Who is liable when your AI is wrong
Where your real exposure lives when an AI feature speaks for your business, and the cheap habits that stop a model's mistakes from becoming your legal problem.
Most small operators have quietly assumed that if an AI tool says something wrong, that is the tool maker’s problem. A German court just made that assumption look expensive. The decision is narrow and under appeal, but the question it raises is one every business putting AI in front of customers will eventually face, so it is worth thinking through now, while the stakes are still hypothetical for you.
The ruling that reframed the question
In late May, the Regional Court of Munich found Google directly liable for false claims its AI Overviews made about two local publishers, as we covered in the news brief. The legal move that matters is not the result but the reasoning: the court treated the AI summary as Google’s own statement, not a neutral pointer to other people’s pages. Once the output counts as your words in the eyes of a court, the usual shrug, that the model generated it, stops working as a defense.
You are not Google, and a German regional court does not bind your jurisdiction. But judges read each other, and the underlying logic travels. If you choose the tool, point it at the public, and publish what it produces under your name, you look a lot like the author.
Why “the AI did it” is a weak defense
Think about how customers experience an AI feature on your site. They do not see a model. They see your logo, your domain, your brand voice. When a chatbot invents a refund policy, misstates a price, or names the wrong competitor in a comparison, the reader attributes it to you, and increasingly so will the law. The tool is a supplier; you are the publisher.
This is the same shift that hit every business that ever outsourced copywriting. You could blame the freelancer privately, but the bad line still went out under your masthead. AI just makes that freelancer infinitely fast and occasionally confidently wrong. The speed is exactly why the old, informal “someone will catch it” net fails: nobody is reading every generated sentence.
Where your exposure actually lives
Not all AI output carries the same risk. Sort yours by how public it is and whether it names real things.
The high-risk zone is anything that reaches people outside your company and makes a checkable factual claim about a named person, company, product, or number. That covers AI-written product descriptions, automated support replies, generated comparison pages, marketing copy, and any “ask our assistant” widget. A wrong fact about a real, named third party is where defamation and false-advertising exposure concentrate.
The low-risk zone is internal and non-factual: brainstorming, rough drafts you will rewrite, summaries only your team reads, formatting and tone work. A model that mangles an internal meeting summary is a productivity annoyance, not a lawsuit, though it still earns the trust-but-verify habit.
Most operators have never drawn this line, which is the real problem. What AI gets wrong is predictable enough that you can plan around it. You just have to decide in advance where a mistake is cosmetic and where it is a liability, instead of finding out from an angry email.
A practical liability checklist
You do not need a lawyer on retainer to cut most of this risk. You need a few standing rules.
- Put a human between the model and any public claim about a named third party. This is the single highest-leverage rule. If the output mentions a real person, company, or specific number a reader could act on, someone reviews it before it ships.
- Keep the receipts. When an AI feature states a fact, it should trace back to a source you can produce later. The same verification habit that protects your readers also protects you if anyone asks how the claim got there.
- Label AI-assisted surfaces honestly. A short “answers may be imperfect, please verify important details” notice will not make you immune, but it sets expectations and shows you took care. Several regulators are moving toward requiring disclosure anyway.
- Constrain the model’s scope. A support bot that may only answer from your approved help-center articles is far safer than one improvising from the open web. Narrow retrieval beats open generation for anything customer-facing.
- Read your vendor’s terms for the indemnity clause. Some providers offer limited legal cover for outputs on their paid tiers; many explicitly disclaim all of it. Knowing which one you bought is part of choosing AI tools for your business.
- Log what shipped. If an AI feature publishes at volume, keep a record of what it produced. You cannot fix, retract, or defend what you cannot reconstruct.
What this ruling does not mean
It does not mean you should rip AI out of your stack. The Munich decision is one court, in one country, on appeal, about a specific kind of unsourced fabrication. Most AI uses are low-risk, and the productivity case is real. Panic is not a plan.
It also does not mean disclaimers are magic. A footer that reads “generated by AI” will not save you if your assistant confidently libels a competitor. Courts look at what you actually did, not what your fine print claimed.
The honest takeaway is smaller and more durable than the headline. The law is slowly deciding that AI output is speech, and speech has an author. If a model speaks for your business, you are the most likely candidate for that role. Build your process as if that is already settled, because for the price of one review step and a few standing rules, you come out covered whichever way the appeals go.