In late 2023, a man named Jake Moffatt asked Air Canada's website chatbot about bereavement fares after a family death, and the bot told him he could apply for a reduced fare retroactively after booking at full price. That was wrong. Air Canada's actual policy required the request before travel, and when Moffatt tried to claim the discount afterward, the airline refused — then argued, in front of the British Columbia Civil Resolution Tribunal, that the chatbot was "a separate legal entity" responsible for its own information.

In February 2024, the tribunal rejected that argument outright and ordered Air Canada to pay damages. The reasoning was straightforward: a company is responsible for the information its own tools give customers, regardless of whether a human or a chatbot delivered it. That is a settled answer for a chatbot that gives wrong information — a correctable harm, contained to bad advice someone has to notice and undo.

Agents that act rather than answer raise the same question with a harder edge, because the harm is a completed action in the world by the time anyone notices. When an agent books the wrong flight, sends the wrong payment, or cancels the wrong subscription, undoing it is someone else's problem, and the responsibility question Moffatt's case settled for advice has not been settled for action.

Responsibility in most agentic systems today is distributed across a stack nobody fully owns: the model provider that generated the decision, the platform that granted the agent permission to act, the company that deployed it for a specific task, and the user who authorized it, often without fully understanding what they were authorizing. Both OpenAI's Operator and Anthropic's Claude, when given the ability to act on a screen or complete a task autonomously, ship with explicit warnings urging human supervision for anything consequential — an implicit admission from both companies that the liability question remains open even as the products ship.

Traditional liability law assumes a chain of human decisions that can be traced and examined. An agent that strings together several tool calls to complete a task can produce an outcome no single human decided on in the legal sense, even though humans built every component and set the agent loose on the task. That breaks the assumption underneath most existing liability frameworks without yet producing a replacement.

Organizations moving carefully are building reversal and escalation paths before expanding what their agents can do unsupervised, not because most jurisdictions currently require it, but because the reputational and operational cost of an unaccountable failure is higher than the cost of building the guardrail first.

Moffatt's case points at the likely shape of the eventual settlement: responsibility assigned to whoever had the most control over the design decision that produced the failure, not whichever party is easiest to blame. Air Canada could not outsource responsibility to its own chatbot. The company that sets an agent's permissions is unlikely to be able to outsource it to the user who clicked allow on a dialog they didn't fully read, either — and the institutions that build agentic systems now, before that principle gets tested in a harder case than a bereavement fare, are the ones setting the precedent the rest of the industry will inherit.