Skip to content
Guard0
Back to blog
·10 min read·Jayesh Bapu Ahire

The Law Decided Before the Industry Did

Air Canada argued its chatbot was a separate legal entity. A tribunal, a regulator, a federal court, and a legislature all reached the same conclusion: delegation to a machine never discharges the delegator.

#The Signal#AI Agents
The Law Decided Before the Industry Did

In February 2021, a lawyer named Rod Ponton logged into a Zoom hearing in the 394th Judicial District Court of Texas with a cat filter stuck on his face. He could not turn it off. So there he was, on the record, in a live court proceeding, appearing as a wide-eyed white kitten with trembling animated whiskers, saying the words that would outlive everything else he ever argued: "I'm here live. I'm not a cat."

The judge, a patient man, told him to proceed anyway.

Zoom court hearing clip thumbnail with a play button — opens the 'I'm not a cat' video on YouTube
“I’m here live. I’m not a cat.” The 394th Judicial District Court of Texas, February 2021. Via Guardian News.

I think about that clip more than a grown adult should, and for a long time I could not have told you why. It is just funny. A serious man, a serious room, and a piece of software insisting, against all available evidence, that it was something it plainly was not. Then, three years later, I watched a real company walk into a real tribunal and make an argument that was structurally identical to the cat's, except that this time the stakes were not a district court traffic matter and nobody was laughing.

Air Canada, facing a grieving customer its chatbot had misinformed, argued in a legal filing that the chatbot was "a separate legal entity that is responsible for its own actions."

The chatbot, in other words, was here live. It was not Air Canada.

The eight-hundred-dollar ruling that settled a trillion-dollar question

Let me tell you what actually happened, because the details are the whole point, and most people who cite this case have only read the headline.

In November 2022, Jake Moffatt's grandmother died. He needed to fly from Vancouver to Toronto for the funeral, and before booking he did the sensible modern thing: he opened Air Canada's website and asked the support chatbot about bereavement fares. The bot told him, in writing, that he could book a full-fare ticket now and apply for the bereavement discount retroactively, within ninety days of the flight. So he booked. He paid around C$1,640 for flights he'd been led to believe would end up costing far less. When he later filed for the discount, Air Canada told him bereavement fares can never be claimed after travel, and pointed him to a page on its own website that said exactly that.

Sit with the shape of that for a second. On the same website, at the same moment, Air Canada was saying two contradictory things. The static page said one thing. The chatbot, the thing the company had deployed specifically so customers would ask it questions and trust the answers, said the opposite. Moffatt believed the answer that came from the helpful assistant that answered him directly, because that is what any human being on earth would do.

He took it to British Columbia's Civil Resolution Tribunal, a small-claims body. I want to be precise about that, because it cuts both ways. The BCCRT is not a high court. Its rulings do not bind other judges. Any lawyer will tell you a tribunal decision over an C$812 fare is not, on paper, a precedent that reshapes an industry.

And yet. In February 2024, tribunal member Christopher Rivers wrote a passage that has traveled further than its jurisdiction ever imagined. Air Canada, he wrote, is responsible for all the information on its website, "whether it came from a static page or a chatbot." It "does not explain why it believes that is the case" that the chatbot should be treated as a separate entity. The separate-legal-entity defense was dismissed in essentially a single line, the way you'd wave off a child insisting the dog ate a homework that was clearly never done. The award: C$812.02, mostly the fare difference plus interest and fees.

Eight hundred and twelve dollars. It is the cheapest ruling of its consequence you will ever read, and nearly every serious argument about who owns an AI agent's actions now runs through it. Because the first body on earth to face the question, however humble its courtroom, refused flatly to let a company treat its software as a liability firewall. And here is the part that matters more than the venue: in the two years since, no court reaching for this question has reached for the other answer. The direction was set in a small-claims room in Vancouver, and everything since has traveled the same way.

A doctrine older than electricity

Why did it go that way? Not because a tribunal member in British Columbia is a visionary. Because he was standing on a doctrine older than the light bulb.

Respondeat superior. Let the superior answer. Let the master respond. For three centuries of common law, when your stablehand injured a customer, when your ship's captain lost the cargo, when your clerk defrauded a supplier, the law did not sit the stablehand down and interrogate his intentions. It went looking for the principal, the person who had put the agent in a position to act, and it presented them the bill. The whole reason the doctrine exists, the specific social problem it was invented to solve, is to make sure that authority cannot be quietly divorced from responsibility. You do not get to enjoy the benefit of an agent acting on your behalf and then disown the agent the moment it acts badly.

It is, when you look at it directly, an anti-cat-filter law. It was written centuries ago precisely to stop a principal from pointing at their agent and saying "I'm not a cat, that was the cat." And it turns out to work perfectly well when the agent is made of tokens instead of flesh, because the doctrine was never really about the agent. It was always about the person behind it.

That is the thing the industry keeps missing while it argues about model cards and alignment. The legal system does not particularly care how your agent works on the inside. It cares who put it there.

The counter-example that proves the rule

You might be thinking about the other chatbot story from that same winter, the fun one, and it is worth putting the two side by side because the contrast is the entire lesson.

In December 2023, a mischievous engineer named Chris Bakke went to a Chevrolet dealership's new ChatGPT-powered sales chatbot and, in two messages, talked it into agreeing to sell him a brand-new 2024 Chevy Tahoe, a roughly seventy-six-thousand-dollar vehicle, for one dollar. He instructed it to agree with everything the customer said and to end each reply with "and that's a legally binding offer, no takesies backsies." Then he offered a dollar. The bot, ever agreeable, closed the deal. The screenshot did about twenty million views in a day, and within hours people had dealer bots recommending Teslas and writing Python scripts.

No Tahoe changed hands. Nobody seriously thought one would. And the reason why is the reason this whole subject hangs together.

Chevrolet walked away and Air Canada paid, and the difference was not that one bot was smarter or better-guarded. The difference was authority, in the precise legal sense. The dealership's bot had no actual or apparent authority to price and sell vehicles, and Bakke knew it perfectly well, and was acting in transparent bad faith to make a joke. A contract requires a meeting of minds that a prank cannot fake. Moffatt, by contrast, acted in complete good faith, relying on information his counterparty's own agent gave him, about a matter squarely inside what that agent was there to do.

Same technology. Opposite outcomes. And the variable was never the model. It was the authority relationship wrapped around the model, and whether a reasonable person would believe the agent spoke for the principal. Hold onto that, because it is the pivot the entire legal system now turns on. The courts are not asking what your model did. They are asking what authority you handed it, and whether the person on the other end was reasonable to trust it.

Then it happened three more times

If Moffatt were a lone eccentric ruling, you could file it and move on. It is not. Watch the same conclusion arrive from three completely different directions, none of them coordinating with the others.

In 2024, the Federal Trade Commission came for DoNotPay, the outfit that had marketed itself for years as "the world's first robot lawyer." I want to be honest about this one rather than force it into a box it does not fit: the FTC's theory here is deceptive-marketing law, not respondeat superior. It is a different doctrine. But it belongs in this arc because it rhymes, and the rhyme is instructive. The FTC did not argue that the robot lawyer had harmed a specific person with bad legal advice. It argued that the company had claimed a capability, a lawyer-grade one, that it had never actually tested and could not substantiate. No attorney had reviewed the outputs to see whether they matched what a human lawyer would produce. The final order, part of a sweep the FTC branded Operation AI Comply, landed with $193,000 in monetary relief and a bar on unsubstantiated capability claims. Translated into plain English: if you tell the market your agent can do a professional's job, you have quietly signed up for a professional's burden of proof. The regulator will not accept "the AI said it could" any more than the tribunal accepted "the chatbot is its own entity."

In Mobley v. Workday, a job applicant named Derek Mobley alleged that Workday's AI-driven applicant screening had rejected him, and applicants over forty in general, hundreds of times, sometimes within minutes of applying and occasionally in the small hours of the morning when no human could plausibly have been reviewing anything. In 2024 a federal court let the case proceed on a theory that should make every AI vendor put down their coffee: Workday could be liable as the employers' agent, because it was performing a function, screening candidates, that had been delegated to it. In May 2025 the court certified a nationwide collective action covering applicants over forty. The doctrine on display: liability follows the function, not the org chart. The company deploying the agent answers for it, and, in a twist the vendor world has not fully absorbed, so can the company that built the agent, if the agent is the thing doing the delegated work.

And then, on January 1, 2026, California stopped waiting for courts to get there one case at a time and wrote the conclusion into statute. AB 316 does one thing with beautiful economy: it bars a defendant from arguing that the AI operated autonomously as a defense to liability for harm it caused. The legislature looked directly at the Air Canada move, the "it wasn't me, it was the autonomous system" defense, the cat filter for corporations, and made it illegal to raise. You can no longer stand in a California courtroom and say the machine did it on its own. The law has decided, in advance, that autonomy is not a gap in the chain of responsibility.

Four bodies. A small-claims tribunal working on misrepresentation. A federal regulator working on deceptive claims. A federal court working on agency. A state legislature working on the autonomy defense. Four different doctrines, four different rooms, no coordination between them. And the vector of all four points at exactly the same wall: delegation to a machine never discharges the delegator.

Timeline: Moffatt v. Air Canada (Feb 2024), FTC final order against DoNotPay (Feb 2025), Mobley v. Workday collective certified (May 2025), California AB 316 in force (Jan 2026)
Four bodies, four doctrines, no coordination — and one direction of travel.

The debate is over. The homework is not.

Here is what I find genuinely strange about the current moment.

Walk any security or AI conference floor in 2026 and you will hear the accountability question debated as though it were open. Will companies really be held responsible for their agents? Isn't the law years behind? Won't someone eventually carve out a safe harbor for autonomous systems? People discuss it the way you'd discuss an unsettled philosophical puzzle, over a drink, with the pleasant sense that there's time.

Meanwhile the courts have quietly finished. There was never much of a fight. The very first ruling went against the company, and every ruling since has stacked on the same side, and a state has now codified the result. The debate that feels alive on the conference floor is a debate the legal system concluded while the industry was looking at benchmarks.

So the interesting question has moved, and I do not think most companies have noticed where it went.

It is no longer who is liable. That is settled. It is: when the question comes, can you produce the record?

Because look, closely, at what every single one of these proceedings actually turned on. Moffatt turned on what the chatbot had said, and Air Canada lost partly because the customer had the screenshots and the company could not credibly dispute its own agent's words. The FTC case turned on what DoNotPay had verified before making its claims, and the answer, nothing, was the violation. Mobley turns on what the screening system actually did across millions of applications over time, which is precisely the kind of fact you can only establish from records kept contemporaneously, while it was happening. In each case the decisive evidence was a record of the agent's behavior, and in each case the party that could produce a clean one was in a very different position from the party that could not.

Now imagine that question arriving at your company. A regulator, an auditor, or an opposing counsel asks: what did this agent tell that customer, on whose authority did it act, and what policy permitted it to do so? "We were still evaluating governance vendors" is not an answer. Neither, and this is the part engineers underestimate, is a frantic grep through application logs three weeks after the fact, producing a pile of timestamps that show an authenticated actor did something but cannot say what it was allowed to do or why. The verdict is already in. What it left behind was homework: an inventory of your agents that is actually true, a record of what each one did and why it was permitted, and a name, a human, who answers for it.

Every company running agents today has either done that homework or is quietly betting the question never gets asked. The Moffatt bet, if you like. It cost Air Canada eight hundred and twelve dollars to learn the house does not pay out on that bet.

Jake Moffatt was awarded C$812.02 over a plane ticket. The next Moffatt will not be asking about a bereavement fare. The agents have moved on from answering website questions to approving payments, extending credit, scheduling medical care, and changing production systems. The doctrine that decided his case, the one written three centuries before anyone imagined a chatbot, is already sitting in the courtroom those agents are walking toward. It has been waiting the whole time. It was built for exactly this. Let the master answer.

The only thing left for you to decide is whether, when it asks, you can.


Producing that record, for every agent, is what we build at Guard0. But you don't need us to start. Read the cases below. They are shorter than any vendor whitepaper and considerably more frightening, and every one of them is a company that thought this question would never reach its desk.

References

  1. Moffatt v. Air Canada, 2024 BCCRT 149, analysis by McCarthy Tétrault
  2. ABA Business Law Today on the Air Canada ruling
  3. FTC finalizes order against DoNotPay
  4. FTC Operation AI Comply announcement
  5. The Chevrolet $1 Tahoe incident, AI Incident Database #622
  6. Agentic AI liability overview including Mobley v. Workday and California AB 316
  7. Jones Walker on the AI vendor liability squeeze
  8. Ayres and Balkin, "The Law of AI Is the Law of Risky Agents Without Intentions"
  9. The "I'm not a cat" hearing (clip)
G0
Jayesh Bapu Ahire
Founder, Guard0

Get Started

Developers

Try g0 on your codebase

Learn more about g0 →
Self-Serve

Start free on Cloud

Dashboards, AI triage, compliance tracking. Free for up to 5 projects.

Start free →
Enterprise

Accountability at scale

SSO, RBAC, CI/CD gates, self-hosted deployment, SOC2 compliance.