When AI gets the brand wrong
You answer for what your chatbot asserts. For what a third-party model asserts about you, nobody answers — and no channel exists to have it corrected.
There are two errors that look like the same error and are not. In the first, your assistant asserts a policy that does not exist. In the second, a model that is not yours attributes to your brand a price, a return condition, a product or a lawsuit that is not there. They look like the same problem — false information circulating in your name — but they have opposite regimes: for the first you answer, for the second nobody does.
The first side is settled. The Civil Resolution Tribunal of British Columbia held Air Canada liable for what its chatbot had told a passenger about bereavement fares, information that contradicted the policy published on another page of the same site. The airline had argued that it could not answer for what one of its agents says, chatbot included. From the decision:
“In effect, Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission. While a chatbot has an interactive component, it is still just a part of Air Canada’s website. It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.”
(Moffatt v. Air Canada, 2024 BCCRT 149, 14 February 2024. Award: CAD 812.02.)
The amount is trivial and is not the point. The point is the characterisation: ordinary standard of care, no allowance for the fact that the error was produced by a system. It is a small-claims decision in Canada and binds no European court — it counts as an indication of how the problem gets framed the first time it is put, not as precedent. And the cost, when it arrives, is almost never a judgment: in April 2025 Cursor’s support bot invented a one-device limit that had never existed, the thread reached the front page of Hacker News, some users cancelled, and the co-founder had to deny it personally. That was the bill.
On the other side there is no door
The corpus records the claim in one line: “a hallucination about the brand is reputational damage with no channel for correction”. It is verifiable, and the void has four independent layers.
The GDPR does not apply to you. Recital 14 is explicit: the Regulation “does not cover the processing of personal data which concerns legal persons and in particular undertakings established as legal persons, including the name and the form of the legal person and the contact details of the legal person”. The right to rectification in Article 16 is a right of the natural person. A brand does not have it. This is not a procedural gap: it is out of scope by design.
The vendors’ channel is for removal, not correction, and it is for natural persons. OpenAI offers one: it is called “Remove my personal data from ChatGPT responses”, the outcome is that the information stops appearing — not that it gets corrected — and the documentation requires “a government-issued ID or alternative proof”. A company does not have one. The same page warns that the request may be declined and that removal from ChatGPT “does not remove it from external websites or search engines”. On Google’s side, the only in-product tool is the thumbs-down under the AI Overview with the Report a problem option: a contribution to product quality that opens no case, produces no reference and promises no reply.
The AI Act does not fill the void. The obligations on providers of general-purpose AI models (Art. 53) are technical documentation, information to downstream providers, a copyright policy and a summary of training content: no obligation of output accuracy, no mechanism for third parties to request a correction. Article 85 opens the complaint to the market surveillance authority to “any natural or legal person” — the brand is included here — but the object is an infringement of the Regulation, and a wrong statement about a company is not, in itself, an infringement of the Regulation. The Commission’s supervisory powers over GPAI providers became operative on 2 August 2026.
And the national authority may not be the national one. In March 2026 the Court of Rome annulled the EUR 15 million fine the Italian data protection authority had imposed on OpenAI, upholding the plea of lack of jurisdiction: with the Irish single establishment recognised since 15 February 2024, competence over cross-border processing passes to the one-stop-shop mechanism and the lead authority. The merits were not examined.
One route remains, and it is ordinary litigation. In the United States the solar installer Wolf River Electric sued Google because an AI Overview described it as the target of a lawsuit by the Minnesota attorney general, which did not exist; the complaint alleges a USD 150,000 contract terminated by a customer and quantifies damages between 110 and 210 million. It is a pending case, decided so far only on a procedural point: everything concerning the facts is one party’s allegation. It counts as a demonstration that this is the only lever left, not as a finding.
How often it happens: the honest answer is that nobody knows
It is worth saying, because the opposite temptation is strong. There is no rigorous, independent, brand-specific measure of how often AI gets brands wrong. The two solid studies measure news: the EBU and the BBC had professional journalists assess 3,062 AI assistant responses across 18 countries and 14 languages and found 45% with at least one significant issue, with sourcing as the leading cause (31%) — and among the worst cases precisely the one where “a response misattributes an incorrect claim to them” (October 2025). Columbia’s Tow Center, across 1,600 tests, found over 60% incorrect citations, with the constant that the systems get it wrong confidently rather than declining to answer (March 2025).
On brands there is only research by AI visibility vendors, that is, by parties selling the solution to the problem they measure. The most transparent about its numbers, across 1,257 factual claims concerning 182 verified businesses, does draw a distinction worth more than the total: 1.9% of claims contradicted by the evidence, 38.1% of claims no source supports (August 2026). If the figure holds, the prevailing problem is not outright invention: it is the unsupported assertion. That distinction changes what you do, because the first can only be discovered and the second can be prevented by working on the sources upstream.
Effect on the professions
- Digital PR / Reputation — This is the role the watch falls to, with a mandate that has no equivalent in the previous work: there is no newsroom to ask for a correction here, and no press office to call. The only lever is the earned one — reviews, industry forums, authoritative mentions, consistency of brand data across sources — but used correctively rather than promotionally, on a timescale that is not the timescale of a denial. Budget also for the case where the upstream source is correct and the error arises downstream, in the synthesis: there, there is nothing to act on.
- Legal / Compliance — The position to clarify is twofold, and the two sides do not resemble each other. Outward: on your own assistant, liability for what it asserts is ordinary, and the Air Canada precedent shows that the “the system said it” argument gets treated as unserious. Towards the model vendor: there is no title on which to found a request for correction, because the GDPR does not cover legal persons and the AI Act does not impose output accuracy. Ordinary litigation remains, with a single known case, still pending. The useful question is not which procedure to follow — there isn’t one — but at what threshold of damage you move from reputational handling to legal handling.
- AI Visibility Analyst — One more object of measurement joins the list: not only whether the brand appears, but whether what is said is true. It is technically simpler than share of presence — a claim can be checked against a source — and structurally more incomplete, because it observes the answers to your own questions and not to users’. To be reported alongside the figure: your own error rate is not comparable to anything, because no sector benchmark exists.
- Content Strategist — Owned content acquires a function it did not have: being the unambiguous source against which a claim is checked. That shifts priorities towards the information nobody writes because it seems obvious — return conditions, warranty terms, geographic availability, certifications, corporate structure — and towards its consistency between the site and third-party sources. It is the least visible work in the craft, and in this phenomenon it is the only prevention available.