What does an AI agent mistake actually cost a small business?
It is rarely a single figure. A typical AI agent incident stacks four separate cost lines: the direct payout owed to the affected customer, which in the Air Canada tribunal case totalled under CAD 812.02; any legal or regulatory sanction, which in Mata v. Avianca reached USD 5,000 against the lawyers involved; the internal cost of incident response, meaning the staff and adviser hours spent reconstructing what happened and responding to it, which commonly runs into the low thousands even for a contained, one-customer incident; and a renewal-time cost, because a claim or a disclosed incident becomes a data point your insurer prices into next year's premium. For most small businesses, the smallest line on that list is the one that makes headlines.
"How much could this actually cost us" is the question that gets asked in the room right after someone says "our AI agent got something wrong." The honest answer is not a single number, and treating it as one is how businesses underestimate their real exposure. This article breaks the cost of an AI agent mistake into the four line items that actually appear on a small business's ledger after an incident, using two widely cited real cases as reference points, and sets out what changes each line's size.
Key takeaways
- An AI agent mistake produces at least four distinct cost lines: direct payout to the affected party, legal or regulatory sanction, internal incident response cost, and a renewal-time premium effect. Treating any one of these as "the cost" understates the real number.
- In Moffatt v. Air Canada, 2024 BCCRT 149, the tribunal-ordered payout totalled under CAD 812.02. The case became internationally cited not because of that figure, but because the tribunal rejected the argument that a chatbot could be treated as a separate, disclaimable entity.
- In Mata v. Avianca, the court imposed a USD 5,000 sanction on the lawyers who filed a brief containing AI-fabricated case citations, separate from any reputational and professional consequence that followed.
- Staff and adviser hours spent reconstructing what an agent was told, what it said, and what it did are consistently the largest and least visible cost line, and are directly reduced by having the agent log its inputs and outputs from day one.
- A claim, and in some cases a disclosed near-miss that never became a claim, can move a business into a higher pricing tier at the next insurance renewal, a cost that lands months after the original incident is closed.
Why "how much did it cost" is the wrong first question
Ask a founder what an AI agent mistake cost their business and most will quote the settlement, the refund, or the fine, because that is the number with a receipt attached. It is also, in almost every documented case, the smallest of the real costs involved. Insurance brokers who have handled AI-related claims describe a consistent pattern: the payout to the customer is negotiated and closed within weeks, while the internal cost of figuring out what actually happened, and the external cost of what the insurer does with that information at renewal, unfold over months and are rarely added back into the original tally.
This matters for a small business specifically because SMEs tend to have the least spare capacity to absorb the hidden lines. A large enterprise has a legal team and a dedicated compliance function that treats incident response as a fixed cost of doing business. A ten-person company does not, which means every hour spent reconstructing an incident is an hour not spent on the business, and every point added to next year's premium is a real line in a much smaller budget.
Line one: the direct payout, and why it is usually smaller than assumed
The case most frequently cited in this space, Moffatt v. Air Canada, is instructive precisely because the money involved was modest. Jake Moffatt asked Air Canada's website chatbot about bereavement fares after a family death, and the chatbot gave him incorrect information about how and when he could apply for the discount. Air Canada refused to honour the chatbot's advice after the fact, arguing, among other things, that the chatbot was "a separate legal entity that is responsible for its own actions." The British Columbia Civil Resolution Tribunal rejected that argument outright and ordered Air Canada to pay Moffatt CAD 650.88 in damages plus CAD 161.14 in tribunal fees and pre-judgment interest, a total under CAD 812.02.
That is not a figure that threatens a national airline's balance sheet, and it should not have been read as one. What made the case expensive for Air Canada, and for every other operator watching it, was not the award. It was the precedent: a tribunal explicitly closing off the argument that a company can point at its own customer-facing AI system and disclaim responsibility for what it said. That precedent is now cited in briefings, policy reviews, and underwriting conversations well beyond the original CAD 812.02, which is the real cost the case generated, just not one that appears on Air Canada's books.
For an SME, the lesson from the size of the Air Canada payout is not "this is cheap so it does not matter." It is that the direct payout for a single, contained customer-facing error is often manageable on its own. The problem is that it rarely arrives alone.
Line two: the legal or regulatory sanction
Mata v. Avianca shows a different, sharper cost line. A lawyer representing a client in a personal injury claim against Avianca used an AI tool to help draft a legal brief. The tool fabricated several case citations, complete with plausible-sounding names and quotations, none of which existed. The lawyer filed the brief without independently verifying the citations. When opposing counsel could not locate the cases, the fabrication came to light, and the presiding judge sanctioned the lawyer and his firm USD 5,000 under the court's inherent authority, in addition to requiring the lawyer to notify his client and the judges whose names had been falsely invoked in the fabricated opinions.
The USD 5,000 figure is a real, citable number, and it is a useful anchor for a specific kind of cost: the sanction a court, regulator, or professional body imposes for relying on unverified AI output in a formal, professional setting, separate from any damages owed to a harmed third party. For SMEs in regulated or professional-services contexts, including law firms, accountants, and recruitment agencies, this is the line most likely to apply, and it is a line that standard professional indemnity cover was not written to anticipate, because the loss originates from a professional conduct failure rather than from ordinary negligence.
The reputational half of this line does not carry a dollar figure, but professionals in Mr. Mata's position report that the professional consequence, being the subject of a widely circulated cautionary case, outlasts the financial sanction by years. That cost is real, is not covered by any insurance product, and should be weighed alongside the sanction figure when a business is deciding how much verification discipline an AI-assisted workflow actually needs.
Line three: incident response, the cost nobody quotes
Between the moment an AI agent mistake surfaces and the moment it is resolved, someone has to do a specific, unglamorous set of work: pull the conversation or transaction log, establish exactly what the agent was told and what it said or did, brief a lawyer or insurance broker on the facts, draft a response to the affected customer, and decide whether the incident meets any threshold that makes it reportable to a regulator, an insurer, or a data protection authority. None of that work shows up in a settlement figure, and all of it costs real money in staff time and, frequently, external legal or advisory fees.
The single biggest variable in how much this line costs is whether the agent was logging its inputs and outputs before the incident happened. A business that can pull a timestamped record of exactly what the customer asked, what data the agent had access to, and what it replied can usually close the reconstruction phase in hours. A business that has to reconstruct the same sequence from memory, screenshots, and a support agent's recollection of a conversation from three weeks ago can spend days on the same question, at proportionally higher cost, before the substantive response even begins. This is why logging is the first, cheapest control recommended after almost every documented AI agent incident, and why its absence is consistently the most expensive gap identified after the fact rather than before it.
What actually drives the size of the incident response bill
- Whether the agent logs inputs and outputs. A timestamped log turns a multi-day reconstruction into a same-day one.
- Whether a human reviewed the interaction before it reached the customer. Fully autonomous customer-facing responses generate longer investigations than agent drafts a person approved.
- Whether legal or broker advice was needed at all. A documented, low-severity error a business can resolve directly costs far less than one requiring outside counsel from the first hour.
- Whether the business had already mapped which regulator or insurer, if any, needed notifying. Deciding this in the moment, under pressure, is slower and more expensive than having the answer on file already.
Line four: what happens at your next renewal
The cost line SMEs most consistently miss is the one that arrives after the incident is already closed. Insurers writing professional indemnity, cyber, and general liability cover have, since 2025, been adding AI-specific questions to renewal questionnaires: what AI tools does the business use, what oversight exists, has there been an incident or near-miss in the past policy year. A paid claim is an obvious data point for the underwriter. A disclosed near-miss, an incident that did not result in a claim but that the business is required to disclose under the policy's notification clause, can also move pricing at renewal, even though no payout was ever made.
The practical defence against this is documentation, not silence. A business that can show an insurer exactly what went wrong, what was fixed afterward, and what new control, a logging requirement, a human sign-off step, an updated vendor contract, was put in place, is in a far stronger position to argue against a blanket premium increase than a business that discloses an incident with no accompanying record of what changed. Brokers who specialise in this space describe the difference in framing as the single most useful thing a small business can do between an incident and its next renewal conversation.
What this adds up to for a small business
Put the four lines together and the shape of the real cost becomes clearer than any single case study can show. A contained, one-customer AI agent mistake, of the kind the Air Canada case represents, might produce a direct payout in the hundreds of dollars, a reconstruction and response cost in the low thousands depending on how well the incident was logged, no formal sanction if no professional or regulatory line was crossed, and a modest but real effect on the next renewal quote. A mistake that crosses into a professional or regulatory context, of the kind the Avianca case represents, adds a sanction line that can run into the thousands, plus a reputational cost that resists being quantified but is reported by those who have lived through it as the most durable part of the whole episode.
None of these figures are projections or invented statistics. They are the documented outcomes of two widely cited cases, presented as reference points rather than as a universal price tag, because the actual cost of any specific incident depends on the facts, the sector, and the jurisdiction involved. What is consistent across both cases, and across the incident-response pattern more broadly, is that the headline figure is never the whole bill.
Before your next AI agent deployment goes further, it is worth running the three-question diagnostic on The Questions page to see where your own exposure sits across these four lines, and reviewing the pre-deployment insurance checklist for SMEs before the agent, not the incident, is the thing you are documenting. If a mistake has already happened, the first 72 hours response guide sets out the sequence that keeps the incident response line as small as it can be. For the underwriting side of this same picture, specifically how a European carrier prices a business's AI risk profile at renewal, see the companion analysis on what changes at AI insurance policy renewal on agentinsured.eu.
Frequently asked questions
What does an AI agent mistake actually cost a small business?
It is rarely one number. A typical incident stacks four separate cost lines: the direct payout or damages owed to the affected customer, which in the Air Canada case was a partial refund plus tribunal-ordered damages under CAD 812.02 in total; any legal or regulatory sanction, which in Mata v. Avianca reached USD 5,000 against the lawyers who filed the fabricated citations; the internal cost of incident response, meaning staff and adviser hours spent investigating, documenting, and responding, which for a small business commonly runs into the low thousands even for a contained incident; and a renewal-time cost, since a claim or a disclosed incident is now a data point insurers price into next year's premium. The single-case payout is often the smallest line on the list.
Was the Air Canada chatbot case actually expensive for the airline?
The tribunal award itself was modest. In Moffatt v. Air Canada, 2024 BCCRT 149, the tribunal ordered Air Canada to pay the customer CAD 650.88 in damages plus CAD 161.14 in tribunal fees and pre-judgment interest, a total under CAD 812.02. The financial exposure that made the case widely cited was not the award. It was the precedent: a tribunal explicitly rejecting the argument that a chatbot is a separate legal entity whose statements a company can disclaim.
Does my business insurance cover the cost of investigating an AI agent incident?
Sometimes, and it depends on wording most SMEs have not checked. Some professional indemnity and cyber policies include a defined sublimit for incident response or breach response costs, separate from the limit for damages paid to a third party. Many general liability and standard errors and omissions policies do not, particularly where an AI exclusion has been added at a recent renewal. Ask your broker directly whether your policy has a named incident response sublimit and whether any AI exclusion applies to it.
Will one AI agent incident raise my insurance premium even if my policy pays out?
It can. Insurers price renewals partly on claims history and increasingly on AI-specific risk questions added since 2025. A paid claim, or a disclosed near-miss, can move a business into a higher-risk pricing tier at the next renewal even where the original policy responded in full. Documenting what went wrong and what was fixed afterward is one of the few things a business can do to argue against that increase.
What is the single biggest cost driver after an AI agent mistake?
For most SMEs it is staff and adviser time, not the headline payout. Reconstructing what the agent was told and what it did is far cheaper if the agent already logs its inputs and outputs, and far more expensive if it does not, which is why logging is consistently the first control recommended after any AI agent incident.