Companies deploying artificial intelligence systems can be held fully liable for mistakes made by those systems, even when the errors stem from vendor training data or algorithmic design, according to an analysis published by ZDNET. The report examines three cases across transportation, healthcare, and hiring where businesses faced legal exposure for AI-generated harms they didn't directly cause. Courts and regulators are refusing to let companies defer responsibility to the platforms they chose to use, creating what experts describe as an uninsured risk for organizations rushing to automate decision-making.
The cases span multiple industries and regulatory jurisdictions. In Moffatt v. Air Canada, a British Columbia court held the airline completely responsible for damages after its AI chatbot incorrectly told a passenger they qualified for a refund, rejecting the company's argument that the chatbot was a third-party integration. The National Transportation Safety Board launched investigations into Waymo robotaxis that illegally drove past school bus stop signs in Austin and Atlanta, leading Waymo to recall over 3,000 vehicles while working on fixes. A 2019 study found Optum's Impact Pro risk assessment algorithm systematically classified Black patients as healthier than white patients with identical medical conditions, directly affecting whether patients received enrollment in extra care programs. In Mobley v. Workday, an ongoing class action lawsuit alleges the company's AI-based screening platform rejected candidates disproportionately based on age, disability, and race across at least 1.1 billion applicant reviews.
Missy Cummings, Director of the Mason Autonomy and Robotics Center and a former safety advisor for the National Highway Traffic Safety Administration, told ZDNET that Waymo's traffic violations resulted from switching to an end-to-end learning model that mimics real-world driving patterns but doesn't prioritize traffic rules as thoroughly as earlier algorithms. "These are not isolated cases," she said. "They are the predictable outcome of attempts to scale when the technology is being held together with bandaids." Ziad Obermeyer, a UC Berkeley professor whose research uncovered the Optum bias, explained that the algorithm used health costs as a stand-in for health needs, but among Black patients with the same disease burden, annual medical expenses ran $1,800 lower than white patients due to unequal access to care rather than actual medical need. According to the report, if the algorithm had functioned correctly, the share of Black patients selected for extra care programs would have jumped from 17.7% to 46.5%.
The liability chain extends beyond AI vendors to the organizations that deploy their tools. A 2025 court ruling in the Workday case treats an AI vendor as an extension of the employer that hired it, meaning responsibility doesn't stop with the platform provider. A new rule under Section 1557 of the Affordable Care Act, which took effect in May 2025, explicitly refuses to let hospitals, clinics, and insurers defer responsibility to the tools they used when discrimination allegations arise. Tabitha Weinstein, former executive director of HR for the Maryland Department of Public Safety, explained that many HR teams can't answer basic questions about which AI tools touch their hiring, when those tools were last checked for adverse impact, or who can overrule the machine. The report recommends that decision-makers fully review and audit model training and testing data from vendors wherever possible, and maintain a clear accountability plan before allowing an AI platform to access systems and workflows rather than waiting until after an incident occurs.
Weinstein said the fixes aren't complicated: HR leaders should know every AI platform in their stack, read a vendor's bias audit before deploying while making their own adverse impact calculations, and keep human recruiters in the loop with authority to override these platforms. McDermott Will & Schulte, a law firm specializing in healthcare litigation, advises hospitals and clinics to regularly audit any tools or algorithms used to aid clinical decision-making and maintain a detailed paper trail of these audits to justify that reasonable efforts were made to ensure non-discrimination. Deepika Shrivastava, COO of The Doctors Company, said in a 2025 interview that physicians should approach AI with the same care as any clinical tool and carefully document all AI use with the explicit understanding that it may be scrutinized in court. Organizations that assume vendors guarantee the safety, privacy, and responsible use of their products face serious compliance risks that affect clients and users downstream, even when vendors don't set out to build unsafe systems. The legal precedent emerging from these cases signals that experimental technology and procedural gaps won't shield businesses from liability when algorithms miss the mark.

