The Bot Desk
Prices checked Sep 2026

Who Is Liable When Your Automation Makes a Mistake

Published terms from OpenAI, Zapier, Make and UiPath disclaim warranties and exclude lost profits, lost data and business interruption, then cap what is left at fees paid or a flat $1,000. The practical loss, and the regulator's attention, stays with the business running the workflow.

The Bot Desk staff · September 2, 2026 · 9 min read

When an automation makes a costly mistake, the loss almost always lands on you. The vendor's terms disclaim warranties, exclude exactly the kind of damages a broken workflow produces, and cap whatever is left at a number that is usually small — sometimes a fixed $1,000, sometimes twelve months of what you paid. Meanwhile the regulator, the customer and the counterparty all deal with your company, not the software.

This is not a scandal. It is the standard allocation of risk in American commercial software, it is disclosed in documents you can read before signing, and almost nobody reads them. Here is what four widely used vendors actually publish.

What the terms say

Vendor / agreementWarrantyCap on liability
OpenAI — Services Agreement (business terms)"THE SERVICES ARE PROVIDED 'AS IS.'"Total amount paid to OpenAI in the 12 months before the event
Zapier — Terms of Service"THE SERVICE IS PROVIDED STRICTLY ON AN 'AS IS' AND 'AS AVAILABLE' BASIS"Fees paid during the current subscription term
Make — Master Service Agreement (Celonis, Inc.)Limited express warranty for paying subscribers; otherwise "'AS-IS' WITHOUT WARRANTY OF ANY KIND""$1,000.00" where exclusion of liability is prohibited by law
UiPath — Community Agreement (free tier), version dated 27 July 2026Software "provided on an 'AS-IS' and 'AS AVAILABLE' basis""ONE THOUSAND (1,000) USD"

Take OpenAI's business terms as the fully articulated version. Beyond the "as is" line, the agreement disclaims any "REPRESENTATION, WARRANTY OR GUARANTEE THAT SERVICES WILL MEET CUSTOMER'S REQUIREMENTS OR EXPECTATIONS, THAT CUSTOMER CONTENT WILL BE ACCURATE, THAT DEFECTS WILL BE CORRECTED." The cap reads: "EACH PARTY'S TOTAL LIABILITY UNDER THE AGREEMENT WILL NOT EXCEED THE TOTAL AMOUNT CUSTOMER PAID TO OPENAI DURING THE TWELVE MONTHS IMMEDIATELY PRIOR TO THE EVENT GIVING RISE TO LIABILITY."

Advertisement

Zapier's Terms of Service follow the same architecture: neither party is liable "FOR ANY... INDIRECT, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, SPECIAL... DAMAGES," with the cap set at fees actually paid during the current subscription term.

The two fixed-dollar caps are worth sitting with. Make's published Master Service Agreement, which names Celonis, Inc. as the contracting entity, provides an express limited warranty to paying subscribers and then states that where an exclusion of liability is prohibited by law, "OUR TOTAL AGGREGATE LIABILITY SHALL NOT EXCEED $1,000.00." UiPath's Community Agreement — the free tier, in the version dated 27 July 2026 — says "IN NO EVENT SHALL UIPATH AND ITS AFFILIATES' TOTAL LIABILITY... EXCEED ONE THOUSAND (1,000) USD," after excluding "LOSS OF PROFITS, REPUTATION, USE, OR REVENUE, LOSS OR CORRUPTION OF DATA, OR INTERRUPTION OF BUSINESS."

Negotiated enterprise agreements can and do differ from the published self-serve terms. But the published terms are what governs you unless you signed something else, and most small businesses did not.

The exclusions are the whole story

People fixate on the cap. The exclusion of consequential and indirect damages does more work.

Think about what actually goes wrong when a bot fails. A billing automation double-charges 400 customers: the loss is refunds, chargeback fees, churn and a week of staff time. A sync misfires and overwrites your CRM: the loss is data and the revenue attached to it. A scheduled filing does not run: the loss is a penalty. Every item in that list is lost profit, lost revenue, lost data or business interruption — the exact categories the standard clause excludes.

What is left after the exclusions is direct damages, which for a software subscription usually means something close to the subscription fee. Then the cap applies to that. The recovery is small by design.

Advertisement

Caps normally have carve-outs. OpenAI's cap does not apply to gross negligence, willful misconduct, indemnification obligations, or payment obligations. When you read any agreement, find the carve-out list — it tells you what the vendor was unwilling to disclaim, which is a decent proxy for what it takes seriously.

Why US law lets this stand

Limitation-of-liability clauses between businesses are ordinarily enforceable. The framework most often cited is Uniform Commercial Code section 2-719, adopted in some form by every state. As enacted in New York, subsection (3) reads: "Consequential damages may be limited or excluded unless the limitation or exclusion is unconscionable. Limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable but limitation of damages where the loss is commercial is not."

Read that last clause again. Where the loss is commercial — your business losing money — the limitation is not presumed unconscionable. That is the default the whole SaaS industry is built on.

Two caveats, both genuinely unsettled at the edges. First, UCC Article 2 governs transactions in goods, and courts have not reached one answer on whether a cloud subscription is a good, a service, or a license; the analysis can differ by state and by contract. Second, subsection (2) provides that "where circumstances cause an exclusive or limited remedy to fail of its essential purpose, remedy may be had as provided in this Act" — and courts disagree about whether a remedy failing its essential purpose also knocks out a separate consequential damages exclusion. If you are in a dispute that turns on either point, that is a question for your attorney and the law of your state, not for a checklist.

Indemnity runs the other way

The same agreements that limit what you can recover typically obligate you to defend the vendor. Zapier's terms state: "YOU AGREE TO DEFEND ZAPIER... AND INDEMNIFY... FROM AND AGAINST ANY AND ALL LOSS, COSTS, DAMAGES... ARISING OUT OF OR RELATED TO (I) YOUR VIOLATION... OF THESE TERMS, OR (II) CUSTOMER CONTENT."

The same agreement also assigns you the risk of the connections you build: "If you choose to grant a Third-Party Service any access to your Zapier Account, you are solely responsible for that Third-Party Service having access to your data, including Customer Content." In a multi-app workflow, that is most of the surface area.

The contract limits what you can get back. It does not limit what you owe everyone else.

Regulators deal with you

Contract terms allocate risk between two companies. They do not bind a regulator or your own customers.

The FTC has made this concrete. In its 2014 case against GMR Transcription Services, the Commission alleged the company "never required the individual typists it hired as contractors to implement security measures, such as installing anti-virus software," after a service provider stored and transmitted files in clear text on a server accessible online without authentication. The settlement required GMR to build a security program covering information "the company provided to independent service providers." The vendor's failure; the client's order.

Where a specific rule applies, the obligation is written down. The FTC's Safeguards Rule, at 16 C.F.R. § 314.4(f), requires covered financial institutions to "select service providers with the skills and experience to maintain appropriate safeguards," to spell out security expectations in the contract, and to periodically reassess them. Choosing badly is itself the violation.

So where does the risk land

On the business operating the automation, in almost every direction that matters: refunds and remediation to your customers, penalties for missed filings, regulatory exposure for data you were responsible for, breach of your own contracts, and the staff time to unwind it. What you can recover from the vendor is a fraction of that, and it is capped.

Which suggests a short set of habits rather than a legal strategy:

  1. Read the cap before you build. If a workflow can create six-figure exposure, do not put it behind a tool whose aggregate liability is $1,000.
  2. Gate irreversible actions. Payments, mass sends, deletions and filings should require a human approval step. Approval is cheap; reversal is not.
  3. Set volume limits. Most catastrophic automation failures are a small error executed thousands of times. A ceiling on records per run converts a disaster into an incident.
  4. Reconcile. A daily check that counts what the automation did against what it should have done finds problems in hours instead of at month end.
  5. Keep logs you can export. If you have to prove what happened, you will need them, and the vendor's retention window may be shorter than your problem.
  6. Ask your broker about coverage. Technology errors and omissions and cyber policies exist precisely because contractual recovery is limited. Whether your current policy responds to an automation error is a question worth asking before you need the answer.
  7. Negotiate when the stakes justify it. Caps, indemnities and security terms are negotiable at contract sizes where a vendor has a sales team.

The Bot Desk publishes information, not legal advice. We are not a law firm, and nothing here creates an attorney-client relationship. Contract terms change, vendors publish different agreements for different plans, and enforceability turns on the law of your state and the facts of your situation — have a qualified attorney review any agreement you are relying on.