Compliance stories are usually told as fines. The cases that matter most to small and mid-sized organisations are less dramatic and more instructive: a tribunal, a settlement, an order that stops you using a tool. Here are five.
A chatbot's promise is your promise
In Moffatt v. Air Canada (British Columbia Civil Resolution Tribunal, February 2024), the airline's website chatbot told a grieving passenger he could apply for a bereavement fare after buying his ticket. The written policy said the opposite. Air Canada argued the chatbot was "a separate legal entity responsible for its own actions". The tribunal called that a "remarkable submission", found the airline had a duty to take reasonable care that its chatbot was accurate, and ordered it to compensate the passenger. The amount was small (about CAD 812 including fees). The precedent was not: what your AI says to customers is what you said.
Deploying without testing is an unfair practice
In December 2023 the US Federal Trade Commission banned Rite Aid from using facial-recognition surveillance for five years. The FTC's complaint said the retailer had "failed to test, assess, measure, document, or inquire about the accuracy" of the technology, that false matches were more common in stores in plurality-Black and Asian neighbourhoods, and that staff were not trained on the tool's limits. Customers were followed and accused of shoplifting on the strength of bad matches. No AI-specific law was needed: the FTC used its ordinary unfair-practices power.
Old discrimination law applies to new tools
iTutorGroup's application software automatically rejected female applicants aged 55 or over and male applicants aged 60 or over. The company settled with the EEOC in 2023 for USD 365,000. Mobley v. Workday, filed in 2023 and still in progress, goes further: the court allowed a nationwide collective of applicants aged 40 and over to proceed against the software vendor itself, on the theory that a vendor whose tool screens candidates can be liable as an agent of the employer.
Privacy regulators reach the model
Clearview AI scraped billions of face images from the web to build a recognition service. Between 2022 and 2024 data-protection authorities in Italy, Greece and France each fined it EUR 20 million, the UK fined it GBP 7.5 million, and the Dutch authority added EUR 30.5 million in September 2024 with an order to stop. The Netherlands also warned that Dutch organisations using Clearview could themselves be fined.
Overclaiming is deceptive
DoNotPay marketed a "robot lawyer" that could replace a human. The FTC found no evidence it could, and in 2024 the company agreed to pay USD 193,000 and to notify past subscribers of the service's limits. Selling AI with claims you cannot back is treated like any other false advertising.
What these have in common
- None depended on a new AI statute; consumer-protection, anti-discrimination and privacy law were enough.
- In every case, the organisation could not show it had tested the tool, told people about it, or kept a human able to correct it.
- Small organisations were as exposed as large ones.
Not legal advice
These summaries are drawn from the official decisions and press releases linked below. They are simplified for teaching and are not legal advice. If any resembles your situation, talk to counsel before changing anything.