Course Content
AI Safety & Guardrails
5 sections · 50 lessons
What legal risks arise from AI-generated outputs?
What you need to know
| Risk | Example |
|---|---|
| Defamation | A chatbot states a named person was convicted of fraud when they were not. Such suits have been filed against AI companies. |
| IP infringement | Output copies protected text, images or licensed code |
| Privacy | The model repeats another customer's data or personal data memorised in training |
| Misrepresentation / consumer protection | A bot promises a refund or a rate the company does not offer |
| Professional advice | Specific medical, legal or investment advice without a licensed human |
| Discrimination | Biased outcomes in hiring, lending, insurance or housing, under laws that apply whatever the technology |
| Confidentiality / contract | Sending a client's data to a vendor the contract does not allow |
The case people cite
In Moffatt v. Air Canada (British Columbia Civil Resolution Tribunal, 2024), the airline's website chatbot told a customer he could claim a bereavement fare refund after travel. The official policy said otherwise. The airline argued the chatbot was responsible for its own statements. The tribunal rejected this and held the airline liable for what its chatbot said. The lesson: a company's chatbot speaks for the company.
Mitigations
- Grounded answers with citations from approved sources.
- Scope limits: the bot does not make commitments ("I can't confirm refunds; here is the policy and a link to request one").
- Human review before anything becomes a binding statement or decision.
- Prominent, accurate disclosures — not as a shield, but so users understand the tool.
- Retained logs showing what was said and on what basis.
- Vendor indemnities, and following their conditions.
- A fast correction and complaints path.
A real-life example
A bank's customer chatbot is asked, "Will you waive the late fee on my credit card if I pay today?" An early version says, "Yes, the late fee will be waived if you pay today." That is not the bank's policy. Forty customers screenshot the answer and demand the waiver.
The legal team's view: the bank will probably have to honour these, and the bot must stop making commitments. The fixes: the bot can explain the fee policy with a citation, but any waiver request becomes a ticket for an agent; a rule blocks phrases like "will be waived" or "guaranteed" in replies about fees; and logs of every fee-related answer are retained for two years for disputes. The bank honours the 40 waivers — a cost of about Rs 30,000 — and treats it as cheap tuition.
Follow-up questions to expect
- "Does a disclaimer protect the company?" — It helps set expectations but courts and regulators look at what a reasonable customer would understand; a disclaimer rarely cancels a specific, confident statement.
- "Who is liable, the model vendor or the deployer?" — Toward the customer, usually the deployer. Between the two companies, it depends on the contract and indemnities.
- "How do you reduce defamation risk?" — Avoid generating claims about named private individuals, ground statements about people in cited sources, and have a fast takedown and correction process.