Can companies escape chatbot liability through careful training?
Whether a company's liability for its chatbot's false statements can be reduced or eliminated by investing in accurate training data and proper programming. This matters because it shapes how organizations should budget for AI deployment risk.
Germany's Higher Regional Court of Hamm (OLG Hamm, Judgment of May 12, 2026 – I-4 UKl 3/25) ordered a cosmetic surgery clinic to cease and desist after its website chatbot told a user that the clinic's two managing directors were "specialists in plastic and aesthetic surgery" and "specialists in aesthetic medicine" — titles neither doctor actually held. The clinic had shut the chatbot down but refused to issue a cease-and-desist declaration, so the court ruled on the merits: the chatbot's incorrect responses were "misleading commercial acts by the company itself" under Section 5(1) and (2)(3) of the German Unfair Competition Act (UWG).
The court's reasoning rests on two points the summary calls out explicitly. First, "the chatbot is not to be regarded as a 'third party' within the meaning of competition law" — it is part of the company's business organization, so its statements are attributed to the operator directly, not treated as an independent actor's speech. Second, and more consequential, "even correct programming does not preclude liability": the summary notes that the ruling applies even if the chatbot were trained exclusively on accurate data sets, the company would still answer for a false output. The Swiss law firm's gloss is the old doctrine applied to a new tool: cura in eligendo, instruendo, custodiendo — the company must carefully select, instruct, and supervise the AI it deploys, just as it would an employee or contractor.
This cuts in the opposite direction from Does the UN panel misframe the OpenAI breach as alignment?, where the UN panel's brief recast a corporate security failure as a technical alignment problem, sidelining the deploying organization's liability. OLG Hamm does the reverse: it refuses to let training quality or technical correctness function as a defense, and keeps responsibility squarely on the company that put the chatbot on its site. It also sharpens Can three-tier AI oversight actually prevent deployed system harms?, whose company-side duty was pre-deployment testing — this ruling extends that duty into the post-deployment output itself, under ordinary national competition law rather than the AI Act. The liability pattern also differs from Do small law firms misuse AI more often than large ones?, where the exposed party was the practitioner who submitted AI output into a legal filing; here it is the company that deployed the chatbot to the public, with no intermediary human reviewing each answer before a customer saw it.
The excerpt establishes a national unfair-competition holding, not a general theory of AI liability: the ruling is "not yet final," and the Senate granted leave to appeal to the Federal Court of Justice precisely because of "the particular significance of the issues regarding the attribution of false statements made by chatbots." The extensions to GDPR, the AI Act's Article 50 disclosure duty, e-commerce law, and personality/trademark rights are the law firm's forward-looking commentary, not holdings the court reached. What the ruling does establish, at least for German (and the firm argues, likely Swiss) unfair-competition law, is that accurate training data is not a liability shield — which implies companies deploying customer-facing chatbots need output-level monitoring (filters, guardrails, escalation, spot checks) rather than relying on input-side quality control alone.
Inquiring lines that read this note 4
This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.
What governance mechanisms can effectively constrain widely deployed AI systems? What enables conversational agents to guide rather than just respond? How can AI systems reliably guide voters without introducing political bias?Related concepts in this collection 4
This note in its neighbourhood — explore the map, then jump to a related concept in the list below.
Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph
-
Does the UN panel misframe the OpenAI breach as alignment?
Examines whether the UN's AI panel incorrectly diagnoses the OpenAI-Hugging Face breach as a model alignment failure rather than a corporate oversight failure, and what that framing obscures.
contrast: this ruling assigns responsibility to the deploying company rather than recasting the harm as a technical problem
-
Can three-tier AI oversight actually prevent deployed system harms?
A 2026 call by the European Commission and 22 national leaders proposes mandatory company testing, government incident reporting, and a UN exploratory institution. The question is whether this tiered approach can address risks from AI systems already in operation.
extends the companies' pre-deployment testing duty into post-deployment output liability under competition law
-
Do small law firms misuse AI more often than large ones?
A database of 114 court cases with AI-tainted filings shows 90 percent involved small or solo firms. But does this reflect higher misuse rates, or simply better detection of errors in smaller practices?
a different liability pattern: the deploying company itself, not an intermediary practitioner, bears the exposure here
-
Can a company escape chatbot liability by calling it separate?
When an AI chatbot deployed by a company gives customers wrong information, can the company disclaim responsibility by treating the chatbot as an independent entity? This matters for how AI deployment affects corporate liability.
Evidence for: a Canadian tribunal independently reached the same liability result, rejecting the separate-entity defense for chatbot misstatements
Related papers in this collection 8
Papers most semantically related to this note, ranked by cosine similarity in the embedding space.
- Liability for AI: German court takes action (OLG Hamm I-4 UKl 3/25)
- Moffatt v. Air Canada, 2024 BCCRT 149 (McCarthy Tetrault summary)
- Steering LLM Viewpoints through Fabricated Evidence Injection
- Are Customers Lying to Your Chatbot?
- ProsocialDialog: A Prosocial Backbone for Conversational Agents
- The UN's AI Panel Sees Misalignment. We See Corporate (Mis)Behavior.
- Psychological Influences of Conversational AI: Research and Design Directions for Reducing Harm and Promoting Well-Being
- The Insanity of Relying on Vector Embeddings: Why RAG Fails
Original note title
OLG Hamm rules a company is liable for its chatbot's false statements regardless of how accurately it was trained