11 min read

When Google Became the Answer, It Inherited the Liability

When Google Became the Answer, It Inherited the Liability

THE TECHNOLOGY BLIND SPOT

Two Munich publishers learned they were running scams from a machine that made it up.

Searchers who typed the companies’ names into Google saw an AI Overview open with a verdict: yes, this company is known for dubious business practices. The summary built out from there. A tidy structure. Red flags for the alleged fraud. A note about subscription traps. Tips on how to avoid getting burned. The two companies had no connection to any of it. The genuinely shady operators the AI had folded them in with were different businesses entirely, and not one of the websites Google linked beneath the summary drew the connection the summary asserted. Google’s own system composed the accusation, then footnoted it with sources that never made the claim.

For thirty years, Google’s answer to a complaint like that stayed the same. Those are not our words. We index the web, we point, and the people who wrote the pages answer for what the pages say. That defense built the largest information company in history. On May 28, 2026, a court in Munich ruled that the AI Overview broke it.

What Munich Held

The Regional Court of Munich I issued a temporary injunction barring Google from repeating the false claims about the two publishers, in Case No. 26 O 869/26. The reasoning carries further than the result. The court classified Google as a direct infringer, not an intermediary, because the AI Overview is Google’s own content. A traditional search engine makes third-party pages findable, and German courts had long shielded that function on the theory that the engine merely surfaces what other people wrote. An AI Overview does something the court refused to treat as the same act. It evaluates, combines, and rewrites those sources into independent statements, in its own words and its own structure, and it produces claims that appear in none of the underlying pages. Only Google can check those statements against the sources it drew them from. So Google answers for them.

Google argued that users could click through and verify the summary for themselves. The court rejected the premise. A statement that reads as self-contained and authoritative does not shed liability because a diligent reader might have disproved it. The court reached for press law, where a publisher answers for a headline that defames on its own terms, even when the full article corrects it and most readers never reach the article.

The court added a point that should unsettle every provider in the market. An AI-generated statement, it held, carries weaker free-expression protection than a human opinion, because the output is the product of an algorithm rather than a conviction anyone actually holds. Offering AI answers, the court reasoned, expresses Google’s commercial activity more than anyone’s protected belief. Strip the speech interest down to a business function, and the reputation of the people the machine names starts to outweigh it.

This ruling is not final. Google is reviewing it and can appeal, and a German trial court binds no one in the United States. The question it forced onto the table is already sitting on American desks, and the American answer so far points the other way.

America Went the Other Way

In May 2023, a journalist named Fred Riehl asked ChatGPT to describe a real federal lawsuit involving the Second Amendment Foundation. The chatbot returned a fluent summary of a complaint that accused a man named Mark Walters of embezzling funds from the organization. Walters is a nationally syndicated radio host. He was not a party to the lawsuit. No one had accused him of embezzling anything. The complaint ChatGPT described did not exist. Riehl checked the actual filing, caught the fabrication, and published nothing.

Walters sued OpenAI for defamation anyway. On May 19, 2025, the Superior Court of Gwinnett County, Georgia, granted OpenAI summary judgment and dismissed the case. The court gave three reasons. No reasonable reader, it held, would treat the chatbot’s output as a statement of fact, given OpenAI’s disclaimers and Riehl’s own immediate recognition that the output was wrong. Walters, as a public figure, had to prove actual malice, and knowing that a tool can err is not the same as knowing a specific statement is false. And Walters conceded that he suffered no actual damages.

Two courts, two continents, one question: when a machine generates a confident falsehood about a person, who answers for it? Munich said the company that built the machine. Gwinnett County said no one.

Pull the Three Legs Out

An easy reading treats those outcomes as a tidy split between a permissive American regime and a stricter European one. That reading misses what actually decided the American case. Walters did not hold that AI output is never defamatory. It held that this output, claimed by this plaintiff, on this record, was not actionable. Pull the three legs out and look at each one.

The first leg is the reasonable-reader holding: nobody treats AI output as fact. That premise is decaying in real time. A Pew Research Center study tracked the browsing of 900 American adults across roughly 69,000 searches in March 2025. When an AI Overview appeared, users clicked a source link inside it 1 percent of the time. They ended the search session 26 percent of the time, up from 16 percent without the summary. People are not treating the Overview as a starting point to verify. They read the answer and close the tab. The longer that behavior holds, the harder it becomes to argue that no reasonable reader relies on what the machine says.

Actual malice is the second leg. Walters carried that burden because he is a public figure, and New York Times Co. v. Sullivan sets that bar for public figures. A private business does not carry it. Under Gertz v. Robert Welch, Inc., a private-figure plaintiff defamed on a matter of private concern need prove only negligence, and states set the standard from there. Google’s AI branded the two Munich publishers, both private businesses, as scammers. That is the plaintiff who never has to prove the machine acted with malice.

Damages are the third leg. Walters conceded he had none, in part because Riehl never published the fabrication. A business that watches customers vanish after an AI Overview calls it a scam operation has the opposite problem. It has a number. Trade libel lives on exactly that proof: a false statement of fact, about a business, published to third parties, causing measurable economic loss.

Picture the case that does get tried. A regional medical-device distributor, or a family lender, or a staffing agency searches its own name and finds the Overview telling prospective customers it runs a subscription trap. Sales calls drop. A distributor cancels a contract. The company can put a number on the quarter. None of the trade-libel elements requires proving the machine wanted to cause harm. They require proving the statement was false, that it reached customers, and that the customers left.

The question is not whether American law lets AI companies off the hook. The question is whether it lets them off the hook against the right plaintiff. Walters was the wrong plaintiff. A defamed business with a customer exodus is the right one, and that case has not been tried yet.

A Shield Built for the Index

Behind the defamation elements sits the larger shield, the one the Walters court never had to reach. Section 230 of the Communications Decency Act tells courts not to treat an interactive computer service as the publisher of information provided by another content provider. For thirty years that single sentence has absorbed nearly every claim aimed at a platform over what its users posted.

Read the next clause. The statute defines an information content provider as anyone responsible, in whole or in part, for the creation or development of the information. A platform loses the shield for content it helped create. The entire German ruling is a finding that the AI Overview is created content, not surfaced content. That is the precise line Section 230 already draws. When Google indexes a defamatory page, the page is another provider’s content and the shield holds. When Google’s model generates the defamatory sentence, the sentence is Google’s own development of the information, and the statute stops protecting it by its own terms.

This is the same classification problem that runs through every corner of AI law, surfacing here on the liability side. A system cannot be a neutral conduit when that defeats a copyright claim and an original author when that defeats a defamation claim. The artifact does not change to suit the defense. [See The Better Your AI Gets, the Less You Can Own It, The Technology Blind Spot (2026).]

The ownership cases ask who made the expression and answer that no human did, so no one owns it. The liability cases ask the same question and arrive somewhere more dangerous for the platform. If Google made the expression, Google owns the consequences.

Where Opposing Counsel Is Right

Give the contrary case a fair hearing, because a managing partner will hear it from opposing counsel within the hour. It runs like this. Walters is the controlling American authority, and it went clean for the AI company on three independent grounds. Defamation requires fault, and an algorithm sampling a probability distribution forms no intent and holds no knowledge, so the fault element may be impossible to satisfy. Disclaimers put every user on notice that the output can be wrong. A German injunction from a trial court carries no precedential weight in any American courtroom. And federal courts have read Section 230 expansively for three decades. Stacked together, that is a formidable wall.

Most of it is true. Walters is real law, the fault question for machine output is genuinely unsettled, and a Munich injunction decides nothing in Memphis. A lawyer who tells a client otherwise is selling false confidence.

The wall has a gap, and the gap is the plaintiff. Every one of those defenses faced only a public figure who admitted he never believed the output and lost nothing. None has faced a private business with a documented customer exodus and a screenshot showing the AI asserted a fact that appears in none of its cited sources. The actual-malice defense does not touch that plaintiff. The no-damages holding does not survive a revenue chart. And the creation-or-development text of Section 230 fits the situation where the platform composed the sentence itself.

This argument has limits worth naming before an opponent names them. German personality and unfair-competition law have no clean American twin, so the Munich reasoning travels as persuasion, not precedent. The fault problem is real, and a court may yet hold that a model’s output cannot carry the scienter a defamation claim requires, which would end most of these suits before damages come up. A US court could also classify AI output as protected opinion rather than a statement of fact. The case for liability is strong. It is not a certainty, and selling it as one repeats the vendor’s mistake in the opposite direction.

An Accusation That Regenerates

Return to the two Munich publishers, because their problem did not end when the specific summaries came down. The court flagged the risk that the algorithm would generate the same defamation again. Google had made no binding commitment to stop, and nothing in the architecture prevented the model from reaching the same false conclusion on the next query. A human who defames you can be told to stop and will. A model that defames you keeps regenerating the accusation until someone changes what it does, and only the company that built it can do that. The harm is not a one-time error to be corrected. It is a standing condition that reasserts itself, which is why the court located the duty with Google and nowhere else.

Before Thursday

The hinge in the Munich case was notice. The publishers sent a cease-and-desist, Google failed to cure, and that failure drove the repeat-violation finding. Notice is the part a litigator controls, and it is the part to build now.

This week, run an exercise that takes twenty minutes. Type your firm’s name, and the names of your three largest clients, into Google and read the AI Overview. Then ask a consumer chatbot the questions a prospective client or an opposing party might ask about each of them. When the AI states a fact, open the sources it cites and check whether the fact appears there. Screenshot every claim that does not, and date the screenshot. That dated capture is constructive notice. It is the document that starts the clock and the evidence that the statement originated with the model, not with any page the model linked.

If you find a falsehood about a client, the next document is a cease-and-desist that does three things: it identifies the specific false statement, it shows that the statement appears in none of the cited sources, and it demands correction by a deadline. That letter is not a long-shot filing. It is the record that converts the provider from a neutral pipe into the author of a statement it was warned about and chose not to fix. The first American business to win one of these cases will win it on a record that looks like that. [See Your AI Research Tool Fabricated the Quotation, The Technology Blind Spot (2026).]

The two publishers in Munich were branded scam operators by a system that composed the words itself, then cited sources that never said them. For thirty years, Google’s defense against that kind of harm ran to three words. Not our words. The AI Overview is the moment the company started writing the sentence. When you write the sentence, you own what it does to the person it names. American courts have not said so yet. They are waiting, whether they know it or not, for a plaintiff who relied on the answer and can prove what it cost. That plaintiff is not a radio host who caught the lie and published nothing. It is a business that never saw it coming and watched the customers leave.

About the Author

JD Morris is Co-Founder and COO of LexAxiom, an Agentic AI platform for the business of law. Over a 25-year career, he has built and scaled enterprise technology products across Dell, EMC, VMware, and Cisco, including the first exabyte eDiscovery platform. He holds dual MBAs from Columbia Business School (Finance) and UC Berkeley Haas (Marketing), a Master of Legal Studies in Cybersecurity Law from Texas A&M, and a Master of Engineering from George Washington University. He writes The Technology Blind Spot on the intersection of emerging technology and law. Connect with him on LinkedIn at www.linkedin.com/in/jdavidmorris, on X at @JDMorris_LTech, or on Bluesky at @JDMorris-ltech.bsky.social.

References

1. Landgericht München I [Regional Court of Munich I], May 28, 2026, Az. 26 O 869/26 (Ger.).

2. Walters v. OpenAI, LLC, No. 23-A-04860-2 (Ga. Super. Ct. May 19, 2025).

3. New York Times Co. v. Sullivan, 376 U.S. 254 (1964).

4. Gertz v. Robert Welch, Inc., 418 U.S. 323 (1974).

5. 47 U.S.C. § 230(c)(1), (f)(3) (2018).

6. Restatement (Second) of Torts § 558 (Am. L. Inst. 1977).

7. Athena Chapekis, Samuel Bestvater, Emma Remy & Gonzalo Rivero, Google Users Are Less Likely to Click on Links When an AI Summary Appears in the Results, Pew Rsch. Ctr. (July 22, 2025), https://www.pewresearch.org/short-reads/2025/07/22/google-users-are-less-likely-to-click-on-links-when-an-ai-summary-appears-in-the-results/.

8. Matthias Bastian, Landmark German Ruling Declares Google’s AI Overviews Are Google’s Own Words and Makes It Liable for False Answers, The Decoder (June 11, 2026), https://the-decoder.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-answers/.



Originally published on LinkedIn Newsletter — The Technology Blind Spot

Leave a Reply

Discover more from The Technology Blind Spot

Subscribe now to keep reading and get access to the full archive.

Continue reading