A regional court in Munich has determined that Google bears legal responsibility for statements produced by its artificial intelligence within search results. This follows a legal case in which the AI generated false allegations against two publishers based in Munich. This unprecedented decision serves as a significant signal across the globe; the judiciary is reminding the platform of its duties in shaping the modern information environment. Google has launched an appeal against the verdict.[1]
The long-held principle that generative AI tools should not be held accountable is beginning to crack. The Munich court has handed down a firm ruling: Google can be held responsible for summaries created by AI Overviews, the summary feature in its search engine results. Google’s AI had associated the claimants, two Munich-based publishers of books and magazines who were anonymized in the final ruling, with dubious and prohibited commercial practices. These included the use of subscription traps, which involve inducing customers to take out paid subscriptions without their knowledge.
The court decided the links displayed by Google did not support the claims made by AI Overview. This is the latest skirmish in a decades-old battle over internet publishing. Historically, there were two different types of information distributors: carriers and publishers. A phone company is a carrier. It transmits whatever you say, even discussions about committing a crime. Words are words, and the phone company does not know, nor is it liable for, the words you choose to speak.
A newspaper, on the other hand, is a publisher. It decides the words it publishes and what quotes to include in its articles. If those words or quotes are defamatory or otherwise illegal, it is liable. Significantly, this time the court examined the freedom of expression on which Google could, in principle, rely in such circumstances. Its conclusion was that freedom of expression carries limited weight in this case: the disputed statements were primarily the result of an algorithm and commercial activity, not the expression of a human conviction.
Since the statements were generated autonomously by an AI system integrated into Google’s service, they were more than simple keyword search results displayed as a series of links. They constituted a response. The court also rejected the idea that internet users could verify the accuracy of the summaries themselves by consulting the cited sources. These AI-generated summaries are presented as assertions, which makes their status comparable, for example, to that of a headline read by a hurried reader, for which a media outlet is responsible even if the public does not take the time to verify the claims by clicking on a link.
Google has said it will appeal, and the court’s ruling could be revised. Its scope also remains limited to the specific case it addresses. Nevertheless, it contains the seeds of an urgent need: to clearly establish who is speaking when an AI system generates text, particularly in an information context, and therefore who is responsible for its failures, as well as what measures should be taken to mitigate the risks.
In the European Union, the Digital Services Act requires very large platforms to assess their systemic risks, and the EU Artificial Intelligence Act establishes transparency obligations for AI-generated content, which applies to AI Overview. But the current state of EU law remains insufficient. Neither law establishes an accountability framework adapted to the specific case of information summaries produced by generative AI systems in search engines.
The court ruled in favor of the plaintiffs on most counts. It banned claims about scams, connections to dubious companies, subscription traps, phone calls that never happened, and lack of availability. Only two minor requests were denied.
The risk of repeated violations remained, even though the specific texts were no longer being displayed. Google had not issued a cease-and-desist declaration with a penalty clause, and nothing stopped the algorithms from generating the same statements again. Google covers 80 percent of the legal costs; the plaintiffs pay 10 percent each. This ruling may also have international reach, the court has said.
This article is shared at no charge for educational and informational purposes only.
Red Sky Alliance is a Cyber Threat Analysis and Intelligence Service organization. We provide indicators of compromise information (CTI) via a notification/Tier I analysis service (RedXray) or an analysis service (CTAC). For questions, comments, or assistance, please contact the office directly at 1-844-492-7225 or feedback@redskyalliance.com
- Reporting: https://www.redskyalliance.org/
- Website: https://www.redskyalliance.com/
- LinkedIn: https://www.linkedin.com/company/64265941
Weekly Cyber Intelligence Briefings:
REDSHORTS - Weekly Cyber Intelligence Briefings
https://attendee.gotowebinar.com/register/7855487668891299929
[1] https://www.cybersecurityintelligence.com/blog/german-court-rules-google-liable-for-ai-errors-9523.html
Comments