
Who is liable if AI makes a mistake?
Key Facts
- Traditional 99.99% uptime SLAs provide little comfort when AI agents make costly errors because uptime measures infrastructure availability, not model correctness according to Mayer Brown
- AI models left unchanged for six or more months saw error rates increase by 35% without proper monitoring per research on AI service level agreements
- The FTC and OCC hold deploying organizations accountable for AI outputs even when a third-party vendor operates the model per regulatory guidance on AI service contracts
- TCPA treats AI-generated voices as regulated technology requiring prior express written consent with zero first-call safe harbor according to TCPA attorney Andrew Cove
- Industry SLA templates target 98% successful task completion monthly and under 1% material hallucination rate in adjudicated samples per the wavect AI agent SLA template
- Vendors typically cap liability at 12 months of fees paid, which rarely covers actual damages from material AI failures per AI service contract analysis
- Company approval of an escalated action shifts liability away from the provider, making human-in-the-loop triggers a critical liability boundary per Mayer Brown legal analysis
The Liability Gap: Why Uptime SLAs Don't Cover AI Errors
Most businesses sign SLAs promising 99.9% or 99.99% uptime, then discover the guarantee is meaningless when the AI agent is "up" but giving wrong answers. Mayer Brown notes that 99.99% uptime provides little comfort if the agent is making costly errors, because uptime measures infrastructure availability, not model correctness. An API can return HTTP 200 while the agent cites a source that does not exist, calls the wrong tool, or leaves a customer waiting in a dead queue.
The problem compounds over time. Research shows that AI models left unchanged for six or more months saw error rates increase by 35% without proper monitoring. This model drift means a system passing every uptime check can quietly degrade in accuracy, resolution rate, and compliance adherence — exactly the outcomes that create liability for the deploying business.
Regulators do not care who operates the model. The FTC and OCC hold organizations accountable for AI outputs they deploy, even when a third-party vendor runs the system. For outbound calling, the TCPA treats AI voices as regulated technology requiring prior express written consent with zero first-call safe harbor. A single non-compliant call can trigger liability that no uptime credit will cover.
My AI Call Center addresses this gap by structuring SLAs around campaign outcomes — not server uptime. The liability boundary is drawn through three practical mechanisms:
- Delegation-of-authority clauses that define exactly what AI agents can and cannot do on calls (confirm, qualify, remind — never offer refunds or accept liability)
- Mandatory human-escalation triggers for regulated decisions, out-of-scope requests, and actions above approval thresholds
- Outcome-based service credits tied to disposition codes — confirmed, qualified, renewed, opted out — with evidence retention for auditability
This mirrors the shift from SaaS licensing to managed services that legal experts recommend. When the contract measures what the campaign actually delivers — and the provider stands behind those results — the liability gap closes.
How Liability Is Actually Assigned: The Five Clauses That Matter
Liability for AI mistakes is not decided after something goes wrong — it is decided by the contract language both parties signed before launch. In practice, five specific clauses do most of the work of assigning fault, and understanding them helps you read any AI service agreement with clearer eyes.
The delegation-of-authority clause comes first. It defines what the AI can do on a call and what it cannot — for example, confirm an appointment or qualify a lead, but never offer a refund or accept liability on your behalf. Legal analysis from Mayer Brown notes that the more precisely you define this delegation of authority, the more willing a provider will be to warrant that its AI stays within that scope. This is why My AI Call Center scopes every campaign around one clear goal before launch — a tight scope makes liability defensible for both sides.
Outcome-based SLAs replace the uptime guarantees that traditional software contracts rely on. An agent can be "up" at 99.99% availability while making costly errors, because uptime measures infrastructure availability, not model correctness. Enforceable AI contracts instead tie remedies to measurable targets, such as successful task completion at or above 98% monthly, a material hallucination rate under 1% in adjudicated samples, and zero uncontained Severity 1 hallucination events, per an industry SLA template. A metric with no owner, denominator, or evidence source is not yet testable — so the numbers must be specific.
Indemnification with carve-outs handles third-party claims. Providers generally will not warrant perfection; quality is addressed through circumscribed warranties and service credits as the remedy. Companies should seek indemnification for claims arising from the AI's autonomous performance of the service, while expecting carve-outs for client misconfiguration, faulty client data, and human-approved actions.
Human-in-the-loop escalation triggers draw the liability boundary in daily operations. When the AI hits a trigger — an out-of-scope request, a regulated decision, an action above an approval value — it hands off to a person. Crucially, your approval of an escalated action shifts liability away from the provider. This is why "nothing launches until you approve" is more than a courtesy step; it is a liability mechanism.
Audit rights and decision logs make attribution possible after the fact. "We have logs" is not an audit clause if you cannot retrieve the evidence during a dispute, as the template guidance puts it. Strong contracts specify queryable traces for 90 days and archived records for 12 months. Per-call notes, disposition codes, and opt-out logs — reported without invented numbers — give you the evidence trail to determine what actually happened.
Read these five clauses together and the answer to "who is liable?" becomes concrete rather than hypothetical.
AI Calling Raises the Stakes: TCPA Consent and Zero Safe Harbor
Outbound calling is where AI liability stops being theoretical. Under the Telephone Consumer Protection Act, an AI-generated voice is treated as regulated technology — the same category as autodialers and prerecorded messages. As TCPA attorney Andrew Cove puts it, "The law doesn't care how advanced the technology is. If it's not a live human making the call, it falls into a regulated category."
That classification carries hard requirements. Marketing calls made with AI voices require prior express written consent from the recipient before the phone ever rings. And unlike violations of the National Do Not Call list — which carry a one-call safe harbor — AI and regulated-technology violations have zero safe harbor. "There's no grace period here," Cove warns. "If you use AI to place a solicitation call without proper consent, that first call can be a violation."
The operational standards around compliant outbound calling are specific:
- Scrub contact lists against the DNC registry at least every 31 days
- Process internal opt-out requests within 10 business days per updated FCC guidance
- Call only during permissible hours — 8 AM to 9 PM in the US, in the recipient's local time
- Document consent records, DNC requests, and calling windows for every campaign
Here is the part that matters most for liability: regulators hold the deploying business accountable, not the vendor. The FTC and OCC have published guidance holding organizations responsible for AI outputs even when a third-party vendor operates the model. For AI calling platforms specifically, liability for non-compliant calls — consent, DNC lists, calling hours — falls on the business deploying the agent. Even under laws like TCPA and PECR, a single non-consented call can result in violations.
This is why consent documentation belongs to the client, and why any serious service level agreement should say so plainly. A managed provider can run disciplined campaigns — this is the model My AI Call Center uses, calling only approved, permissioned, or reviewed lists with consent records checked before launch — but it cannot manufacture consent that does not exist. If a client supplies a purchased list with no clear permission records, no SLA clause shifts that risk onto the provider. The defensible structure is a documented client attestation to consent records, backed by the provider's pre-launch review and opt-out logging.
Cove's advice distills it: "Treat AI outreach like any other regulated telemarketing activity. Get proper consent. Maintain clean lists. Respect opt-outs. Document everything." In an SLA, that translates into clear allocation — the client owns consent and list provenance, the provider owns execution within approved windows, and both parties know where the boundary sits before the first call is dialed.
How My AI Call Center Assigns Liability in Every Campaign SLA
When an AI call goes wrong, the question "who pays for this?" is answered long before the call happens — it is answered in the SLA. Legal analysis from Mayer Brown shows that liability for AI errors is not assigned by default; it is negotiated through contract structure, using mechanisms like delegation-of-authority clauses, escalation triggers, and audit rights.
One clear goal as a delegation-of-authority boundary. Mayer Brown's guidance is that contracts should define what an AI agent can and cannot do — that defined scope becomes "a defensible liability guardrail." My AI Call Center builds this in naturally: every campaign is scoped around one clear outcome (confirm, qualify, remind, renew), quoted before launch. The AI confirms appointments; it does not offer refunds or accept liability. A narrow mandate is a liability boundary.
Consent review with client attestation. Regulators hold the deploying business accountable for AI outputs even when a vendor operates the model, per FTC and OCC guidance. And under the TCPA, AI voices are regulated technology with zero first-call safe harbor — a single non-consented marketing call can be a violation, as TCPA attorney Andrew Cove puts it: "There's no grace period here." That is why the pre-launch list and consent review includes client attestation, and bought lists without clear permission records are flagged or declined.
Approval before launch. Nothing launches until the client approves the script, disclosure, opt-out handling, and escalation path. This mirrors the human-in-the-loop model — when the client approves an escalation path, approval shifts liability accordingly.
Outcome reporting instead of uptime promises. A system can be "up" 100% of the time while giving wrong answers; uptime measures availability, not correctness. So campaign SLAs report disposition codes, not infrastructure:
- Dispositioned outcomes: confirmed, qualified, renewed, opted out, no answer
- Per-call notes for every conversation
- Opt-out and DNC logs, honored immediately and carried into client records
- Completion and coverage reports per campaign
Evidence retention. As the wavect template warns, "we have logs" is not an audit clause if the customer cannot retrieve the evidence during a dispute. Per-call notes and opt-out/DNC logs make error attribution possible — supporting no invented numbers accountability. Clients remain responsible for obtaining legal guidance before launch; the SLA says so plainly.
Your Pre-Launch Liability Checklist: Five Questions to Ask Any AI Vendor
Before you sign any AI calling contract, remember this: liability is not assigned by default — it is negotiated. The vendors who seem confident in their AI are usually the ones whose contracts say the least about what happens when it errs.
Here are five questions to put to any AI vendor before launch.
1. What is the AI authorized to do on calls? Legal analysis from Mayer Brown shows that a well-drafted "delegation of authority" clause — stating explicitly what agents can and cannot do — creates clarity for you and a defensible guardrail for the provider. A campaign built around one clear goal makes this easy to define.
2. How are errors defined and measured? A 99.99% uptime guarantee means little if the agent is "up" but making costly errors. As AI contracting guidance notes, uptime measures infrastructure availability, not model correctness. Insist on outcome-based metrics — for example, reference SLA templates target 98% successful task completion monthly and a material hallucination rate under 1% in adjudicated samples.
3. What happens when a call escalates to a human? Mandatory escalation triggers — regulated decisions, out-of-scope requests, actions above an approval threshold — matter because company approval of an escalated action shifts liability away from the provider. Get the handoff path in writing before launch.
4. What evidence can you retrieve in a dispute? One SLA template puts it bluntly: "We have logs" is not an audit clause if you cannot retrieve the evidence during a dispute. Look for queryable decision traces — one benchmark is 90 days of queryable logs with 12-month archives — plus per-call notes and disposition codes.
5. Who attests to consent records? Regulators hold the deploying business accountable for AI outputs, even when a third-party vendor runs the model. And under the TCPA, AI voice calls carry zero safe harbor for first-call violations — the first non-consented call can be a violation. Your checklist before launch:
- Confirm the vendor reviews list source and consent records before any campaign runs, and flags lists without clear permission
- Verify DNC scrubbing frequency (at least every 31 days) and opt-out processing windows
- Confirm AI disclosure on every call, with keyword opt-outs honored immediately
- Get escalation paths, disposition reporting, and opt-out logs written into the SLA itself
One final reminder: campaign requirements vary by location, industry, and consent status, and clients are responsible for obtaining appropriate legal guidance before launch. My AI Call Center's free campaign review covers your goal, list, consent records, and escalation path — with the full cost known before you approve anything, so liability questions get answered before the first call goes out, not after.
Frequently Asked Questions
If the AI vendor is running the system, aren't they liable when the AI makes a mistake?
Doesn't a 99.99% uptime SLA protect me if the AI gives wrong answers?
Can AI models get worse over time even if nothing changes?
What happens legally if my AI makes a marketing call without consent?
Which contract clauses actually determine who pays when AI errs?
If something goes wrong, how do I prove what the AI actually said?
Liability Isn't Found — It's Negotiated
The answer to "who is liable if AI makes a mistake?" is rarely discovered after the error — it is written into the contract before the first call. Uptime guarantees offer little protection when an agent can be "up" 99.99% of the time while giving wrong answers, and regulators like the FTC and OCC hold the deploying business accountable regardless of who runs the model. For AI calling, the stakes are sharper still: the TCPA treats AI voices as regulated technology with zero first-call safe harbor. The businesses that stay out of trouble are the ones that insist on delegation-of-authority clauses, outcome-based SLAs, human escalation triggers, retrievable evidence logs, and documented consent attestation — before launch, not after. If you are evaluating AI calling, run your vendor through the five questions above and demand answers in writing. My AI Call Center's free campaign review covers your goal, list, consent records, and escalation path, with the full cost known before you approve anything. Get your questions answered before the first call goes out — book your review at myaicallcenter.app.