← Back to Publications
Computer screen showing an error screen, referencing the ChatGPT technical outage
JULY 27, 2026

When ChatGPT Fails: the Legal Risk of Business Reliance on AI

This week "chatgpt" spiked in Google Trends Colombia, with search volume jumping more than 100%. The most likely explanation is not an exclusively Colombian phenomenon or a cultural novelty: it is a technical incident at OpenAI that sent thousands of people searching for the service to try to log in, check whether it was down, or understand what was happening. As a lawyer focused on economic criminal law and compliance, what interests me is not the search spike itself, but what it reveals about the legal exposure of companies that now depend on these tools to operate.

OpenAI acknowledged two active issues: intermittent errors loading or continuing conversations, whose mitigation remained under tracking, and failures generating images, on which it posted an update on July 27. The timing lines up with the search spike: the trend climbed sharply shortly after the failures were acknowledged. One point is worth clarifying, since it is often misread: the "20K+" in a trends report does not count users, it is aggregated search volume over a period; "+100%" means the query is running at roughly double its expected level, and "Active" means it is still trending above its usual baseline. These are public-interest metrics, not a census of affected users.

The legal question starts here: for any company that has integrated ChatGPT or another AI API into customer service, document drafting, or internal workflows, an outage like this is not an unforeseeable event — it is a perfectly foreseeable business-continuity risk that should have been addressed in the contract. Most AI providers' terms of service include weak or nonexistent availability guarantees and broad liability waivers, often invoking force majeure for any outage. The issue is not that the provider limits its own liability; it is that this waiver does nothing to protect the contracting company from its own clients when, because of the provider's failure, it cannot deliver on what it committed to deliver.

During an outage or a service restart, a relevant gray area also opens around personal data: what happens to conversations, documents, or information uploaded while the system was failing. Under Colombia's Law 1581 of 2012, the company using the tool remains the data controller before its own clients or employees, even when it delegates technical processing to a third party acting as processor. The AI provider's failure does not transfer or dilute that responsibility: if data is exposed or lost during the incident, the party that must answer to the data subject — and to the Superintendency of Industry and Commerce — is the contracting company, not OpenAI.

Which is why my recommendation to executives and compliance teams is concrete: before integrating any AI tool into a critical process, get legal advice on whether the contract defines availability levels with real consequences (not merely aspirational ones), whether there is a clear data processing agreement defining the provider's role as processor, and whether the company has a manual contingency procedure so it does not depend entirely on the system when it fails. A two- or three-hour outage should not become a contractual breach with your own client, and it won't — only if that contingency was designed beforehand, not during the failure.

This week's search spike is, on its own, a footnote: it will resolve within hours and become one more entry in OpenAI's incident history. What should not resolve within hours is the deeper question it leaves behind: how much business operation — and how much legal liability toward third parties — today depends on a service the company does not control and, often, has no contractual clause protecting it against. Due diligence is not googling "is ChatGPT down"; it is knowing, before that happens, who is liable and under what terms when the tool fails.

Pedro Bonett — Criminal Defense Attorney, Economic Criminal Law and Compliance