Updated September 15, 2026
In April 2025, a developer emailed Cursor's support to ask why he kept getting logged out every time he switched machines. An agent named Sam replied that Cursor was designed to work with one device per subscription, as a core security feature.
No such policy existed. Sam was a bot. The logouts were a session bug.
The reply went up on Reddit and Hacker News, where people read it as an announcement and started cancelling.
Looking for a Public Relations agency?
Compare our list of top Public Relations companies near you
A human from Cursor turned up about three hours later to say none of it was true.
Three hours is fast by any support standard. It was still far too slow, because by then the fake policy had been screenshotted, quoted, and argued about by developers who had no idea they'd been talking to software.
This article covers who pays when your bot invents a policy, what happens when someone else's AI invents something about you, the disclosure rules already in force, and the three controls that prevent most of it.
The company that deployed it. This isn't a philosophical position. It's what tribunals and courts have actually decided when asked.
You can chase your vendor afterward under whatever your contract says. That's a separate fight, invisible to the customer, and it starts only after you've already paid.
A language model finishes sentences. Ask it a question it can't answer from anything it has access to, and it doesn't hit a wall and stop.
It produces the most plausible-sounding continuation, in the register you trained it to use, at the same confidence level it uses for things it does know. There's no tonal difference between a correct answer and an invented one.
Support is the worst possible place for this, because support is nothing but edge cases. Refund windows. Grandfathered pricing.
Whether a policy applies to a customer in Ontario who bought through a reseller in 2023. If the system isn't wired to your actual policy documents and can't tell the difference between a bug and a deliberate restriction, it will pick fluency over accuracy every single time.
An awkward "I'll get a person for you" costs you nothing. A smooth wrong answer costs you the customer and, sometimes, the ruling.
A chatbot on your website is your website. In February 2024, the British Columbia Civil Resolution Tribunal ordered Air Canada to pay CA$812.02.
Jake Moffatt's grandmother died in November 2022.
He asked Air Canada's chatbot about bereavement fares, and it told him he could book at full price and apply for the reduced fare within 90 days of the ticket's issuance.
The words "bereavement fares" in that same answer were linked to Air Canada's real policy page, which said the opposite: no claims after travel is completed. He booked, flew, applied with his grandmother's death certificate and a screenshot of the chat, and was refused.

Air Canada's defense was that the chatbot was a separate legal entity responsible for its own actions.
The tribunal member called this a remarkable submission and pointed out the obvious, which is that a company is responsible for everything on its own website, regardless of whether it comes from a static page or an interactive box.
Eight hundred dollars is the total financial exposure, which is why people underrate the case.
The airline's own representative had already admitted to Moffatt that the bot used misleading words, told him they'd noted it so the chatbot could be updated, and still refused the refund. He sued over the refusal, not the error.
This is now the harder problem, because you have no controls to tighten and no vendor to call.
On 28 May 2026, the Regional Court of Munich I ruled that Google can be held directly liable for false statements produced by AI Overviews.
Two Munich publishers found the feature linking their names to scams, subscription traps, and dubious business practices. The connections appeared in none of the sources that the summary cited.
The AI had confused them with an entirely different company and then written confident copy about it, opening with lines to the effect of "yes, this company is known for dubious business practices," followed by a tidy list of red flags.
German law has long shielded search engines from liability for what they link to.
The court said that the shield doesn't reach here, because an AI summary isn't a list of links. It rewrites and evaluates material in its own words and structure, producing what the ruling described as independent, new, and substantive statements. Google's content, in other words.
Google argued users could click through and verify. The court responded that the ability to disprove a statement through further research doesn't generally excuse making it, and that the feature's whole value proposition collapses if users are expected to check every claim in it.
Now, put a smaller company in that position.
A Minnesota solar installer sued Google in 2025, claiming AI Overviews had invented a state Attorney General lawsuit against it, citing sources that said no such thing.
Their complaint lists the damage by contract: a customer who terminated on 3 March, contract value $39,680. Another who walked away on 4 March, proposal value $26,400. A third person sent over a screenshot of Google's claim and asked what was going on.
That business did nothing wrong. It bought no AI, deployed no chatbot, and wrote no policy. Someone else's model made something up about it, and it lost five figures of pipeline in a week.
If you handle brand reputation, this is the thing to start monitoring now, and almost nobody is.
The exposure runs through hiring too. Candidates research employers by asking an assistant, and the answer gets assembled from job boards, review sites, and forum threads the model may well be conflating.
Stale listings are a large part of what it reads: a req you never closed in 2023 looks, to a summarizer, like a job nobody will stay in.
Deven Patel, Founder of Role, a job search engine that pulls listings straight from company career sites, sees the damage from the data side.
Patel says, "The posting you forgot to close is still teaching an assistant what it's like to work at your company. Most of the employer brand damage we see in AI answers isn't anyone saying something false about you, it's old data being summarized confidently. If your listings live on aggregators and nowhere authoritative, you've handed the summary over to whoever scraped you last."
Search your own company name, your founders, and your products in the major assistants, monthly at minimum. Screenshot what you find. Cease-and-desist letters do work, and in the Munich case, the failure to respond adequately to one was part of what pushed it into court.
More than most teams realise, and one of them went live three weeks ago.
Article 50 of the EU AI Act has applied since 2 August 2026. If your chatbot talks to people in the EU, it has to tell them it's a machine, clearly, at first contact.
Burying it in terms and conditions or three menus deep is specifically called out as not good enough.

AI-generated content needs machine-readable marking, with a grace period until 2 December 2026 for systems already on the market. Deepfakes and AI-written text on public interest topics need visible labels. Penalties run up to €15 million or 3 percent of worldwide turnover.
Many companies missed this due to the Digital Omnibus, which pushed high-risk system deadlines back to December 2027. Article 50 was deliberately left out of that delay. If you read "AI Act delayed" in a headline last spring and filed it away, check again.
Article 4 has been applied since 2 February 2025 and gets ignored far more because it carries no penalty schedule of its own: it requires that whoever operates your AI system is actually trained on it, scaled to their role.
Teams cover that with a one-off internal briefing that ages badly, a SaaS LMS with an off-the-shelf compliance module, or a custom LMS development company like Academy Smart building something that tracks completion against your own escalation rules. Which route matters less than being able to show who was trained, on what, and when.
In the US, there's no equivalent disclosure statute at the federal level, but the FTC has been consistent that Section 5 doesn't care what tool you used.
Operation AI Comply started in September 2024 and has kept going through a change of administration, with more than a dozen cases in 2025 alone.
The most instructive one is small: Workado marketed its AI content detector as 98 percent accurate. The FTC found the real figure was 53 percent. No fine, but an order to stop making accuracy claims, notify customers, and submit to monitoring.
Grounding, escalation, and logs. Most of the rest is theatre.
Grounding means the system answers using your real policy documents rather than whatever it absorbed during training. Conversational AI systems such as visual AI agents can use approved knowledge sources to provide more relevant, context-aware responses. If a customer asks about refunds and the model can't find refund language in your actual sources, it should say so and hand over. Cursor's bot invented a device policy because nothing stopped it from filling the gap itself.
Escalation means an explicit, visible route to a person, triggered by uncertainty rather than by the customer's persistence. Watch what you measure here, because a resolution-rate target quietly punishes the bot for admitting it doesn't know. You will get the behavior you incentivize.

Logging means you can reconstruct what was said. Moffatt won partly on a screenshot. If a customer has a record of your system's answer and you don't, you're arguing from memory against evidence.
Then the shorter list:
The gating question gets sharper the closer the answer sits to something a customer does immediately. A bot that gives a wrong shipping date costs you a complaint. A bot that gives a wrong temperature, dosage, or age range costs you more than that.
Lucy Rendler-Kaplan, PR Manager at Thyseed, a baby care brand whose bottle warmers and sterilisers sit in the daily routine of new parents, sees it from the consumer side.
Rendler-Kaplan notes, "A parent asks how hot a bottle should be or whether a part is safe to sterilise, and they act on the answer within five minutes. If a summary attaches the wrong number to our name, the correction arrives long after the decision. We keep our own product instructions published and current so there is something authoritative for anything to read."
And write the disclosure properly. Under Article 50 you may have to anyway, but the Cursor incident is worth studying on this point alone: a large part of the anger was that "Sam" read as a person. People forgive a machine for being wrong far more readily than they forgive a company for hiding that a machine was talking.
Say what happened, name it as an error, and fix the mechanism in public.
Cursor's co-founder posted within hours, called it an incorrect response from a front-line support bot, apologised, and started labelling AI replies.
It was messy, and it worked well enough that the company is still growing. Air Canada spent fifteen months arguing that its chatbot was a separate legal person, and bought itself a precedent that now gets cited in every article on this topic, including this one.
The gap between those two responses cost roughly the same amount of money. It did not cost the same amount of reputation.