“The AI Did It by Itself”: a Defense to Liability?
Updated: Aug 11
When a company’s chatbot promises a refund the company never offered, when an AI agent signs a deal no human reviewed, or when an automated system misleads a customer, the instinct is understandable: blame the machine. “The AI did it by itself” sounds like it should shift responsibility away from the business. In civil litigation, it does not. Across contract, tort, and consumer-protection law, that argument likely fails, and for the same underlying reason each time. This blog post explains why.
The threshold problem: AI is not a legal person
The premise breaks immediately. An artificial intelligence system has no legal personhood. It cannot hold rights, owe duties, own assets, or be sued. The law therefore attributes an AI’s actions to the people and companies that build, deploy, and profit from it. No American court has (yet) recognized AI as a legal person or accepted machine autonomy as a liability shield. Every doctrine below assumes a human or a company stands behind the system, and that is where the liability lands.
Contract: the machine’s deal is your deal
Contract law resolved this years before generative AI arrived. The Uniform Electronic Transactions Act (UETA) § 14 provides that a contract may be formed by the interaction of “electronic agents” of the parties “even if no individual was aware of or reviewed the electronic agents’ actions or the resulting terms.” An “electronic agent” is a program that acts “without review or action by an individual” (UETA § 2). The federal ESIGN Act agrees: 15 U.S.C. § 7001(h) validates a contract formed by an electronic agent “so long as the action of any such electronic agent is legally attributable to the person to be bound.” Attribution to the human is the whole point.
California (Cal. Civ. Code § 1633.1 et seq.), New Jersey (N.J.S.A. 12A:12-1 et seq.), Pennsylvania (73 P.S. § 2260.101 et seq.), and Illinois, which adopted UETA in 2021 (815 ILCS 333), all agree. New York is the outlier, relying on its Electronic Signatures and Records Act (N.Y. State Tech. Law §§ 301-309), but it reaches the same result through common-law agency and federal ESIGN.
Traditional agency law reinforces the point. A principal is bound by acts taken within the authority it confers, and an AI tool deployed to transact on your behalf is an instrumentality, not an independent actor who can shoulder the blame. The subtler risk is apparent authority: if your chatbot appears authorized to state policy or make promises, a customer may reasonably rely on what it says even when it exceeds what you intended, as the Air Canada dispute below shows. The practical response is to build authority limits into agentic systems, transaction caps, approval gates for high-value commitments, and clear statements of what the bot can and cannot bind, rather than to assume a court will treat the bot as a stranger to your business.
Tort: choosing to use the tool is the negligence
When an AI system causes harm, “it acted on its own” does not break the chain of responsibility. A business that deploys a system it cannot fully predict owes a duty of reasonable care in selecting, testing, monitoring, and supervising it, and harm a reasonable deployer should have foreseen is the deployer’s responsibility. This is usually framed as direct negligence, negligent deployment or supervision, rather than vicarious liability, because an AI is not an “employee.” But vicarious liability still reaches the business through the back door: when an employee uses an AI tool negligently within the scope of employment, respondeat superior places the loss on the employer just as it would for any other workplace mistake.
Misrepresentation is the most common flashpoint. In Moffatt v. Air Canada, 2024 BCCRT 149, a case from British Columbia, an airline’s chatbot gave a passenger wrong information about bereavement fares. Air Canada argued the chatbot was “a separate legal entity that is responsible for its own actions.” The tribunal rejected that and held the airline liable for negligent misrepresentation, reasoning that it was responsible for all information on its website, bot or not. The decision is Canadian and persuasive rather than binding, but American negligent-misrepresentation law would likely reach the same company the same way.
Product liability is the fast-moving frontier. Whether an AI system is a “product” that can be “defective,” or a “service” outside strict products liability, is being litigated now. In Garcia v. Character Technologies, Inc., 785 F. Supp. 3d 1157 (M.D. Fla. 2025), a wrongful-death case, the court allowed product-liability, negligence, and failure-to-warn claims to proceed past a motion to dismiss, treating the chatbot as a “product” and rejecting the argument that its outputs were merely protected speech.
In early 2026, a California court consolidated roughly a dozen product-liability actions against another AI developer. These rulings are early and fact-specific, but the direction is unmistakable: courts are applying ordinary tort and product-liability doctrine to AI, and none has recognized an “autonomous AI” defense.
Consumer protection: deception has no intent requirement
For customer-facing AI, the state consumer-protection statutes are often the sharpest tool, because many of them do not require intent. Liability turns on whether a practice was deceptive or unfair to a reasonable consumer, not on whether a human meant to deceive. “The AI generated it” is therefore no answer: the business made the representation, and the statute measures the customer’s impression, not the machine’s state of mind.
New Jersey’s Consumer Fraud Act (N.J.S.A. 56:8-1 et seq.) authorizes treble damages and attorney’s fees, and an affirmative misrepresentation can violate it without proof of intent. New York’s General Business Law § 349 bars deceptive acts and practices and gives consumers a private right of action for actual damages or $50, trebled up to $1,000 for willful violations, plus fees; § 350 covers false advertising, and a 2025 amendment (the FAIR Business Practices Act) added “unfair” and “abusive” prongs enforceable by the Attorney General. Pennsylvania’s Unfair Trade Practices and Consumer Protection Law (73 P.S. § 201-1 et seq.) likewise provides a private right of action with treble damages and fees. California layers three statutes: the Unfair Competition Law (Cal. Bus. & Prof. Code § 17200), the False Advertising Law (§ 17500), and the Consumers Legal Remedies Act (Cal. Civ. Code § 1750 et seq.). Behind all of them sits the Federal Trade Commission, which enforces the prohibition on deceptive practices under Section 5 of the FTC Act (15 U.S.C. § 45) and has made clear that a business is responsible for the claims its AI tools make.
Allocating the risk before it lands
None of this makes AI un-deployable. It makes risk allocation a drafting and operations problem rather than a hope. Three levers matter most.
First, your vendor contract: negotiate indemnification for infringing or harmful outputs, meaningful representations and warranties, and a limitation-of-liability clause you can actually live with, and scrutinize who owns your data and who may train on it.
Second, your customer-facing terms: well-drafted terms of use can allocate risk between sophisticated businesses, but they rarely erase a duty owed to a consumer or a foreseeable third party, and enforceability depends on real notice and assent rather than a buried link.
Third, insurance: confirm whether your technology errors-and-omissions, cyber, and media-liability coverage reaches AI-caused harms, because some policies now carve them out. Layer these over genuine oversight, pre-deployment testing, human review of consequential decisions, and logging, and the exposure becomes manageable.
The bottom line
“The AI did it by itself” is not a civil defense. It is a description of how you caused the problem. Liability follows the human and the company that chose to deploy the system, approved its prompts, and put it in front of customers. The protection is not a disclaimer that the bot is on its own; it is real oversight and deliberate risk allocation: test before deployment, keep a human in the loop for consequential decisions, allocate risk with your vendors by contract and indemnity, honor the representations your systems make, and document your diligence.
The machine may act without a human reviewing it. The law will still find the human who let it.
Legal note: This article provides general information and is not legal advice.

Authorities: Moffatt v. Air Canada, 2024 BCCRT 149; Garcia v. Character Techs., Inc., 785 F. Supp. 3d 1157 (M.D. Fla. 2025). Uniform Electronic Transactions Act §§ 2, 14; ESIGN Act, 15 U.S.C. § 7001(h); Cal. Civ. Code § 1633.1 et seq.; N.J.S.A. 12A:12-1 et seq.; 73 P.S. § 2260.101 et seq.; 815 ILCS 333 (Ill. Pub. Act 102-0038); N.Y. State Tech. Law §§ 301-309 (ESRA). N.J.S.A. 56:8-1 et seq.; N.Y. Gen. Bus. Law §§ 349, 350; 73 P.S. § 201-1 et seq.; Cal. Bus. & Prof. Code §§ 17200, 17500; Cal. Civ. Code § 1750 et seq.; FTC Act, 15 U.S.C. § 45.



Comments