Legal exposure from incorrect AI-generated answers

A business owner sitting at a desk reviewing documents on a laptop in a well-lit small office
TL;DR

AI tools can produce plausible-sounding but incorrect information about legal rights, prices, tax treatment, and data handling. Under UK law, your business is responsible for every output generated under its name, not the tool or its vendor. The risk is not theoretical: half of UK accountants now report clients losing money from incorrect AI-generated advice. A human-review policy on high-stakes outputs is the practical first step.

Key takeaways

- Under UK law, AI tools have no legal standing. Your business is responsible for everything an AI generates under your name, regardless of which tool produced it. - A 2025 BBC and European Broadcasting Union study found roughly 45% of AI queries to major tools returned errors, including incorrect statements about current laws and rights. - Research by Dext found half of UK accountants report clients suffering financial losses from incorrect AI-generated advice, with 31% encountering such mistakes weekly. - The main risk zones for a services firm are customer communications, financial and tax outputs, personal data processing, and automated decisions about individuals. - The proportionate first response is a human-review policy on any AI output that touches legal rights, financial figures, personal data, or regulated obligations, not a wholesale ban on AI tools.

An automated email quotes the wrong price. A chatbot tells a customer she can cancel within 60 days; the actual window in your terms is 14. A generated invoice applies the wrong VAT rate and goes out unchecked.

Each of these scenarios is already being documented by UK business lawyers. The question they raise is the same every time: who is legally responsible for what the AI said?

The answer, under UK law, is your business.

Under UK law, an AI system has no legal standing. It cannot be sued or enter contracts. Your business can, which means what an AI generates under your name is treated as your output. A mispriced chatbot quote is your quote. An incorrect refund policy in an automated email is your communication. Technology vendors almost always contractually shift responsibility back to you.

UK legal commentary puts it plainly: when an AI tool “sends false information, makes an unrealistic promise, or miscalculates an invoice, your business could be liable, not the technology provider.” That framing comes from Butcher and Barlow LLP, a UK law firm that has published guidance on business liability for AI mistakes.

The Digital Markets, Competition and Consumers Act 2024 updated the consumer protection framework from April 2025. Misleading AI-generated messages aimed at consumers can now be treated as unfair commercial practices, placing them in the same legal category as deceptive pricing or misleading advertising. Misrepresentation, breach of contract, and consumer protection complaints can all follow from AI outputs that affect whether a customer buys, cancels, or claims a right they were incorrectly told they had.

Why is the error rate higher than many businesses assume?

A 2025 BBC and European Broadcasting Union study tested four major AI tools, including ChatGPT, Microsoft Copilot, Gemini, and Perplexity, on current affairs and regulatory questions. Roughly 45% of responses contained errors, including incorrect statements about laws directly in force. Separately, research from accounting software firm Dext, reported in City A.M., found half of UK accountants said clients had lost money from incorrect AI-generated advice.

The same Dext research found 31% of accountants were encountering AI-caused client mistakes on a weekly basis. And 43% expected more inappropriate or fraudulent claims to be justified by AI outputs over coming years.

These figures do not describe specialist deployments. They cover ordinary tools used in day-to-day business. General-purpose language models are confident by design. When asked about a refund right or a regulatory threshold they do not hold reliably in their training data, they generate a plausible-sounding answer rather than a disclaimer.

The Law Society Gazette has reported UK judges being warned about lawyers submitting fake case citations generated by AI. If that risk has reached the courtroom, it has already reached the back office.

Where will you actually encounter this risk?

The risk is not limited to customer-facing chatbots, appearing across customer communications, financial and tax work, personal data handling, automated decisions about individuals, and regulated financial promotions if your firm operates under FCA oversight. The DMCC Act 2024, in force from April 2025, means misleading AI-generated consumer messages can be treated as unfair commercial practices under the updated UK consumer protection regime.

Customer communications. If an AI tool misstates your refund terms, overstates service capabilities, or misrepresents pricing, those messages can trigger misrepresentation claims or breach of contract. The customer’s reliance on the statement, not how it was generated, is what matters in law.

Financial and tax work. Half of UK accountants report clients suffering financial losses from incorrect AI-generated advice. HMRC is expanding its compliance capacity, with around 5,000 additional officers planned by 2029/30. Errors in VAT treatment, relief claims, or filings driven by inaccurate AI outputs carry growing risk of penalties as that capacity comes online.

Personal data and automated decisions. The ICO applies UK GDPR and the Data Protection Act 2018 to all personal data processed by AI tools. Pasting client information into a public AI tool is data processing, and it needs a lawful basis, a privacy notice, and appropriate security controls. The ICO has also stated that token human sign-off on an AI recommendation is not sufficient for compliance with the Article 22 rules on automated decisions; a human must genuinely weigh and interpret the output.

Equality Act exposure. The Equality and Human Rights Commission has confirmed that AI used in recruitment or service access falls within its remit under the Equality Act 2010. If an AI screening tool produces unjustified impacts on people with protected characteristics, due to biased training data or flawed design, the business deploying it carries the liability.

When does the risk stay manageable?

The risk is not uniform across all uses. Purely internal work where AI outputs are heavily edited before anyone acts on them creates minimal regulatory exposure. Generic website content with no factual claims about rights, prices, or service performance carries lower consumer law risk. Minor stylistic errors or slightly clumsy wording rarely create legal liability unless they misled a customer and caused loss.

Tightly scoped, domain-specific AI tools also carry meaningfully less risk than general-purpose chatbots. A system built to search your own verified document library, with human review of every output, is a different risk profile from a public language model answering customer queries with no guardrails.

UK legal guidance on AI liability draws a practical line: the relevant question is whether the AI output affected a commercial decision, a financial position, or personal data. If none of those three applies, the error is a service quality issue, not a legal one. That framing is a useful guide to where to focus oversight.

What does a proportionate response look like?

You do not need a legal team or a compliance officer to reduce this risk meaningfully. The core move is to treat AI as a drafting tool, not a decision-maker. Any output that touches customer rights, financial figures, personal data, or regulated advice should pass through a human review before it reaches a client. That one discipline directly reduces your exposure from the start.

Beyond that, four areas deserve attention.

Define your no-go zones. Legal rights and remedies, tax and accounting figures, regulated financial advice, and eligibility decisions are all areas where unsupervised AI output creates disproportionate risk. Write this as a short policy, not an assumption. Relevant staff should know which categories require sign-off before anything reaches a client.

Check your data protection position. If AI tools are processing personal data, your privacy notice should reflect that. Staff should know which tools are approved for which tasks. For any AI that profiles individuals or makes decisions about them automatically, a Data Protection Impact Assessment is likely required under ICO guidance.

Review vendor contracts. SaaS agreements commonly cap or exclude the vendor’s liability for incorrect outputs. Check what warranties exist for accuracy, what security standards the vendor commits to, and which party holds the data processing role under UK GDPR.

Add AI to your risk register. The ICO, FCA, CMA, and NCSC are all signalling that existing regulatory frameworks apply to AI. If your firm has a risk register, AI tools should be on it, with a brief note of which tools are approved, what they are used for, and what oversight applies.

None of this requires specialist legal advice to start. It requires the same discipline you would apply to any business system that goes out under your name.

Sources

- ICO (2024). Guidance on AI and data protection. UK regulator's position on lawful basis, transparency, and security obligations when using AI tools to process personal data. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/ - ICO (2024). Automated decision-making and profiling. Rights and obligations under UK GDPR Article 22 for AI-driven decisions about individuals. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/guide-to-data-protection/guide-to-the-uk-gdpr/individual-rights/rights-related-to-automated-decision-making-including-profiling/ - EHRC (2024). Artificial intelligence (AI) and discrimination. Equality and Human Rights Commission guidance on Equality Act 2010 obligations for businesses deploying AI in recruitment and service access. https://www.equalityhumanrights.com/en/advice-and-guidance/artificial-intelligence-ai - FCA (2022). DP5/22: Artificial Intelligence and Machine Learning. FCA position on ongoing liability and compliance obligations for regulated firms using AI, including consumer duty and financial promotions rules. https://www.fca.org.uk/publications/discussion-papers/dp5-22-artificial-intelligence-and-machine-learning - UK Government (2024). Digital Markets, Competition and Consumers Act 2024. Updated consumer protection framework bringing misleading AI-generated communications within the unfair commercial practices regime from April 2025. https://www.gov.uk/government/collections/digital-markets-competition-and-consumers-act-2024 - HM Treasury (2024). Spring Budget 2024 documents. Announced plans for approximately 5,000 additional HMRC compliance officers by 2029/30, increasing enforcement risk for AI-driven tax and filing errors. https://www.gov.uk/government/publications/spring-budget-2024-documents - City A.M. / Dext (2026). Businesses are suffering financial losses from faulty AI advice. Research finding 50% of UK accountants report client losses from incorrect AI-generated financial advice and 31% encounter such mistakes weekly. https://www.cityam.com/businesses-are-suffering-financial-losses-from-faulty-ai-advice/ - Bersin, J. (2025). BBC finds that 45% of AI queries produce erroneous answers. Summary of BBC and European Broadcasting Union study on error rates across ChatGPT, Copilot, Gemini, and Perplexity on regulatory and factual questions. https://joshbersin.com/2025/10/bbc-finds-that-45-of-ai-queries-produce-erroneous-answers/ - Butcher and Barlow LLP (2024). AI mistakes: could your business be liable? UK law firm guidance on business liability when AI tools produce false information, unrealistic promises, or miscalculated invoices. https://www.butcher-barlow.co.uk/news/commercial-dispute-resolution/ai-mistakes-could-your-business-be-liable/ - Law Society Gazette (2024). Stop referencing fake case citations, judges warned. Coverage of UK judiciary warnings on AI-generated false legal citations entering court proceedings. https://www.lawgazette.co.uk/news/stop-referencing-fake-case-citations-judges-warned/5125602.article

Frequently asked questions

If my AI tool gives a customer the wrong information, am I legally responsible?

Yes, under UK law. AI systems have no legal standing of their own, so what an AI generates under your name is treated as your output. Whether it creates legal liability depends on whether it misled the customer into a decision or caused loss. The Digital Markets, Competition and Consumers Act 2024 brought misleading AI-generated consumer messages explicitly within the unfair commercial practices regime.

Does the ICO expect my firm to treat AI-processed personal data any differently?

The ICO applies UK GDPR and the Data Protection Act 2018 to all personal data processed by AI, including data that staff paste into public AI tools. Your firm needs a lawful basis, a privacy notice covering AI use, and appropriate security controls. If your AI makes automatic decisions about individuals with a legal or significant effect, Article 22 of UK GDPR imposes additional obligations.

Which AI uses carry lower legal risk for a small services firm?

Purely internal work where AI outputs are heavily edited before anyone acts on them carries minimal regulatory exposure. Generic content with no claims about legal rights, prices, or service performance is lower risk. The key questions are whether the output could have misled someone into a commercial decision, affected a financial position, or involved personal data. If none applies, the issue is usually a service quality matter rather than a legal one.

This post is general information and education only, not legal, regulatory, financial, or other professional advice. Regulations evolve, fee benchmarks shift, and every situation is different, so please take qualified professional advice before acting on anything you read here. See the Terms of Use for the full position.

Ready to talk it through?

Book a free 30 minute conversation. No pitch, no pressure, just a useful chat about where AI fits in your business.

Book a conversation

Related reading

If any of this sounds familiar, let's talk.

The next step is a conversation. No pitch, no pressure. Just an honest discussion about where you are and whether I can help.

Book a conversation