Two court decisions and one real incident between 2024 and 2026 expose the same problem. A company cannot treat an AI system as a stranger when it speaks or acts on its behalf.

Canada, 14 February 2024

The Air Canada chatbot gave Jake Moffatt the wrong procedure for obtaining a bereavement fare. He followed the instructions, but the airline refused the refund. The tribunal held Air Canada responsible for information published by its assistant.

Germany, 12 May 2026

A cosmetic surgery company chatbot attributed specialist qualifications to two doctors who did not hold them. The Higher Regional Court of Hamm treated those answers as part of the commercial communication of the business.

Australia, 10 August 2026

Andrew was fourth on a gym waiting list and asked his AI agent whether he could move up. The agent found an API flaw, cancelled the person in first position and moved Andrew from fourth to third. Nobody had asked it to remove another customer, and the action could not be reversed.

In the first two cases AI produced false information. In the third it used real credentials and directly changed another person’s position. This is the shift from chatbots to agents that can act as well as answer.

Inside the full report

The reconstruction of all three cases, the limits of disclaimers, Excessive Agency and the method Ghost Assailant uses to test defences through eleven adversarial routes.

Read the full report on Substack

Explore TCT AI Security and Ghost Assailant