Who is liable for false statements made by AI chatbots?
The company that deploys the chatbot. Following the judgment of the Higher Regional Court (OLG) of Hamm of 12 May 2026 (case 4 UKl 3/25), answers given by an AI chatbot on a company's own website are attributed to the operator as its own commercial communication. Fault is irrelevant under German unfair competition law – the company is liable even for statements the AI simply invented.
With this decision, a question lawyers have debated since the launch of ChatGPT has been answered by a German appellate court for the first time. It affects everyone who delegates customer communication to an AI system: from the product advisor bot in an online shop to the service assistant on a clinic website. What exactly was decided, why the usual lines of defence fail, and which measures make sense now – step by step.
The case: a chatbot invents medical specialist titles
The claimant was the consumer protection association of North Rhine-Westphalia (Verbraucherzentrale NRW); the defendant operates several clinics for aesthetic medicine. The website chatbot answered questions about the physicians' qualifications – and attributed specialist titles to them that they do not hold. Some of the titles it named do not even exist in the German medical training regulations. To patients it sounded like verified credentials; in reality, the AI had generated the claims.
The defendant relied on an argument many companies consider solid: only correct data had been fed into the system, so the false answers were autonomous behaviour of the AI. The court rejected this. The full judgment is published on the official North Rhine-Westphalia court portal (in German), with a summary by the German Wettbewerbszentrale.
The court's key findings
- ▸An AI chatbot is not a third party but a tool of the company. According to the court, its statements are “in principle to be judged no differently than oral or written statements of the advertiser itself”.
- ▸Liability does not depend on fault: whether the company knew about the false statement or tried to prevent it is irrelevant for injunctive relief under the German Unfair Competition Act (UWG).
- ▸The company is liable as the perpetrator of a misleading commercial practice – not merely as an intermediary that failed to supervise someone else's conduct.
- ▸Engaging an external IT service provider does not help either: its contribution is attributed to the operator under Section 8(2) UWG.
- ▸Carefully curated training data and technical safeguards do not change the attribution – they reduce the risk, but they do not remove the responsibility.
The judgment is not yet final. Because of its fundamental importance, the court allowed an appeal to the Federal Court of Justice (BGH). For day-to-day practice this changes little: until a higher court rules otherwise, the attribution of chatbot statements is the standard companies must plan for. A legal analysis is available from LTO (in German).
Why disclaimers and the black-box argument do not protect you
The notice “AI can make mistakes” now sits under almost every chat window. As a liability shield it is worthless. Whoever advertises in the course of business must stand behind the accuracy of their claims; a blanket caveat does not make a misleading statement lawful. The same applies to the black-box argument that nobody can predict what a generative AI system will output in a specific case. In the court's view, precisely this unpredictability is not a defence – it is the risk the operator knowingly accepts by deploying the chatbot.
Prompt rules and keyword filters, which the defendant also relied on, did not exonerate it either. Such measures are still worthwhile: they substantially reduce the likelihood of false statements – they just do not shift the legal responsibility away from the company.
Not an isolated case: Air Canada and the Kiel Regional Court
The Hamm decision fits an international pattern. In Canada, Air Canada had to honour a discount its chatbot had invented – the tribunal rejected the argument that the bot was a separate entity responsible for its own information. And as early as February 2024, the Regional Court of Kiel (case 6 O 151/23) held a business information portal responsible for AI-generated false information about a company. Whoever relies on automatically generated content is liable for it – this principle is taking hold across jurisdictions.
What is at stake
Misleading chatbot answers can be attacked like any other advertising claim. Competitors, business associations and consumer protection bodies can issue formal warnings (Abmahnung). What follows: a cease-and-desist declaration with contractual penalties, court and legal fees in case of dispute, and potentially damages. Regulated industries face an extra layer: if a bot promises healing effects for a food supplement or overstates medical services, German health advertising law and the EU Health Claims Regulation come into play – more on that in our guide to chatbot compliance.
The German IT law firm IT-Recht Kanzlei titled its analysis of the ruling “the new warning-letter trap: AI chatbots” – for good reason: a chatbot produces dynamic statements in unlimited numbers, and every single one can be an infringement. The attack surface grows with every conversation.
How to reduce your liability risk: 6 measures
- ▸Proactively test the answer repertoire: systematically ask your bot the questions customers would ask – including the uncomfortable ones. Legal commentators explicitly recommend testing the response behaviour “as far as possible” before things go wrong.
- ▸Curate the knowledge base: the bot should answer from a maintained, verified data source instead of free-styling from the language model or an unfiltered website crawl.
- ▸Set guardrails: define topics the bot must not make claims about (qualifications, health effects, prices, legal advice), with fixed fallback answers.
- ▸Build in escalation: for sensitive questions the bot should hand over to a human instead of improvising.
- ▸Monitor continuously and document it: for learning systems, recurring checks are mandatory – documented test runs help you prove diligence in a dispute.
- ▸Implement the transparency duties: since 2 August 2026, the EU AI Act additionally requires chatbots to identify themselves as AI – all details in our guide to the AI labelling obligations.
Our verdict
“The AI did it” does not work in court. If you operate an AI chatbot on your own website, you legally adopt its statements as your own – with all consequences of unfair competition law. That does not make chatbots too risky to use. It makes a chatbot a piece of corporate communication that deserves the same quality control as website copy or ad campaigns: verified content, clear boundaries, regular checks. What such an audit looks like in practice is covered in our guide to the AI statement audit.
Transparency note: this article summarises publicly available court decisions and legal commentary. It is not legal advice for your individual case – for concrete disputes, consult a specialised law firm.
