- Why the law looks at your business before it looks at the software
- Four different kinds of "legal responsibility"
- When a wrong AI answer becomes a consumer law problem
- When an AI mistake becomes a privacy problem
- When an AI decision becomes a discrimination problem
- What about the software provider? The second conversation
- If something has already gone wrong, start by naming the problem
- What to put in place before the next mistake
- How a lawyer helps you work out where the liability lands
- The software changes, the obligation does not
Your business puts a chatbot on its website so customers can get answers after hours. One evening it tells a customer they have no right to a refund, when Australian consumer law gives them one. Or a staff member pastes a client list into a free AI writing tool, and that data ends up somewhere it should not have gone. Or an AI screening tool quietly filters out job applicants on a basis nobody intended. The question in each case is the same: who is legally responsible for what the AI just did? The short answer is that the law usually looks first at your business, then at what your business did with the tool, and only later at the software provider.
Why the law looks at your business before it looks at the software
The simplest reason is also the most important. The customer dealt with your business, not with the AI provider. If a chatbot makes a false statement about your refund policy, the customer was misled by your business, because the chatbot was speaking on your behalf. "The software made the mistake" may explain what happened. It does not usually end the legal analysis.
Australian regulators take the same approach. They do not treat AI as a separate legal actor. They treat it as part of your business's systems, governance and conduct. The Office of the Australian Information Commissioner (OAIC) states in its guidance on commercially available AI products that the Privacy Act applies to all uses of AI involving personal information. The ACCC applies the misleading conduct provisions of the Australian Consumer Law (Cth) to AI-generated statements just as it would to any other statement made in trade or commerce. ASIC made the same point for financial services in Report 798, Beware the gap: governance arrangements in the face of AI innovation, released in October 2024 after reviewing how 23 licensed firms were using AI. ASIC warned of a governance gap where AI adoption runs ahead of risk controls and oversight.
That does not mean your business is automatically liable every time an AI output is wrong. It means your business is the first place the law looks, and the analysis starts with what your business did: what it represented to customers, what data it handled, and what decisions it made.
Four different kinds of "legal responsibility"
Much of the confusion about AI liability comes from the fact that "legally responsible" means several different things. There is no single rule that decides who pays when AI gets something wrong. Instead, there are at least four separate conversations, and an incident can trigger more than one of them:
- Customer dispute: a refund demand, a complaint, or a claim that goods or services did not meet the consumer guarantees.
- Regulatory exposure: scrutiny or enforcement by a regulator such as the ACCC, the OAIC or ASIC over the business's conduct.
- Privacy incident: an obligation to assess whether personal information was mishandled, and possibly to notify the OAIC and affected individuals.
- Contractual recourse: a separate fight with the software provider over who bears the loss internally.
Whether any of these bite depends on the facts, the harm caused, and which legal framework is engaged. A clumsy or inaccurate chatbot answer might be a service issue with no real legal consequence. The position changes when the output causes financial loss, affects a person's legal rights, involves personal information, or contributes to an unfair outcome. The practical question for a business is not "is AI liable?" but "which of these frameworks has been triggered?"
When a wrong AI answer becomes a consumer law problem
The clearest example is customer-facing information. Under section 18 of the Australian Consumer Law (the ACL), which is Schedule 2 of the Competition and Consumer Act 2010 (Cth), a person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. Section 18 does not require intention. A chatbot that tells a customer they have no right to a refund, when they do, can breach it even though nobody deliberately set out to mislead anyone.
Section 29 of the ACL goes further. It prohibits false or misleading representations about goods or services, including representations about price, quality, the availability of repair facilities, and the existence or effect of any right or remedy, including a consumer guarantee. AI-generated content that misstates pricing, service inclusions, cancellation rights, delivery timeframes, subscription terms or product features can all fall within it.
The consumer guarantees also survive whatever the AI says. Goods supplied to a consumer must be of acceptable quality under section 54 of the ACL, and services must be reasonably fit for the purpose the consumer made known under section 61. The ACCC explains that businesses can be investigated for misleading consumers about their consumer guarantee rights, and that consumers can seek a repair, replacement, refund or cancellation when a guarantee is not met. Once AI speaks on behalf of your business, the question becomes whether your business can stand behind the representation.
When an AI mistake becomes a privacy problem
Privacy is the second major pressure point, and it is the one small businesses most often underestimate. The OAIC's guidance, published in October 2024, makes three points that matter here.
First, privacy obligations apply to personal information entered into an AI system and to the output the AI generates, where that output contains personal information. That includes information the AI invents. The OAIC's guidance notes that inferred, incorrect or artificially generated information about an identified or reasonably identifiable individual, including hallucinations and deepfakes, is personal information that must be handled under the Australian Privacy Principles.
Second, the principles that commonly bite are accuracy, security and use. Under Australian Privacy Principle 10 an APP entity must take reasonable steps to ensure the personal information it collects, uses and discloses is accurate, up to date, complete and relevant. That obligation matters when a probabilistic AI tool is known to produce plausible but wrong answers. Under Australian Privacy Principle 11 the entity must take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. And under Australian Privacy Principle 6, personal information collected for one purpose generally cannot be used for an unrelated purpose, which is why the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools.
Third, there is an important threshold that many articles on AI and privacy gloss over. The Privacy Act's protections bind APP entities, and section 6D of the Privacy Act 1988 (Cth) exempts genuine small businesses. A business whose annual turnover was $3 million or less in the previous financial year is generally outside the Australian Privacy Principles, unless an exception applies, for example if it provides health services and holds health information, trades in personal information, or acts as a contracted service provider for a Commonwealth contract. So a very small business using a chatbot may not be caught by the Privacy Act at all. But that exemption has limits, and state privacy laws, industry codes and contractual duties can still apply.
Where the Act does apply, an AI-related incident can trigger the notifiable data breach scheme in Part IIIC. If personal information held by an APP entity is subject to unauthorised access, unauthorised disclosure or loss, and that is likely to result in serious harm to affected individuals, it is an eligible data breach. The entity must carry out a reasonable and expeditious assessment, with all reasonable steps taken to complete it within 30 days of becoming aware of reasonable grounds to suspect a breach, and must notify the OAIC and affected individuals as soon as practicable. The consequences of getting this wrong are not trivial. For a serious interference with privacy, a court can order a corporation to pay the greater of $50 million, three times the value of the benefit obtained, or 30 per cent of adjusted turnover.
When an AI decision becomes a discrimination problem
Some AI risks are less obvious because they live in the decision rather than the statement. AI used to screen applicants, rank customers, triage complaints, detect fraud or assess eligibility for a service can produce unfair outcomes even when no individual output is "wrong" in a factual sense.
The Australian Human Rights Commission has repeatedly warned about this. Its technical paper Using artificial intelligence to make decisions: addressing the problem of algorithmic bias set out how AI systems trained on existing data can reproduce and entrench bias, and its September 2025 thematic report on AI and racial discrimination examined how AI can reinforce discriminatory outcomes. Where an AI-assisted decision affects who gets a job, a loan, insurance or a service, it can engage Commonwealth and state anti-discrimination protections, and for current employees, potentially the adverse action protections in workplace law.
For a small business the practical implication is that the risk is not only in what the AI says but in what the AI does. The more a tool influences a real-world decision about a person, the more important human review, transparency and proper oversight become. The Australian Government has also consulted on mandatory guardrails for high-risk AI, and while those proposals are not yet law, they signal the direction of travel.
What about the software provider? The second conversation
None of this means the vendor is off the hook. It means the vendor's role is usually the second question, not the first.
From the customer's point of view, the relevant relationship is with your business. From your point of view, the next question is whether your contract with the AI provider gives you any recourse. That is where liability caps, warranties, indemnities, data-use clauses, service levels and exclusions start to matter. Many standard software and AI terms are drafted to protect the provider. They often limit what the provider promises, cap liability heavily, and push responsibility for reviewing outputs back onto the business using the tool.
So there are two different liability conversations happening at once. One is external, between your business and the customer or regulator. The other is internal, between your business and the vendor. Confusing those two conversations is one of the easiest ways to misunderstand AI risk, because the contract that protects you from the vendor does nothing to protect you from the customer, and vice versa.
If something has already gone wrong, start by naming the problem
When an AI-related problem has already happened, the first step is to work out which kind of legal issue it actually is. Three questions usually narrow it down:
- Was a customer misled about their rights, the price, or the service being provided?
- Was personal information entered into a system, or disclosed, in a way that creates privacy risk?
- Did the AI output affect a hiring, service-access, compliance or other decision about a person?
Once the problem is characterised, the response becomes practical. The business may need to correct the statement, review its complaint handling, check whether a consumer remedy is available, and examine the supplier contract for recourse against the vendor. Where personal information is involved, an APP entity may need to start a breach assessment immediately, because the 30-day assessment clock in the notifiable data breach scheme starts running as soon as the business becomes aware there are reasonable grounds to suspect a breach. It is also worth preserving the prompts, outputs and decision records from the AI tool, because they may be needed to reconstruct what happened.
What to put in place before the next mistake
The more useful legal work happens before the incident, and most of it is ordinary housekeeping that AI has made urgent:
- Privacy documentation: update the privacy policy and collection notices so they disclose how AI is used, and make sure any public-facing chatbot is clearly identified as AI, as the OAIC's guidance expects.
- Customer terms: check that website terms and conditions reflect the reality that customer interactions may be AI-assisted, and do not promise human review that does not exist.
- Staff rules: put in place an internal AI use policy that says what staff can and cannot enter into AI tools, reflecting the OAIC's recommendation against entering personal information into publicly available generative AI products.
- Supplier agreements: review the terms with AI vendors for warranties, liability caps, data handling and indemnities, rather than accepting a click-through agreement.
- Human oversight: identify the higher-risk workflows, such as customer-facing advice, recruitment or eligibility decisions, where a human needs to review the AI output before it takes effect.
The OAIC's guidance also encourages due diligence before adopting an AI product, including whether it has been tested for the intended use, how human oversight will be embedded, and who will have access to any personal information. For higher-risk uses a privacy impact assessment is the standard tool.
How a lawyer helps you work out where the liability lands
An article can set out the frameworks, but it cannot tell you which one has been triggered in your particular situation. That is a judgement call that depends on the facts of the incident, the documents you have in place, and the wording of your supplier contract. That is where a lawyer earns their fee.
A lawyer can characterise an incident and identify the obligations that have actually been triggered, including whether a notifiable data breach assessment is required and when the clock started. They can review and, where possible, renegotiate supplier terms so the vendor bears an appropriate share of risk. They can draft an internal AI use policy and update privacy documentation so they match how the business actually operates. And where an incident has already occurred, they can manage the response, including contact with regulators, so the business does not make the position worse. Artificer Legal can help with all of that, whether you are choosing an AI tool, reviewing the contracts around it, or responding to something that has already gone wrong.
The software changes, the obligation does not
The biggest misconception about AI in business is that using a sophisticated tool shifts legal responsibility somewhere else. Often the opposite is true. The more a business relies on AI in communication, data handling and decision-making, the more existing legal obligations are engaged, and the more the law looks at the business that chose to deploy the tool. AI does not create a new legal universe. It funnels existing obligations, under consumer law, privacy law and anti-discrimination law, through a new channel, and it does so at speed and at scale.
The practical takeaway for a business owner is simple. If your business is using AI, the legal question is not whether the tool works. It is whether your contracts, privacy documents, staff rules and oversight processes are ready for what happens when it does not. If a customer was misled, the customer's rights do not depend on whether the misleading statement came from a human or a machine. If personal information leaked, the question is not where the leak happened but what obligations were triggered when it did. And if an AI decision affected a person, the fairness of the decision is judged by the same standards as any other decision. The tool changes. The obligation does not, and it will usually be your business that answers for it.