ACCC Consumer Law and AI for Australian Midsize

The Moffatt Precedent: Why an AI Agent's Words Bind the Business
In February 2024, the British Columbia Civil Resolution Tribunal handed down its decision in Moffatt v Air Canada (2024 BCCRT 149). Jake Moffatt asked the airline's website chatbot about bereavement fares, and the chatbot told him he could book a flight and apply for the discount within ninety days. That was not Air Canada's actual policy. When Air Canada refused the refund, Moffatt sued. The tribunal rejected the airline's argument that the chatbot was a "separate legal entity" and held the airline liable for the representations its automated agent had made.
The case was Canadian, the venue was a small claims tribunal, and the sum at stake was a few hundred dollars. None of that matters. The legal logic is the same logic an Australian court will apply under the Australian Consumer Law (ACL). A business is responsible for the representations made by its agents, whether those agents are human staff, third-party contractors, or a generative model running on someone else's GPUs. The Air Canada precedent has been widely cited internationally and it is the cleanest illustration available of where AI consumer-law liability actually sits.
This article is the legal companion to four earlier pieces in our AI-agents-for-Australian-businesses series. The build-time risks of DIY agents and the operating reality of agents in production both flagged ACL exposure as a top-tier concern. The staffing gap and vendor selection pieces noted that legal-and-compliance ownership of AI is often unclear inside the businesses deploying it. This piece answers the direct question: what is your actual legal exposure under the ACL when your AI agent makes representations to customers, and what is the safe-harbour pathway?
Thesis: every AI customer-facing system is a representation-making machine. Under the ACL it exposes the business to sections 18, 29, 60 to 62, and 64. The exposure is real, the regulator is active, and the controls a business needs are not exotic, but they do need to be in place before the agent talks to its first customer.
Part 1: Why the ACL Applies to AI Exactly the Way It Applies to Humans
The ACL (Schedule 2 of the Competition and Consumer Act 2010) is technology-neutral. The text does not say "by a human employee" anywhere. A representation in trade or commerce is a representation whether the speaker is a contact-centre agent, a salesperson, a marketing email, a printed brochure, or a large language model.
The ACCC has been explicit on this point. In its August 2024 statement on AI and the Australian Consumer Law, the regulator said that businesses using AI in their interactions with consumers remain fully responsible for compliance with the ACL, and that the law applies "regardless of the technology used". The ACCC's published Compliance and Enforcement Priorities include consumer and fair trading issues arising from manipulative or deceptive advertising and marketing practices, which the ACCC has explicitly tied to algorithmic and AI-driven conduct.
The four provisions a CIO, COO, or general counsel needs to be able to recite in their sleep:
Section 18 (misleading or deceptive conduct). A person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. There is no requirement of intent. A confidently wrong AI output is enough.
Section 29 (false or misleading representations). Prohibits false or misleading representations about the standard, quality, value, grade, composition, performance characteristics, or sponsorship of goods and services. Also covers price, place of origin, testimonials, and warranty terms. Pecuniary penalties for a body corporate are the greater of $50 million, three times the value of the benefit obtained, or 30 per cent of adjusted turnover during the breach period.
Sections 60 to 62 (consumer guarantees for services). Services must be supplied with due care and skill (s60), be reasonably fit for any disclosed purpose (s61), and be supplied within a reasonable time where no time is specified (s62). These guarantees attach to services supplied to a consumer, and when AI assists in delivering a service, the guarantees attach to that service.
Section 64 (non-excludable nature). Consumer guarantees cannot be excluded, restricted, or modified by contract. A terms-of-service clause that says "the chatbot's outputs are not binding" does not actually release the business from its s60 to 62 obligations to a consumer.
A brief note on directors' duties. Under sections 180 to 181 of the Corporations Act 2001, directors and officers have duties of care, diligence, and good faith. Foreseeable AI-amplified consumer-law risk is the kind of operational risk that a reasonable board is now expected to know about and govern. This is not a separate cause of action against directors in most AI-ACL scenarios, but it does mean "we didn't realise the chatbot could do that" is not a sustainable governance posture.
Part 2: The Four Representation Traps in AI Customer-Facing Systems
The pattern of failure is consistent. AI customer-facing systems get a business into ACL trouble in four predictable ways.
The Four Representation Traps
| Metric | Common failure pattern | What good looks like | Improvement |
|---|---|---|---|
| Pricing (s18, s29) | Agent confirms a price returned from a stale system, or is prompt-injected into accepting an absurd offer (the Chevrolet of Watsonville '$1 Tahoe' incident, December 2023, is the canonical example) | Pricing answers are retrieved from a single source-of-truth API with a hard refusal pattern outside an authorised range, and material-value transactions require human confirmation | ACL s18, s29 |
| Refund / warranty / return (s18, s29, s60) | Agent invents or misstates the refund window, return conditions, or warranty coverage, as in Moffatt v Air Canada | The agent retrieves the live published policy, quotes it verbatim, and refuses to extend or modify the policy without a human approver | ACL s18, s29, s60 |
| Product capability or performance claims (s18, s29, s61) | Agent affirms a use case the product does not actually support, or overstates compatibility, integrations, or compliance certifications | Capability answers are constrained to a curated knowledge base, and unsupported claims trigger a refusal or human handover | ACL s18, s29, s61 |
| Service delivery commitments (s18, s62) | Agent promises an SLA, callback time, delivery date, or availability the business cannot meet | Time commitments are computed against live capacity data, never asserted as guarantees the business has not signed off on | ACL s18, s62 |
The Chevrolet of Watsonville incident in December 2023 is worth knowing in detail because it shows how cheaply this goes wrong. A user prompt-injected the dealership's customer-service chatbot into "agreeing" to sell a 2024 Chevrolet Tahoe for one dollar and stating "no takesies backsies". The dealership did not honour the offer, and the legal consensus was that the dealer probably did not have to (offer and acceptance, capacity of the agent, etc.), but the reputational damage and the question of whether the dealership had to defend that position in court at all is exactly the kind of foreseeable risk an ACL exposure review should be picking up before the agent goes live.
The Moffatt case is the cleanest refund / warranty illustration because the tribunal explicitly rejected the "the AI is its own entity" defence. Australian businesses should assume an Australian court would do the same.
Part 3: How Liability Actually Flows
The chain from "customer asks the AI a question" to "ACCC infringement notice" is not long.
Representation Liability Flow Under the ACL
Notice what is absent from the chain. There is no step where the AI vendor absorbs the liability. There is no step where a terms-of-service disclaimer breaks the chain. There is no step where "but it was a hallucination" reduces the obligation. The chain runs from the consumer through your agent to your business, and the ACL plugs in at step five whether you are ready for it or not.
For deeper coverage of how the production-operations side of this risk presents itself, see the operating AI agents in production companion piece in this series.
Part 4: Three Things Vendor Pitches Will Tell You That Are Wrong
When a business is evaluating an AI customer-service product, the vendor sales motion will reliably reach for three reassurances. All three are wrong in ways that matter.
Myth 1: "It is the AI vendor's responsibility, not yours." Wrong. The ACL attaches to the supplier in trade or commerce, which is the business deploying the agent, not the platform vendor. The ACCC's published position is that businesses using AI remain fully responsible for compliance. A vendor indemnity clause may give you a downstream commercial claim against the vendor, but it does not stop the ACCC from acting against you, and it does not bind the consumer who is suing you in QCAT, VCAT, NCAT, or the federal courts.
Myth 2: "Terms and conditions disclaim it." Partly wrong, dangerously so. Section 64 of the ACL makes consumer guarantees under s60 to 62 non-excludable. You cannot contract out of due care and skill. You cannot contract out of fitness for purpose. You can place reasonable scope-of-service descriptions in your terms, but you cannot use terms to override the consumer guarantees regime. The ACCC has published guidance on unfair contract terms that further constrains what disclaimers can do.
Myth 3: "It is just a chatbot, not a representation." Wrong, and the Moffatt decision is the cleanest counter. Courts and tribunals are treating agent output as company output. The character set, the speaker, and the deployment surface are immaterial; what matters is whether a reasonable consumer would treat the output as a statement of the business. They do.
The vendor evaluation framework in our AI vendor selection questions piece includes a specific section on getting these myths out of the room during procurement. The legal-and-compliance signoff cannot be deferred to "we will sort it out after the pilot".
Part 5: The Safe-Harbour Pathway
There is no formal safe harbour under the ACL for AI-mediated representations. There is, however, a stack of controls that materially reduces exposure and creates an evidentiary record a regulator, a court, or a tribunal can review favourably. Implementation cost is given as a directional estimate for an Australian business building this stack for a first customer-facing deployment.
Safe-Harbour Control Stack (Pre-Deployment Through Steady State)
The transparency requirement is worth a separate note. The Privacy and Other Legislation Amendment Act 2024 introduces automated decision-making transparency obligations that commence on 10 December 2026. If your organisation uses automated decision-making that could reasonably be expected to significantly affect an individual's rights or interests, the privacy policy must disclose that fact, including the types of personal information used and how an individual can request human review. The OAIC's guidance on privacy and AI extends the disclosure expectation further. Maximum penalties for a serious interference with privacy now reach $50 million for body corporates under the 2022 amendments. Disclosure is cheap. Failure to disclose is not.
For broader coverage of the privacy and governance overlay, see our AI agent governance, data access, privacy, and human override piece, and the data sovereignty guide for the underlying data-location and cross-border concerns.
Part 6: What Exposure Level Is Your Deployment?
Not every AI deployment carries the same exposure. The distinguishing factors are direct customer interaction, the kind of representations the agent can make, whether a human is in the loop for material commitments, and whether the deployment has been signed off at the right level.
ACL Exposure Level of Your AI Deployment
The high-exposure outputs are not rare. A common pattern is that an operations team or a marketing team has stood up an AI tool quickly, the legal-and-compliance function has not been consulted, and the deployment is making representations the business is not aware of. This is the scenario article one of this series flagged as the most expensive failure mode of DIY AI deployment.
Part 7: Pre-Launch Compliance Readiness Checklist
A general counsel, CIO, or compliance lead should be able to answer all of these before a customer-facing AI deployment goes live. If the answer to any of them is "I do not know", that question is your next two weeks of work.
- Authorised representations. Have we documented every category of representation the AI is authorised to make, and every category it must refuse?
- Logging. Where do we log every AI input and output, what is the retention period, and who in the business can retrieve a specific interaction within four hours of a customer complaint?
- Change control. Who internally signs off on a new system prompt, a new RAG source, or a model upgrade, and is there a written change log?
- Customer disclosure. What is the customer-facing disclosure that they are interacting with an AI, where does it appear, and has it been reviewed against current OAIC guidance?
- ACL mapping. Have we mapped every AI customer touchpoint to relevant ACL sections (s18, s29, s60 to s62) and identified the failure modes?
- Human-in-the-loop thresholds. Above what dollar value or risk category does a representation require human approval before reaching the customer?
- Out-of-scope handling. When the AI receives a query outside its scope, does it refuse, hand over, or guess? Can we evidence that behaviour with test cases?
- ACCC notification path. If a deployed agent generates a misleading representation that reaches multiple customers, what is our notification posture, who decides, and who has authority to communicate with the ACCC?
- Insurance coverage. Have we confirmed in writing that PI, cyber, and management liability policies cover AI-amplified ACL exposure, including hallucinated representations?
- Vendor liability allocation. Does our agreement with the AI platform vendor allocate liability for misleading outputs in a way that survives Section 64 and is commercially meaningful?
- Sector-specific obligations. If we operate in a regulated sector, have we consulted the relevant regulator's published AI guidance (ASIC for financial services, AHPRA for health practitioners, TGA for therapeutic goods, AER for energy retail)?
- Board reporting. Is AI deployment risk being reported to the board or executive committee on a defined cadence, with the right metrics?
A useful internal litmus test: take the most senior non-technical person in the business, sit them in front of the agent, ask them to try to break it, and watch what happens. If they can produce a representation the business would be unhappy to honour, the deployment is not ready.
For the operations rhythm that keeps this discipline alive after launch, see the production reality and staffing gap pieces. For the procurement-side controls, see AI vendor selection questions. For the upstream data-leakage exposure that often coexists with consumer-law exposure, see wrong AI tools leak business data.
What Solve8 Can Help With
The pattern we keep seeing in Australian businesses is that the legal, technical, and operational sides of AI deployment have not been brought into the same room. A vendor pitch is moving forward. A pilot is live in one department. The privacy policy has not been updated. The agent's scope of authority has not been written down. And the GC has not been asked.
Our consulting work in AI strategy and managed AI services is built around bringing those threads together. The technical capability comes from real product work, including the on-premise investigation product RootCauseAI and the ESG automation platform Carbonly, both of which had to think about regulated-environment representations and audit-grade logging from day one.
If a customer-facing AI deployment is on your roadmap for the next two quarters, the cheapest possible investment is a pre-launch ACL exposure review. The most expensive position is the one where the ACCC contacts you first.
Book a 30-minute pre-launch ACL exposure review
In thirty minutes we can map your customer-facing AI touchpoints to the relevant ACL sections, identify the two or three highest-exposure failure modes, and tell you what would need to change before launch. No vendor pitch, no obligation.
Related Reading:
- AI Agents for Australian Businesses: Why Not to DIY - Article 1 in this series, covering the build-time risks that create downstream ACL exposure.
- Operating AI Agents in Production: The Australian Reality - Article 2, covering the operations and TCO side, including the Moffatt precedent in operational context.
- The AI Agent Staffing Gap in Australian Business - Article 3, on who actually owns AI risk inside a business.
- AI Vendor Selection Questions for Australian Businesses - Article 4, the procurement-side companion to this legal-side piece.
- AI Agent Governance, Data Access, Privacy, and Human Override - The governance overlay that sits underneath the ACL controls described here.
Sources:
Citations: Moffatt v Air Canada [2024] BCCRT 149 (British Columbia Civil Resolution Tribunal, February 2024). Competition and Consumer Act 2010 (Cth), Schedule 2 (the Australian Consumer Law), sections 18, 29, 60-62, 64. ACCC, Compliance and Enforcement Priorities (current edition, accc.gov.au). ACCC statement on emerging technologies and the ACL (August 2024). OAIC, Guidance on privacy and the use of commercially available AI products (October 2024, updated 2025). Privacy and Other Legislation Amendment Act 2024 (Cth), automated decision-making provisions, commencement 10 December 2026. Corporations Act 2001 (Cth), sections 180-181. Chevrolet of Watsonville chatbot incident, December 2023 (widely reported, including AFR coverage).