AIR-2026-014 · AI Agent Incident Register
Verbraucherzentrale NRW v Aesthetify: a German court makes a clinic answer for the false specialist titles its chatbot gave its doctors
Incident: 2026-05-12 · Parties: Verbraucherzentrale Nordrhein-Westfalen e.V. (claimant, a qualified consumer association) v Aesthetify GmbH (defendant, a Recklinghausen business offering minimally invasive cosmetic treatments, which ran the chatbot); Oberlandesgericht Hamm, 4th Civil Senate, judgment of 12 May 2026, 4 UKl 3/25, ECLI:DE:OLGHAM:2026:0512.4UKL3.25.00
Liability locus: Deployer-carried. the organisation that deployed the agent answers for its output. How this compares across the corpus.
Legal analysis by Michael K. Onyekwere, CIPP/E · Janus Compliance · Published 2026-09-27 · Last reviewed 2026-09-27. Analysis of public facts. Not legal advice.
What happened
Aesthetify GmbH offers minimally invasive cosmetic treatments, among other services, from Recklinghausen. Its website ran a chatbot. It answered visitors' questions in real time and offered to book appointments.
On 3 April 2025 the chatbot was asked whether the business's two managing doctors were specialists in plastic and aesthetic surgery. It said they were. Asked which specialist title they held, it said both were specialists in aesthetic medicine. Asked simply whether they were specialists, it called them specialists in aesthetic treatments. Each answer ended with an offer to book an appointment.
Neither doctor has completed specialist training in plastic and aesthetic surgery. The other two titles do not exist. Both points were undisputed, and the website itself never described the two doctors as specialists.
Verbraucherzentrale Nordrhein-Westfalen, a qualified consumer association, sent a warning letter on 10 April 2025. It asked for a penalty-backed cease-and-desist undertaking and €260 in costs. Aesthetify switched the chatbot off at once. It then had it reworked, with a prompt instruction to answer neutrally any question containing the word "Facharzt" (specialist) and a keyword filter that suppresses the word. On 23 April 2025 it admitted in writing that the answers were wrong, calling them a regrettable technical oversight. It did not sign the undertaking. The association sued under Germany's Injunctions Act (UKlaG), and because claims under that Act go directly to the Higher Regional Court for the defendant's seat, the 4th Civil Senate in Hamm heard the case at first instance.
Aesthetify ran three arguments. It said the chatbot, as an AI system, works autonomously within the operating framework set for it, on the basis of statistical probability calculations, and is not steered or controlled in detail, so no human decision stands behind any answer. It added that no one could tell whether a given answer came from the question asked, faulty training data, missing safeguards or a mix of these. Its second argument was that a consultancy had developed and trained the chatbot using only the content loaded into its vector database, such as the business's own website text and FAQs, so a reasonable business would have had no reason to prepare for these questions. The association pleaded no knowledge of either account. It was undisputed that this content said nothing false about the doctors' specialist qualifications. Aesthetify's third argument was that the false titles lacked commercial relevance, because the people the chatbot addressed know AI answers are prone to error and would in any case look at the doctor's profile on the website, which was accurate.
The court granted the claim in full on 12 May 2026. Aesthetify may not, in its commercial dealings with consumers, describe its managing directors, who practise as doctors, by any of the three titles (for the first, unless they complete the corresponding specialist training). For each culpable breach the court threatened Aesthetify with a fine of up to €250,000, with detention in default of payment, or detention of up to six months, up to two years in total for repeated breaches. Any detention is enforced against its managing directors. Aesthetify must also pay the €260 with interest, and the costs. The court gave permission for an appeal on points of law (Revision) to the Federal Court of Justice, on the ground that the case is of fundamental importance. Its press release said new legal questions about attributing a chatbot's false statements were decisive. The North Rhine-Westphalia judicial database and the consumer association both record the judgment as final.
The duty engaged
The propositions below about the judgment are the court's unless marked as this register's reading. The paragraphs on the UK and the AI Act set out the statutes, and for the UK the regulator's guidance, from the texts cited under Sources, with this register's reading, since the judgment discusses neither. Quotations from the judgment are in German, with this register's translations.
Whose commercial practice was it? Section 3(1) of the German Act against Unfair Competition (UWG) prohibits unfair commercial practices. Under section 5, a misleading practice is unfair if it is likely to lead a consumer to a decision they would not otherwise have taken, and statements capable of deceiving about a trader's qualifications and status are misleading. Nobody disputed that the titles were false, so the case turned on attribution. The court decided that under the UWG's own definition of a commercial practice in section 2(1) no. 2: conduct for the benefit of a business, objectively connected with promoting its sales. It found the answers had that connection to Aesthetify's sales, and then asked whether they were Aesthetify's own conduct.
The chatbot is the business's tool. The court read "conduct" widely enough to cover the use of technical means, and relied on a 2021 Federal Court of Justice decision, in a legal-services case, that treated a contract document generated purely by software as the act of the company behind the software. It saw no material difference in a chatbot. Aesthetify ran the chatbot and had decisive influence over how it spoke to customers, as the ease of its later repair showed. Even if the chatbot answered autonomously, the business set the framework it answered within. So it was "(lediglich) ein technisches Mittel" (only a technical means) that the business used to communicate with potential customers and patients, and over which it had sufficient control. The black-box objection failed for a similar reason. No human decision stood behind each software-generated contract either, and the decision to deploy the chatbot in its particular form was taken by the business and its IT contractor. From all this the court concluded, adopting a view it described as correct, that the use of AI, including chatbots, is a commercial practice of the operator, "weil dieser hinreichenden Einfluss auf das System hat und es in Gang setzt" (because the operator has sufficient influence over the system and sets it in motion). The court added that this reading matches the EU Unfair Commercial Practices Directive, under which a commercial practice is "any act, omission, course of conduct or representation, commercial communication including advertising and marketing, by a trader, directly connected with the promotion, sale or supply of a product to consumers".
It is not a third party. Aesthetify argued that liability under the duty-of-care doctrine first requires a duty to check, monitor or prevent, and that no such duty arose because the answers were unforeseeable. The court held that doctrine does not apply. It applies only where a business, by its conduct in trade, creates a serious risk that third parties will infringe interests protected by competition law, an online marketplace being the court's example. The judgment says the chatbot is not a third party in this sense ("nicht um einen Dritten in diesem Sinne"), so the claim was for Aesthetify's own infringement. The Federal Court of Justice's autocomplete ruling on search engines did not help either, since the disturber liability it discussed is no longer available for wrongs of this kind.
In the alternative, the error was foreseeable. The court added that the result would be the same under the doctrines Aesthetify relied on. A substantial part of the consumers Aesthetify addresses, people seriously interested in cosmetic procedures, have a heightened interest in whether its doctors hold a specialist title in their field, and Aesthetify knew it, because it advertised other doctors' titles on its website. Health care calls for especially strict standards of market conduct. A careful business should have expected patients to put this question to the chatbot. It had to be plain to a business in Aesthetify's position acting conscientiously and prudently, or to the contractor it answers for under section 8(2) UWG, that the chatbot, asked the natural question about its managing directors' specialist qualifications, "unzutreffende Antworten halluzinieren könnte" (could hallucinate incorrect answers), as in the end it did. How Aesthetify dealt with the problem once it learned of it showed that reprogramming the chatbot was easy, so it was also reasonable to require it to make sure before launch that the chatbot gave no false answers about its practitioners' specialist qualifications. The court left open whether answers provoked by a tendentious question are treated differently, since the questions here were neither tendentious nor leading.
Consumer awareness of AI errors was no answer. The court found no rule of experience that people discount chatbot answers. It found that a large part of the consumers addressed place particular trust in a computer-generated answer, "da Maschinen im Allgemeinen als weniger fehleranfällig als der Mensch wahrgenommen werden" (since machines are generally perceived as less prone to error than people). Had potential customers generally distrusted the answers the AI produced, it added, Aesthetify would certainly not have chosen to put a chatbot on its website. The judgment does not deal separately with the point about the website profiles.
A repaired chatbot did not end the claim. The risk of repetition is presumed from the breach. The court found nothing pleaded or otherwise apparent to suggest the risk had lapsed, and noted that Aesthetify never gave a penalty-backed undertaking, which is as a rule required to end it.
The UK. Since 6 April 2025 unfair commercial practices have been governed by the Digital Markets, Competition and Consumers Act 2024. A commercial practice includes "an act or omission by a trader relating to the promotion or supply of" the trader's product to a consumer (section 225(3)). A practice involves a misleading action if it involves "the provision of false or misleading information relating to a product, a trader or any other matter relevant to a transactional decision" (section 226(1)(a)). It is unfair, and so prohibited, if as a result it is likely to cause the average consumer to take a transactional decision they would not have taken otherwise (section 225(1) and (4)(a)). The Competition and Markets Authority's guidance, Complying with consumer law when using AI agents, published on 9 March 2026, says a business is responsible for what an AI agent does "in the same way you are responsible for what an employee does", even if someone else designed or provides the agent. As at 27 September 2026 this register has found no UK decision on chatbot answers under the Act, and none applying that guidance. This register's reading is that a UK court would likely treat the chatbot's answers as the trader's own commercial practice, the result Hamm reached. For the definition of a trader, section 225(6)(a) makes it immaterial whether the trader (P) acts personally "or through another person acting in P's name or on P's behalf". In UK legislation a person includes a body of persons, corporate or unincorporate (Interpretation Act 1978, Schedule 1). A chatbot is neither, so on this reading its answers are the trader's own act.
The AI Act. Article 50(1) requires providers to ensure that AI systems intended to interact directly with people are designed and developed so those people "are informed that they are interacting with an AI system", unless that is obvious to a reasonably well-informed, observant and circumspect person, given the circumstances and the context of use. It applies from 2 August 2026, after both the answers and the judgment, and the Digital Omnibus on AI left paragraph 1 unchanged. The judgment does not discuss whether the chatbot was labelled as AI.
The liability chain
The register tags this deployer. This section is this register's reading of where the judgment leaves each party, and it names the court wherever it reports a holding. The business that put the chatbot in front of patients carries the liability, and the court rejected each of Aesthetify's arguments that the answers were not its own.
The deploying business, for its own conduct. The court treated the answers as Aesthetify's own infringement. It reached the rules on supervising others only in the alternative. This register's reading is that, on the court's main route, foreseeability plays no part where a business runs a customer-facing chatbot, has sufficient influence over it and sets it in motion, at least under German unfair competition law. What remains is whether the chatbot's answers, given in promoting the business's services, were misleading and likely to lead a customer to a decision they would not otherwise have taken.
The contractor Aesthetify says built it. On Aesthetify's account a consultancy developed and trained the chatbot. The court treated that contractor as someone Aesthetify answers for under section 8(2) UWG, which extends injunction claims to a business owner for infringements by its employees or agents. The association sued only Aesthetify. The judgment does not consider whether the consultancy could have been sued itself, or any claim over against it. This register's reading is that the builder's practical exposure on these facts runs to its customer, through the development contract.
The model provider. The judgment names no underlying model. It describes the chatbot as an algorithm based largely on probability calculations, and treats that as no obstacle to attribution. No party argued that a model provider was responsible, and the judgment says nothing about one.
Patients. The court put no fact-checking burden on them.
The size of the exposure. The only sum the judgment fixes is €260 with interest, the association's flat-rate charge for the warning letter, and Aesthetify also bears the costs of the action. Its injunction is backed by the threat of a fine of up to €250,000 against the business for each culpable breach, or detention enforced against its managing directors. A consumer association brought the claim on three answers, and the judgment records no complaint from any patient. The case joins Moffatt v Air Canada, where a Canadian tribunal held an airline liable in negligent misrepresentation for its chatbot's invented policy. California Civil Code section 1714.46, discussed in AIR-2026-012, removes the autonomy defence by statute. On this register's reading, Hamm reaches the same result for the business running the chatbot through the UWG's general definition of a commercial practice, with no AI-specific statute.
What would have prevented it
- Test the obvious questions before launch. In its alternative reasoning, the court expected a careful business to anticipate that patients would ask the chatbot about its doctors' specialist titles. List the high-stakes facts about the business (qualifications, prices, cancellation rights, clinical claims) and test the chatbot against them before launch and after every change.
- Answer regulated facts from a verified source, or decline. The court relied on Aesthetify's own repair, a prompt instruction and a keyword filter, to show that the business controlled its chatbot and, in its alternative reasoning, that preventing the error before launch was easy. For credentials and regulated claims, the chatbot should quote an approved statement or hand the question to a person.
- Check the outputs as well as the source content. On Aesthetify's account the chatbot drew only on the business's own content, and it was undisputed that this content said nothing false about the doctors' qualifications. It still produced three false titles.
- Review what the chatbot says about the business. Log its answers about the business's people, prices and qualifications, and check a sample regularly.
- Write accuracy controls into the build contract. Section 8(2) UWG extends injunction claims to a business for infringements by its employees or agents, and the court applied it to the contractor that, on Aesthetify's account, built the chatbot. Testing, guardrails, change control and an indemnity belong in the agreement.
Mapped controls
- OWASP Top 10 for Agentic Applications 2026: as in AIR-2026-003, no category squarely covers non-adversarial hallucination to a consumer. The nearest is ASI09 Human-Agent Trust Exploitation, and the court's finding on consumer trust in machine answers describes that risk. Mapped as a partial analogue, flagged as such.
- Singapore IMDA Model AI Governance Framework for Agentic AI (v1.5, published 20 May 2026, updated 5 June 2026): "Make humans meaningfully accountable". The court located the accountable human decision in the choice to deploy the chatbot in its particular form.
- NIST AI RMF: MEASURE, because the chatbot went live without safeguards against a foreseeable high-stakes question, which the court, in its alternative reasoning, held it was reasonable to ensure before launch. MANAGE, because the risk was controlled only after the warning letter. GOVERN, because on Aesthetify's account a contractor built the chatbot, and the court treated the business as answerable for that contractor under section 8(2) UWG.
- Consumer law: Unfair Commercial Practices Directive 2005/29/EC, Articles 2(d) and 6(1)(f), with sections 3(1) and 5 UWG in Germany. Digital Markets, Competition and Consumers Act 2024, sections 225 and 226, in the UK.
- EU AI Act: Article 50(1), applicable from 2 August 2026.
- The general rule the case stands for, on this register's reading: a chatbot a business puts in front of customers, and has sufficient influence over, is the business's own means of communication, and its answers are the business's own commercial practice. The court's stated reason was that the operator has sufficient influence over the system and sets it in motion. The court applied that to a chatbot which, on its operator's account, was built by a contractor, trained only on the business's own content (which, it was undisputed, said nothing false about the doctors' qualifications) and answered without human review of each answer. The judgment cites neither Moffatt nor Amazon v Perplexity. This register reads it alongside both. Moffatt held an airline liable in negligent misrepresentation for what its chatbot told a customer, and in Amazon v Perplexity a Ninth Circuit panel, whose decision the full court declined to rehear in September 2026, treated an AI agent as "a tool, not a person for statutory purposes" under the Computer Fraud and Abuse Act.
Sources
- Oberlandesgericht Hamm, judgment of 12 May 2026, 4 UKl 3/25 (ECLI:DE:OLGHAM:2026:0512.4UKL3.25.00) - the full judgment in the North Rhine-Westphalia judicial database, read in full in German. Primary for every fact and holding in this entry attributed to the court: the chatbot's three answers of 3 April 2025, the undisputed absence of the specialist qualifications, the warning letter, the prompt instruction and keyword filter, the admission of 23 April 2025, Aesthetify's three-part defence as pleaded, first-instance jurisdiction under section 6 of the Injunctions Act, the UWG provisions it applied (sections 3(1) and 5, and the section 2(1) no. 2 definition of a commercial practice), the attribution reasoning and the Federal Court of Justice decisions it relies on, the rejection of the duty-of-care and disturber arguments, the alternative foreseeability holding, the question left open on tendentious prompts, the finding on consumer trust in machine answers, the operative order, and the permission to appeal. The database records the judgment as final. The judgment anonymises the parties. Translations are this register's - checked 27 September 2026 [primary]
- Oberlandesgericht Hamm, press release of 12 May 2026, "Urteil in Sachen Verbraucherzentrale Nordrhein-Westfalen e.V. gegen Aesthetify GmbH" - the court's press office. Primary for the names of the parties, for the court's statement that new legal questions on attributing a chatbot's false statements were decisive to its permitting an appeal, and for its statement that the business answers even if the chatbot was trained only on correct data; corroborates the holding that the chatbot is not a third party - checked 15 September 2026 [primary]
- Verbraucherzentrale NRW, "Zurechnung von Falschangaben eines KI-Chatbots auf einer Webseite" - the claimant's own case note, as at 1 June 2026. Names Aesthetify GmbH as the defendant, gives the court, date and file number (I-4 UKl 3/25), and states that the judgment is final - checked 27 September 2026 [primary]
- Directive 2005/29/EC, the Unfair Commercial Practices Directive (consolidated text of 28 May 2022) - primary for the Article 2(d) definition of a commercial practice, which the court cites, and Article 6(1)(f) on misleading information about the trader's qualifications and status - checked 15 September 2026 [primary]
- Gesetz gegen den unlauteren Wettbewerb, section 3 and section 5 - the federal statute text. Primary for section 3(1), which prohibits unfair commercial practices, and for section 5(1) and 5(2) no. 3, under which a misleading practice is unfair if it is likely to lead to a decision the consumer would not otherwise have taken, including a statement capable of deceiving about the trader's qualifications and status - checked 23 September 2026 [primary]
- Gesetz gegen den unlauteren Wettbewerb, section 8 - the federal statute text. Primary for section 8(2), extending injunction claims to the owner of a business for infringements by its employees or agents - checked 15 September 2026 [primary]
- Digital Markets, Competition and Consumers Act 2024, section 225 and section 226 - the revised statute on legislation.gov.uk. Primary for the definition of a commercial practice, the unfairness test and misleading actions, and for commencement on 6 April 2025 by S.I. 2025/272 - checked 27 September 2026 [primary]
- Competition and Markets Authority, "Complying with consumer law when using AI agents", 9 March 2026 - the regulator's guidance on GOV.UK, part of the publication "Using AI agents: complying with consumer law". Primary for the CMA's statement that a business is responsible for what an AI agent does as it is for what an employee does, including where someone else designed or provides it - checked 27 September 2026 [primary]
- Interpretation Act 1978, Schedule 1 - primary for the definition of a person as including a body of persons corporate or unincorporate - checked 23 September 2026 [primary]
- Regulation (EU) 2024/1689, the AI Act and Regulation (EU) 2026/1744, the Digital Omnibus on AI - the Official Journal texts. Primary for Article 50(1) and its application from 2 August 2026, and for the Omnibus, which replaces Article 50(7), leaves Article 50(1) unchanged and adds a new Article 111(4) giving providers of systems generating synthetic audio, image, video or text content that were on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2) - checked 15 September 2026 [primary]
Cite this entry as: Onyekwere, Michael K., AIR-2026-014, AI Agent Incident Register, CompanyScope, https://companyscope.io/register/air-2026-014, as at 2026-09-27. Entry IDs are stable; corrections publish as dated addenda on this page. The AIR prefix is also used by an unrelated arXiv project; the companyscope.io URL identifies this register.
Talk to Michael about your agent deployment - or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe - freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
This analysis is the work Janus Compliance does for clients before the incident. For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Browse the full register or the vendor compliance index.