AI chatbots are legally permissible in Germany, and companies have long been using them widely in customer service. However, permissible does not mean without obligations. An AI chatbot does not operate in a legal vacuum, and a recent ruling has demonstrated just how far the operator's responsibility extends. Those who understand the legal situation can set up their chatbot so that it reduces workload without creating a liability risk.
Three areas of law define the framework: data protection, the transparency obligation under the EU AI Act, and liability for the chatbot's statements. The third has been much more clearly defined since May 2026.
In short: permissible, but with three obligations
An AI chatbot is permitted as long as it meets three requirements. It must process personal data in accordance with the GDPR. It must be recognizable to the user as an AI system, as required by the EU AI Act. And its information must be factually correct and permissible under competition law, as the operator is liable for it just as they would be for their own statements.
The first two points are well known. The third has gained weight due to case law.
The OLG Hamm ruling: Operators are liable for chatbot statements
With its judgment of May 12, 2026 (Ref. 4 UKl 3/25), the Higher Regional Court (OLG) Hamm decided that a company is fully liable for the false statements made by its AI chatbot. Legally, a chatbot is considered a tool of the company; its outputs are directly attributed to the operator as their own commercial action.
In the decided case, a provider in the field of aesthetic medicine had a chatbot on its website through which interested parties could ask questions and book appointments. Upon inquiry, the chatbot named specialist titles for the treating physicians that did not exist or were not held as such. The information was entirely fabricated. The Consumer Association of North Rhine-Westphalia (Verbraucherzentrale Nordrhein-Westfalen) warned the company for misleading advertising and was upheld by the OLG Hamm.
Two points from this decision are important for operators. Liability applies regardless of fault, meaning it does not matter whether the operator is at fault for the selection or monitoring. Furthermore, the defense that the chatbot was trained with correct data is not sufficient for the court. Even with carefully curated training data, the responsibility for the specific output in individual cases remains. A hallucination of the model does not exonerate the operator.
The ruling is not yet legally binding; the senate has allowed the appeal to the Federal Court of Justice (BGH). This changes little in practice regarding the direction: Anyone operating a chatbot should take its statements as seriously as any other information on their own website.
Where the risk is greatest
The danger grows where a false statement is particularly legally sensitive. Three areas stand out.
Advertising bans and protected statements. For food products, health-related claims are strictly regulated, and disease-related statements are prohibited. If the chatbot confirms such an effect upon inquiry, this is legally sensitive under competition law.
Information on legal topics. Answers regarding warranty, cancellation, or contract terms are risky. The generated information can be legally incorrect or contradict your own Terms and Conditions (AGB) and thus become misleading.

Warning trigger words. Statements about guarantees, testing and certifications like a CE marking, or formulations such as "test winner" are well-known targets. A chatbot that utters them unchecked opens the door to a warning letter.
To make matters worse, the response behavior of a learning system is difficult to predict completely. Targeted inquiries can entice a model into making a statement that would not occur during normal operation.
Data protection and transparency: the other two duties
In addition to liability, the two well-known obligations remain in place. When it comes to data protection, where the data is processed is what matters. Processing in Germany without transfer to third countries, supported by a data processing agreement (AVV), is the robust path. More on this can be found in the article on GDPR- and EU AI Act-compliant AI chatbots.
The transparency obligation arises from the EU AI Act. Users must be able to recognize that they are speaking with an AI system, unless this is already obvious. A clear note at the beginning of the dialogue meets this requirement.
How operators reduce liability risk
A clear instruction for construction follows from the legal situation. The risk decreases when the chatbot only says what is proven and remains silent where it is not.
The most effective lever is grounding in verified sources. If the answers come from approved company content and are not freely formulated, the most common cause of false statements is eliminated. The second lever is clear boundaries. The chatbot should not answer defined topics at all, especially legal inquiries, and should hand over to a human instead. The third lever is control. Conversation logs should be recorded and checked on a random sample basis, especially after system updates.
The guiding principle behind this is simple: better no answer than a false one. A chatbot that hands over to the service team when there is no basis protects the operator better than one that answers something to every question.
How Mercury.ai addresses this
Mercury.ai is designed specifically for this requirement. An orchestra of specialized models recognizes the intent, finds and verifies the appropriate source, and only formulates at the very end. The language model verbalizes, while the facts come from the company's verified knowledge base. If no reliable source is found, the assistant provides no information and hands over to the Agent Desk. This significantly reduces the risk of fabricated and thus potentially warning-prone statements. How this source-bound architecture works is described in the article on hallucinations in AI chatbots.
Added to this is the legal framework: Data is processed in Germany, the AI notification for the transparency obligation can be set at the beginning of the dialogue, and the business department retains control over the approved content via the knowledge base. Learn more about the architecture under Mercury Intelligence.
Frequently Asked Questions
Are AI chatbots legally permissible?
Yes. In Germany, the use of AI chatbots is permitted as long as data protection, the transparency obligation under the EU AI Act, and the factual accuracy of the statements are maintained.
Is a company liable for its chatbot's statements?
Yes. According to the OLG Hamm ruling of May 12, 2026, the statements of an AI chatbot are attributed to the operator as their own commercial action. Liability also applies in the event of a model hallucination.
Must a chatbot be labeled as AI?
Yes. The EU AI Act requires that users must be able to recognize they are interacting with an AI system, unless this is obvious. A notification at the beginning of the dialogue is sufficient.
How do you reduce the liability risk of an AI chatbot?
By grounding answers in verified sources, setting clear thematic boundaries with a hand-off to a human for legal questions, and continuously monitoring conversation logs.
Are AI chatbots GDPR-compliant?
They can be. The prerequisites are processing within the EU, a data processing agreement, and grounding the answers in verified sources. At Mercury.ai, data is processed in Germany.
Control beats trust
AI chatbots are permissible and an effective tool in customer service. Case law has merely clarified what applies to any commercial statement: the operator is held responsible. Anyone who grounds their chatbot in verified knowledge, sets clear boundaries for it, and monitors its answers utilizes the advantage of automation without taking on a liability risk.
Would you like a chatbot that only provides evidence-based information? Talk to us or take a look at Mercury Intelligence.
This article reflects the legal situation in a generally understandable manner and does not replace legal advice. For the assessment of individual cases, please consult expert legal counsel.
About the Author: Dr. Maximilian Panzner is CTO and co-founder of Mercury.ai. He holds a PhD in computer science from the CITEC Institute at Bielefeld University, where he conducted research on multimodal machine learning and intelligent interaction systems. He has been working on Artificial Intelligence, human-machine interaction, and dialogue-oriented AI platforms for corporate use for over 20 years.
Sources
OLG Hamm, judgment of May 12, 2026, Ref. 4 UKl 3/25: A company is liable for false statements made by its AI chatbot; the outputs are attributed to it as its own commercial action. Not yet legally binding, appeal to the BGH allowed.
Verbraucherzentrale Nordrhein-Westfalen: Plaintiff in the proceedings regarding the attribution of false information from an AI chatbot.
Regulation (EU) 2024/1689 (EU AI Act): Transparency obligation when interacting with AI systems.






