· Messy Works

AI self-healing is powerful. It still needs a human in the loop, 24x7

Real incidents show what happens when an AI support system acts with no human positioned to catch it first, and where the line should sit.

Automated systems that spot a problem and fix it before a person even notices are one of the genuine, non-hype benefits of applying AI to IT operations. A service that restarts itself, reroutes traffic around a failing node, or rolls back a bad deployment without waking anyone up is a real improvement on the alternative, which is a human finding out only once customers do.

The evidence for where this goes wrong is not hypothetical. It is a growing list of companies that let an AI system speak or act on their behalf without a human positioned to catch it first.

When nobody was watching

DPD, 2024. A frustrated customer got DPD’s support chatbot to swear at him and write a poem calling DPD “the worst delivery firm in the world.” DPD’s explanation was that an error had followed a system update. It disabled the AI element the same day.

Air Canada, 2024. A customer asked Air Canada’s website chatbot about bereavement fares. The bot told him he could apply for a discount retroactively after booking. That was wrong, and contradicted Air Canada’s own policy stated elsewhere on its site. When the customer tried to claim it, Air Canada told Canada’s Civil Resolution Tribunal that the chatbot was a separate entity responsible for its own words. The tribunal disagreed:

“It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.”

Air Canada was ordered to pay damages.

Cursor, 2025. Users of the AI coding tool Cursor started getting logged out when switching devices, the result of a genuine bug in how sessions were managed. When they asked support what was going on, an AI support agent told them that Cursor’s policy now restricted accounts to one device. There was no such policy. People cancelled paid subscriptions over a rule that never existed, before Cursor’s co-founder corrected the record in public and confirmed the affected developer got a refund.

None of these three companies set out to let an unsupervised system make promises, invent rules, or insult customers. Each one put an AI system in a role that could speak with the company’s authority, and did not put a human between the system’s output and the person receiving it, until after it had already gone wrong in public.

The pattern underneath

Look at what these have in common. In every case, the AI was confidently wrong, not uncertainly wrong. It did not flag doubt or ask for a human to check first. It answered as though it knew, because that is what these systems are built to do, and the honest answer, “I don’t know, let me find out,” is not something you get by default.

That is precisely why self-healing infrastructure and AI-assisted support are worth having and worth watching closely. An automated system that quietly fixes a server fault is not making a promise to a customer. An automated system that states your refund policy, or decides which alert does not need a human, is doing something closer to acting on your behalf, in public, in real time.

Automate the fix. Keep a human on the decision.

None of this is an argument for turning AI support and AI operations off. It is an argument for being precise about which parts run themselves and which parts need a person with the authority to say “wait.”

In practice that means a small number of clear rules. AI can act freely on anything reversible and low-stakes, like restarting a service or clearing a cache. Anything that touches money, a customer commitment, or data it is about to delete needs a human to confirm before it happens, not to review it afterwards. And that human needs to actually be reachable at 3am on a Sunday, not just during business hours when the incident happens to be convenient.

That is the case for 24x7 cover that is not purely automated. Self-healing catches the routine failures fast. A person catches the one nobody anticipated, before it becomes a tribunal case or a viral screenshot.

← All insights