
AI and Australian Consumer Law: What Businesses Need to Know (2026)
Last updated: August 2026.
There is a comfortable assumption running through a lot of AI adoption: that a statement made by software carries less weight than one made by an employee. It is worth examining that assumption before your agent makes a representation you have to stand behind.
On This Page
Written by Dr Priya Jaganathan — Go High Level Certified Admin, Certified AI Tech Stack Consultant and keynote speaker. This is an operations guide, not legal advice. Australian Consumer Law obligations depend on your circumstances and you should take advice from a qualified lawyer.
The basic position
Australian Consumer Law, in the Competition and Consumer Act 2010, prohibits conduct in trade or commerce that is misleading or deceptive or likely to mislead or deceive. It also prohibits false or misleading representations about goods and services.
Nothing in that framework distinguishes between a statement typed by a staff member and one generated by a system that business configured and deployed.
The practical position most advisers would take is straightforward: it is your conduct. You chose to deploy the system, you configured what it could say, and the customer dealt with your business.
"The AI said it, not us" is not a distinction a customer will accept, and it is unlikely to be one a regulator or court finds persuasive either.
Where the risk actually concentrates
The risk is not evenly distributed. Four areas account for most of it.
Price representations. An agent quoting a price that has changed is making a representation about cost. This is the most common failure and usually stems from stale data rather than anything exotic.
Availability and timeframes. Telling a customer you can do something by a date you cannot meet is a representation about your service. Agents that promise turnaround times without checking real capacity create this routinely.
What the service includes. An agent describing inclusions generously — because the description it was given was loose — creates an expectation the customer paid for.
Invented detail. The hardest to catch. A system asked something beyond its data may produce a plausible, specific, wrong answer, and plausibility is precisely what makes it dangerous.
| Risk area | Usual cause | Design fix |
|---|---|---|
| Wrong price quoted | Stale price data | Single source of truth; quarterly review |
| Unachievable timeframe promised | No link to real capacity | Quote from live availability only |
| Overstated inclusions | Loose service descriptions | Precise wording, reviewed |
| Invented specifics | Asked beyond its data | Constrain; teach it to say "I don't know" |
| Undisclosed automation | Human name, no disclosure | Disclose at the start, plainly |
If you want your agent's claim surface reviewed before it causes a problem, book a CRM transition call — alongside proper legal advice.
Reducing the exposure by design
The most effective risk control is not better prompting. It is reducing what the system is permitted to assert.
An agent that states a call-out fee and books an inspection makes one narrow, verifiable claim. An agent that estimates a full job price makes a claim that depends on things it cannot see. The first is a design decision that removes a category of risk entirely.
Similarly, an agent that offers times from your live calendar cannot promise a slot you do not have. An agent that says "we can usually fit you in this week" can.
Every claim your system is allowed to make should be traceable to a specific, maintained data source. If you cannot point to where a statement comes from, the system should not be making it.
Then add the constraint that matters most: explicit instruction to say it does not know and offer a person, tested by asking obscure questions. Our guide on what to do when your AI agent gets it wrong covers the response side.
Consumer guarantees still apply
Worth noting separately because it is sometimes overlooked.
Australian Consumer Law provides consumer guarantees — that services will be provided with due care and skill, be fit for purpose, and be delivered within a reasonable time. Those apply to the service you deliver regardless of how the customer booked it.
Automating your booking process does not change what you owe the customer afterwards. Nor does it change your obligations if something goes wrong with the service itself.
And a customer who booked through an automated system has the same remedies as one who rang you, which is another reason to treat automated representations with the same care as spoken ones.
Practical steps
1. List every claim your agent can currently make. Prices, timeframes, inclusions, availability. Most businesses have never done this and are surprised by the list.
2. Trace each to a maintained source. Anything untraceable should be removed from the system's permitted scope.
3. Disclose the automation plainly. At the start, in clear language, with a route to a person.
4. Test adversarially before launch. Try to make it overstate, over-promise and invent. Fix what you find.
5. Review quarterly. What changed in pricing, services or capacity, and does the system know? Drift is the most common cause of an inaccurate representation.
6. Take advice. If your business is in a regulated sector or your agent makes substantive claims about your services, this is worth a conversation with a lawyer rather than a blog post.
Frequently Asked Questions
Are we responsible for what our AI agent tells customers?
Australian Consumer Law prohibits misleading or deceptive conduct in trade or commerce without an exception for software-generated statements. The prudent position is that representations made by a system you deployed are representations by your business. Take advice on your circumstances.
What if the agent quotes the wrong price?
You have made a representation about price. Most businesses honour it where the amount is reasonable, because the commercial cost of a dispute exceeds the margin, and it is also the response most consistent with the representation you made.
Where does most of the risk sit?
In four places: price representations, promised timeframes, descriptions of what a service includes, and invented specifics when the system is asked something beyond its data. Stale information causes most real-world instances.
How do we reduce the risk?
By reducing what the system is permitted to claim rather than trying to make it more accurate. An agent that states a call-out fee and books an inspection has a much smaller claim surface than one estimating full job prices.
Do consumer guarantees apply if someone books through AI?
Yes. Guarantees around due care and skill, fitness for purpose and reasonable time apply to the service you deliver regardless of how it was booked, and a customer who booked automatically has the same remedies as one who phoned.
Is undisclosed automation a legal problem?
Actively representing an automated system as a human employee sits uncomfortably against the prohibition on misleading conduct. Disclosure costs nothing and removes the question, which is a good reason to do it regardless of where the line sits.
Should we get legal advice?
If your agent makes substantive claims about price, timeframes or service inclusions, or if you operate in a regulated sector, yes. This article describes the general shape of the obligation, not your specific position.
If you're not sure what claims your agent is currently making, that's worth listing. Book a CRM transition call, or see how we work at Pivot 2 Thrive.
Related Articles
Services
Related guides
- What to Do When Your AI Agent Gets It Wrong
- Australian Privacy Principles and AI Agents
- AI Disclosure: What to Tell Your Customers
- When Not to Automate: Five Signs
More
