AI Governance for Chatbots, Copilots and AI Agents
At a recent conference, I saw an article displayed on screen about a case that should already be on the agenda of every board of directors, legal committee, and operations team: Moffatt v. Air Canada. In that case, a tribunal in British Columbia held Air Canada responsible for inaccurate information that a chatbot on its website provided to a customer. The central issue was not whether the chatbot had made a mistake, but who was accountable for it. The answer was clear: the company.
The case offers a strategic lesson for any organization incorporating artificial intelligence into its operations: chatbots, copilots, and AI agents are more than technology tools. They are extensions of the company’s operations, commercial activities, and reputation.
The question is no longer whether companies should use AI. The question is what governance framework guides that use.
From Emerging Technology to Business Risk
Over the past several years, companies have enthusiastically adopted AI tools: customer service chatbots, copilots for drafting documents, sales assistants, contract analysis systems, HR tools, compliance systems, and, more recently, agents capable of carrying out tasks with some degree of autonomy.
The problem is that many companies have treated these tools as ordinary productivity applications. Their implications extend much further.
When a chatbot responds to a customer, it may create expectations that carry contractual implications. When a copilot drafts a legal communication, it may introduce errors or unverified claims. When an agent automates decisions, it may affect rights, pricing, response times, regulatory compliance, or business relationships.
In other words, AI does not eliminate responsibility; it redistributes it within the organization. If that redistribution is not documented, supervised, and governed, the risk ultimately falls where it always does: on the company, its directors, and its governing bodies.
AI Governance Is a Business Necessity
AI governance is the set of policies, controls, roles, processes, and metrics that enables a company to use artificial intelligence safely, maintain traceability, apply safeguards proportionate to risk, and align its use with the business model.
Globally, regulation is moving toward classifying AI uses by risk level, imposing requirements that vary accordingly, and reinforcing principles such as transparency, human oversight, security, and accountability.
Although many Latin American companies are not yet subject to specific AI regulatory frameworks, international standards are evolving rapidly. AI governance will increasingly come under scrutiny in cross-border operations, technology contracting, data protection, financial services, consumer matters, employment, and compliance.
The message is consistent: companies can innovate, but they must be able to explain, control, and audit how they use the technology.
Three Risk Profiles for Chatbots Copilots and Agents
Not all AI carries the same risk. Effective governance starts by distinguishing the type of tool and its impact.
Chatbots interact directly with customers, users, or third parties. Their primary risk lies in the information they communicate. If they make promises, offer interpretations or recommendations, or influence a decision, they may expose the company to commercial, contractual, consumer protection, or reputational risks.
Copilots support internal teams by drafting, summarizing, researching, comparing, or preparing materials. Their primary risk is overreliance. When people fail to review, validate, or put the output in context, a copilot’s error becomes a professional error.
AI agents go a step further: they can take action, trigger workflows, respond to emails, update records, create tasks, or interact with systems. Their primary risk is autonomy. The greater their ability to act, the greater the need for boundaries, permissions, audit logs, and oversight.
Governance must be proportionate to risk. A tool that summarizes internal emails does not require the same controls as an agent that responds to customers, provides service quotes, or handles sensitive information.
The Guiding Principle Is That Accountability Cannot Be Delegated
An organization can outsource technology, but it cannot outsource its accountability to customers, regulators, or the market.
Every enterprise AI strategy should therefore start with five basic questions:
- Who authorized the use of this tool?
- What data does it use, and where does that data come from?
- What is it allowed—and not allowed—to say or do?
- Who reviews its output?
- How are errors, incidents, and corrective actions documented?
If a company cannot answer these questions clearly, it does not have AI governance. It is improvising with technology.
A Practical AI Governance Framework for Businesses
From a legal and strategic perspective, companies should build their AI governance around seven pillars.
Inventory of Tools and Use Cases
A company needs to know which AI tools are being used, by whom, for what purpose, with what data, and in which parts of the business. Many risks arise from “shadow AI”: employees using public tools without authorization, confidentiality safeguards, or basic security standards.
Risk Classification
Each use case should be classified according to its legal, financial, operational, reputational, and personal data implications. A tool used to brainstorm marketing ideas has a different risk profile from one used for legal advice, hiring, credit scoring, or handling customer complaints.
Clear Internal Policies
Policies should define permitted and prohibited uses, rules for handling confidential information, mandatory human review, evidence retention requirements, approval criteria, and consequences for noncompliance.
Meaningful Human Oversight
Human oversight cannot be a formality. A designated individual or team must be responsible for reviewing outputs, identifying errors, intervening when appropriate, and suspending use if the tool creates unacceptable risks.
Data Quality
AI fed outdated, incomplete, or inaccurate information can produce dangerously convincing results. AI governance also requires data governance: reliable sources, regular updates, access controls, and traceability.
Transparency With Users
When someone interacts with an automated system, the company should assess whether that fact needs to be disclosed. Transparency reduces legal risk and builds trust. In business, financial, legal, or customer service settings, concealing the use of AI can increase reputational exposure.
Incident Management
Every company using AI should have a protocol for handling errors: how they are reported, who investigates them, how they are corrected, when customers are notified, and what changes are made to the system. The worst-case scenario is not simply that a tool makes a mistake. It is that the company has no process for responding.
AI Requires a New Management Discipline
Artificial intelligence should not remain confined to the IT department. It requires involvement from executive leadership, legal, compliance, operations, HR, sales, and data teams.
At GLC Legal, we approach this issue with a clear conviction: the companies that benefit most from AI will not necessarily be those that buy the most tools, but those that best integrate technology, processes, people, and accountability.
AI can speed up operations, improve the customer experience, reduce friction, and create new business opportunities. Without governance, however, it can also multiply errors, erode trust, and create liabilities the company did not even realize it was assuming.
Latin America Needs an Ambitious and Disciplined Approach to AI
For Latin American companies, this is a particularly important moment. Our region has a tremendous opportunity to use AI to close productivity gaps, raise professional standards in service delivery, scale operations, and compete globally. Realizing that opportunity requires discipline.
The goal is to make innovation sustainable, without slowing it down.
A company that adopts AI without governance may gain speed for a few months while losing control. A company that adopts AI with governance can build a real competitive advantage through greater efficiency, traceability, trust, and better decisions.
AI Needs Clear Ownership Rules and Documentation
The Air Canada case reminds us of an essential point: when artificial intelligence speaks, responds, or acts on behalf of a company, the market sees the company behind it.
Leaders therefore need to ask more than which AI tool they plan to implement. The deeper strategic question is this:
Are we prepared to be accountable for what our AI says, recommends, or does?
The answer should not depend on luck. It should depend on governance.
BY Augusto Arce Marín
CEO of GLC Legal








