AI can help businesses save time and reduce costs, but tools such as ChatGPT and specialised AI systems also introduce risks, particularly when their output is inaccurate or goes unchecked.

It has never been easier to access AI tools or develop your own. While the technology may be new, many of the underlying risks are familiar. These include intellectual property infringement, incorrect advice, privacy breaches caused by inadequate safeguards, and operational errors that are not identified or corrected.

What makes AI different is the speed and scale at which an error can spread. A person might make several processing mistakes before the problem is detected. An AI system without appropriate oversight could repeat the same mistake across hundreds or thousands of transactions.

For business owners, the important point is that using AI does not remove the business’s responsibilities to its customers, suppliers or regulators. The business may still be responsible when an AI tool is involved.

The law does not give AI a free pass

The Australian Consumer Law prohibits misleading or deceptive conduct and false or misleading representations. These obligations apply to information a business provides through its website and other communication channels, including information generated by an AI chatbot.

A widely reported Canadian case illustrates how this can play out. Air Canada’s customer service chatbot gave a passenger incorrect information about bereavement fares. In 2024, the British Columbia Civil Resolution Tribunal found that the airline was responsible for information provided through its website and ordered it to compensate the passenger. While the decision does not establish Australian law, it demonstrates the potential consequences of allowing unchecked AI-generated information to reach customers.

Where the risks can arise

The exposure is not limited to chatbots. A few common examples:

  • Customer-facing chatbots providing incorrect prices, terms or information, potentially misleading customers and exposing the business to claims.
  • Marketing and social content misrepresenting a product or suggesting a human endorsement that does not exist.
  • Paperwork and order processing containing incorrect prices, customer details or payment instructions.
  • Governance and reporting relying on inaccurate or incomplete AI-generated information. Directors and officers remain responsible for meeting their legal and regulatory obligations.

If something goes wrong, who pays?

Business owners may assume that the developer or technology provider will be responsible if an AI tool fails. However, liability will often depend on the contract between the parties. These contracts may limit the supplier’s liability and place responsibility for checking and using the output on the customer.

Managing the risk

  • Keep a person involved. Review AI-generated content before it reaches customers, particularly information relating to pricing, advice, policy terms or product claims.
  • Check the contract terms. Understand how liability is allocated and what remedies are available if the tool fails.
  • Protect confidential information. Avoid entering personal, commercially sensitive or protected information into public AI tools without appropriate safeguards.
  • Document your oversight. Record how AI output is reviewed, who is responsible and how errors are identified and addressed.
  • Review your insurance. AI-related exposures may cross several traditional policy categories, so it is important to understand which policies may respond.

Where insurance fits

AI is still an emerging area for insurers. Business owners should tell their insurance adviser how they use AI and discuss whether the use of this technology affects their risk profile or disclosure obligations. Depending on the circumstances and policy wording, relevant cover may include:

  • Cyber insurance, which generally focuses on incidents such as data breaches, privacy events and network attacks. It may not cover losses caused solely by an inaccurate AI-generated decision.
  • Professional indemnity insurance, which may respond when incorrect professional advice or an alleged infringement of intellectual property rights causes a third party financial loss. Coverage will depend on the nature of the claim and the policy wording.
  • Management liability insurance, which may be relevant when directors or officers face claims or regulatory action arising from alleged governance failures.
  • Crime or cyber insurance, which may be relevant to fraudulent payment instructions or funds transferred to an incorrect account, depending on the circumstances and policy wording.

Talk to your insurance adviser

If your business uses ChatGPT or other AI tools, it is worth understanding where your legal and financial exposures sit and confirming that your current insurance remains appropriate. Speak with your Insurance Advisernet Adviser, who can review how your business uses AI and recommend cover suited to your needs and budget.

Contact Lewis Insurance Services on 07 3217 9015 or send us an email by clicking here.

General advice warning: The information provided is general advice only. You should consider whether it is appropriate for your objectives, financial situation and needs before acting on it. You should obtain and consider the relevant Product Disclosure Statement before making any decision to purchase a financial product.

This article was published by our AFSL Licensee, Insurance Advisernet Australia P/L, www.insuranceadviser.net