Who Is Liable When AI Makes a Business Decision?
Last Updated: September 2026
AI decision liability is the question of who answers when a business acts on AI output and someone gets hurt. The law does not treat the software as the one who decided. It looks past the tool to the firm that switched it on, the people who set it up, and at times the vendor who built it. Blame follows control, and control still sits with people.
AI Smart Ventures has guided growing businesses through AI adoption in operations, hiring, credit, and customer service. The same gap shows up again and again. Teams can name the tool that made a call, but not the person who owns it. Ownership gets settled after something goes wrong, which is the worst moment to sort it out.
That gap gets costly fast. A refused claim, a bad quote, or a poor hiring screen becomes your problem the moment a customer or a watchdog asks who decided. Wait until then, and the answer gets built under pressure, by lawyers, from records nobody kept.
Key Takeaways
- The business is on the hook, not the tool: a tribunal in British Columbia held Air Canada to bad advice from its chatbot, and threw out the claim that the bot was a separate legal person.
- Nobody is clearly in charge yet: the ISACA 2026 AI Pulse Poll of 3,400 staff found just 28% named the board or top leaders as answering for AI harm, and 20% did not know.
- Name the owner before the call is made: pick one person with the power to change the workflow, then write that name beside the system, not in a policy nobody opens.
- Keep a record a stranger could follow: log the inputs, the model version, the reviewer, and the date, because that file turns a claim into a defence.
Ownership is the one part you cannot buy in. A vendor can hand you the model, the audit trail, and the guardrails, and you still carry the call. So this work looks less like a legal task and more like change management: someone has to hold the job, and everyone has to know who.
Who Is Legally Liable for an AI Decision?
Your business is liable for an AI decision it acts on, in almost every case. Courts treat an AI system as a tool the firm chose, set up, and ran. So the output belongs to the firm, the same way a staff email would. Air Canada found this out in 2024, when a tribunal held it to fare advice its chatbot had made up. A vendor may share the blame later, but the customer’s claim still starts with you.
The chain matters more than the label. A claim can land on the firm that used the system, the one that built it, or the manager who waved the output through without reading it. A federal court, in the Mobley case against Workday, let bias claims go ahead on the view that the screening vendor acts as an agent of the employers using it. That puts both sides in scope. Contracts move money between companies; they rarely move the duty you owe the person in front of you.
Can AI Be Held Accountable for Its Decisions?
No. An AI system is not a legal person. It holds no assets and owes no duty of care, so there is nothing there to blame. Air Canada argued that its chatbot was a separate entity, in charge of its own actions, and the tribunal threw that out: the bot was part of the airline’s own website. Real ownership means someone who can explain the call, change the system, and answer for what it did. Software does none of those three things.
Most firms have not made that call yet. The ISACA 2026 AI Pulse Poll asked 3,400 IT, risk, and privacy staff who answers when an AI system harms. Just 28% named the board or top leaders, 18% named the CIO or CTO, and 20% did not know. The same poll found only 36% said people sign off on most AI actions before they run. A decision nobody signed is still your decision. The only thing missing is a name.

What Is Changing in AI Liability Law in 2026?
Two things changed. The European Commission pulled its draft AI Liability Directive in October 2025, so no special AI fault regime is coming. Claims now run through normal product and tort law. In its place, the revised EU Product Liability Directive covers goods placed on the market after 9 December 2026, and it counts standalone software and AI systems as products. Strict liability, written for toasters, now reaches the model in your workflow.
US courts are moving first, one case at a time, rather than through a single new law. Hiring, lending, and pricing are where the claims land, because those calls are watched and on file. For a growing business, the effect is the same on both sides of the Atlantic. You will be asked to show what the system did, who checked it, and what you knew. That is a records question long before it turns into a legal one.
| Where the decision sits | Who is first in line | What settles it |
|---|---|---|
| Customer-facing chatbot | The firm that published it | Whether it was fair to rely on |
| Hiring or screening tool | Employer, often the vendor as its agent | Outcome data and who set the filters |
| Pricing or credit model | The firm making the offer | Records of review and the reason given |
| Software you sell on | You, as the maker of the product | Whether the fault was there at launch |
How Do You Name an Owner Before a Decision?
Name one person, by name, for every AI-assisted decision your business makes, and do it before the system goes live. The owner needs power over the workflow, not just interest in the tool. They can change the inputs, pause the system, and answer for the result. Teams cannot own decisions, because you cannot ask a team a question. Write the name where the work happens, in the process notes, not in a policy file somewhere else.
This is where tool-first AI agencies tend to stop short, handing over a working system with no named human tied to its output. The fix is small, and it is yours to make. Boards are not closing the gap on their own. Research from Diligent Institute and Corporate Board Member found that just 8% of directors rate their board as strong on AI, while 66% use AI for board work and only 22% have rules covering it.
- Name the person, not the team: write “Priya in operations owns the quoting model” into the process notes, and name a stand-in for holidays.
- Spell out the call they own: one line in plain words, covering what the system decides alone and what it must pass to a person.
- Give them a stop button: the owner must be able to switch the system off without calling a meeting, and the team should know that.
- Set a review date: put a date in the calendar for the next check of outputs, so nobody has to remember to raise it.
Naming owners across your AI-assisted decisions takes an afternoon, and it removes the question that does the most harm later. AI Smart Ventures provides AI consulting for growing businesses that want ownership settled before the first hard question lands.
What Records Prove a Human Made the Call?
A solid record shows the inputs the system saw, the version that ran, the output it gave, the person who checked it, and the date they signed off. That set answers the only question that counts in a dispute: was a competent human really in charge? Screenshots and memory will not do it. The record has to be made as the work happens, because one pulled together afterwards looks exactly like what it is.
Most teams keep half of this and never join it up. The model log sits with IT, the sign-off sits in an inbox, and the reason given to the customer sits in a CRM note. Pull the three into one entry per decision type, and keep it as long as you keep the contract it backs. AI literacy matters here too. A reviewer who cannot say what the model weighed did not really check it.
| Record | What it proves | Where it usually lives |
|---|---|---|
| Input snapshot | What the system was given | App or data platform |
| Model and version | Which logic actually ran | Vendor logs or your settings |
| Reviewer and date | A human made the call | Sign-off workflow, not an inbox |
| Reason given | What the customer was told | CRM or customer record |
Frequently Asked Questions
Who is liable when AI goes wrong?
The business that switched the AI system on is liable first, and it usually stays there. Courts and watchdogs look at who picked the system, who set its controls, and who gained from the call. A vendor can be pulled in later, and an insurer may cover part of the loss. Neither removes the duty you owe your customer. Your contract moves money between firms; it does not move that duty.
Can you sue the company that built the AI tool?
Sometimes, though, the route depends on the harm. In the Mobley case, a federal court let bias claims against a screening vendor go ahead, on the view that it acted as an agent of the employers using it. From 9 December 2026, revised European rules treat software as a product. That opens a strict liability route for faulty AI systems sold there.
Does a vendor contract move AI liability away from you?
Rarely, and never with the person who was harmed. A contract can set who pays whom after a loss, through caps and payback clauses. The customer, applicant, or watchdog still brings the claim against the business they dealt with. Read those limits closely, because many AI terms cap the vendor’s exposure well below a real claim. Assume you take the first call anyway.
What counts as meaningful human oversight of AI?
Real oversight means a named person reads the output, knows enough to disagree with it, and can stop the system. Rubber-stamping does not count. The ISACA 2026 AI Pulse Poll found only 36% said people sign off on most AI actions before they run, while 11% step in only after an alert. Oversight you cannot show is treated, in practice, as oversight that never happened.
Do you have to tell people an AI made the decision?
It depends where you trade and what the call affects, so check the rules that apply to you. Duties to tell people are widest for hiring, credit, and other calls with legal weight. Practice lags well behind: ISACA’s 2026 research found 32% have no rule on telling anyone at all. Saying so plainly settles more complaints than any policy document ever will.
What should an AI decision log contain?
A good log records the input the system got, the model and version that ran, the output, the named reviewer, the date, and the reason given to the person affected. Keep one entry per decision, not one summary per month. Store it where the work happens, so writing it is not a separate chore. Keep it as long as you keep the file it belongs to.
Who owns AI liability in a founder-led business?
The founder owns it by default, and that is worth fixing early. With no legal or risk team, nobody is watching the gap between what the tool decides and what the business can defend. Pick one person per decision type, even if that person is you for now, and write it down. Diligent’s 2026 director research found just 8% of boards rate their AI skill as strong.
How do you start assigning AI decision ownership?
Start with a list, not a policy. Write down every decision AI touches in your business, mark the ones that hit a customer, an applicant, or a price, and give each one a named owner this week. Scope drives the effort: one workflow is an afternoon, a sweep across every team takes weeks. Schedule a consultation to work through your own list with an AI advisory team.
Executive Summary
AI decision liability lands on the business that switched the system on, never on the software. A tribunal held Air Canada to what its chatbot said, and US courts are now testing whether vendors share the duty as agents of their clients. Europe pulled its draft AI Liability Directive and routes claims through product law instead, from 9 December 2026. The practical answer has not changed. Name one person for each AI-assisted decision, give them the power to stop it, and keep a record showing a human was in charge.
What Should You Do Next?
This week, list every decision an AI system already shapes in your business, and mark the ones a customer or applicant would feel. Give each one a named owner who can switch it off, then add the reviewer’s name and date to the record you keep. Start with the call that would be hardest to explain out loud.
AI Smart Ventures offers AI consulting for growing businesses that want AI-assisted decisions owned, checked, and written down before anyone asks. Schedule a consultation to map your decisions to named owners with practical AI you can defend.
People Also Read
- How AI Is Changing SEO Forever: A Business Leader’s Guide to AEO and GEO
- What Is Edge AI? How On-Device AI Processing Changes Business in 2026
About the Author
Nicole A. Donnelly is the Founder of AI Smart Ventures and an AI Adoption Specialist with 20 years of experience as a founder and CEO and over a decade leading AI adoption initiatives. She helps businesses integrate artificial intelligence with clarity and confidence, driving innovation and sustainable growth. Nicole has trained over 20,217 professionals in Applied AI, delivered 624 workshops, and worked with close to 1,000 organizations across diverse industries.
Expertise: AI Transformation, AI Strategy, AI Implementation, AI Adoption, Applied AI, Marketing, Business Operations
Disclaimer: This content is for informational purposes only and does not constitute professional business or technology advice. Results vary based on industry, existing systems, and implementation commitment. Contact AI Smart Ventures for a consultation regarding your specific situation.


