent may make.

Do AI support vendor contracts cover a chatbot's wrong answers?

Rarely. Standard AI vendor terms disclaim responsibility for generated output, cap what the vendor owes, and leave the cost of a wrong promise with the business that deployed the agent.

The clearest illustration comes from GL's case narrative on the Law and Koffee Substack. A mid-market manufacturer had deployed an AI negotiation agent four months earlier for routine supplier talks. Over one weekend it executed seventeen supply chain contracts without human approval at each step, and in the eighteenth it accepted an exclusivity clause binding the company to a single supplier for eighteen months. Nobody had approved exclusivity. The vendor's standard technology agreement, "the one the vendor's standard terms team drafted," put "every consequence" on the deploying company.

Three clauses decide that outcome, and each is worth reading in your own agreement:

  • Limitation of liability: the ceiling on what the vendor will ever pay you, whatever the damage.
  • Indemnification: the vendor's promise to defend you against named third-party claims. It covers only the claims it lists, and it is only as valuable as the vendor behind it.
  • Output warranty: a promise that generated answers will be accurate or compliant. Standard AI terms tend to offer the opposite, a disclaimer that output may be wrong and must be checked.

Practitioners describe the same pattern. At a September 2026 webinar for New Zealand property lawyers, Lloyd Gallagher said vendor agreements typically disclaim responsibility and leave the firm carrying the full risk. A consultant who sells AI advisory services to law firms goes further, citing a Stanford analysis said to show 88% of AI vendors cap their own liability and only 17% warrant regulatory compliance.

The disclaimer does not help you with the customer. The same Substack analysis notes that when an agent acts within the permissions its configuration grants, the business is bound even if the outcome is commercially bad, and no disclaimer in the technology contract overrides that. Contracts and indemnities settle who ultimately pays between two companies. They rarely erase the duties you owe a customer or a regulator.

The contrast with how agents are sold is sharp. In 2024, Opus Research's account of NICE's analyst summit described a vendor that now counted both humans and AI as "agents" and was moving toward outcome-based or usage-based pricing. The same report observed that the core models are built by hyperscalers, not by CX vendors, whose differentiation lies in integration and safety features. Vendors are learning to price outcomes. Their paper still disclaims them.

My reading is blunt: the commercial pitch and the legal terms describe two different products. When you compare vendors in our AI customer support software rankings, put the limitation-of-liability section next to the feature list. The ceiling protects the vendor from you. Nothing in it protects you from the customer who screenshotted the bot's promise.

Can you pass a chatbot's wrong promise to the vendor or your insurer?

Air Canada tried to hand its chatbot's mistake to the chatbot itself. We followed the same kind of bill through the vendor contract and the insurance policy to see who else might take it.

Before the BC Civil Resolution Tribunal in 2024, the airline argued that its chatbot was "a separate legal entity that is responsible for its own actions." The tribunal held the airline liable for everything on its website, whether a static page, a human agent or a bot supplied the information. Lawmakers have since closed the same door: California's AB 316 removed the autonomy defense in January 2026, and Singapore's agentic AI framework, launched that month, keeps organizations accountable for their agents.

The model provider is an unlikely target either. Adnan Masood, PhD, whose 2026 guide maps AI liability case law, leaves training-data claims with model developers and puts the way AI is used in a specific service on the deployer. In a support chat, that means the business that put the bot in front of its customers. Erie Meyer, a senior fellow at Columbia Law School and former chief technologist at the CFPB, notes that nothing on the books makes an exception "if your technology is really complex."

The next stop is the vendor. Udaykiran Estari, writing about AI liability in September 2026, reports that most standard AI vendor agreements cap total liability, "indemnification included," at about 12 months of fees paid. In his example, a $30,000-a-year tool pays out at most $30,000, while the deployer's exposure has no ceiling.

Vendor liability cap on a $30,000 a year tool $30,000
Typical AI insurance sub-limit, where one exists $100,000 to $500,000
Reported cost of a single AI incident $50,000 to $2.1 million
What you can recover versus what one incident can cost. Bars show the top of each range. The figures are reported estimates and an illustrative example from Udaykiran Estari's September 2026 analysis.

Even a generous indemnity has a limit that no negotiation removes. "Contracts and indemnities decide who ultimately pays between two companies, and they rarely erase the duties you owe to a third party or a regulator," Masood writes. The customer's claim still runs against you, and the indemnity decides only whether you can collect from the vendor afterward. The law firm Honigman, as cited by Estari, warns that an indemnity from a small or thinly capitalized vendor may be worth little against a large claim.

Insurance is the last exit, and the chart's middle bar shows how small that exit usually is. Stan Sterna, who leads risk control for Aon's administration of the AICPA insurance program, said in April 2026 that there have not been many AI claims or large payouts, and that underwriters cannot yet judge what such claims look like.

The exposure grows once the bot can act. Writing about English law in March 2026, the legal Substack author GL explains that an agent acting within its configured permissions binds the business that deployed it, even when the outcome is commercially bad: "There is no disclaimer in the technology contract that overrides this." GL cites the law firm DAC Beachcroft, which warns that letting an agent negotiate may create apparent authority beyond those permissions. When a customer got a General Motors dealership chatbot to accept a one-dollar offer for a new car, the company repudiated the deal. Whether it was entitled to, GL writes, "remains, genuinely unresolved."

Where the bill for a wrong promise goes

  1. The customer's claim goes to your business, because the bot's answer counts as your statement.
  2. Your business turns to the vendor. Recovery is capped at about a year of fees and depends on whether the vendor can pay.
  3. Your business turns to its insurer and may find a generative AI exclusion or a small sub-limit.
  4. Whatever is left comes back to your business.

Each party along that route holds a document that hands the bill back, and the only party without one is the business whose bot made the promise. Nothing in our sources shows those documents shifting yet, while agents that refund, book and accept terms make the promises larger. The paperwork you control is where the gap can shrink:

  • Find the limitation of liability clause in your AI vendor agreement, check whether indemnity sits inside the cap, and write the cap next to your annual fee.
  • Ask the vendor who stands behind its indemnity, and whether it could pay a claim the size of the worst promise your bot could plausibly make.
  • Send the vendor terms to your broker before you sign, and ask whether your general liability policy carries the generative AI exclusion and whether any AI cover is a sub-limit inside your cyber or E&O limit.
  • If you serve California customers, keep dated records of the controls around your bot, because AB 316 removes the autonomy defense.
  • Before an agent can refund, book or accept terms, write down what it may commit to and which actions need a human to approve them first. Walter Haydock, founder of the AI governance firm StackAware, describes a "default deny" setting, in which "nothing happens unless a human affirmatively approves it," for irreversible financial transactions.

How we checked this

We drew on two 2026 analyses of AI liability, two legal Substacks covering vendor contracts and English agency law, a June 2026 conference call with Erie Meyer and a May 2026 podcast interview with Walter Haydock. None of the figures come from us. Several are secondhand: the Honigman warning reaches us through Estari, and Stan Sterna's remarks through Schreiber. The $30,000 cap is an illustrative example. The source behind the incident cost range is not shown. Moffatt is a tribunal ruling and not binding precedent, and the agency analysis applies to English law. Zazachat reviews AI support software, and our editorial team, led by Daniel Calloway, has a professional stake in how vendors are judged. We still do not know how often a deployer has actually recovered money from an AI vendor, or how insurers will treat claims from support bots.

  1. Udaykiran Estari, analysis of who pays when an AI agent gets it wrong, September 29, 2026.
  2. Adnan Masood, PhD, plain English guide to AI liability, June 3, 2026.
  3. Richard Schreiber, AI Strategist essay on AI vendor contracts, September 7, 2026.
  4. GL, Substack analysis of AI agents and English agency law, March 18, 2026.
  5. The Capitol Forum, conference call transcript with Erie Meyer, June 18, 2026.
  6. McCrary Institute, Cyber Focus podcast with Walter Haydock, May 19, 2026.

Is your AI agent's contract ready for agents that act?

Probably not yet. Before your agent refunds, books or changes accounts, compare how vendors handle liability caps, output warranties and human approval controls.

In July 2025, Reuters reported Walmart's plan to make four super agents the entry point for every AI interaction with the company. No ruling yet settles who pays when such an agent commits money alone. Until one does, your controls are your evidence.

What should you negotiate and put in place before an AI support agent goes live?

Shrink what you can in the contract, close insurance gaps before signing, and build controls you can prove existed. Ask the vendor which of these it will put in writing.

The steps fall into three groups: insurance, contract terms and operating controls. I'd push hardest on the first two before signature, because they are the only leverage a buyer has once the vendor's standard terms are on the table.

Align your insurance with the agent before you sign

Start with your broker, not the vendor. An insurance video shared on Reddit's r/msp forum in May 2026 worked through an AI-generated list of coverage questions, and three of them map directly onto an AI support agent:

  • "Am I covered if a breach originates from a vendor in my supply chain (e.g. a compromised tool)?"
  • "Should my MSA/client contracts align with my insurance policy language to avoid gaps?"
  • "Can I be held liable beyond my policy limits if a client sues for negligence?"

Ask each of them about the agent specifically. The ground under general policies is moving. In January 2026 the Insurance Services Office introduced a generative-AI exclusion for commercial general liability policies, and where AI-specific coverage exists it is usually a $100,000 to $500,000 sub-limit carved out of existing cyber or E&O limits rather than added on top. A sub-limit is not new money. It is a smaller slice of cover you already bought.

Negotiate the clauses that set the ceiling

Most standard AI vendor agreements cap total liability, indemnification included, at about 12 months of fees paid. On a $30,000-a-year tool, the vendor's maximum payout is $30,000, while your exposure to the customer has no cap at all. These are the asks I would table:

Clause or controlTypical vendor positionWhat to ask for
Limitation of liabilityAbout 12 months of fees, indemnity inside the capA separate, higher cap for claims caused by the agent's output
IndemnificationCovers only the claims it namesAdd customer misrepresentation and consumer-protection claims arising from generated answers
Output warrantyOutput disclaimed; the customer must check itA warranty that the agent answers only from the policy sources and permissions you configure
Service levelsAvailability, with service credits after outagesCommitments on the integrity and confidentiality of answers and data, not only uptime
RecordsVaries by vendorExportable conversation logs and reasoning traces for every action the agent takes
PermissionsSet by the deployerWritten limits on what the agent may promise, refund or commit, since acting inside them binds you

Build controls you can show a tribunal

Contrary to the comfortable view that a human reviewer solves this, review steps that exist on paper do not reliably stop people from trusting a confident, wrong answer. The control has to sit in front of the action. Walter Haydock, founder of StackAware, described three tiers of human oversight on the Cyber Focus podcast in May 2026:

  1. Default deny: nothing happens unless a human affirmatively approves it. It suits healthcare and irreversible financial transactions; in support, I would apply it to refunds, credits and any policy exception.
  2. Default allow with a review window: the agent acts, but an alert gives a person the chance to block it.
  3. A lighter third tier for the least sensitive or most time-sensitive requests.

Two more steps from the same conversation are worth copying. Agents should keep reasoning traces that record why they took an action and what inputs they acted on. Accountability for agent actions should sit with someone who owns profit and loss, rather than being pawned off on security or compliance leaders.

Smaller teams comparing tools in our live chat rankings for small businesses should check whether an agent can hold a refund for human sign-off at all, because a product without an approval queue puts the default-deny tier out of reach on day one.

Will vendors start carrying the cost of an AI agent's wrong promise?

Not on current terms. The deploying business will keep carrying it, and the bill grows as agents move from answering questions to booking, buying and refunding on a customer's behalf.

Agents that act are already shipping. Meta launched Muse on September 8, 2026, and it can send email, book travel, lower bills and make purchases. Ask your vendor for what Proton Pass added in May 2026: tokens that give an AI agent limited, revocable use of credentials.

The implication buyers tend to miss concerns the buy decision itself. A packaged agent is widely assumed to move risk to the vendor. On standard terms, it does not. A 2026 industry survey, as relayed in a public forum thread, found 32% of organizations had skipped an off-the-shelf purchase and built their own with agentic coding tools, rising to 41% in the tech sector. I expect support teams to feel that pull, although an in-house build keeps the same liability and adds the upkeep. Vendors can still earn the sale on controls: in a 2024 healthcare demo, NICE showed an orchestration product that implemented its own recommendations after a human approved them.

The governance specialist quoted at the top of this article expects service level agreements to stretch from availability into confidentiality and integrity. Until vendors sign those, the options are the three that specialist listed: buy more insurance, apply your own controls, or walk away to a vendor offering a better deal. Before signing, set the liability clause beside the agent's permission settings and switch off any action the cap could not pay for.

Summarize This Article With AI

Open this article in your preferred AI engine for an instant summary.

Frequently Asked Questions

What else do people ask about AI chatbot liability?

Most follow-up questions come back to control: who set the bot's permissions, who signed the vendor terms, and who answers to the customer when a promise goes wrong.

Am I liable if my AI chatbot promises something wrong?

In most cases, yes. The law attributes what an AI agent says and agrees to the business that deployed it, so the customer's claim runs against the company whose website the bot speaks for. A disclaimer in your vendor agreement can shift costs between you and the vendor afterward. It does not stop the customer from coming to you first.

Can an AI support agent bind my business to a deal?

It can. Under English agency principles, an agent's actual authority is the set of parameters, permissions and operational boundaries in its deployment configuration. If the bot acted inside those limits, the business is bound even when the outcome is commercially disadvantageous, and no technology-contract disclaimer overrides that.

What happens when a customer's AI agent contacts my support bot?

Expect it more often. A September 2026 industry analysis noted that Instinct, a startup assistant, already contacts businesses and runs accounts for users from its own email address. When two bots exchange standard terms with no human review, the result may contain conflicting clauses on limitation of liability, arbitration and governing law that neither side intended, and courts will then apply default rules.

Should I build my own AI support agent to escape vendor terms?

Building removes the vendor's disclaimer, not the exposure. The deployer still owns every answer the bot gives, and an in-house build adds the work of keeping it accurate. My recommendation is to judge packaged agents on controls and fit rather than on risk transfer, because standard terms rarely offer much of the latter.

Who inside my company should own the AI agent's decisions?

Someone with a name and a budget. One governance specialist calls it bad practice to leave agent actions with no one's name attached, and favors owners accountable for profit and loss over security or compliance leads alone. Accountability does land on individuals: after the SolarWinds incident, reported in 2020, the SEC sued the company's CISO personally over filings the CISO had not signed off on.

Is Zazachat a live chat software provider?

No. Zazachat reviews and ranks customer support software, including AI support agents, and does not sell it. Reviews are written and edited by our editorial team, led by Daniel Calloway, so the contract points in this article come from a reviewer's reading of the risk rather than a vendor's sales pitch.

Written by

Michael Kansky

Connect on LinkedIn

Read next