Artificial intelligence has quietly become an increasingly common feature of customer communication. Across industries, companies are using AI-powered chatbots, virtual assistants, and automated customer journeys to support or replace traditional customer support. In some cases, AI is a first point of contact before more complex or sensitive matters are escalated to human agents. The business case is obvious: faster responses, round-the-clock availability, and lower operating costs.
The legal consequences are becoming increasingly obvious as well.
As generative AI moves from pilot projects, niche applications, and proof-of-concept trials into daily business operations, a growing number of disputes are emerging at the intersection of technology, consumer protection, and corporate liability.
Questions that until recently belonged to conference panels and academic papers are now finding their way into courtrooms. Consumer associations, competitors, regulators, and private claimants are starting to test the legal limits of AI-generated customer communications, particularly where inaccurate or misleading outputs affect customers and commercial decision-making.
Link to The Aesthetify case: When the chatbot went a little too far The Aesthetify case: When the chatbot went a little too far
One of the first publicly known German cases concerning AI hallucinations in customer communications involved Aesthetify, a cosmetic medicine provider operating an AI-powered chatbot on its website. The chatbot answered patient inquiries and assisted with appointment bookings. When users asked about the qualifications of the clinic’s founders, however, the system became somewhat more creative than accurate.
According to the Higher Regional Court of Hamm (OLG Hamm), the chatbot informed prospective patients that the founders, publicly known as “Dr. Rick” and “Dr. Nick,” held specialist qualifications in aesthetic and plastic surgery that they did not possess. It even invented professional designations that do not exist under German medical regulations.
One might say Aesthetify’s chatbot attempted a cosmetic enhancement of the facts. However, this intervention did not survive judicial scrutiny.
The Consumer Association of North Rhine-Westphalia (Verbraucherzentrale NRW) challenged the statements as misleading commercial conduct under German unfair competition law. As Aesthetify declined to provide a cease-and-desist declaration, litigation followed.
In its decision of 12 May 2026 (Case No. 4 UKl 3/25), the OLG Hamm held that the chatbot’s statements were attributable to the company itself. The court rejected the argument that the AI system operated as an independent third party. Even if the chatbot had been trained exclusively on correct information, the operator remained responsible for the inaccurate output generated through its customer-facing communication channel.
The significance of the decision extends, of course, beyond customer service cases. The court effectively rejected what some organisations may have assumed would become a standard defence in future AI cases: the AI did it, not us. Where the AI functions as part of a company’s commercial communication, German courts appear willing to treat its statements as the company’s own.
Link to AI liability without an AI liability regime AI liability without an AI liability regime
The Aesthetify decision also highlights a sometimes misunderstood aspect of European AI regulation: while the EU has adopted extensive rules governing the development and deployment of AI, it has not created a comprehensive AI-specific civil liability framework, as the proposed AI Liability Directive was ultimately withdrawn.
But this does not create a legal vacuum; quite the opposite. As is often the case with emerging technologies, existing legal frameworks must now be applied to a technology that was not necessarily foreseeable when those laws were conceived. It leaves disputes involving AI-generated harm to be resolved largely through existing national laws. Therefore, businesses deploying AI remain exposed under a wide range of established causes of action, including the following:
- unfair competition and misleading advertising claims
- contractual liability arising from inaccurate AI-generated information
- product liability claims involving AI-enabled products
- professional negligence claims
- intellectual property disputes
- claims arising from reputational harm caused by false AI-generated statements
The legal analysis in Aesthetify was conventional. The court did not engage in a broader philosophical discussion about machine autonomy, emergent behaviour, or the technical nature of hallucinations. Instead, it asked a straightforward question: were consumers presented with misleading commercial information attributable to the company operating the chatbot? The answer was yes. The fact that the information originated from an AI system did not alter the outcome.
Link to The AI Act as a future source of disputes The AI Act as a future source of disputes
The EU AI Act can be viewed primarily as a compliance framework. But it may also become a source of future disputes.
The AI Act regulates how AI systems must be designed, deployed, monitored, and governed. It imposes obligations relating to risk management, human oversight, documentation, transparency, cybersecurity, and post-market monitoring. For providers of general-purpose AI and generative AI systems, additional transparency requirements apply. These rules are intended to reduce risks before harm occurs.
What the AI Act does not do is answer the question of who ultimately bears the costs when harm nevertheless occurs. It allocates responsibility, but it does so on the regulatory plane, distinguishing providers from deployers and backing those roles with market surveillance and administrative fines, but conferring no right of action on the person who suffers the loss.
The instrument intended to close that gap no longer exists. The proposed AI Liability Directive, conceived as the civil-law counterpart to the AI Act, was withdrawn in 2025. What remains at EU level is the revised Product Liability Directive (EU) 2024/2853, which brings software, including AI systems, within the definition of a product. Member states must transpose it by 9 December 2026; in Germany, the government’s draft modernisation of product liability law has been before the Bundestag since March 2026.
Even that leaves a substantial gap. The revised regime addresses death, personal injury, property damage, and the destruction or corruption of data suffered by natural persons. It does not reach the pure economic and reputational loss a company sustains when an automated system publishes something untrue about it. Those claims continue to be governed by national tort, personality, and unfair competition law.
The AI Act therefore does not itself establish liability. What it creates is evidence. Missing transparency notices, deficient documentation, weak governance structures, or a failure to implement effective human oversight are precisely the findings a claimant will rely on to establish breach of duty, and regulatory records will increasingly supply them.
Link to Beyond chatbots: The next wave of AI disputes Beyond chatbots: The next wave of AI disputes
The Aesthetify case is unlikely to remain an isolated incident.
Across Europe, disputes involving AI-generated misinformation are already emerging. In Germany, the District Court Munich I recently addressed a case involving AI-generated search summaries that falsely reported a company to be insolvent (Case no. 26 O 869/26). Injunctive relief followed, providing another indication that courts are willing to intervene where AI-generated misinformation causes tangible harm.
Nevertheless, the contours of liability for AI-generated content are still taking shape. For example, only a few days later, the District Court Berlin II took a different approach. It rejected the argument that AI-generated search summaries should be attributed to the search engine operator as its own communication in proceedings concerning trademark and unfair competition claims (Case No. 52 O 62/26 eV). However, the case can be distinguished on the facts. The AI did – according to the Court – not form part of the company’s own commercial communications; rather, it functioned as a tool that aggregated and summarized information from third-party websites.
Looking ahead, several categories of disputes appear particularly likely:
- AI systems communicating incorrect pricing or product information
- customer-service agents inadvertently concluding contracts or making binding commitments
- discriminatory algorithmic decision-making
- inaccurate medical, insurance, or financial recommendations
- copyright and training-data disputes
- deepfakes and synthetic content
- AI-generated defamation
- cybersecurity incidents involving manipulated or compromised AI systems
Particularly interesting are the growing concerns surrounding unintended cyberattacks by the latest and most powerful AI models.
Link to Litigation is catching up with innovation Litigation is catching up with innovation
The broader lesson from Aesthetify is not simply that companies may be liable for chatbot hallucinations.
The lesson is that AI disputes have entered a new phase. The first generation of AI related dispute risk discussions was largely hypothetical. The next generation will likely be fought through cease-and-desist letters, regulatory investigations, injunction proceedings, and finally through damages claims.
For businesses deploying AI, the era of treating AI disputes risk as an afterthought is rapidly coming to an end. AI may be capable of generating answers automatically. Responsibility, however, remains decidedly human.
Link to Contractual safeguards: Vendor agreements as a line of defence Contractual safeguards: Vendor agreements as a line of defence
Beyond questions of statutory liability, the Aesthetify case also illustrates the importance of the contractual layer surrounding AI deployments. Chatbots and other AI-powered customer service tools are frequently developed, trained, or hosted by external providers rather than built entirely in-house. The agreements governing these relationships – covering development, licensing, hosting and ongoing support – play a central role in allocating responsibility when an AI system produces inaccurate or misleading output. This has always been a key consideration in IT contracts involving external developers and service providers, and it continues to apply with undiminished importance in the AI context.
Service descriptions deserve close attention. Where the scope of services, permissible use cases, quality standards, monitoring obligations and escalation procedures are defined clearly, the parties are better placed to determine which of them is responsible if the AI system operates outside its intended parameters. Vaguely drafted service descriptions, by contrast, tend to shift disputes back into the grey area which the Aesthetify decision has shown courts are increasingly unwilling to leave unresolved.
DLA Piper’s AI disputes and advisory teams can support you on AI governance, regulation and litigation. We cover the full AI lifecycle, from AI readiness assessments and compliance programs to regulatory investigations, consumer protection disputes, unfair competition claims, AI-generated misinformation, and litigation.
