The chatbot invents facts. Who is liable? What the Hamm judgment means for AI agents
False specialist qualifications in a chatbot and new assistants from OpenAI, Meta and Grok: why businesses should separately control answers, approvals and actions.
From answers to actions
OpenAI introduced dots on 29 September 2026. Meta presented Muse on 8 September, while Grok Bot was announced on 11 August. According to their respective providers, these assistants can use their own computer and connected applications to carry out tasks. Approval mechanisms, access rights and availability differ. These are not three identical products, nor do they provide blanket permission for unsupervised action.
For businesses, this makes an existing question more pressing: what happens when AI tells a customer something false? And what changes when that answer becomes an email, an offer or a booking? The judgment below concerns the first question. Our recommendations for agents deliberately go a step further.
The case: specialist qualifications the doctors did not hold
A company provided aesthetic treatments. When asked, its website chatbot confirmed specialist qualifications for its physician managing directors, although they had not completed the relevant specialist training. The answers also offered appointment booking. The human-written website copy did not make those claims. The court was therefore examining a chatbot error in its own right, rather than merely the repetition of a misleading web page (paras 3 to 15).
The Higher Regional Court of Hamm treated the answers as the company’s own commercial practices. The bot was a communication tool deployed by the company, not an independent third party. Automated generation did not prevent attribution (paras 63 to 77). The misleading statements were relevant to patients’ treatment decisions (paras 98 to 104).
What the judgment decides, and what it leaves open
The company was ordered to cease the statements and pay a flat EUR 260 in warning-letter costs plus interest. This is not a damages judgment against the doctors personally. Permission to appeal on points of law was granted; the official publication now marks the judgment as final. Our research did not identify a subsequent published decision overturning this ruling.
The court expressly left open whether errors provoked by tendentious user questions might require different treatment. In this case, the questions were neither tendentious nor suggestive (para 96). Nor did the court decide private AI use, autonomous orders or every conceivable loss caused by language models. Reducing the ruling to “the operator is always liable” omits these limits.
Why correct source material is not enough
The company relied, among other things, on its accurate source information and its inability to control each individual answer. That did not protect it in this case. For foreseeable questions about practitioners’ qualifications, the court considered safeguards before launch reasonable (paras 89 to 95). It also rejected the assumption that users would invariably fact-check AI answers themselves (para 104).
Our practical conclusion is to test the actual answers produced. Include straightforward questions about prices, authorisations, qualifications and service limitations. A warning about possible AI errors should not replace this assessment. Whether a particular notice affects the likelihood of deception in an individual case is a separate question from the effectiveness of technical safeguards.
AI agents: three assessments rather than one liability formula
Our assessment for more advanced agent workflows is to distinguish public statements, legally relevant declarations and internal data actions. An invented certification in a customer answer raises different questions from a dispatched offer or an incorrect CRM change. The Hamm judgment cannot be applied to all three without examining the particular facts.
Consider a hypothetical case: a sales assistant reads an outdated price list, quotes the wrong price to a customer and then sends an order confirmation. The advertising statement, possible contract formation and responsibility as between the business and its technical supplier need separate examination. An approval log can help reconstruct events. It does not replace legal assessment.
What businesses should define before deployment
The following list sets out our recommendations for organising deployment. It is not a universal checklist mandated by the court or a guarantee against legal infringements.
- Authoritative information: which price lists, qualifications and service descriptions may the AI use, and who keeps them current?
- Action permissions: may the assistant only draft, or also send, book, publish and change data?
- Approvals: which commitments and expenses require a designated responsible person? Critical limits should be enforced technically.
- Incident process: preserve relevant answers and configuration, restrict affected functions and obtain an assessment of claims. Do not hastily sign a pre-drafted cease-and-desist undertaking.
Sources & further information
- Hamm Higher Regional Court, judgment of 12 May 2026, 4 UKl 3/25: official full text ↗
- Section 5 German Act Against Unfair Competition: misleading commercial practices ↗
- OpenAI: Introducing dots, 29 September 2026 ↗
- Meta: Introducing Muse, 8 September 2026 ↗
- Grok Bot: announcement of 11 August 2026 ↗
- Related reading: AI books a service. Who is bound by the contract? ↗
This article provides general guidance. The options available depend on your specific situation.