Submit incident
Documented

New York City Deployed a Chatbot to Help Businesses Follow the Law. It Told Them to Break It.

January 1, 2024
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiaaic:AIAAIC1419View source ↗
LinkedInX

What happened

New York City deployed a Microsoft-powered AI chatbot in early 2024 with a specific mandate: help businesses understand and comply with the rules governing how they operate in the city. By March 2024, reports showed it was giving wrong advice, and in several cases steering users toward conduct that would put them on the wrong side of city law.

The launch was not a quiet experiment. Mayor Eric Adams described the technology as a once-in-a-generation opportunity to more effectively deliver city services, and the chatbot was framed publicly as a legitimate, trusted channel for businesses seeking guidance on compliance. That official positioning is what made the failure matter beyond the technical. A tool quietly put online and found to be wrong is a software problem. A tool put online with mayoral endorsement and presented as authoritative, then found to be wrong, is a public-trust problem.

The risk built into this specific deployment is not hard to describe. Businesses consulting a city-run chatbot to understand labor rules, licensing requirements, or other regulatory obligations have no structural reason to doubt what it says. The interface presents confident answers. The source is the city itself. When the underlying output is wrong, the user has no signal that tells them to verify before acting. That is the precise gap that makes AI deployment in compliance-adjacent contexts dangerous: the surface-level experience of using a tool is the same whether the answer is accurate or fabricated.

The legal exposure that follows lands on the business, not on the system. A company that acts on bad advice from a city-run chatbot cannot cite that advice as a defense when a regulator finds a violation. The chatbot gave the guidance and the business followed it, but the record that would make that trail visible simply does not exist in most deployments. There is no log the business can point to, no timestamp on the recommendation, and no way to reconstruct what the tool actually said when the question was asked.

That asymmetry is what the documentation gap in incidents like this one makes concrete. When a system gives compliance guidance with no log of what it said, no linkage to a verified source, and no audit trail a business or regulator could later inspect, there is no provable record of what the system did. Accountability requires that record: not just knowing that a chatbot was running, but being able to show exactly what it told a specific user, when, and whether what it said was accurate. Without that layer, the next miscalculation lands just as silently as the last.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AIAAIC Repository
Also catalogued in
New York City Deployed a Chatbot to Help Businesses Follow the Law. It Told Them to Break It.
2024