Skip to content
Individually trained

Law, privacy & accessibility

An assistant processes input from visitors — which brings data protection and transparency obligations. This category sets out the requirements: notices about automated processing, legal bases and consent, storage locations and retention periods for conversation logs, data processing agreements with providers, handling personal data entered by accident, and the rules of the EU regulation on artificial intelligence. Accessibility is part of it too: a chat window has to be operable by keyboard, and focus and status messages have to remain perceivable for screen readers. We describe checkpoints and typical mistakes. The articles do not replace individual legal advice, but they prepare those discussions. We also show which notices users should see before the first chat and how to phrase them briefly and understandably.

OLG Hamm · 12 May 2026 · Case 4 UKl 3/25Whoever sets the scope of the bot answers for what it saysHow the court attributed the answer1User question in chat“Are A and B specialists in plastic surgery?”2The chatbot's answer“Yes, both are specialists …” — hallucinated3Sec. 8(2) UWG: no third partyThe bot is a technical means, not an agent4The operator's own conductThe operator retains sufficient control5Sec. 5(2) no. 3 UWGInjunction, penalty up to 250,000 eurosBlack box defence failed: reprogramming proved to be easyWhat the chatbot invented2 of 3titles simply made upThree specialist titleswere named by the chatbot on request.Two of them do not exist in Germanmedical training law at all.Source: OLG Hamm, case 4 UKl 3/25Two architectures, two risk profilesGeneric bot on open model knowledgehigh risk· Answers from training data, unverified· No topic limits on qualifications or prices· Disclaimer as the only safeguardAssistant on a sourced knowledge basecontrolled· Answers only from curated, sourced content· Hard topic limits for regulated statements· Escalation to humans, logs as evidence

Chatbot Liability: What the OLG Hamm Ruling Means

On 12 May 2026 the OLG Hamm ruled that companies are liable for misleading statements made by their AI chatbot. What the judgment means for operators.

12 min read
Accessible AI Chat AssistantYour Website AssistantHow can I help you today?Is the chat accessible?Yes. It is fully keyboardoperable and screen-reader ready.Fully keyboard operable:TabEnterEscType a message ...Visible focus ring when tabbingTested against WCAG 2.2 AAKeyboard operationReachable without a mouseScreen-reader supportSemantics and ARIA rolesVisible focusFocus ring with 3:1 contrastContrast to AAText at least 4.5:1Scaling up to 200%Zoom without text lossText contrast4.5:1AA minimummeets EN 301 549Built accessible: WCAG 2.2 AA · EN 301 549 · EAAFull keyboard operation, screen-reader support and visible focus from day one

Accessible AI Chat Assistant: Meeting WCAG and the EAA

The EAA has applied since 28 June 2025: what an accessible AI chat assistant needs - keyboard operation, screen readers, visible focus and WCAG 2.2 AA.

12 min read
EU AI Act · Article 50 · Disclosure DutyTransparency for AI chats from 2 August 2026Your Website AssistantAINotice: you are chatting with anAI assistant, not with a human.Am I talking to a human here?No, I am the AI assistant. Fortricky cases I bring in a colleague.Hand over to a humanDisclosure shown before the first messageWrite a message ...How to meet Article 50AI notice before first contactClearly visible in the widget, not the footerHandover to a human at any timeOne click from chat to a staff memberAccessible and distinguishableLegible, high-contrast, clearly namedDocumentation for market surveillanceEvidence for the supervisory authorityBreach of Article 50: fines up to EUR 15m or 3 % of turnoverMarket surveillance in Germany: Bundesnetzagentur

EU AI Act 2026: Chatbot Disclosure Duties Explained

From 2 August 2026, Article 50 of the AI Act applies: users must be able to tell they are chatting with an AI, not a human. What it means for your website chat.

11 min read
GDPR-Compliant AI AssistantYour Website AssistantWe only use your details tohandle your request.And where is it stored?On servers in Germany, GDPR-compliant, with a processingagreement and automatic deletion.EU hostingDPAEncryptedHandover to a human at any timeWrite a message ...Four Data-Protection Layers1Hosting in Germany and the EUData centres under EU law2Data-processing agreement (DPA)Contract under Art. 28 GDPR3Encryption and access controlProtected in transit and at rest4Deletion concept and rightsRetention and data-subject rightsNo sharing. No training on your data.Data sovereignty stays with you: your data never leaves the EUHosting in Germany, a processing agreement and a deletion concept as the foundation

GDPR-Compliant AI Assistants: Hosting and Data Protection

What makes an AI chat assistant GDPR-compliant: hosting in Germany and the EU, a data-processing agreement, data sovereignty, a deletion concept and no sharing.

12 min read
Securing Against Prompt InjectionTwo attack pathsDirect injectionInstruction in the input fieldIndirect injectionHidden in website contentGuardrailsInput filteringOutput checksNo secrets in promptMonitoring & loggingDefense in depthOWASP rank 1Protected assistantForeign instruction flaggedOnly approved actionsNo secrets in contextAnomalies are loggedWhy hardening matters25%GenAI apps with incidentsper year by 2028 (Gartner)9%2025 baseline of GenAIsecurity incidents (Gartner)36%of companies in Germanynow use AI (Bitkom)Separate data from instructions, add guardrails, monitor anomalies

Prompt Injection: Securing Your AI Assistant

Why prompt injection tops the OWASP Top 10 for LLM applications, what direct and indirect attacks are, and which guardrails protect your AI chat assistant.

12 min read