Who's liable when your chatbot gets it wrong?
A German court has ruled a company owns what its website chatbot says — even if the bot was only ever fed correct information. What UK businesses should take from it.
A cosmetic surgery company in Germany put a chatbot on its website to book appointments and answer questions. Sensible enough — it’s exactly the sort of job these things are good at.
The chatbot told prospective patients that the company’s managing directors were “specialists in plastic and aesthetic surgery”, “specialists in aesthetic medicine” and “specialists in aesthetic treatments”. They held none of those titles. In Germany those are protected professional designations, and using them when you don’t hold them is unlawful.
On 12 May 2026, the Higher Regional Court of Hamm held the company liable for what its chatbot had said.
What the court actually decided
The consumer association Verbraucherzentrale Nordrhein-Westfalen brought the case against Aesthetify GmbH under German unfair competition law (case 4 UKl 3/25). The company had switched the chatbot off after receiving the warning letter, but refused to sign an undertaking not to do it again — so the case went ahead.
Its defence was the obvious one: we didn’t say that, the chatbot did.
The court rejected it. The chatbot, it held, is not a “third party” within the meaning of the law. And here’s the part that should give every business owner pause: the court said the company would bear responsibility for the false statements even if it had had the chatbot programmed exclusively with correct data.
It didn’t need to establish where the claim came from. Whether someone typed it in or the model invented it made no difference to the outcome.
The law firm DLA Piper, in its analysis published on 15 June 2026, reads this alongside a Canadian case as a possible direction of travel — while being careful to note that neither involves a high-level court and the German one is still open to appeal. Read with that caveat, its summary is worth quoting:
[The] two decisions may indicate a broader trend: courts effectively holding companies strictly liable for statements made by their chatbots on the companies’ own websites. Companies deploying chatbots in the commercial context may not be able to rely on arguments that those chatbots are third parties or that another company – such as a developer or a vendor – is solely responsible for what the chatbots say to consumers.
The company has been given leave to appeal to Germany’s Federal Court of Justice, so this isn’t settled. But nobody should be planning on the basis that it gets overturned.
It fits a pattern
The Canadian case DLA Piper has in mind is Moffatt v Air Canada, decided by British Columbia’s Civil Resolution Tribunal in 2024, where the airline’s website chatbot invented a bereavement fare policy. Air Canada argued the chatbot was a separate legal entity responsible for its own actions. That went about as well as you’d imagine.
In 2025, California passed AB 316, which bars defendants from arguing that an AI system autonomously caused the harm.
And in May 2026, the Regional Court of Munich I granted a preliminary injunction against Google over its AI Overviews, which had wrongly connected two Munich publishers to scams and shady dealings. Reports of the ruling say the court drew a distinction between AI Overviews, which generate new text loosely based on sources, and ordinary search results, which quote and link — and that the first makes Google directly responsible for the words. Reportedly, telling users to double-check AI results was not enough to escape liability.
Be careful with that last one. It’s a preliminary injunction from a regional court, it’s appealable, it isn’t binding precedent, and we’re relying on secondary reporting rather than the judgment. We mention it because the direction of travel matters more than any single case.
Where the UK actually stands
There is no UK AI Act. The King’s Speech on 13 May 2026 contained no AI Bill. The nearest measures were a Regulating for Growth Bill — introduced “to reduce the burden of unnecessary regulation through innovation”, and widely expected to be the vehicle for the government’s cross-economy regulatory sandbox — a Cyber Security and Resilience Bill, and digital ID legislation.
That doesn’t mean nothing’s coming. The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 were made on 16 April 2026 and came into force on 12 May. They require the Information Commissioner to prepare a statutory code of practice on using personal data in AI and automated decision-making. The duty to write it has already bitten; the code itself is what’s on the horizon. And a statutory code is not guidance you can politely ignore.
Meanwhile the ICO has been unusually clear about what worries it. Its tech futures report on agentic AI, published 8 January 2026, contains the line every business deploying this stuff should have pinned up somewhere:
Poorly implemented agentic systems will increase the risks of data protection harms. For example, this could include systems that: have no clear purposes; are connected to databases not needed for their tasks; or have no measures in place to secure access, monitor or stop activity, or control the further sharing of information.
And, flatly: “organisations remain responsible for data protection compliance of the agentic AI they develop, deploy or integrate in their systems and processes.”
The ICO can fine up to £17.5 million or 4% of annual worldwide turnover, whichever is higher. It hasn’t yet issued a fine specifically for a business’s deployment of AI. It has opened formal investigations into X and xAI over Grok, announced on 3 February 2026, and in the same month it fined Reddit £14.47 million over children’s privacy — a penalty Reddit has appealed to the First-tier Tribunal. The appetite is there.
There’s also a gap worth knowing about. Ofcom opened an investigation into X on 12 January 2026 under the Online Safety Act. In a separate statement in February it said that because of the way the Act relates to chatbots, it is currently unable to investigate the creation of illegal images by the standalone Grok service. The legislation wasn’t drafted with standalone AI chatbots in mind. Expect that to be fixed, and expect the fix to be broader than the problem.
What to actually do about it
None of this is a reason not to put a chatbot on your website. Plenty of ours are out there answering questions at two in the morning and doing a decent job of it. It’s a reason to treat the thing as something you publish, rather than something you install.
Constrain what it’s allowed to say. The Aesthetify bot produced professional credentials because nothing stopped it. A bot that answers only from your own approved content, and says “I’ll get someone to come back to you on that” for anything else, is less impressive in a demo and enormously safer in practice. This is the single biggest lever and most people skip it.
Never let it speak to price, eligibility or qualifications unscripted. DLA Piper names healthcare, finance, employment, law, insurance and consumer relations as the contexts where this bites hardest. If you’re regulated, or you make claims a regulator cares about, those answers need to be fixed text, not generated.
Log every conversation, and read some. You cannot defend what you can’t see, and you can’t improve it either. Half an hour a week reading real transcripts will teach you more about your customers than any analytics dashboard.
Say it’s a bot. Partly because it’s honest and people can tell anyway. Partly because if you sell into the EU, the AI Act’s transparency obligations are the near-term ones. The heavy high-risk requirements were pushed back under the AI Omnibus that came into force on 27 July 2026 — to 2 December 2027 for standalone high-risk systems, and 2 August 2028 for AI embedded in physical products. But the transparency side moved the other way: the grace period for implementing transparency solutions for AI-generated content was cut from six months to three, landing on 2 December 2026.
Give it a limit and a human. The ICO’s list is really one idea repeated: scope it narrowly, connect it only to what it needs, and make sure someone can watch it and stop it.
The uncomfortable summary is that the law is settling on a simple principle, and it isn’t the one the technology industry was hoping for. If it’s on your site, it’s you talking. “The AI made it up” is not a defence you can use!