Business Strategy

ACCC Consumer Law and AI for Australian Midsize

ACCC Consumer Law and AI for Australian Midsize

ACCC Consumer Law and AI for Australian Businesses

The Moffatt Precedent: Why an AI Agent's Words Bind the Business

In February 2024, the British Columbia Civil Resolution Tribunal handed down its decision in Moffatt v Air Canada (2024 BCCRT 149). Jake Moffatt asked the airline's website chatbot about bereavement fares, and the chatbot told him he could book a flight and apply for the discount within ninety days. That was not Air Canada's actual policy. When Air Canada refused the refund, Moffatt sued. The tribunal rejected the airline's argument that the chatbot was a "separate legal entity" and held the airline liable for the representations its automated agent had made.

The case was Canadian, the venue was a small claims tribunal, and the sum at stake was a few hundred dollars. None of that matters. The legal logic is the same logic an Australian court will apply under the Australian Consumer Law (ACL). A business is responsible for the representations made by its agents, whether those agents are human staff, third-party contractors, or a generative model running on someone else's GPUs. The Air Canada precedent has been widely cited internationally and it is the cleanest illustration available of where AI consumer-law liability actually sits.

This article is the legal companion to four earlier pieces in our AI-agents-for-Australian-businesses series. The build-time risks of DIY agents and the operating reality of agents in production both flagged ACL exposure as a top-tier concern. The staffing gap and vendor selection pieces noted that legal-and-compliance ownership of AI is often unclear inside the businesses deploying it. This piece answers the direct question: what is your actual legal exposure under the ACL when your AI agent makes representations to customers, and what is the safe-harbour pathway?

Thesis: every AI customer-facing system is a representation-making machine. Under the ACL it exposes the business to sections 18, 29, 60 to 62, and 64. The exposure is real, the regulator is active, and the controls a business needs are not exotic, but they do need to be in place before the agent talks to its first customer.


Part 1: Why the ACL Applies to AI Exactly the Way It Applies to Humans

The ACL (Schedule 2 of the Competition and Consumer Act 2010) is technology-neutral. The text does not say "by a human employee" anywhere. A representation in trade or commerce is a representation whether the speaker is a contact-centre agent, a salesperson, a marketing email, a printed brochure, or a large language model.

The ACCC has been explicit on this point. In its August 2024 statement on AI and the Australian Consumer Law, the regulator said that businesses using AI in their interactions with consumers remain fully responsible for compliance with the ACL, and that the law applies "regardless of the technology used". The ACCC's published Compliance and Enforcement Priorities include consumer and fair trading issues arising from manipulative or deceptive advertising and marketing practices, which the ACCC has explicitly tied to algorithmic and AI-driven conduct.

The four provisions a CIO, COO, or general counsel needs to be able to recite in their sleep:

Section 18 (misleading or deceptive conduct). A person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. There is no requirement of intent. A confidently wrong AI output is enough.

Section 29 (false or misleading representations). Prohibits false or misleading representations about the standard, quality, value, grade, composition, performance characteristics, or sponsorship of goods and services. Also covers price, place of origin, testimonials, and warranty terms. Pecuniary penalties for a body corporate are the greater of $50 million, three times the value of the benefit obtained, or 30 per cent of adjusted turnover during the breach period.

Sections 60 to 62 (consumer guarantees for services). Services must be supplied with due care and skill (s60), be reasonably fit for any disclosed purpose (s61), and be supplied within a reasonable time where no time is specified (s62). These guarantees attach to services supplied to a consumer, and when AI assists in delivering a service, the guarantees attach to that service.

Section 64 (non-excludable nature). Consumer guarantees cannot be excluded, restricted, or modified by contract. A terms-of-service clause that says "the chatbot's outputs are not binding" does not actually release the business from its s60 to 62 obligations to a consumer.

A brief note on directors' duties. Under sections 180 to 181 of the Corporations Act 2001, directors and officers have duties of care, diligence, and good faith. Foreseeable AI-amplified consumer-law risk is the kind of operational risk that a reasonable board is now expected to know about and govern. This is not a separate cause of action against directors in most AI-ACL scenarios, but it does mean "we didn't realise the chatbot could do that" is not a sustainable governance posture.


Part 2: The Four Representation Traps in AI Customer-Facing Systems

The pattern of failure is consistent. AI customer-facing systems get a business into ACL trouble in four predictable ways.

The Four Representation Traps

Metric
Common failure pattern
What good looks like
Improvement
Pricing (s18, s29)Agent confirms a price returned from a stale system, or is prompt-injected into accepting an absurd offer (the Chevrolet of Watsonville '$1 Tahoe' incident, December 2023, is the canonical example)Pricing answers are retrieved from a single source-of-truth API with a hard refusal pattern outside an authorised range, and material-value transactions require human confirmationACL s18, s29
Refund / warranty / return (s18, s29, s60)Agent invents or misstates the refund window, return conditions, or warranty coverage, as in Moffatt v Air CanadaThe agent retrieves the live published policy, quotes it verbatim, and refuses to extend or modify the policy without a human approverACL s18, s29, s60
Product capability or performance claims (s18, s29, s61)Agent affirms a use case the product does not actually support, or overstates compatibility, integrations, or compliance certificationsCapability answers are constrained to a curated knowledge base, and unsupported claims trigger a refusal or human handoverACL s18, s29, s61
Service delivery commitments (s18, s62)Agent promises an SLA, callback time, delivery date, or availability the business cannot meetTime commitments are computed against live capacity data, never asserted as guarantees the business has not signed off onACL s18, s62

The Chevrolet of Watsonville incident in December 2023 is worth knowing in detail because it shows how cheaply this goes wrong. A user prompt-injected the dealership's customer-service chatbot into "agreeing" to sell a 2024 Chevrolet Tahoe for one dollar and stating "no takesies backsies". The dealership did not honour the offer, and the legal consensus was that the dealer probably did not have to (offer and acceptance, capacity of the agent, etc.), but the reputational damage and the question of whether the dealership had to defend that position in court at all is exactly the kind of foreseeable risk an ACL exposure review should be picking up before the agent goes live.

The Moffatt case is the cleanest refund / warranty illustration because the tribunal explicitly rejected the "the AI is its own entity" defence. Australian businesses should assume an Australian court would do the same.


Part 3: How Liability Actually Flows

The chain from "customer asks the AI a question" to "ACCC infringement notice" is not long.

Representation Liability Flow Under the ACL

Customer query
Consumer interacts with the AI agent in trade or commerce
AI processes
Retrieval, generation, or both; output is shaped by training data, prompts, and tool calls
Representation made
The agent's output reaches the consumer as the business's statement
Customer reliance
Consumer acts on the representation: books, buys, claims, cancels
Enforceable representation
The output is treated as the business's representation under ACL s18, s29, s60-62
Exposure crystallises
ACCC complaint, infringement notice, civil action, class action, or AFCA referral if in regulated industry

Notice what is absent from the chain. There is no step where the AI vendor absorbs the liability. There is no step where a terms-of-service disclaimer breaks the chain. There is no step where "but it was a hallucination" reduces the obligation. The chain runs from the consumer through your agent to your business, and the ACL plugs in at step five whether you are ready for it or not.

For deeper coverage of how the production-operations side of this risk presents itself, see the operating AI agents in production companion piece in this series.


Part 4: Three Things Vendor Pitches Will Tell You That Are Wrong

When a business is evaluating an AI customer-service product, the vendor sales motion will reliably reach for three reassurances. All three are wrong in ways that matter.

Myth 1: "It is the AI vendor's responsibility, not yours." Wrong. The ACL attaches to the supplier in trade or commerce, which is the business deploying the agent, not the platform vendor. The ACCC's published position is that businesses using AI remain fully responsible for compliance. A vendor indemnity clause may give you a downstream commercial claim against the vendor, but it does not stop the ACCC from acting against you, and it does not bind the consumer who is suing you in QCAT, VCAT, NCAT, or the federal courts.

Myth 2: "Terms and conditions disclaim it." Partly wrong, dangerously so. Section 64 of the ACL makes consumer guarantees under s60 to 62 non-excludable. You cannot contract out of due care and skill. You cannot contract out of fitness for purpose. You can place reasonable scope-of-service descriptions in your terms, but you cannot use terms to override the consumer guarantees regime. The ACCC has published guidance on unfair contract terms that further constrains what disclaimers can do.

Myth 3: "It is just a chatbot, not a representation." Wrong, and the Moffatt decision is the cleanest counter. Courts and tribunals are treating agent output as company output. The character set, the speaker, and the deployment surface are immaterial; what matters is whether a reasonable consumer would treat the output as a statement of the business. They do.

The vendor evaluation framework in our AI vendor selection questions piece includes a specific section on getting these myths out of the room during procurement. The legal-and-compliance signoff cannot be deferred to "we will sort it out after the pilot".


Part 5: The Safe-Harbour Pathway

There is no formal safe harbour under the ACL for AI-mediated representations. There is, however, a stack of controls that materially reduces exposure and creates an evidentiary record a regulator, a court, or a tribunal can review favourably. Implementation cost is given as a directional estimate for an Australian business building this stack for a first customer-facing deployment.

Safe-Harbour Control Stack (Pre-Deployment Through Steady State)

1
Pre-deployment
Legal scope review
External counsel or experienced internal GC maps every category of representation the agent is authorised to make. Output is a written scope-of-authority document. Typical cost: $8k to $20k for a focused review.
2
Pre-deployment
Guardrails and refusal patterns
System prompts, refusal patterns for out-of-scope queries, escalation triggers for high-value or high-risk interactions. Built into the agent before any customer traffic. Typical cost: included in build effort, 1 to 3 weeks of senior engineering time.
3
Pre-deployment
Full-content logging and retention
Every customer interaction logged with prompt, output, timestamp, user identifier, and model version. Retained for the longer of warranty period plus limitations period, or relevant record-keeping rules. ATO record-keeping minimums of 5 years apply where transactions are involved.
4
Pre-deployment
Human-in-the-loop for material commitments
Refunds above a threshold (commonly $500 to $2,000 for midsize retailers), pricing exceptions, warranty extensions, SLA promises: all routed to a human approver before the customer hears yes.
5
Go-live
AI-interaction disclosure
Customer is told they are interacting with an AI, in plain language, at the start of the interaction. Aligns with OAIC and emerging international guidance and with the December 2026 commencement of automated decision-making transparency rules under the Privacy and Other Legislation Amendment Act 2024.
6
Steady state
Incident response runbook
Documented path for triaging an AI-generated misleading representation: containment, customer remediation, internal escalation, ACCC notification posture for systemic issues, board reporting.
7
Steady state
PI / management liability insurance review
Confirm in writing that the existing professional indemnity, cyber, and management liability policies cover AI-amplified ACL exposure. Many policies have AI exclusions or sub-limits introduced in 2024 to 2025 renewals.

The transparency requirement is worth a separate note. The Privacy and Other Legislation Amendment Act 2024 introduces automated decision-making transparency obligations that commence on 10 December 2026. If your organisation uses automated decision-making that could reasonably be expected to significantly affect an individual's rights or interests, the privacy policy must disclose that fact, including the types of personal information used and how an individual can request human review. The OAIC's guidance on privacy and AI extends the disclosure expectation further. Maximum penalties for a serious interference with privacy now reach $50 million for body corporates under the 2022 amendments. Disclosure is cheap. Failure to disclose is not.

For broader coverage of the privacy and governance overlay, see our AI agent governance, data access, privacy, and human override piece, and the data sovereignty guide for the underlying data-location and cross-border concerns.


Part 6: What Exposure Level Is Your Deployment?

Not every AI deployment carries the same exposure. The distinguishing factors are direct customer interaction, the kind of representations the agent can make, whether a human is in the loop for material commitments, and whether the deployment has been signed off at the right level.

ACL Exposure Level of Your AI Deployment

What controls are in place on your customer-facing AI?
AI is internal-only, no direct customer contact, outputs reviewed by staff before any customer communication
→ Low exposure: standard governance controls and accuracy monitoring are sufficient
AI talks directly to customers, but only on narrow informational topics (e.g. opening hours, store locations), no pricing or refund authority, with human escalation at every turn
→ Low-to-medium exposure: ensure logging, disclosure, and escalation paths are working
AI talks directly to customers and can quote pricing, policies, or product capabilities, with logging and disclosure in place, but no formal pre-deployment legal scope review
→ Medium exposure: commission a scope-of-authority review before further rollout, tighten refusal patterns on s29 categories
AI talks directly to customers, can commit the business to refunds, pricing, or SLAs without human review, full logging not in place, no written board or exec sign-off
→ High exposure: pause customer-facing operation, install human-in-the-loop on material commitments, complete legal scope review and logging before resuming
AI operates in a regulated sector (financial services, health, legal services, energy retail) with direct customer interaction
→ High exposure regardless of other controls: regulator-specific obligations stack on top of the ACL, requires sector-specific compliance review (ASIC, AHPRA, TGA, AER as applicable)

The high-exposure outputs are not rare. A common pattern is that an operations team or a marketing team has stood up an AI tool quickly, the legal-and-compliance function has not been consulted, and the deployment is making representations the business is not aware of. This is the scenario article one of this series flagged as the most expensive failure mode of DIY AI deployment.


Part 7: Pre-Launch Compliance Readiness Checklist

A general counsel, CIO, or compliance lead should be able to answer all of these before a customer-facing AI deployment goes live. If the answer to any of them is "I do not know", that question is your next two weeks of work.

  1. Authorised representations. Have we documented every category of representation the AI is authorised to make, and every category it must refuse?
  2. Logging. Where do we log every AI input and output, what is the retention period, and who in the business can retrieve a specific interaction within four hours of a customer complaint?
  3. Change control. Who internally signs off on a new system prompt, a new RAG source, or a model upgrade, and is there a written change log?
  4. Customer disclosure. What is the customer-facing disclosure that they are interacting with an AI, where does it appear, and has it been reviewed against current OAIC guidance?
  5. ACL mapping. Have we mapped every AI customer touchpoint to relevant ACL sections (s18, s29, s60 to s62) and identified the failure modes?
  6. Human-in-the-loop thresholds. Above what dollar value or risk category does a representation require human approval before reaching the customer?
  7. Out-of-scope handling. When the AI receives a query outside its scope, does it refuse, hand over, or guess? Can we evidence that behaviour with test cases?
  8. ACCC notification path. If a deployed agent generates a misleading representation that reaches multiple customers, what is our notification posture, who decides, and who has authority to communicate with the ACCC?
  9. Insurance coverage. Have we confirmed in writing that PI, cyber, and management liability policies cover AI-amplified ACL exposure, including hallucinated representations?
  10. Vendor liability allocation. Does our agreement with the AI platform vendor allocate liability for misleading outputs in a way that survives Section 64 and is commercially meaningful?
  11. Sector-specific obligations. If we operate in a regulated sector, have we consulted the relevant regulator's published AI guidance (ASIC for financial services, AHPRA for health practitioners, TGA for therapeutic goods, AER for energy retail)?
  12. Board reporting. Is AI deployment risk being reported to the board or executive committee on a defined cadence, with the right metrics?

A useful internal litmus test: take the most senior non-technical person in the business, sit them in front of the agent, ask them to try to break it, and watch what happens. If they can produce a representation the business would be unhappy to honour, the deployment is not ready.

For the operations rhythm that keeps this discipline alive after launch, see the production reality and staffing gap pieces. For the procurement-side controls, see AI vendor selection questions. For the upstream data-leakage exposure that often coexists with consumer-law exposure, see wrong AI tools leak business data.


What Solve8 Can Help With

The pattern we keep seeing in Australian businesses is that the legal, technical, and operational sides of AI deployment have not been brought into the same room. A vendor pitch is moving forward. A pilot is live in one department. The privacy policy has not been updated. The agent's scope of authority has not been written down. And the GC has not been asked.

Our consulting work in AI strategy and managed AI services is built around bringing those threads together. The technical capability comes from real product work, including the on-premise investigation product RootCauseAI and the ESG automation platform Carbonly, both of which had to think about regulated-environment representations and audit-grade logging from day one.

If a customer-facing AI deployment is on your roadmap for the next two quarters, the cheapest possible investment is a pre-launch ACL exposure review. The most expensive position is the one where the ACCC contacts you first.

Book a 30-minute pre-launch ACL exposure review

In thirty minutes we can map your customer-facing AI touchpoints to the relevant ACL sections, identify the two or three highest-exposure failure modes, and tell you what would need to change before launch. No vendor pitch, no obligation.


Related Reading:


Sources:

Citations: Moffatt v Air Canada [2024] BCCRT 149 (British Columbia Civil Resolution Tribunal, February 2024). Competition and Consumer Act 2010 (Cth), Schedule 2 (the Australian Consumer Law), sections 18, 29, 60-62, 64. ACCC, Compliance and Enforcement Priorities (current edition, accc.gov.au). ACCC statement on emerging technologies and the ACL (August 2024). OAIC, Guidance on privacy and the use of commercially available AI products (October 2024, updated 2025). Privacy and Other Legislation Amendment Act 2024 (Cth), automated decision-making provisions, commencement 10 December 2026. Corporations Act 2001 (Cth), sections 180-181. Chevrolet of Watsonville chatbot incident, December 2023 (widely reported, including AFR coverage).