PAN Lab example
Air Canada chatbot
A policy the chatbot invented and the company that answered for it
Air Canada's website chatbot told a customer they could claim the reduced bereavement fare after booking. The airline refused, and a tribunal held it liable.
See more
Air Canada ran a support chatbot on its own website to answer customers' questions about its policies. Its answers appeared with the same authority as the airline's published policy pages. The record does not name who built the chatbot.
What happened
A customer arranging travel after a death in the family asked the chatbot about bereavement fares. The chatbot said they could apply for the reduced fare retroactively, after booking. That was not Air Canada's policy.
The customer relied on the answer, booked the flight, and then submitted the claim. Air Canada's human staff refused it, pointing to the actual policy the chatbot had misstated.
The ruling
The customer took the dispute to British Columbia's Civil Resolution Tribunal. The case is Moffatt v. Air Canada, 2024 BCCRT 149, decided on February 14, 2024. The tribunal found the airline liable for negligent misrepresentation. It awarded 650.88 Canadian dollars in damages, plus fees.
The damages were small. The case matters for the precedent it sets. The ruling is decided, with published reasons, so this case states its holding as a finding.
What each side said
Air Canada argued that the chatbot was a separate legal entity responsible for its own actions. On that argument, the airline would not be liable for what the chatbot said.
The tribunal rejected it. It held that the airline is responsible for all the information on its website, whether it comes from a static page or a chatbot. A customer has no way to know, and no obligation to work out, which of the two sources to trust.
The duty the ruling sets
An organization must take reasonable care that what its chatbot tells customers is accurate. It owes the same care for its published pages. The chatbot is a tool the organization deploys, not an entity that answers for itself.
The case file reads that duty this way. Every system that writes its own answers will sometimes state something false. A made-up policy is a known failure, not a freak event. So the duty is not to make the chatbot never wrong. It is to build an accuracy check on what the chatbot says, and to own its answers. A disclaimer that the AI speaks only for itself does not move that responsibility.
Where the chatbot and the staff disagreed
The chatbot said yes, and the staff said no. The customer was left holding the difference.
Staff were the point where Air Canada could have honored or corrected the chatbot's answer before it became a harm. Instead, the gap between the chatbot's promise and the staff's refusal was the injury. The record documents no process that kept the chatbot's answers in line with the actual policy before the ruling.
After the ruling
The record reports that Air Canada removed the chatbot from its website after the ruling. It does not say what, if anything, replaced it.
What this network is drawn from
This network follows the accountability pattern in the case file. It is not a reconstruction of Air Canada's actual system. It shows the chatbot, the staff who handle customer claims, the ownership of the chatbot's answers, the policy records, and the published policy pages. No customer outcome is computed on it.
What the available tools can and cannot address
A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other.
Explore (No Targets) sets no targets. Under Service Targets Only, the targets can be met within this case's budget of 8 units. The cheapest way costs 2 units and uses one tool, Mark AI-written records. Other ways pair two tools, such as Review on schedule and Escalate checks for 4 units.
Under Service and Safety Targets and All Governance Targets, the targets are not fully addressable with the available tools. One failure pathway stays open whatever you choose: Staff set what the chatbot may state. In this example, a mistake in what staff set for the chatbot would be repeated to customers by the chatbot. None of the tools offered here acts on it.
The closest you can come costs 7 units: Gate record entries, Mark AI-written records, and Escalate checks. It closes every other failure pathway and meets the service targets. Adding Check with a second model, the tool that adds the accuracy check, would cost 3 more units, over the budget, and would still leave that pathway open. Using every tool at its strongest setting, at any cost, still leaves that pathway open, and the added checks leave the chatbot too little useful work.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Customer-chatbot-class the organization answers for network: 5 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
Show all 5 assumptions
- assumed
This example includes Air Canada's published policy pages as a second source of answers. The ruling puts them on the same footing as the chatbot: the airline answers for all the information on its website, chatbot or static page alike. So two sources answer the same question in the airline's name, and the harm is the gap between them. A customer reading one has no way to know the other says something else. The example also assumes more work than staff can handle: a public website answers the whole airline's customers, while the policy staff are staffed for unusual cases.
- baseline
This example follows the accountability pattern in the case file. It is not a reconstruction of Air Canada's actual system. The chatbot described a bereavement fare policy that did not exist. The customer relied on it and was refused by human staff. A civil resolution tribunal found the airline liable for negligent misrepresentation. It rejected the argument that the chatbot was a separate legal entity responsible for its own actions. It held the airline responsible for all the information on its website, chatbot or static page alike. The ruling is decided and published, so this example treats its holding as a finding.
- baseline
This example includes a check that compares the chatbot's answers with the actual policy before a customer relies on them. That check is a form of the reasonable care the ruling requires. A system that writes its own answers will sometimes state something false, and a made-up policy is a known failure. So the check is the safeguard. The record documents no such check, and the chatbot gave a customer a policy that did not exist as the airline's own word.
- assumed
This example includes an owner for the chatbot's answers: the people who answer for them as the airline's own word. It is also the point where a person could honor or correct an answer before it causes harm. Air Canada's separate-entity argument tried to disclaim exactly this ownership, and the tribunal rejected it. The chatbot is a tool the airline deploys, not an entity that answers for itself. So building that ownership is the airline's job.
- assumed
This example does not show what happened to any customer. It shows how errors move among the chatbot, the staff, and the records. The customer who relied on the chatbot's answer is outside the network. The false answer, the ruling, the rejected separate-entity argument, and the damages come from the case file. Nothing in the network computes them.
What this example does not show
Show all 2 limitations
- This example does not show what happened to any customer. It shows how errors move among the chatbot, the staff, and the records. The customer who relied on the chatbot's answer is outside the network. The false answer, the ruling, the rejected separate-entity argument, and the damages come from the case file. Nothing in the network computes them.
- The ruling is a decided civil resolution tribunal decision with published reasons. So this example states its holding as a finding: the airline is responsible for what its chatbot says. The network includes two checks from the case file: an accuracy check on the chatbot's answers and the ownership of those answers. It does not compute a harm from either.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
An airline's customer-facing website chatbot told a customer they could claim a bereavement fare retroactively — a policy that did not exist. The customer relied on the chatbot's statement, bought a ticket, and was then refused the fare by the airline's human staff. A civil-resolution tribunal found the airline liable for negligent misrepresentation and awarded damages, and in doing so rejected the airline's argument that the chatbot was a separate legal entity responsible for its own actions. The tribunal held that the organization is responsible for all the information on its website, whether it comes from a static page or a chatbot, and that a customer has no way to know which source to trust. This is the contact-centre domain's cleanest accountability ruling: the bot is a tool the company answers for, not an entity that answers for itself.
empirical- Government Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 14, 2024). https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html
- Reference Sookman, B.B. (2024, February 19). Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot. McCarthy Tétrault TechLex blog https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot
The duty the ruling establishes is that an organization must take reasonable care that its chatbot's representations are accurate, because the chatbot is a tool it deploys rather than a separate entity that answers for itself. A hallucinated policy or a wrong rule stated by the bot is therefore the organization's own misrepresentation, and a posture that treats the AI as speaking only for itself does not transfer that responsibility away. The governable reading is that a customer-facing chatbot is a channel the organization is accountable for exactly as it is accountable for a page on its own website — so the accuracy control on what the bot states, and the ownership of what it says, are the organization's to build, not the bot's to carry.
empirical- Reference Sookman, B.B. (2024, February 19). Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot. McCarthy Tétrault TechLex blog https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot
- Government Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 14, 2024). https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
All of them in context on the Customer service & contact-centre AI domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Mark AI-written records — Provenance labeling
- Pause AI on alarms — Deployment circuit-breaker
- Review on schedule — Oversight cadence & retrospectives
- Check with a second model — Cross-model verification
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model