There is no universal rule assigning every AI error to either the provider or the customer. Responsibility depends on the parties’ roles, the promises made, the cause of the problem, the use of the output, the applicable law, and the available remedies. An organization may face consequences toward its own customers even when its recovery from an AI supplier is limited.
For leaders, the relevant question is how a wrong result moves through the business. Does it remain an internal draft, reach a customer as advice, trigger a transaction, or become part of a service the organization has agreed to deliver? Each path creates a different set of commitments.
The error is only the beginning of the analysis
Generative AI can produce plausible statements that are false. NIST describes this as a confabulation risk in its Generative AI Profile.1 But an organization’s exposure depends on more than the existence of a wrong answer.
Consider a hypothetical technology provider whose AI-assisted support service tells a customer to delete a directory that contains important records. A customer employee follows the instruction, and the business incurs restoration costs and interruption.
The immediate questions concern the instruction, the information available to the system, the provider’s service commitments, and the customer’s actions. There may be issues involving the model, the integration, the source material, the delivery process, or several of them together. Calling the event an “AI hallucination” does not resolve those questions.
Nor does an error establish liability by itself. A claim still depends on the relevant legal requirements and facts. The organization’s practical costs, however, can begin well before responsibility is resolved.
The promise to the customer may be broader than the supplier’s promise
A business selling an AI-enabled service may promise expertise, a defined result, or a level of care. Its supplier may provide access to a general-purpose model subject to substantial limitations. Those two arrangements need to be evaluated together.
If the business promises that its customer can rely on a recommendation, it cannot assume that the underlying provider has made the same commitment. The supplier may expect the customer to evaluate outputs, restrict certain uses, or accept that results can be inaccurate.
This gap is especially consequential for service providers that incorporate several technologies into one offering. The client buys the provider’s service, while the provider obtains a collection of components. The provider’s responsibility toward the client and its recourse against each supplier are separate questions.
A gap may be commercially acceptable when the provider understands it and has designed, priced, and supported the service accordingly. An unseen gap can undermine the economics of an otherwise attractive offering.
Availability and accuracy are different commitments
An application can be available and responsive while producing an incorrect result. A service-level commitment about uptime or response speed therefore may offer little protection against the loss the organization is concerned about.
Even an accuracy claim needs context. Performance on a defined test may not establish how the service performs with different information, unusual cases, or the organization’s intended use. A broad percentage can conceal the distinction between an inconsequential mistake and a rare error with substantial consequences.
The FTC’s 2025 Workado matter illustrates the scrutiny performance claims can receive. The agency alleged that claims about an AI-content detector’s accuracy were false, misleading, or unsubstantiated.2 That allegation does not establish a universal accuracy standard for AI products. It shows why a business needs a supportable basis for what it says its own service can do.
For a buyer, the corresponding issue is the commitment actually made in the agreement. A compelling demonstration and a contractual promise can answer different questions.
A remedy can exist and still leave a substantial loss
Contract terms operate together. A warranty may describe expected performance, a remedy may limit the response to correction or re-performance, and a liability provision may restrict the amount or categories of recoverable damages. The result depends on the language and applicable law.
A credit against a future bill may have limited value to an organization facing restoration costs, a customer dispute, or replacement work. A right to terminate can stop future charges while leaving the organization responsible for an expensive transition.
Indemnity requires equally careful analysis. An obligation addressing third-party intellectual-property claims does not necessarily address inaccurate output, loss of customer data, or a failure to deliver a promised service. The existence of an indemnity clause says little without its scope, exclusions, and relationship to other limits.
There is no universally correct liability cap for AI services. The appropriate bargain depends on the service, control over the exposure, available alternatives, economic value, and the parties’ capacity to bear loss. Counsel’s role includes making the practical effect of that bargain clear before the organization relies on it.
Human review has to be assessed in context
Meaningful review can prevent a wrong output from becoming a harmful action. Its significance depends on what the reviewer could reasonably identify and do in the particular setting. A qualified person reviewing a source-supported recommendation is in a different position from an employee expected to approve unfamiliar material immediately.
The contract may also make certain review practices relevant to the parties’ rights. A failure to follow an agreed process can become part of a dispute. Conversely, the presence of a reviewer does not automatically excuse a supplier from its own commitments.
Private agreements can allocate responsibility between their parties. They do not, by themselves, determine the rights of an affected customer, employee, regulator, or other person outside that agreement. Whether a particular limitation or allocation is enforceable requires its own analysis.
This is why the business process and the contract belong in the same discussion. A paper requirement for review should reflect work that the service can actually support.
Response costs and recovery prospects belong in the business case
When an error causes a problem, the organization may need to correct records, contact affected people, restore operations, and investigate what happened. Those needs can arise before it has a clear claim against anyone else.
Access to relevant records and cooperation from suppliers can affect that response. So can the ability to stop the affected function without disabling the entire service. An organization that depends on a vendor for the explanation of a failure also depends on that relationship when deciding what it can accurately tell others.
Insurance may contribute to recovery, but coverage turns on the policy and the facts. It should not be assumed from a product label or a supplier’s statement that it carries insurance. Contractual remedies, insurance, practical collection, and the organization’s own financial capacity each address a different part of the exposure.
The objective is a service the organization can stand behind
AI can support a valuable offering without eliminating the possibility of error. The business decision is whether the service’s benefits, limitations, supervision, and legal commitments form an arrangement the organization can sustain.
Org Law helps providers and organizational users connect AI contracting with customer commitments, supplier terms, and the intended use. A focused AI Contract & Use Review can make the remaining exposure visible before a purchase or launch.
Read the Technology, AI, and Data Risk guide for the wider picture, or the companion article on AI governance decisions for how authority and oversight affect the operating model.
Sources
- NIST AI 600-1, Generative Artificial Intelligence Profile (July 2024), § 2.2. The technical risk does not itself determine legal liability.
- FTC, Workado AI-detection claims matter (April 2025). The discussion identifies the agency’s allegations and does not treat the matter as a general allocation of AI liability.