Who Is Liable When Your AI Makes a Mistake?

Glowing chat bubble icon on a circuit board, representing AI tools making decisions inside business software

Key takeaways

  • AI is a tool, not a legal person. When it gets something wrong, responsibility lands on the business using it, and sometimes on the vendor as well.
  • Courts have already weighed in. Two cases, one about an AI hiring tool and one about an airline chatbot, arrived at the same idea: automating a decision does not move the accountability.
  • Most policies were written before any of this. An AI claim might touch professional liability, cyber liability, or employment practices coverage, and some policies exclude technology risk outright.
  • The useful work here is unglamorous: know where AI is running in your business, keep a human on the decisions that matter, and read what your vendor contracts actually promise.
  • Businesses across DC, Maryland, and Virginia are operating under a patchwork of state rules rather than one federal standard, so the answer can shift depending on where your employees sit.

Most of the businesses we work with in the DC metro area are using AI somewhere, and a fair number of them never sat down and decided to. It arrived inside software they already had. A resume screener in the applicant tracking system. A chatbot on the contact page. A forecasting feature in the accounting platform. A scheduling assistant that quietly reshuffles the week.

It works, and that is the point. AI takes the repetitive parts of a job and hands your team back the hours. But every one of those tools is now making or shaping decisions that affect real people, and when one of them gets something wrong, the question that follows is not a technical question. It is a liability question. Even though a computer made the call, your business can still be the one that answers for it.

AI is confident. That is not the same as correct.

AI systems move through enormous amounts of data faster than any person could, and they are not error proof. Some lose track of earlier details in a conversation as the prompts get longer. Others fill gaps with a plausible guess rather than admitting they do not know. A few will agree with whatever you push back with, which feels helpful and is the opposite of helpful.

The common failure modes look like this:

  • Guessing when the data is thin, and presenting the guess with the same confidence as a fact
  • Misreading data or misinterpreting what was actually asked
  • Learning from information that was flawed, biased, or out of date
  • Deciding without the full context a person in the room would have had
  • Becoming agreeable under pressure, which turns a second opinion into an echo
  • Carrying out an instruction it should have refused

When those decisions reach a customer, an applicant, or an employee, the consequences are ordinary business consequences: money out the door, a discrimination claim, a regulatory inquiry, a reputation that takes a year to rebuild.

Two cases worth knowing about

This is no longer hypothetical. Two matters have shaped how businesses should think about the question.

An AI hiring tool and a nationwide age discrimination claim

In Mobley v. Workday, an applicant alleged that an AI-powered screening system repeatedly rejected him and others in ways that tracked legally protected characteristics, including age, race, and disability. The claims have moved forward under Title VII, the ADEA, and the ADA, and in May 2025 the court granted preliminary certification of a collective action on the age claim. The case is still being litigated.

The detail that matters most for employers is how the court handled the vendor. Workday argued it could not be liable because it is not the employer. The court disagreed, treating the software provider as an agent of its client employers and therefore within reach of those statutes. That is worth reading twice, because it cuts both ways: the vendor can be pulled in, and the employer is still standing right there next to them. Handing the screening to an algorithm did not hand off the legal duty.

A chatbot that gave a customer the wrong answer

An Air Canada customer asked the airline chatbot about bereavement fares. The chatbot told him he could buy a full-price ticket and apply for a refund afterward. That was wrong. He bought the ticket, was denied the refund, and took it to the British Columbia Civil Resolution Tribunal.

He won. In Moffatt v. Air Canada, the tribunal found the information misleading and held that the company, not the chatbot, was responsible for what the chatbot said. The airline had argued the bot was a separate entity. That argument did not land.

The takeaway for a business with a chat window on its website: whatever your bot tells a customer, you told the customer.

So who is actually responsible?

AI cannot be held legally responsible, because it is a tool rather than a person. Responsibility falls on the business using it, on the vendor that supplied it, and often on both. In practice, the business using the tool is the one with the customer relationship, the employment relationship, and the exposure.

Meanwhile the rules are still being written. Lawsuits and regulations touching AI are expanding across hiring, data use, and intellectual property, and businesses are navigating a patchwork of state laws rather than one federal standard. For a company with employees in DC, Maryland, and Virginia, that can mean three sets of expectations for the same hiring process. The courts, so far, keep circling the same conclusion: when AI is involved, the company is still accountable for the outcome.

The question is not whether you use AI. It is how you use it, and how ready you are if something goes sideways.

An old kind of risk with a new player

Most businesses picture risk in familiar shapes. A break-in. An employee injury. Water where water should not be. A bad human decision. Insurance has spent a century getting good at those, largely because a person sits at the center of each one.

AI introduces something structurally different: exposure created by an autonomous decision nobody reviewed. An AI is only as reliable as the data behind it, and if the design, the data, or the decision logic carries a flaw, the outputs carry it too. When a system pulls bad data, decides on it, and writes the result back into the same place it pulls from, the error compounds quietly until someone notices.

Four things worth doing this quarter

None of this argues for avoiding AI. It argues for using it on purpose.

Find out where AI already is

Start with an inventory, because the answer is almost always longer than expected. Which of your tools have AI features switched on, what are they doing, and where do the prompts your team types actually get stored. That last one matters: personal or client data typed into a prompt may be sitting somewhere you would not have chosen.

Keep a human on the decisions that count

Automation is fine for drafting and sorting. Decisions that affect someone’s job, coverage, or money deserve a person. If you use AI to draft client contracts, build a procedure around it: keep the iterations, and mark clearly which version was AI output and which was reviewed and edited by a human. When a question comes up two years later, that record is the whole ballgame.

Read what your vendor contract actually says

Understand what your technology providers take responsibility for and what they hand back to you. This was already true before AI. Using a cloud service never absolved anyone of liability for client data. Using an AI vendor does not absolve you for the chatbot on your own website.

Write a short policy and train on it

It does not need to be long. What tools are approved, what data never goes into a prompt, who reviews what, and who to tell when something looks wrong. Fold it into the data privacy and cybersecurity training your team already sits through.

Your current policies may not reach this

Here is the part we would rather tell you now than during a claim. Most standard policies were not drafted with AI in mind. Depending on what happened, an AI-related claim may fall under coverage you already carry:

  • Professional liability, also called errors and omissions, where the issue is advice or work product
  • Cyber liability, where the error traces back to a cyberattack or a data exposure
  • Employment practices liability, where the issue arose in hiring, promotion, or termination

It may also fall nowhere. Some policies exclude technology-related risk. Others simply do not address AI, which leaves a gap that only becomes visible at the worst possible moment. Finding out which of those describes your program is a twenty-minute conversation now and a very expensive surprise later.

Let us look at this with you

We believe the future of insurance gets more personal, not less. AI will keep making the transactional parts of this business faster and cheaper, and when it does, what separates one advisor from another is whether someone knows your operations well enough to spot the exposure before it finds you.

So if your business is using AI, or is about to, let us go through it together. We will look at where the tools are running, what your current coverage would and would not respond to, and what is worth changing. Capitol Benefits works with businesses across Gaithersburg, DC, and Northern Virginia, and this is the kind of review we would rather do on a Tuesday than in the middle of a claim.

Frequently Asked Questions

Does our business insurance already cover AI mistakes?
Possibly, and possibly not. Depending on what went wrong, an AI claim might respond under professional liability, cyber liability, or employment practices liability. Some policies exclude technology-related risk, and many older forms do not mention AI at all. The only way to know is to read your specific policies against how you are actually using the tools.

We only use AI features built into software we already pay for. Does that still count?
Yes. The exposure comes from what the tool decides, not from whether you bought it as an AI product. A resume filter inside your applicant tracking system or a chat widget on your website creates the same questions as a standalone AI platform. This is why the inventory step matters so much.

If the AI vendor made the error, can we point to them?
Sometimes, and it is worth knowing what your contract says. But in Mobley v. Workday the court found the vendor could be treated as an agent of its client employers, which pulled the vendor in without pushing the employer out. Assume you are still in the conversation, then negotiate your vendor terms accordingly.

What is the single most useful thing we can do this quarter?
Build the inventory. You cannot manage or insure exposure you have not identified, and nearly every business we walk through this with finds at least one AI feature running that nobody had flagged.

Do the rules differ across DC, Maryland, and Virginia?
They can. AI regulation is developing as a patchwork of state and local rules rather than one federal standard, so a business with employees in all three jurisdictions may be working under more than one set of expectations for the same process. It is a good reason to document how your AI-assisted decisions get made.

Related reading from Capitol Benefits

Ready when you are

Let's take a look at what you've got.

A real review of your current coverage. No deck, no pressure, and usually some money saved along the way.