# Evidence: Liability

12 of 108 entries in the collection “Evidence” by Robert Haase, as of 21 September 2026.

Page: https://robert-haase.de/en/evidence.html · Overview of all claims: https://robert-haase.de/en/evidence.md · JSON: https://robert-haase.de/en/evidence.json · Deutsch: https://robert-haase.de/belege-haftung.md

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Please cite the primary source, not this page.

This file is generated from the page. Where the two differ, the page applies.

## How this collection is built

Every figure is traced back to the body that measured it, not to the article citing it. On their way through the retellings, figures lose their denominator first, then their caveat, and finally their origin. Where a figure is only accessible through a third party, that intermediary is named in the source line. Own measurements carry their method with them; they have not been independently verified yet.

**The limit belongs to the number.** The most common error is not the wrong number but the right one carrying a claim that reaches further than the evidence. That is why every entry has two parts, and the second one matters more. Above each figure sits what kind of evidence it is, from verified study to single case. That decides how far it carries.

What does not survive the check does not get in, or gets taken out, my own articles included. One of them claimed that 44 percent of US online shoppers begin their purchase journey in a language model, attributed to Bain. Bain gives two other figures, 17 percent and 30 to 45 percent, which had merged into one along the way. Both are here now; the 44 is not.

This page ages. Every entry carries its date; superseded numbers get replaced, not quietly deleted. If you find an error, [write to me](mailto:hallo@robert-haase.de) and I will correct it and note the date.

The collection does not map the state of the research, only the figures I needed for my own texts. Free to use with attribution. When in doubt, link the primary source rather than this page.

## Grades in this topic

+ Verified study, vendor documentation, or court decision (4) → air-canada, olg-hamm, perplexity-cfaa, screenshot-metadaten
+ Preliminary: prototype, single test, forecast, or vendor figure (1) → ai-overview-muenchen
+ Status, case report, or market observation (7) → cursor-bot, ai-act, produkthaftung-komplexitaet, auftragsverarbeitung-weisung, chevrolet-dollar, dpd-chatbot, nyc-mycity

---

## air-canada

**Claim:** Air Canada is liable for what its chatbot promised. The defence that the bot was responsible for its own actions was called "a remarkable submission" by the decision-maker.

**What the case is and is not:** It concerns a bereavement fare and 650.88 Canadian dollars in damages, not a general refund practice. It was decided by the Civil Resolution Tribunal in British Columbia, **not a court**, and it binds no one in Europe. The load-bearing sentence still reaches far beyond the case: it makes no difference whether information comes from a static page or a chatbot. The pointed phrase "separate legal entity" is the decision-maker’s summary, not the airline’s wording.

**Source:** Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia · 14 February 2024 · [full decision](https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html) · [Source](https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-february/bc-tribunal-confirms-companies-remain-liable-information-provided-ai-chatbot/)

**Grade:** Tribunal decision · Group: Verified study, vendor documentation, or court decision

**Permalink:** https://robert-haase.de/en/evidence.html#air-canada

---

## cursor-bot

**Claim:** Cursor’s support agent invented a usage rule that never existed and replied under the name "Sam".

**What the case shows:** The damage came not from a wrong answer alone but from the fact that it sounded like a binding company rule. The co-founder publicly clarified that no such rule existed and apologized; users then reported cancelling subscriptions. No figure for that exists. A single incident, but with the same pattern as the others: the agent speaks as the brand.

**Source:** The Register, 18 April 2025 (invented rule, apology) · [Fortune, 19 April 2025](https://fortune.com/article/customer-support-ai-cursor-went-rogue) (the name "Sam", cancellations) · [Source](https://www.theregister.com/2025/04/18/cursor_ai_support_bot_lies/)

**Grade:** Documented incident · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#cursor-bot

---

## ai-act

**Claim:** The EU AI Act transparency obligations for chatbots and for AI-generated content have applied since 2 August 2026. Generative systems placed on the market before that date have until 2 December 2026 to add machine-readable marking. The high-risk obligations were postponed to 2 December 2027 and 2 August 2028.

**Who is bound by what:** the marking under Article 50(2) binds the **provider** of the generating system, not a brand using a third-party model; that brand owes Article 50(1) for its own chatbot and Article 50(4) as a deployer of deepfakes. The exemption in Article 50(4) covers only text that has had human review *and* carries editorial responsibility and that informs the public on matters of public interest, not advertising, product copy or support replies; the marking duty in Article 50(2) is untouched. **Scope of the postponement:** what moved is Chapter III, Sections 1 to 3, except Article 6(5). The prohibitions did not move, and two new ones apply from 2 December 2026. The AI-literacy duty still applies but in weaker form: providers and deployers must support the development of their staff’s AI literacy and no longer have to ensure a sufficient level. **What the entry does not prove:** enforcement. Whether market surveillance applies Article 50 is not measured here; what “substantially alter” or “editorial control” mean is unsettled, and there is no case law. The postponement was agreed politically on 7 May 2026 and entered into force only on 27 July 2026, six days before the start date it moved. The direction has been stable, the calendar has not.

**Source:** Regulation (EU) 2024/1689 (AI Act), Article 50(1), (2) and (4) and Article 113 · amended by [Regulation (EU) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj) of 8 July 2026 (Digital Omnibus on AI), Official Journal of 24 July 2026, in force since 27 July 2026: new Article 111(4) and recast Article 113(3), plus recast Article 4 and new points (ba) and (bb) of Article 5(1), these applying from 2 December 2026 under new Article 113(3)(a) · procedure: trilogue agreement 7 May 2026, Coreper 13 May, plenary 16 June, Council 29 June, signature 8 July 2026, per the European Parliament’s Legislative Train ([procedure page](https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai)) · [AI Act full text](https://eur-lex.europa.eu/eli/reg/2024/1689/oj)

**Grade:** Legal status · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#ai-act

---

## olg-hamm

**Claim:** A German higher regional court has ruled, with the judgment now final, that a company is directly liable for the misleading statements of its own AI chatbot. The chatbot is not a third party in the sense of the law.

**What the case is:** The chatbot of Aesthetify GmbH, a provider of minimally invasive treatments, gave its two managing directors, both doctors, specialist medical titles they do not hold. That only correct data had been fed in was undisputed and did not help. What it turns on is control: the false answers could be stopped after the warning letter, with an instruction and a filter. Where that control is absent, the transfer is open. **What it does not give you:** final means binding between the parties, since 21 June 2026. The appeal to the Federal Court of Justice, admitted on grounds of fundamental importance, was not filed, so attribution stays undecided at the highest level. This is competition law, what was awarded was an injunction and 260 euros in costs, not damages, and it concerns the company’s **own** chatbot, for third-party systems nothing is decided. **Corrected on 10 September 2026:** until then this entry said “not final, appeal admitted” and described the defendant as a clinic operator. The first reflected the state on the day of the judgment; the second came from press coverage and made the case bigger than it is.

**Source:** Higher Regional Court of Hamm, judgment of 12 May 2026, case 4 UKl 3/25 (Verbraucherzentrale Nordrhein-Westfalen v. Aesthetify GmbH) · final since 21 June 2026 per the class action register of the Federal Office of Justice · [class action register](https://www.bundesjustizamt.de/DE/Themen/Verbraucherrechte/VerbandsklageregisterMusterfeststellungsklagenregister/Verbandsklagenregister/Unterlassungsklagen/Klagen/2025/172/UKlag_172_2025_node.html) · [Full judgment](https://nrwe.justiz.nrw.de/olgs/hamm/j2026/4_UKl_3_25_Urteil_20260512.html)

**Grade:** Court judgment, final · Group: Verified study, vendor documentation, or court decision

**Permalink:** https://robert-haase.de/en/evidence.html#olg-hamm

---

## produkthaftung-komplexitaet

**Claim:** The new EU Product Liability Directive counts software explicitly among products in Article 4. Under Article 10 a court *shall presume defectiveness* where proving it is “excessively difficult” for the claimant “in particular due to technical or scientific complexity” and they show only that it is likely. The same presumption applies where the defendant fails to disclose evidence it has been ordered to produce. The directive must be transposed by 9 December 2026.

**It does not apply yet:** the directive has no direct effect and covers only products placed on the market after 9 December 2026. Article 21 repeals the old Directive 85/374/EEC on the same date but keeps it in force for products placed on the market earlier. **And it does not reverse the burden of proof:** Article 10(4) applies only “notwithstanding the disclosure of evidence pursuant to Article 9”, and under Article 10(5) the defendant may rebut every presumption. That is an evidential disadvantage, not strict liability. There can be no case law on “excessively difficult” yet, because the rule applies to no product. **On the calendar, as of 21 September 2026:** less than three months before the deadline, Germany has not cleared parliament. The government bill has been before the Bundestag as printed paper 21/4297 since 25 February 2026, first reading 4 March, expert hearing 13 April, no evidenced step after that; it appears on no Bundesrat agenda after 30 January 2026, including the agenda for 25 September as of 18 September. Entry into force under the bill: 9 December 2026. **Limit of our own check:** the Bundestag’s information interface requires a key; it ran instead through the agendas of the Bundesrat, which every adopted statute must pass. A Bundestag decision appears there only with a delay, so the check does not reliably cover the most recent sitting weeks.

**Source:** Directive (EU) 2024/2853 on liability for defective products, 23 October 2024, Article 4(1), Article 9(1), Article 10(1) to (5), Article 21 and Article 22(1) · full text via the Cellar service of the EU Publications Office, because eur-lex.europa.eu refuses automated requests · transposition status retrieved 10 September 2026: Bundestag printed paper 21/4297 of 25 February 2026 ([printed paper](https://dserver.bundestag.de/btd/21/042/2104297.pdf)), verbatim record 21/31 of the committee on legal affairs and consumer protection for the public hearing of 13 April 2026, legislative file BR-Drs. 775/25 and the agendas of Bundesrat sittings 1061 to 1068 ([legislative file](https://www.bundesrat.de/bv.html?id=0775-25)), Federal Ministry of Justice procedure page with status “Entwurf” and last update 5 March 2026 · agenda of sitting 1068 (as of 18 September 2026) retrieved again on 21 September 2026 · [Directive](https://eur-lex.europa.eu/eli/dir/2024/2853/oj/deu)

**Grade:** Legal position · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#produkthaftung-komplexitaet

---

## ai-overview-muenchen

**Claim:** A German regional court granted an injunction barring Google from spreading eight claims about a publishing house and seven about a company belonging to it in its AI Overview, among them fraud scheme and subscription trap. It treated the AI Overviews as Google’s own attributable content rather than mere search results, held Google directly liable as the interferer (unmittelbare Störerin) and denied the liability exemptions for hosting providers and for search engines. After Google appealed, the parties settled.

**What the case is and is not:** The settlement removed the judgment before any higher court could review it; it binds no one, and the legal question stays open. The standard was prima facie evidence, not a full hearing: in part the claimants substantiated the falsity by sworn declaration, in part Google could not substantiate the truth. Of ten and nine points sought, eight and seven were granted; the rest was dismissed. Damages were neither sought nor available in summary proceedings. **Where that status appears:** as an editorial note in the case-law database, not in the judgment; it points to a practitioner comment (Veelken, GRUR-Prax 2026, 426) that was not checked.

**Source:** Regional Court Munich I, final judgment of 28 May 2026, case 26 O 869/26, preliminary injunction proceedings, injunction based on corporate personality rights · Appeal at Higher Regional Court Munich, case 18 U 1744/26 Pre e, ended by settlement, judgment void per the editorial note at BAYERN.RECHT · citations include NJW 2026, 2271 and MMR 2026, 814 · checked 10 September 2026 · [Source](https://www.gesetze-bayern.de/Content/Document/Y-300-Z-BECKRS-B-2026-N-11860)

**Grade:** Preliminary injunction, void after settlement · Group: Preliminary: prototype, single test, forecast, or vendor figure

**Permalink:** https://robert-haase.de/en/evidence.html#ai-overview-muenchen

---

## auftragsverarbeitung-weisung

**Claim:** For processing on behalf of a controller, the General Data Protection Regulation requires a contract or other legal act stipulating that the processor processes personal data only on documented instructions from the controller (Art. 28(3)(a)); Art. 29 binds directly, and the controller must be able to demonstrate compliance (Art. 24(1)). Art. 28(10) sets the tipping point: a processor that infringes the Regulation by determining the purposes and means of processing is considered a controller in respect of that processing.

**What the law does not say:** It governs personal data, not brand claims; carrying it over to agents is an analogy without case law, and it breaks at Art. 28(10): an agent that determines purposes and means itself would no longer be taking instructions. **What gets dropped when quoted:** Art. 28(10) addresses a processor, and the determining must amount to infringing the Regulation; the general rule in Art. 4(7) is a definition, not a tipping rule. Statutory obligations to process remain unaffected.

**Source:** Regulation (EU) 2016/679 (General Data Protection Regulation), Art. 28(3)(a), Art. 29, Art. 24(1) and Art. 28(10) · verified against the Official Journal text and diffed against consolidated version 02016R0679; none of the three corrigenda (OJ L 314/2016, L 127/2018, L 74/2021) touches any of the four provisions; the 2016 and 2021 corrigenda do not exist in English, all three were checked in German; no amendment has ever entered into force, and the two pending proposals, COM(2025) 837 (Digital Omnibus) and COM(2025) 501 (relief for small mid-caps), do not concern Art. 28 or 29 · Official Journal L 119 of 4 May 2016 · [Source](https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng)

**Grade:** Legal status · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#auftragsverarbeitung-weisung

---

## chevrolet-dollar

**Claim:** The ChatGPT-powered chatbot of a Chevrolet dealer agreed to sell a new Tahoe for one dollar and called it a legally binding offer with no take-backs. The user had dictated that exact formula to the chatbot earlier in the same conversation. The chatbot went offline shortly afterwards. No source reports an attempt to enforce the offer.

**What the case does not prove:** neither a liability consequence nor the absence of one. None of the sources reports an attempt to buy, a claim or a proceeding. The widely repeated statement that the dealer refused to honour the deal appears in no contemporaneous source, only in later summaries. The liability question was not answered in the negative here, it was never asked. **On the sourcing:** the chatbot came from the vendor Fullpath, which also operated it on a Chevrolet dealer’s site; after publication GM stated that dealers procure this tool on their own. The exchange is evidenced solely by the user’s screenshot. Whether the dealer or the vendor switched the bot off is reported differently; no price appears here because neither source states one and the figures in later coverage diverge.

**Source:** GM Authority, Jonathan Lopez, 18 December 2023 (wording on both sides, shutdown, GM statement) · Business Insider, Katie Notopoulos, 18 December 2023 (vendor and GM statements; full text behind businessinsider.com’s metered paywall, read free of charge in the licensed Yahoo republication of 19 December 2023) · Original evidence: Chris Bakke’s post on X, 17 December 2023, with screenshot · [Source](https://gmauthority.com/blog/2023/12/gm-dealer-chat-bot-agrees-to-sell-2024-chevy-tahoe-for-1/)

**Grade:** Documented incident · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#chevrolet-dollar

---

## dpd-chatbot

**Claim:** DPD’s chatbot called its own company “the worst delivery firm in the world” after a customer told it to recommend better delivery firms and to be over the top in its hatred. DPD said the AI element had been disabled immediately.

**Where the sentences come from:** The BBC did not observe the bot’s answers itself. They appear in screenshots taken by the customer, and the caption notes that pixelation was added. Only the company statement comes from DPD itself. In its quoted wording the cause is no more than a point in time, “An error occurred after a system update yesterday”; the causal version is reported by both the BBC and the Guardian as DPD’s own account. **What the case does not show:** The bot did not turn against its own brand by itself, it was instructed to. There is no claim, no court, no quantified damage and no measurement of normal operation. The only figure, 800,000 views of the customer’s post in 24 hours, is a platform counter.

**Source:** Tom Gerken, BBC News · statement from DPD, bot replies quoted from the customer’s screenshots · 19 January 2024 · cross-check: Guardian, 20 January 2024 · [Source](https://www.bbc.com/news/technology-68025677)

**Grade:** Documented incident · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#dpd-chatbot

---

## nyc-mycity

**Claim:** New York City’s official MyCity chatbot told businesses to do things that are illegal in the city: go cash-free, take a cut of employees’ tips, and turn away tenants with housing vouchers. Ten members of the newsroom asked the same question and all ten got the same wrong answer. The city defended it as a pilot program; almost two years later, in early February 2026, it was shut down as a budget cut.

**What the case is and what it is not:** a journalistic spot check with no stated population and no error rate. It did not always answer the same way; one reporter got the correct answer. Whether anyone acted on it is unknown. All three prohibitions have exceptions: small owner-occupied buildings under the anti-discrimination rule; telephone, mail and internet purchases paid off the premises under the cash rule. Separately, an employer may count tips against the minimum wage but may not keep them. The city did respond: disclaimers, corrected answers, fewer questions answered. **What the shutdown is not:** an admission of illegality. The trigger was a $12 billion budget gap. Defending the bot and shutting it down were two different administrations; the second took office in early 2026.

**Source:** Colin Lecher, The Markup, copublished with Documented and THE CITY · spot-check testing of New York City’s MyCity chatbot · March 29, 2024 · shutdown confirmed in the February 4, 2026 update to the follow-up article “Mamdani to kill the NYC AI chatbot we caught telling businesses to break the law” by Colin Lecher and Katie Honan, The Markup with THE CITY, January 30, 2026; chat.nyc.gov has redirected since February 3, 2026 to a city page headed “The Chatbot beta test has ended.” · [Follow-up article of January 30, 2026](https://themarkup.org/artificial-intelligence/2026/01/30/mamdani-to-kill-the-nyc-ai-chatbot-we-caught-telling-businesses-to-break-the-law) · [Source](https://themarkup.org/artificial-intelligence/2024/03/29/nycs-ai-chatbot-tells-businesses-to-break-the-law)

**Grade:** Documented incident · Group: Status, case report, or market observation

**Permalink:** https://robert-haase.de/en/evidence.html#nyc-mycity

---

## perplexity-cfaa

**Claim:** A US federal appeals court vacated the preliminary injunction against Perplexity on 4 August 2026 and remanded the case. When someone runs a shopping agent, it is the user who accesses the third-party website under the Computer Fraud and Abuse Act, the agent is the user’s tool and the provider does not access anything itself, as long as the agent runs in the user’s browser and the provider’s servers never call the site themselves.

**What the ruling is and is not:** It is preliminary, only the prospects of success at the injunction stage were tested. On 18 August 2026 Amazon petitioned for rehearing en banc; the court denied the petition, and no judge requested a vote (report of 10 September 2026). It is US law and binds no one in Europe. **What the court leaves open:** It says nothing about server-side agents, it establishes no new legal regime for agentic AI, it decides nothing about liability in tort, and on a different record the provider might exercise enough control to gain entry itself. The case concerns someone else’s agent on your site, not liability for your own. The site’s terms of service remain untouched.

**Source:** Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, United States Court of Appeals for the Ninth Circuit, opinion by Judge Milan D. Smith, Jr. · 21 pages, FOR PUBLICATION, no separate opinion, on appeal from N.D. Cal., Judge Maxine M. Chesney · decided 4 August 2026 · petition for rehearing en banc filed 18 August 2026 as docket entry 66 per the public RECAP docket mirror (CourtListener, docket 72502129), last refreshed 21 August 2026, not from the linked opinion · denial of the petition per Courthouse News, “No 9th Circuit rehearing in Amazon-Perplexity case”, 10 September 2026, the order itself not seen ([report](https://www.courthousenews.com/no-9th-circuit-rehearing-in-amazon-perplexity-case/)) · [Source](https://cdn.ca9.uscourts.gov/datastore/opinions/2026/08/04/26-1444.pdf)

**Grade:** Court ruling, not final · Group: Verified study, vendor documentation, or court decision

**Permalink:** https://robert-haase.de/en/evidence.html#perplexity-cfaa

---

## screenshot-metadaten

**Claim:** A screenshot does not carry the original’s C2PA provenance data: the record lives in the file, and a screenshot creates a new one. Conversely, a C2PA-enabled camera photographing an AI image signs that shot, with no trace of its AI origin. As a rule it records device, time and place in metadata and cannot analyse the content of the image; what goes in is up to the implementer, the same page says.

**What the evidence does not say:** The same answer first records that missing history is flagged: the screenshot stays recognisable as a file without provenance. The page itself limits how much that says, calling Content Credentials a positive signal and not a negative one. The evidence concerns the metadata layer only: it lists watermarking as a technique that survives “cropping, rotation, or screen capture”, and the C2PA specification provides for recovering stripped metadata through a lookup against a watermarked ID or a fingerprint. **Who says so:** The page carries Adobe’s copyright and points alongside to its own remedy, Durable Content Credentials. The watermarking claim is self-reported and unmeasured, the recovery a possibility of the specification, not evidenced routine.

**Source:** Content Authenticity Initiative (Adobe), developer documentation · FAQ, seven questions · retrieved 10 September 2026 · [Source](https://opensource.contentauthenticity.org/docs/getting-started/faqs/)

**Grade:** Vendor documentation · Group: Verified study, vendor documentation, or court decision

**Permalink:** https://robert-haase.de/en/evidence.html#screenshot-metadaten

---

End of file: 12 of 12 entries on Liability. Last entry: screenshot-metadaten.
