Air Canada: the AI chatbot without guardrails
Air Canada
A chatbot invented a non-existent refund policy. Air Canada tried to blame the AI. The tribunal held it responsible for its own agent.
DAMM Scorecard
Health Score
Verdict: Structurally fragile deployment — no decision guardrails
The facts
In November 2022, Jake Moffatt needed to fly for his grandmother's funeral. Before booking, he queried the AI chatbot on Air Canada's website, asking about discounted bereavement fares.
The chatbot gave him a precise, reassuring — and completely false — answer. It told him he could buy the ticket at full price and then request a refund of the difference for the bereavement fare within 90 days of issue. This policy did not exist. Air Canada's actual policy required bereavement fares to be requested before the flight, not refunded afterward. The chatbot had invented a plausible but non-existent procedure.
Moffatt followed the advice: he bought the tickets at full price (over 1,600 CAD) and then submitted the refund claim for the difference. Air Canada refused, explaining that the policy had never existed and that the chatbot had provided incorrect information.
Moffatt took the case to the British Columbia Civil Resolution Tribunal (CRT). Air Canada's defense quickly became famous: the company argued that the chatbot was "a separate legal entity responsible for its own actions." In essence, it tried to offload responsibility onto its own software.
In February 2024, the tribunal rejected this argument outright. It ruled that Air Canada was responsible for all information on its website, including that provided by the chatbot, and that it had no reason to expect a customer to distinguish between a static page and a chatbot. Air Canada was ordered to pay about 650 CAD in fare difference, plus about 36 CAD in interest and 125 CAD in costs — around 812 CAD in total.
The figure is negligible. The real damage was the legal precedent — one of the first rulings in the world to clearly establish that a company is responsible for what its AI agent says — and the global reputational damage: the case circulated worldwide as a textbook example of what happens when you put a customer-facing AI agent into production without guardrails.
DAMM Analysis
Delimitation (2/10): The failure starts here. Air Canada never delimited what the chatbot could or could not promise. An AI agent with customer access was free to state refund policies with no boundary between "information verified in the database" and "statement generated by the model." There was no rule saying: *the bot cannot declare policies that don't appear in the official knowledge base*. Without delimitation, the chatbot could commit the company to anything that sounded plausible.
Asymmetry (2/10): The risk/benefit ratio was radically unbalanced and no one assessed it. The chatbot's benefit was marginal: saving a few seconds of human customer care. The downside was enormous and irreversible: a binding legal commitment, a judicial precedent, and worldwide reputational damage. Putting an autonomous agent in charge of answering questions with legal consequences, to save on support, is the textbook example of ignored asymmetry — the classic "small gain, catastrophic loss."
Room to Maneuver (3/10): There was no space for human review between the bot's answer and its effect on the customer. The chatbot communicated information treated as binding directly, with no check intercepting high-impact statements. A room-to-maneuver guardrail — routing any answer about refunds, policies, or financial commitments to a human — would have stopped the damage before it became irreversible. The technical room existed (a flag would have sufficed), but it was never designed.
Minimum Move (2/10): Air Canada chose the maximum move, not the minimum: putting an autonomous, customer-facing AI agent into production with the power to state policies, without a supervised testing phase on high-risk cases such as bereavement fares. The minimum move would have been the opposite: a bot that, on sensitive questions, replies "let me check with an agent and confirm," generating information without generating commitments. Instead of a small, reversible step, it was a full, irreversible deployment.
What decision guardrails would have changed
The Air Canada case is the perfect demonstration of the limit of linguistic guardrails. The chatbot answered in correct, polite, well-formatted English: no output filter would have blocked it, because the text was neither toxic nor malformed. The problem was not *how* the bot spoke, but *what it decided to promise*.
What was needed were decision guardrails, not linguistic ones. An explicit delimitation — the bot cannot state refund policies absent from the official database — would have blocked the invention at its root. A room-to-maneuver guardrail — answers that financially commit the company go through verification — would have intercepted the statement before it reached the customer as binding. A minimum-move logic — on high-risk questions, reply "let me verify" instead of asserting — would have turned a blind commitment into a safe step.
None of these controls requires a better model. It requires a layer of decision evaluation that almost no 2022 deployment possessed — and that too many still lack today. It is exactly the layer that decision guardrails for AI agents introduce, evaluating every action in its context before it becomes binding.
Key lesson
A customer-facing AI agent without guardrails is not a technical risk, it is a legal risk. The damage comes not from how the bot speaks, but from what it decides to promise. Delimiting what the agent can declare, and a margin of human review on high-impact answers, are not optimizations: they are the minimum condition for putting it into production. A company is always responsible for what its AI agent says.
Want to protect your AI agents' decisions?
Related case studies
Kodak: the buried invention
Management Kodak · 1975–2012
Read analysisBlockbuster: the $50 million that cost an empire
John Antioco, CEO Blockbuster · 2000
Read analysisNetflix: from red envelopes to streaming empire
Reed Hastings, CEO Netflix · 2007–2013
Read analysis