Who is liable when AI gives wrong advice in customer support?
Who is liable when your support AI agent advises wrongly? Court rulings, the labelling duty under Art. 50 AI Act, and four approval tiers for daily work.
Martin Semmele

Contents
Key takeaways
- OLG Hamm, judgment of 12 May 2026, case no. 4 UKl 3/25: operators are liable for false chatbot statements, even where the data fed in was correct
- Air Canada had to pay 812.02 Canadian dollars because its chatbot promised a retroactive bereavement fare that the policy did not provide for. The argument that the bot acted independently failed.
- Art. 50(1) of the AI Act requires, from 2 August 2026, that users can tell when they are speaking to an AI system rather than a human.
- Infringements of Art. 50 of the AI Act can be punished with up to 15 million euros or 3 per cent of total worldwide annual turnover.
- An approval is only effective if the reviewer has time and the source. Automation bias makes blind confirmation worthless.
Three kinds of error. Three different consequences.
Not every AI error is the same. In practice three kinds can be distinguished, and the kind decides how expensive the error becomes and how much checking it deserves. The first kind: an invented product property. The Higher Regional Court of Hamm (OLG Hamm) had to rule on a clinic chatbot that described the two doctors behind the defendant company as specialists in plastic and aesthetic surgery as well as specialists in aesthetic medicine. Those specialist titles do not exist in that form, or are not held by the doctors. The court treated the answers as commercial practices of the company that were unlawful under § 5 Abs. 1, Abs. 2 Nr. 3 UWG (judgment of 12 May 2026, case no. 4 UKl 3/25)1.
The second kind: wrong information about deadlines or prices. The Regional Court of Kiel (LG Kiel) had to rule on a business information service whose automated analysis wrongly reported that the claimant would be struck off for lack of assets. The false statement infringed the company's personality right and gave rise to a claim for an injunction against the operator (LG Kiel, judgment of 29 February 2024, case no. 6 O 151/23)2. The third kind: a commitment nobody can honour. Air Canada's chatbot held out to a customer the prospect of applying for the bereavement fare retroactively, which the actual policy did not provide for. The Civil Resolution Tribunal in British Columbia ordered the airline to pay 650.88 Canadian dollars in damages plus 36.14 dollars in interest and 125 dollars in fees, 812.02 Canadian dollars in total3.
Why the distinction counts: mere information can be wrong and still bind nobody. A commitment, by contrast, binds you immediately, because to the outside world it acts as a declaration by your company. That is exactly why the three kinds of error call for different levels of checking. An invented product property is above all a competition and misleading risk. Wrong information about a deadline or a price feeds through into contractual relationships. An uncovered commitment is the most expensive case, because it has to be honoured straight away.
- Invented property: a misleading and competition risk, as in the case of the specialist titles that were not held, before the OLG Hamm1.
- Wrong information about deadlines or prices: reaches into existing contractual relationships and, as in the Kiel case, can infringe the rights of others2.
- Uncovered commitment: binds the company immediately, like the fare promise made by the Air Canada chatbot3.
For your support day-to-day that means: the closer an answer comes to a price, a deadline or a binding commitment, the higher the approval tier. The four tiers are set out further below.
The principle: the bot works for you.
None of the three courts held the AI itself to account. That is no accident. An AI system is not a legal person and can carry neither rights nor duties. Responsibility always ends up with the operator who deploys the system on their own account. That is precisely how three decisions from two legal systems, two in Germany and one in Canada, saw it independently of one another.
The OLG Hamm treated the chatbot answers as commercial practices of the defendant itself. The company had objected that the faulty answers were not attributable to it as its own commercial practice. The court did not follow that: even if the defendant had had the bot programmed exclusively with correct data sets, it would bear responsibility for the false statements. The chatbot was also not a third party within the meaning of the law, which is why recourse to the requirements of a duty of care was barred1.
The LG Kiel focused on the upstream business decision: whoever knowingly makes use of their own software to produce information is liable as a direct interferer for the fully automated output. The court wrote in as many words that the defendant could not fall back on not having been involved in this automatic process, because it had deliberately made use of an artificial intelligence2.
And the tribunal in British Columbia rejected the argument that the chatbot was a separate legal entity responsible for its own actions. The decision states that a chatbot does have an interactive component but is still only a part of Air Canada's website, and that it makes no difference whether the information comes from a static page or a chatbot3.
Which of this is statutory text and which is interpretation? The statutory text reads: § 280 Abs. 1 BGB: if the debtor breaches a duty arising from the obligation, the creditor may demand compensation for the damage caused thereby. This does not apply if the debtor is not responsible for the breach of duty4. That provision is the typical contractual basis for a claim where wrong support information harms customers. That an AI answer is attributed to the operator as its own declaration is, by contrast, interpretation drawn from the court decisions named above, not literal statutory text. And a note in advance: this article is not legal advice, but an orientation for support work.
Labelling. A duty from August 2026.
Since 2 August 2026 a transparency duty has applied in the EU that many support teams only have on their radar late. Article 50(1) of the AI Act requires AI systems intended to interact directly with natural persons to be designed so that those persons are informed that they are interacting with an AI system. The duty does not apply where this is obvious from the circumstances to a reasonably well-informed, observant and circumspect person5. The date of application follows from Article 113 of the Regulation6.
The IHK Schleswig-Holstein gives a practical pointer on this: the notice should appear right at the start of the communication and not first in the terms and conditions or the privacy policy. As possible wordings the IHK names sentences such as: you are communicating with an AI system. Or: this chatbot answers your request with the help of artificial intelligence6.
Infringements of Article 50 can be punished with fines of up to 15 million euros or, in the case of undertakings, up to three per cent of total worldwide annual turnover. Whichever is the higher amount applies; in the case of SMEs, whichever is the lower76.
- Put the notice at the start of the conversation, not into the terms and conditions6.
- An exception only where the involvement of AI is obvious to users5.
- Fines up to 15 million euros or three per cent of total worldwide annual turnover, the higher amount applies6.
In practice that means: the labelling notice belongs in the chat window itself, visible at first contact. A notice in the website footer is not enough. Labelling, by the way, does not protect against liability for wrong content. It fulfils a duty of its own and creates clarity about whose declaration the answer is: yours.
No log, no defence.
When an error happens, the question is not whether it happened. What matters is whether you can reconstruct it. Only with a log of the conversation, the source cited and the handover can you check what the AI answered, when, and on what basis. Without that log you stand on assertions in a dispute, and assertions are not a defence.
Three things have to remain traceable. First the conversation itself: which question was asked, which answer given, when. Second the source: which knowledge article or document did the AI answer from, or was there no source at all. Third the handover: when and why did the system hand over to a human, or did it precisely not do so although it should have.
On top of that comes the approval itself. The IHK recommends documenting who checked content and who is responsible for the final approval6. Transfer that to support: for every answer approved by a human it should be clear who checked it and on what basis of sources. In a dispute that is the difference between a traceable process and a gap.
- Log the conversation completely: question, answer, time.
- Store the source cited with it: which knowledge article, which document, or no source.
- Document handovers: when, why, to whom.
- Document approvals: who checked and released6.
A word on retention periods: how long you have to keep conversations and logs depends on your statutory and contractual duties, for example from data protection and commercial law. We deliberately name no specific period here, because the right duration depends on the individual case. Settle it deliberately, in writing, and agree it with the person responsible for data protection. Kept too briefly, it costs you the defence; kept too long, it costs you on data protection.
The knowledge base is the liability lever.
The most frequent source of error is not the model. It is outdated or contradictory knowledge. An AI agent that answers from a knowledge base is only as good as the articles, PDFs and pages you give it. A price from 2023 in a PDF that nobody has updated is, for the AI, just as valid a source as your current pricing page. So the error arises not in the model, but in your upkeep.
That is exactly why the source citation is the second most important lever. Every answer that names its source makes errors findable: your team sees immediately which article produced the false statement and can correct it. The damage stays limited to the answers fed from that one source. Answers without a source, by contrast, cannot be checked, and those are precisely the ones you should not allow in the first place.
The Air Canada lesson shows what a source citation cannot rescue. Air Canada argued that the correct policy had been available to read on the website. The tribunal rejected that: it was obvious to Air Canada that the company is responsible for all information on its website, whether it comes from a static page or a chatbot3. Translated: a correct link next to a wrong answer does not protect you. The answer itself has to be right.
- Name those responsible: who maintains prices, deadlines and contractual terms in the knowledge base.
- Versioning for critical articles: keep changes to prices, deadlines and contracts traceable.
- Actively remove outdated sources: an old PDF in the knowledge base is a ticking piece of false information.
- Check contradictions: where two articles answer the same topic differently, the AI picks one of them, not the right one.
An upkeep process needs no large organisation. It needs people responsible, a rhythm and a prioritisation. Critical articles are all those that concern a price, a deadline, a contract or a commitment. Those belong at the top of your checking list, not at the end.
Four approval tiers for daily work.
From everything said so far follows a simple question for every support answer: how much checking does this content need before it goes out? The answer can be captured in four tiers. They are not a rule of law, but a practical translation of the liability position into daily work.
- 01Tier 1: fully automatic answer with a source. For uncritical topics where the source gives the answer unambiguously: navigation questions, general product information, references to documents. The AI answers directly, citing the source.
- 02Tier 2: AI draft, human checks and sends. For topics with medium risk: the AI puts forward a draft with a source, a human reads it, adjusts it and sends. Nothing goes out automatically.
- 03Tier 3: always a human for price, deadline, contract and every commitment. These answers never go out fully automatically. They are written or checked and released by a human, with the source in front of them.
- 04Tier 4: handover to the team where the source does not carry the answer. If the AI finds no reliable source, it does not answer but hands over to a human. That is not a failure, it is the safest tier.

The allocation of typical topics looks like this: order status, invoice download and account access belong in tier 1, as long as the source is unambiguous. Returns and cancellations belong in tier 2 or 3, depending on whether deadlines are involved. Prices, notice periods, contractual terms and every form of commitment, discount, goodwill or special condition belong in tier 3. And everything the knowledge base does not answer unambiguously belongs in tier 4.
A word on the warning about automation bias. The Alexander von Humboldt Institute for Internet and Society points out that people tend to place too much trust in machine pre-decisions, which is known as automation bias8. Transferred to support that means: a click on approve, without having read the source, is not a check. It is a confirmation. The difference is precisely the one that counts in a dispute.
That is why a reviewer needs two things: time, and the source in front of them. A draft without a source citation cannot be checked; a reviewer without time is not a control. If your approval processes are built so that checking goes faster than reading, then nobody is really checking. Plan the time in, or the approval is worthless.
An example from our own setup.
To close, an example from our own workshop, not a pitch. ComLayer is an AI support platform with a widget, a Help Centre, a shared inbox and an AI agent that answers exclusively from your own company knowledge. The agent only answers questions where the stored knowledge carries the answer, and backs every answer with the source. Where the knowledge is not enough, it does not guess but hands over to a human.
How that maps onto the four approval tiers: tier 1 is the automatic answer with a source citation, as the agent delivers it by default. Tier 2 is the AI draft in the shared inbox: for open questions a draft reply with a source is ready, your team reads it, adjusts it and sends. Tiers 3 and 4 are process rules on your side: you set price, deadline and contract questions in your workspace so that they always run via the draft, and the handover where a source is missing is the technical fallback that maps tier 4.
What ComLayer cannot do either: take the content check off the operator. No tool can decide for you whether your pricing article is current or whether a commitment is covered. That stays your responsibility, and that is exactly why the log, the source citation and the approval tiers matter so much. How hallucinations can be prevented technically is set out in preventing hallucinations in support; the data protection side is covered by GDPR-compliant AI in customer service.
Frequently asked questions
Is my company liable if the AI chatbot says something wrong in support?
Yes, according to the case law so far. The OLG Hamm (judgment of 12 May 2026, case no. 4 UKl 3/25) does not see the chatbot as a third party but attributes its errors to the company. A tribunal in British Columbia has also ordered Air Canada to pay 812.02 Canadian dollars, because the chatbot promised a bereavement fare that could be applied for retroactively, which the policy did not provide for. That is a court decision, not statutory text, and it does not replace legal advice.
Do I have to label the fact that an AI system answers in support?
Yes, that follows from Art. 50(1) of the AI Act: AI systems that interact directly with people must be designed so that users are informed of it, unless it is obvious. The duty applies from 2 August 2026. The IHK Schleswig-Holstein recommends placing the notice right at the start of the conversation, not first in the terms and conditions or the privacy policy.
What fines are possible for infringements of the transparency duties in the AI Act?
Infringements of Art. 50 of the AI Act can be punished with fines of up to 15 million euros or up to 3 per cent of total worldwide annual turnover, whichever is the higher amount. For SMEs, whichever is the lower amount applies. The exact penalty depends on the individual case; these figures are the statutory frame.
Does a notice such as “without guarantee” protect me from liability?
No, at least not in the sense of the decisions so far. Air Canada argued that the chatbot was a legal person of its own and that the customer should have followed the linked page. The tribunal rejected that: it makes no difference whether the information comes from a static page or a chatbot. Whether a disclaimer reduces liability in an individual case is a matter of interpretation and unsettled.
What does human oversight mean in customer support?
It means a process in which a human is actively involved in the automated decision, for example by checking, adjusting or releasing AI answers before they reach the customer. The HIIG describes this as an automated process in which people are actively involved in order to monitor the quality of the decisions. Important: the mere existence of a human is not enough, the check has to be genuinely possible and meaningful.
Is it enough if a member of staff just briefly confirms the AI answer?
Probably not. Research on human oversight knows automation bias: people tend to trust machine pre-decisions and to check them only superficially. An approval without time and without a visible source is formally a human check and in fact a formality. Define which topics have to be checked and what the reviewer has to see.
When should the AI hand over to a human instead of answering itself?
As a practical rule: whenever the knowledge base does not yield a solid source, or the topic is legally or financially sensitive. That includes price and deadline information, contractual commitments and individual decisions such as goodwill. That is not a statutory requirement but a derivation from the liability case law: the more serious the consequence of a wrong answer, the more a human belongs in the process.