On 12 May 2026 the Higher Regional Court of Hamm put a sentence into the world that concerns anyone running a chat on their website: an AI chatbot is not a third party, it is a technical means used by the company (OLG Hamm, case 4 UKl 3/25). What the bot says, the company says. The judgment is not yet final and an appeal to the German Federal Court of Justice has been allowed (Legal Tribune Online). The line has been drawn nonetheless, and it calls for neither panic nor switching things off, but for a sober decision about the architecture of your own assistant.
What the OLG Hamm actually decided
The claimant was the consumer association of North Rhine-Westphalia, suing a provider of aesthetic treatments (Legal Tribune Online). On the provider's website, an AI chatbot answered questions from prospective clients. Asked the obvious question about the qualifications of the two managing directors, the bot replied that they were specialists in plastic and aesthetic surgery, elsewhere specialists in aesthetic medicine and specialists in aesthetic treatments (OLG Hamm, case 4 UKl 3/25). Neither of them holds such a specialist qualification. And two of the three designations (OLG Hamm, case 4 UKl 3/25) do not exist in German medical training law at all — the bot had simply invented them.
Because this was a representative action under sec. 2(1) sentence 1 UKlaG, the Higher Regional Court was the first and only court of fact (UKlaG). The 4th Civil Senate prohibited all three designations; each breach carries an administrative fine of up to 250,000 euros or detention of up to six months (OLG Hamm, case 4 UKl 3/25), plus 260 euros in costs (OLG Hamm, case 4 UKl 3/25) with interest. Legally the ruling rests on sec. 3(1) in conjunction with sec. 5(1) and sec. 5(2) no. 3 UWG — the prohibition on deceiving people about a trader's capability, status or authorisation (UWG).
The case in three sentences
Why the chatbot is not a third party
The defence was well constructed: a language model produces its answers statistically, not on the basis of a human decision in the individual case. The defendant was aiming at sec. 8(2) UWG, which governs a business owner's liability for infringements committed by employees or agents (UWG). The hope behind it: an autonomously formulating system is neither, so it drops out of attribution as an independent third party — leaving the operator measured only against general duties of care rather than a strict duty to answer for the result.
The senate did not follow, for a reason that matters in practice: what counts is not whether a human formulated the individual answer, but who sets the frame within which answers are given.
In view of this, the chatbot represents (merely) a technical means which the defendant used to communicate with potential customers and patients, and over which it had sufficient control.
The senate drew a parallel to the case law on software-based contract document generators (BGH, case I ZR 113/20). There too, software produces results without a human deciding the individual case — and there too the result remains the conduct of whoever offers the software (Wettbewerbszentrale). Legally speaking, a language model sits closer to a book of standard forms than to an employee acting on their own initiative. Whoever runs an assistant on their own website runs it as part of their corporate communication, not alongside it.
The black box argument did not work
The senate expressly accepted that answering an individual question cannot be traced back to a human decision (OLG Hamm, case 4 UKl 3/25, para. 71). That is precisely the much-quoted black box problem: nobody can predict from the outside exactly which sentence a model will form next. Legally, however, it does not follow that responsibility evaporates. It remained undisputed that the defendant could give the chatbot targeted instructions for answering user enquiries — and did so.
Whoever can fix it afterwards had influence beforehand
For operators this means: pointing to the opacity of the model is not a shield, it is closer to a boomerang. The easier an assistant can be constrained after the fact, the less convincing the claim that there was no influence before. Conversely, the very instruments of control that establish liability are the ones that reduce the risk beforehand — topic limits, rules and tools that define what the assistant is allowed to do at all.
Why hallucinations are no excuse
The second reflex after a ruling like this is: hallucinations are a known property of the technology, so nobody can answer for them. The senate dismantled that argument too, via foreseeability. A provider of aesthetic treatments must expect prospective clients to ask the chatbot about specialist qualifications — and must equally expect the bot to “hallucinate” incorrect answers to that obvious question (OLG Hamm, case 4 UKl 3/25, paras. 94 f.). The question asked was neither tendentious nor suggestive (OLG Hamm, case 4 UKl 3/25, para. 97); it was simply the question everybody asks.
The court thereby reverses the narrative: a hallucination is not an accident that befalls the operator, it is a foreseeable operating risk of the system deployed. Anyone who knows that a model tends towards confident invention and still lets it answer questions about qualifications without safeguards is making a decision. How that risk can be narrowed technically is described in detail in our article on hallucinations and sourced answers from the knowledge base.
Particularly notable is how the senate handled the objection that discerning consumers would verify AI answers anyway. The defendant produced no evidence of such a pattern, and in the senate's view none exists:
On the contrary, it is the case that a large proportion of the consumers addressed place particular trust in the accuracy of the computer-generated answer.
Which statements are liability-critical
The ruling concerned specialist medical titles, but the reasoning is deliberately general. Sec. 5(2) no. 3 UWG protects against deception about the trader's person, characteristics and rights — identity, capability, status, authorisation, awards (UWG). These six types of statement should therefore be taken out of free-form generation:
Qualifications and titles
Medical specialist, master craftsman, certified adviser: protected designations are the core of the Hamm case (OLG Hamm, case 4 UKl 3/25).
Certificates and authorisations
Standards, seals, memberships and official permits. A bot that invents a certificate invents an authorisation.
Prices and discounts
Pricing is a perennial in German unfair competition practice: on pricing alone, the Wettbewerbszentrale recently counted 644 cases (Wettbewerbszentrale).
Deadlines and delivery promises
Availability, delivery date, processing time. An invented deadline is a statement about the nature of the service, not a casual estimate.
Promises and contract terms
Warranties, withdrawal, goodwill and scope of service. What the bot promises stands, in case of doubt, as a statement of the company.
Health and legal statements
Effects, diagnoses, legal consequences. Here competition law meets sector-specific law — particularly relevant for medical practices and law firms.
The common denominator: these are statements for which a verifiably correct answer exists and on which the reader relies. That is exactly where a language model that plausibly keeps writing is most dangerous — and exactly where a curated knowledge base is most effective.
Why a disclaimer is not enough
The obvious reaction for many operators is a line under the chat window: “These answers are generated by an AI and may contain errors.” After the Hamm ruling, the general assessment is that this offers no reliable protection (Wettbewerbszentrale). The reason lies in para. 105: if a large proportion of consumers place particular trust in the computer-generated answer, a blanket notice does not correct that expectation. A misleading statement does not become lawful because it was announced in general terms.
Disclaimers are transparency, not indemnity
What is needed instead are concrete technical and organisational precautions — measures that stop the problematic statement from arising in the first place, rather than qualifying it afterwards.
Six safeguards instead of switching off
The consequence of this ruling is not to take the chat off your website. It is to give it a narrower and evidenced frame. These six measures address exactly the points the senate emphasised — scope of activity, control, foreseeability:
A narrow knowledge base, not open model knowledge
The assistant answers from your curated content, not from whatever a model saw during training. Which content belongs in it is covered in our guide to building a knowledge base.
Answers only from sourced content
If there is no evidence in the knowledge base for a question, the assistant does not improvise: it says it does not know and offers the next step.
Hard topic limits for regulated statements
Qualifications, prices, deadlines and promises are not formulated generatively but served from fixed, reviewed texts — or not answered at all.
Escalation to humans when it gets binding
As soon as a statement becomes binding, a human takes over with the full conversation context. Our article on handover to staff describes how to do it cleanly.
Logging as evidence
To show which instructions applied since when and what the assistant actually answered, you need a log. Conversation analytics surfaces outliers before somebody else does.
A review step for content changes
Every change to services, prices or qualifications triggers a review of the knowledge base. Otherwise the assistant answers correctly — from an outdated state.
None of this is extra work for lawyers; it is simply good engineering. In our projects these are the same building blocks that raise answer quality (project experience): an assistant that only says what is evidenced comes across as more competent than one that produces something for every question. Before go-live they belong in structured test cases — our article on acceptance and test cases before go-live shows what a solid sign-off looks like.
An architecture question: generic bot or curated assistant
This is the actual point, and it is not a blanket verdict against chatbots. The ruling does not hit “AI”, it hits a particular way of building: a widget that passes a question to a language model and displays its output unchecked. A custom-built assistant with a curated knowledge base produces a different risk profile — not because the technology differs, but because the scope of activity and the means of control are set deliberately.
| Aspect | Generic bot on open model knowledge | Assistant on a sourced knowledge base |
|---|---|---|
| Source of answers | The model's training data, unverified | Curated, sourced company content |
| Questions on qualifications | Freely formulated, invention possible | From a fixed text or referred to a human |
| Topic limits | Effectively none | Defined per type of statement |
| Knowledge gap | A plausible guess | An open “I don't know” plus the next step |
| Evidence | Rarely available | A log of instructions and answers |
| Control after a complaint | Prompt tinkering | Fix the content, tighten the limit, review |
The difference is not a nuance. It decides whether the senate's questions — Could you set the frame? Was the question foreseeable? Could you have prevented it? — are awkward for you or answerable. We compared the two approaches in more depth in custom assistant versus standard chatbot.
How the risk profile shifts per statement type
Not every question in a chat is equally delicate. It is worth going through your own topics once and defining, per type of statement, how an answer is produced. This breakdown has proven itself in our projects (project experience):
| Type of statement | Example from the chat | How it is answered |
|---|---|---|
| Orientation | “What do you actually do?” | Generative from the knowledge base, in your tone of voice |
| Subject explanation | “How does the treatment work?” | Generative, but strictly on the basis of sourced content |
| Qualification and status | “Are you certified specialists?” | A fixed, reviewed text — no free formulation |
| Price and deadline | “What does it cost, and by when?” | Fixed text or a live value from the system, otherwise handover |
| Binding promise | “Can you assure me of that?” | Handover to a human with the full context |
| Outside the frame | “What do you recommend medically?” | Declined, with a pointer to a personal conversation |
This table is the real work after the ruling — and it is done in an afternoon. It forces the question the senate asked: which questions are obvious, and what happens when they are asked? The result can then be expressed technically as a rule; our custom functions and the service overview show the options. The question becomes especially pressing where assistants are meant to act on their own — see our article on AI agents in the shop.
Appeal to the Federal Court: what is still open
The judgment is not final. The senate allowed the appeal on points of law because of the fundamental significance of the questions raised, based on sec. 6(2) UKlaG in conjunction with sec. 543 ZPO (OLG Hamm, case 4 UKl 3/25, para. 119). The Federal Court of Justice could set different accents on attribution — for instance on where the limit of control lies when an operator deploys a third-party model whose behaviour it can influence only indirectly.
For practice this changes little. First, an appeal takes time. Second, the underlying line is not exotic: that companies answer for the tools they use in their communication is not a new invention in German unfair competition law but the continuation of a familiar rationale (Wettbewerbszentrale). Third, the occasion is real: the share of companies in Germany actively using AI has risen to 41 percent, up from 17 percent the year before (Bitkom); another 48 percent are planning or discussing it (Bitkom). And misleading practices are already the focus of complaints today: more than every second legal question examined recently concerned misleading statements, a lack of transparency or information duties, with 241 court proceedings and an increase of 18.1 percent on the previous year (Wettbewerbszentrale).
Context, not legal advice
Your checklist after the ruling
If you run a chat on your website, the need for action can be clarified in a single session. Work through these points:
- Ask your own chat the most obvious qualification question in your sector — and read the answer word for word.
- Check the same for prices, deadlines and promises: does the bot answer there in free-form text?
- Establish where an answer comes from: your curated content or general model knowledge?
- Define per type of statement whether it is generative, fixed text or a handover.
- Decide what happens when the knowledge base has nothing — a guess is the wrong answer.
- Set up a handover to humans for everything that becomes binding.
- Ensure there is a log that makes instructions and answers traceable.
- Anchor a review step whenever services, prices or qualifications change.
If more than one point stays open, that is no reason to switch the chat off — you would lose enquiries without understanding the risk. It is a reason to clarify the architecture. Where your data sits and who processes it is a second, equally concrete question: see our page on data protection and hosting. And if you are unsure where your assistant stands, talk to us — the check is done faster than a warning letter.
Sources and studies