Why AI Risk Management Must Prioritise Business-Led Accountability in Third-Party AI Use

When Air Canada’s customer-service chatbot invented a bereavement discount that didn’t exist, the airline’s defence was that the chatbot was “a separate legal entity” responsible for its own words. Canada’s Civil Resolution Tribunal rejected that argument outright in Moffatt v. Air Canada, ordering the airline to pay $812.02 in damages.

Why worry about such a small amount in damages?

The lesson for any business running AI through a vendor’s platform: whatever the tool says or does, you own the outcome. This may have been one small instance, but it is a learning worth considering.

Vendor assurances are not a liability shield, and the organisations still treating them as one are building risk they can’t see.

The 30-second take

Third-party AI arrangements create risk gaps when businesses rely on a vendor’s word instead of independent evidence and clear internal ownership.

A 2024 tribunal ruling, a new US Treasury-backed control framework, and a 2026 industry survey of 173 financial services professionals all point the same direction: regulators, standards bodies and now a formal government-endorsed framework increasingly treat the deploying organisation — not the AI vendor — as accountable for what the tool does.

Practical AI risk management means naming an internal owner, setting evidence standards for vendors up front, and monitoring continuously rather than ticking a box at onboarding.

The AI Signal BoxTM provides an approach and a tool that helps organisations address this risk and more, to help use AI with strong and clear governance.

The tribunal that ended the “it wasn’t us” defence

In Moffatt v. Air Canada (BC Civil Resolution Tribunal, February 2024), a customer was told by the airline’s AI chatbot that he could claim a bereavement fare discount retroactively.

Air Canada’s actual policy required approval before travel. When the customer sought the refund, Air Canada argued the chatbot was responsible for its own statements. The tribunal disagreed, ruling the chatbot was “part of Air Canada’s website” and the airline was liable for everything on it, ordering Air Canada to pay $812.02 in damages.

The case is now widely cited because it closes off the argument that a vendor-supplied AI tool operates outside the deploying company’s responsibility.

Treasury just raised the bar on vendor AI oversight

In February 2026, the Cyber Risk Institute released the Financial Services AI Risk Management Framework (FS AI RMF), with the US Treasury formally endorsing it days later as part of its AI risk-management deliverable series.

Built on NIST’s Govern, Map, Measure and Manage functions and developed with more than 100 financial institutions and the Financial Services Sector Coordinating Council, the framework sets out 230 control objectives covering fraud, bias, model risk, explainability and cybersecurity.

It isn’t mandatory, but it is the clearest signal yet that regulators expect vendor-supplied AI to be governed with the same rigour as anything built in-house — continuously assessed, not just vetted once at onboarding.

Most boards don’t know what their vendors are doing with AI

Ncontracts’ 2026 State of Third-Party Risk Management Survey, drawing on responses from 173 financial services professionals between November 2025 and January 2026, found AI risk has, for the first time, tied cybersecurity as the top third-party concern for institutions — yet 72% admit they are only partially aware of which of their vendors are using AI, and 16% haven’t assessed vendor AI use at all.

Not a single respondent felt “extremely confident” managing that risk.

That gap between concern and visibility is the real exposure: relying on a vendor’s representations without independent validation and governance is not a defensible position, as the Air Canada tribunal made clear in a much smaller dispute.

Questions to ask before you sign off on the next AI vendor

  • Do we actually know which of our vendors are using AI, and in which parts of our business?
  • Who inside our organisation — by name, not by department — owns the decision to approve an AI vendor?
  • Are we still treating vendor AI risk as a once-off onboarding checkbox, or is it monitored continuously through the life of the contract?
  • If a vendor’s AI tool gives a customer wrong information tomorrow, are we contractually and operationally ready to own that outcome the way Air Canada had to?
  • Does our board risk report show AI vendor exposure as its own line item, or is it still buried inside generic “technology risk”?
  • What’s the escalation path when a use case we classified as low-risk turns out, in practice, to be higher-risk than first assessed?

None of this requires slowing AI adoption to a crawl — it requires knowing, in writing, who owns the decision before the vendor’s tool makes one for you. For a structured way to assess where your organisation stands, visit the Innovation of Risk and run a readiness snapshot.

More from the Reading Room

Beyond Model Risk: Managing AI Risks Embedded in Complex Vendor Ecosystems

Three real 2026 outages — AWS's cascading Middle East failure, Microsoft Copilot's five-hour blackout, and Claude's multi-model cascade — show why AI risk management can't stop at the vendor you signed with. With EU AI Act deployer obligations enforceable from August 2026 and Gartner naming \u201cfourth-party\u201d AI risk directly, boards need to map the AI hiding inside their vendors' vendors.

Why AI Policy Must Be Practical: Turning Guardrails into Actionable Risk Controls

Many organisations have AI policies, but these often fail to guide day-to-day decision making. To manage AI risks effectively, policies need clear guardrails that business teams can apply consistently. This article explains how to translate high-level AI principles into practical standards and controls that enable confident, accountable AI use.

How to Avoid AI Risk Bottlenecks by Defining Clear Ownership and Evidence Standards

Unclear ownership and weak third-party evidence can stall AI initiatives for months. This article explains why business-led accountability and structured evidence checklists are critical to smooth AI risk management and faster decision-making.

Why Relying Solely on Vendor AI Assurances Creates Hidden Risks for Your Organisation

Germany's data regulator fined Vodafone €45 million partly for failing to vet a third-party partner, a 2026 DataGrail report found 64% of AI vendors hide their subprocessors, and a German court has ruled companies — not their AI vendors — are liable when the tool gets it wrong. Three real 2026 examples show why vendor assurances can't substitute for your own verification.