Chatbot Liability: What the OLG Hamm Ruling Means
On 12 May 2026 the OLG Hamm ruled that companies are liable for misleading statements made by their AI chatbot. What the judgment means for operators.
An assistant processes input from visitors — which brings data protection and transparency obligations. This category sets out the requirements: notices about automated processing, legal bases and consent, storage locations and retention periods for conversation logs, data processing agreements with providers, handling personal data entered by accident, and the rules of the EU regulation on artificial intelligence. Accessibility is part of it too: a chat window has to be operable by keyboard, and focus and status messages have to remain perceivable for screen readers. We describe checkpoints and typical mistakes. The articles do not replace individual legal advice, but they prepare those discussions. We also show which notices users should see before the first chat and how to phrase them briefly and understandably.
On 12 May 2026 the OLG Hamm ruled that companies are liable for misleading statements made by their AI chatbot. What the judgment means for operators.
The EAA has applied since 28 June 2025: what an accessible AI chat assistant needs - keyboard operation, screen readers, visible focus and WCAG 2.2 AA.
From 2 August 2026, Article 50 of the AI Act applies: users must be able to tell they are chatting with an AI, not a human. What it means for your website chat.
What makes an AI chat assistant GDPR-compliant: hosting in Germany and the EU, a data-processing agreement, data sovereignty, a deletion concept and no sharing.
Why prompt injection tops the OWASP Top 10 for LLM applications, what direct and indirect attacks are, and which guardrails protect your AI chat assistant.