Skip to main content

OpenLegal

Articles > Startups

Can Businesses be Sued for AI Mistakes?

August 19, 2026  

Artificial Intelligence (“AI”) is increasingly being used in business to improve productivity and efficiency through automated decision-making, document drafting and content generation. However, businesses may still be held legally responsible for harm caused by AI-generated mistakes, including financial loss, reputational harm or other damage. While AI platforms are continually improving, businesses should not rely on them without proper oversight. Under Australian law, existing legal principles can allow individuals and other entities to bring claims against businesses for AI-related harm, even though AI itself is not recognised as a legal person.

Artificial Intelligence: Business Applications, Benefits and Risks

AI refers to computer systems that can perform tasks that would usually require human intelligence, such as analysing information, recognising patterns and making decisions. Businesses are progressively using AI to reduce costs, improve efficiency and automate repetitive tasks. Generative AI tools such as ChatGPT, Claude and Gemini can generate content and assist with tasks including document drafting, research and data analysis. It is steadily becoming more common for AI to be used to provide customer service through chatbots that can respond to routine enquiries without human intervention, allowing constant availability for clients. AI may also assist in summarising documents and generating marketing content, helping employees to complete tasks more quickly and efficiently.

However, greater reliance on AI also creates risks for businesses. AI systems can produce inaccurate or misleading information that appears credible, sometimes referred to as “hallucinations”. Businesses may also face privacy and confidentiality risks when sensitive information is entered into AI systems without appropriate safeguards, leaving the company vulnerableto data breaches and privacy concerns. These risks highlight the importance of proper oversight when corporations use AI and the need to consider how AI-generated outputs are reviewed and relied upon.

Can Corporations be Sued?

Under Australian law, companies are considered separate legal entities from their shareholders and directors and therefore have the ability to sue or be sued in their own name. This principle is established in section 124 of the Corporations Act 2001 (Cth) providing companies with the legal capacity and powers of an individual, enabling it to commence legal proceedings and to be the subject of legal proceedings. AI systems, however, are not currently recognised as legal persons under Australian law and therefore cannot themselves be sued.

Existing Causes of Action

Misleading or Deceptive Conduct

Under the Australian Consumer Law (“ACL”), businesses may face liability where AI-generated content is misleading or deceptive. Section 18 of the ACL prohibits corporations from engaging in conduct that is misleading or deceptive, or likely to mislead or deceive. Importantly, it does not matter whether the business intended to mislead – the focus is on the effect of the conduct. A common example is where an AI chatbot provides customers with incorrect information about its products or services, or if AI-generated advertising contains false claims.

Businesses should also be careful about how they represent and market their use of AI. “AI-washing” occurs when corporations understate or exaggerate the role AI plays in their products, services or operations. While Australian courts have not yet specifically considered AI-washing, similar principles have been applied to “greenwashing”, where businesses make misleading claims about their environmental practices. Companies should therefore ensure that claims about their use of AI are accurate and can be substantiated.

Negligence

Businesses may be liable for negligence where they fail to take reasonable care and this causes foreseeable harm. Depending on the circumstances, a corporation may owe a duty of care to those who could reasonably be affected by its conduct. In the context of AI, this could include properly supervising AI systems and verifying the accuracy of any AI-generated information, particularly where an error could reasonably cause harm.

For example, a business may be negligent if it provides AI-generated advice to a customer without appropriate review and the customer relies on incorrect information to their detriment. Similarly, continuing to use an AI system despite known problems may indicate that the business failed to take reasonable precautions against a foreseeable risk of harm. Any negligence claim would arise from the business’s failure to implement appropriate safeguards and oversight, rather than from the AI system itself.

Privacy and Confidentiality

Corporations that use AI must also consider their obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”). These duties generally require businesses to be transparent about how personal information is collected, used and disclosed, only collect and use information where permitted, and take reasonable steps to protect it from misuse, unauthorised access or disclosure. It is the responsibility of these companies to conduct appropriate due diligence before using an AI platform and consider its privacy settings, data handling practices and contractual terms.

Businesses can also reduce privacy risks by investigating AI vendors, implementing internal policies for handling personal information and using appropriate contractual protections with AI providers. Failure to comply with privacy obligations may result in investigation or regulatory action by the Office of the Australian Information Commissioner (“OAIC”), as well as potential civil penalties.

Conclusion

AI is transforming the corporate landscape, providing various benefits to businesses, including increased productivity and reduced costs. However, it also creates significant legal risks when its outputs are not properly reviewed. Companies should be aware of the consequences resulting from unsupervised AI use and implement appropriate safeguards, policies and staff training to manage these risks and protect their customers and reputation.