The Chatbot That Promised Refunds: Every AI Action Needs an Audit Trail
In 2022, Jake Moffatt's grandmother died. He went to Air Canada's website to book an urgent flight from Vancouver to Toronto, and the airline's AI support chatbot told him he could buy at full price and claim the bereavement discount retroactively, within 90 days of the ticket being issued. He believed it. He booked. He applied for the refund.
Air Canada refused. Its real policy — posted on another page of its own website — said bereavement fares can't be claimed retroactively. When Moffatt pointed to the chatbot, the airline's representatives said the bot had used "misleading words."
So Moffatt took Air Canada to British Columbia's Civil Resolution Tribunal. And the airline's defense, in a legal filing, was this: the chatbot is "a separate legal entity that is responsible for its own actions."
The tribunal member called that argument "remarkable." Then he rejected it, found Air Canada liable for negligent misrepresentation, and ordered the airline to pay Moffatt CAD 812 — the difference between what he paid and the bereavement fare he'd been promised (Wikipedia, https://en.wikipedia.org/wiki/Moffatt_v._Air_Canada).
An airline filed a legal document blaming its own AI. The court made the bot's promise law.
Your Chatbot's Promises Are Your Promises
The decision, published February 14, 2024, remains the closest thing to a rule on AI mistakes: the chatbot is part of your website, so you are fully responsible for the information it provides. As legal analysts at TechFinancials noted in September 2026, the case is still the instructive precedent on when a company must answer for its chatbot's words (https://techfinancials.co.za/2026/09/16/ai-chatbots-and-corporate-liability-a-south-african-perspective/).
And the doctrine is spreading. FTC Chairman Andrew Ferguson said at the Reuters Momentum AI event in Austin that the U.S. should look to existing laws before writing new ones for AI — and as the Elliott advocacy site put it in September, "there's no AI exemption from the laws on the books" (Elliott.org, September 2026, https://www.elliott.org/blog/pace-the-frontier-in-travel-ai-is-already-making-our-lives-miserable/). The same week, the FTC opened its industry-wide rogue-agent probe — the first formal U.S. enforcement action on autonomous agents (The Business Standard, October 1, 2026, https://www.tbsnews.net/world/ftc-opens-probe-ai-giants-including-anthropic-and-openai-1559131).
Translation: the chatbot defense is dead on arrival. A company keeps the savings from automating and hands the customer the risk — and courts and regulators are done accepting the trade.
The "Separate Legal Entity" Defense Failed
Think about what Air Canada actually lacked. Not a better model. A chain.
The chatbot proposed a refund. No policy guard checked the proposal against the actual bereavement policy. No authorization gate asked whether a customer-service bot was allowed to make binding financial promises. Nobody was reading the outputs. When the contradiction surfaced, the company couldn't produce a record of what policy the bot had been checked against — because it had never been checked against anything.
That's the autopsy: it speaks with your authority, there's no fence around its promises, and nobody was reading.
Now scale it. Air Canada's bot answered questions. Today's agents act — issuing refunds, changing bookings, modifying accounts, moving money. Every one of those actions is a promise your company just made, whether a human approved it or not.
Every AI Action Needs an Audit Trail
This is the simplest governance argument there is, and the Air Canada case makes it for us: every sentence your agent speaks, you sign. So sign deliberately.
Run the bereavement chat through Solomon's chain:
- Intent: Customer asks about bereavement fares. Recorded.
- Evidence: The actual policy — retrievable, versioned, pinned to the bytes in force that day.
- Governance: Customer-facing promises about money get checked against the policy before they're spoken. No match, no statement.
- Decision: The agent decides between the approved answer and escalation — not improvisation.
- Authorization: Binding financial representations clear an authorization boundary. A chatbot doesn't get to invent a refund program.
- Audit: Every answer logged with the policy it was checked against. If a dispute ever reaches a tribunal, you don't argue the bot is a separate legal entity. You show the chain.
Air Canada paid CAD 812 because it had no chain. The next company will pay more, because the precedent is set and the FTC is watching.
The rule is simple: the bot is you. Govern it like it's you.
— Ronin Inc. DMs open. ronininc.org.



