When your bot promises a $1 truck: jailbreaks and output liability

July 22, 2026

We’ve covered attackers who run up your bill and attackers who hijack your bot. This one closes the abuse module with a different kind of damage entirely: not what it costs, but what it says — and what that commits you to.

Three that actually happened

The costly thing your bot says isn't a number — it's a promise.

The through-line, and courts are now saying it explicitly: you are responsible for your bot’s output. “The AI said it, not us” is not a defense. Every word your bot emits is an official statement from your company.

Two risks, one root

The defenses (same shape as the whole series)

You can’t make the model perfectly well-behaved, so you bound what its output can do and commit you to:

The pattern, one last time for the module

Every abuse lesson has landed on the same place: don’t rely on the model behaving. Whether the threat is a runaway loop, an injection, a freeloader, or a jailbreak, the durable defense is deterministic boundaries around what the model’s output can reach, spend, and commit you to. A jailbroken bot that can’t bind you to anything is an embarrassment; a jailbroken bot that can is a lawsuit.

Next in the series — the security base (Module 3): keys, token-aware rate limiting, and auth on AI endpoints — the fail-closed plumbing underneath all of this, and the part my background is built on.


If your bot can quote a price, state a policy, or take an action, it can be talked into the wrong one — and putting deterministic boundaries around what it can commit you to is exactly what I do. Every message comes straight to me — I read and reply to each one myself, usually within a day, and what readers send shapes what I build next. It’s just me for now, so that’s genuinely true; it won’t be forever. Send me your bot and I’ll show you what it can currently promise on your behalf — free, within a business day.

Free live workshop: cap your AI spend (Oct 8)

A hands-on 90-minute session — wire a fail-closed spend cap + cost-aware rate limiting against a real stack, live, so a leaked key or runaway agent can't run up your bill. Full details & times → Save your seat (and get each new lesson as it lands):

Double opt-in — one email to confirm. The lessons are free; the course is optional. No spam, unsubscribe anytime.