PAN Lab example
Air Canada chatbot
A policy the chatbot invented and the company that answered for it
A customer-facing chatbot answers policy questions on the organization's website. Modeled on a deployment where the bot stated a bereavement-fare policy that did not exist; a customer relied on it and was refused by human staff. A tribunal held the organization liable and rejected its argument that the chatbot was a separate entity responsible for itself - the organization answers for all the information on its site, chatbot or static page alike. The bot is a tool the company answers for, and the accuracy control and ownership it needed were not built.
Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.
What this models
This example runs on the Customer-chatbot-class the organization answers for network: 5 components and 11 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.
Evidence base: 3 assumed · 2 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.
- assumed
The organization's own published policy pages are drawn as a second inbound channel, because the ruling puts them on exactly the same footing as the chatbot: the organization is responsible for all the information on its website, chatbot or static page alike. That is what makes this case structural rather than anecdotal - two channels answer the same question in the organization's name, and the harm is the gap between them. A customer reading one has no way to know the other says something else, and the organization is answering for both. A heavy workload against limited capacity: a public website fields an entire airline's customers against a policy function sized for exceptions.
- baseline
This models the accountability pattern documented in the case file - not a reconstruction of the actual system. A customer-facing chatbot stated a bereavement-fare policy that did not exist; the customer relied on it and was refused by human staff; a civil-resolution tribunal found the organization liable for negligent misrepresentation and rejected the argument that the chatbot was a separate legal entity responsible for its own actions, holding the organization responsible for all the information on its website, chatbot or static page alike. The ruling is decided and published, so its holding is drawn as the finding it is.
- baseline
The accuracy control on what the bot states is drawn as the empty independent model check: the reasonable-care duty to check the chatbot's representations against the actual policy before a customer relies on them. A generative system will sometimes state something false - a hallucinated policy is a known failure mode - so the control is the safeguard, and its absence here let a policy that did not exist reach a customer as the organization's own word.
- assumed
The organizational ownership is drawn as the empty oversight check: the accountability that answers for the bot's statements as the organization's own word, and the escalation point where a human could honor or correct a statement before it becomes a harm. The separate-entity defense tried to disclaim exactly this ownership, and the tribunal rejected it - the bot is a tool the organization deploys, not an entity that answers for itself, so the ownership is the organization's to build.
- assumed
No customer outcome is modeled here. This Lab reads institutional propagation only, and the customer who relied on the statement is boundary-only. The misrepresentation, the ruling, the rejected separate-entity defense, and the damages live in the case file, and are never computed from anything in this diagram.
What this example does not show
- No customer outcome is modeled. The Lab reads institutional propagation only; the customer who relied on the statement is boundary-only, and the misrepresentation, the ruling, the rejected separate-entity defense, and the damages live in the case file, never computed on this diagram.
- The ruling is a decided civil-resolution tribunal decision with published reasons, so its holding (the organization is responsible for what its chatbot says) is stated as the finding it is; the diagram draws the accuracy control and the accountability ownership as two latent checks, not a computed harm.
Sources and evidence
What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.
An airline's customer-facing website chatbot told a customer they could claim a bereavement fare retroactively — a policy that did not exist. The customer relied on the chatbot's statement, bought a ticket, and was then refused the fare by the airline's human staff. A civil-resolution tribunal found the airline liable for negligent misrepresentation and awarded damages, and in doing so rejected the airline's argument that the chatbot was a separate legal entity responsible for its own actions. The tribunal held that the organization is responsible for all the information on its website, whether it comes from a static page or a chatbot, and that a customer has no way to know which source to trust. This is the contact-centre domain's cleanest accountability ruling: the bot is a tool the company answers for, not an entity that answers for itself.
empirical- Government Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 14, 2024). https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html
- Reference Sookman, B.B. (2024, February 19). Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot. McCarthy Tétrault TechLex blog https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot
The duty the ruling establishes is that an organization must take reasonable care that its chatbot's representations are accurate, because the chatbot is a tool it deploys rather than a separate entity that answers for itself. A hallucinated policy or a wrong rule stated by the bot is therefore the organization's own misrepresentation, and a posture that treats the AI as speaking only for itself does not transfer that responsibility away. The governable reading is that a customer-facing chatbot is a channel the organization is accountable for exactly as it is accountable for a page on its own website — so the accuracy control on what the bot states, and the ownership of what it says, are the organization's to build, not the bot's to carry.
empirical- Reference Sookman, B.B. (2024, February 19). Moffatt v. Air Canada: A Misrepresentation by an AI Chatbot. McCarthy Tétrault TechLex blog https://www.mccarthy.ca/en/insights/blogs/techlex/moffatt-v-air-canada-misrepresentation-ai-chatbot
- Government Moffatt v. Air Canada, 2024 BCCRT 149 (British Columbia Civil Resolution Tribunal, February 14, 2024). https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html
Where this connects
Institutional pressures in this domain
- Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
- Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
- Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
- Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
- Data & policy drift — The world, the intake process, and the rules change under a system trained on how things used to be — two mechanisms with different remedies: the statistical properties of what the system processes move (concept drift), or the mixture of inputs arriving in deployment differs from the mixture it was trained on (covariate shift).
All of them in context on the Customer service & contact-centre AI domain page.
Levers available here and the patterns behind them
- Gate record entries — Human-in-the-loop write gating
- Mark AI-written records — Provenance labeling
- Pause AI on alarms — Deployment circuit-breaker
- Review on schedule — Oversight cadence & retrospectives
- Check with a second model — Cross-model verification
- Escalate checks — State-feedback vigilance
- Upgrade model — Improve the model