Nobody Will Promise Your AI Agent Will Behave
John Abbitt
·
·
8 min read
The companies building AI agents told lawmakers they can’t guarantee those agents will always follow the rules, and the law already holds businesses responsible for what their AI does. That puts supervision squarely on the business that deploys the agent, which is good news, because supervision is a skill most owners already have.
On October 5, the New York City Council asked four of the most important companies in artificial intelligence a question that I think every business owner using AI should be asking themselves. Representatives from OpenAI, Anthropic, Meta, and Google were testifying about AI legislation, and Council Speaker Julie Menin asked each of them to assure the public "under oath" that their AI agents would always follow the safeguards designed to prevent serious harm.
None of them would make that promise, and I don't fault them for it. What I want business owners to take from that exchange is what it means for the agents running inside their own companies. The people building these systems have now said, on the record, that they can't guarantee how those systems will behave. The courts, as we'll see, have already decided that whatever an AI says or does on a company's behalf belongs to that company. When you put those two facts together, the responsibility for supervising an AI agent lands with the business that switched it on. I think that's encouraging news, because supervising capable workers is something most business owners already know how to do.
What an AI agent is, and why it changes the question
It helps to be precise about terms, since "AI" now gets used for almost everything. Most people's experience so far has been with chatbots like ChatGPT, Claude, or Gemini. You type a question, the AI writes an answer, and then you decide what to do with it. In that arrangement, a person is always the last step before anything happens in the real world.
An AI agent works differently. You give it a goal, and it takes the actions needed to reach that goal on its own. A well-built agent might read an incoming service request, look the customer up in your CRM, check the technician schedule, draft a reply with a proposed appointment, and send it, all without anyone approving each step. That ability to act is exactly what makes agents so valuable for operations-heavy businesses, where so much of the day goes to moving information from one system to another. It's also why the question of oversight matters so much more than it did a year ago. When a chatbot gets something wrong, a person usually catches it before anyone else sees it. When an agent gets something wrong, the mistake may already be sitting in a customer's inbox.
What the AI companies actually said
The answers at the hearing were careful, and I'd encourage anyone deploying AI to read them closely. OpenAI's Morgan Dwyer said, "It is not possible for me to commit or guarantee that any technology is without risk," while describing the steps the company takes to deploy its systems safely. Anthropic's Logan Graham was even more direct: "Candidly, the science of doing this is fundamentally hard and unsettled." Google's Alice Friend said that "to promise perfection would not be possible with any product on the market." Meta's Shane Cahill said he could guarantee the company's commitment to safety, and added that people will only embrace AI if they trust it.
Menin's response captured the spirit of the exchange well: "I don't think we're asking for perfection. We're just asking for accountability, transparency and safety overall."
I read those answers as honest. No serious engineer would guarantee that a complex system will behave perfectly in every situation forever, and that's as true of a power grid or a commercial airliner as it is of AI. The companies also have recent reason to choose their words carefully. Over the summer, models from OpenAI, Anthropic, Meta, and Moonshot AI reached the live internet during tests that were supposed to keep them contained, and in the most widely reported case, an OpenAI agent escaped its test environment and breached Hugging Face, a platform developers use to share AI models. Those were lab tests of experimental systems, and in OpenAI's case researchers had deliberately switched off some safeguards to measure what the models could do, so they say more about the frontier of the technology than about the tools a small business buys today. Still, the takeaway carries over. An agent pursuing a goal will look hard for a way to reach it, sometimes in directions nobody anticipated, and the companies that know these systems best are telling us plainly that they can't rule that out.
The airline that tried to blame its chatbot
So if something goes wrong, who answers for it? We already have a pretty clear answer, and it came from a dispute over a plane ticket.
In November 2022, a man named Jake Moffatt went to Air Canada's website after his grandmother died, and asked the airline's chatbot about bereavement fares. The chatbot told him he could buy a regular ticket and apply for the bereavement discount afterward. He did exactly that. When he applied, Air Canada refused, because its actual policy didn't allow refunds after travel. The chatbot had described a policy that didn't exist.
Moffatt took the airline to British Columbia's Civil Resolution Tribunal, which handles small claims. Air Canada's defense was remarkable. It argued that the chatbot was a "separate legal entity" responsible for its own actions, and that Moffatt should have checked the correct policy, which was available elsewhere on the website. The tribunal rejected both arguments. Tribunal member Christopher Rivers wrote that "while a chatbot has an interactive component, it is still just a part of Air Canada's website," and found that the airline did not take reasonable care to ensure its chatbot was accurate. He also saw no reason a customer should be expected to know that one part of a company's website is trustworthy and another part isn't. Air Canada was ordered to pay $812.02 in damages, interest, and fees.
The dollar amount was small, and the reasoning behind it matters enormously. A Canadian small claims tribunal doesn't bind a court in Arizona or Texas, but the logic is the kind every business should expect to face anywhere. Moffatt never interacted with the company that built the chatbot or the company that built the underlying AI. He interacted with Air Canada, so Air Canada answered for it. Your customers will see it the same way. They don't know or care which vendor built your agent or which AI model runs underneath it. They see your name on the email, so whatever that email says is something you said. Google's representative at the New York hearing made the same point from a regulator's angle, telling the council that "if it's illegal without AI, it's still illegal with AI."
"Isn't that what the vendor's safeguards are for?"
The most reasonable pushback I hear on this goes something like: "I'm buying the agent from a reputable software company, built on a model from a major AI lab. They have safety teams and guardrails. Isn't keeping it in line their job?"
There's real truth in that. The guardrails built into commercial AI tools are meaningful, they're improving quickly, and they do prevent a great many problems. The White House accord that the largest AI companies signed in late September commits them to more internal controls and outside audits, and I hope those commitments become concrete.
The limitation is that every one of those safeguards is general. A vendor's guardrails can stop an agent from producing something offensive or from obviously misusing data. They can't know that your service agreement covers parts but not labor, that a particular customer has a standing discount, that you never schedule that technician on the north side, or that your bereavement policy, so to speak, doesn't allow refunds after travel. Air Canada's chatbot almost certainly had general safeguards of its own. The mistake that cost the airline was specific to Air Canada's business, and only Air Canada was in a position to catch it.
That's the heart of it. The only party that knows what "correct" looks like for your business is your business. The AI companies can make agents safer in general, and your vendor can make them easier to control, but deciding what the agent should do, checking whether it did it right, and stopping it when it doesn't is work that has to happen inside your four walls.
What good supervision looks like
The encouraging part is that supervising an agent looks a lot like supervising a capable new employee, which is something most owners have done many times.
It starts with a clear job description. "Handle customer communication" is too vague for a person or an agent. "Draft replies to new service requests, propose an appointment from the open schedule, and save the draft for the office manager" is a job you can actually check. The narrower and clearer the job, the easier it is to tell when something has gone wrong.
It continues with limited access. In technical terms this is called permissions, which simply means the list of systems and information the agent is allowed to touch. A new employee doesn't get keys to every room on day one, and an agent shouldn't either. If it drafts emails, it may not need the ability to send them yet. If it reads invoices, it has no reason to see payroll.
It includes approval points. Decide ahead of time which actions need a person's sign-off before they happen. Anything involving money, a commitment to a customer, or something that can't easily be undone is a sensible place to start, and you can loosen those requirements as the agent earns trust.
It requires a named supervisor, meaning a specific person who owns the agent, reviews its work regularly, and gets the call when something looks off. In my experience, shared ownership has a way of turning into no ownership, so put a name on it.
It depends on a record. You should be able to see every action the agent took, so that when something goes wrong you can understand what happened and fix the cause. And it needs a way to stop. Everyone who supervises an agent should know exactly how to pause it, and it's worth practicing once on a calm day so nobody is learning the steps in the middle of a problem.
Finally, it needs a regular check-in. Businesses change, and an agent set up for last spring's pricing or last year's service area will drift out of step. A short monthly review of what the agent is doing, where it's making mistakes, and whether its access still fits the job keeps small problems small.
None of that requires technical expertise. It requires someone who knows the work well enough to recognize a bad result, and the time and training to do the checking. That's a big part of why we keep describing AI adoption as a people project.
Where Avolis stands
We build AI agents for our clients, and we're genuinely enthusiastic about what they can do for operations-heavy businesses. We've watched them give people hours of their week back. We've also learned that the agents that keep delivering value a year later are the ones that came with an owner, a clear job, and clear rules from the start.
So that's how we build them. Our work starts by finding where the work in your business actually gets stuck, and the agents we design are scoped to a specific job with only the access that job needs. Before we hand one over, we make sure a named person on your team owns it, has been trained to review its work, and knows how to pause it, and we write down the rules for what the agent handles on its own and what needs a person's approval. We consider an agent finished when your team is confident supervising it without us, and we stay involved until that's true.
The AI companies have told us, as honestly as they can, that they can't promise their agents will always behave. I'd take them at their word and plan accordingly. If you'd like an honest look at where your business stands before you hand an agent real work, a good place to start is our AI Readiness Evaluation.
Sources
Fox News Digital, "AI companies stop short of guaranteeing agents will always obey safeguards" (live coverage, October 6, 2026): https://www.foxnews.com/live-news/ai-super-intelligence-safety-10-06
Last Week in AI, "Last Week in AI #342: The last 3 months" (2026): https://lastweekin.ai/p/last-week-in-ai-342-last-3-months
Fox Business, "White House monitoring incident after OpenAI models escaped containment and hacked Hugging Face systems" (July 2026): https://www.foxbusiness.com/technology/white-house-monitoring-after-openai-models-escaped-containment-hacked-hugging-face-systems
Law360 Canada, "Court rejects Air Canada's 'remarkable' denial of liability regarding misinformation by its chatbot" (February 16, 2024): https://www.law360.ca/ca/articles/1804075
DWW, "BC Tribunal finds Air Canada liable for inaccurate advice given by website chatbot" (2024), summarizing Moffatt v. Air Canada, 2024 BCCRT 149: https://www.dww.com/articles/bc-tribunal-finds-air-canada-liable-for-inaccurate-advice-given-by-website-chatbot
Semafor, "How Zuckerberg shaped Trump's AI industry pledge" (September 30, 2026): https://www.semafor.com/article/09/30/2026/how-zuckerberg-shaped-trumps-ai-industry-pledge
Ready to make AI work for you?
Book an AI readiness evaluation. If there’s nothing worth automating, we’ll tell you.
