AI Overviews and the Limits of the Search Safe Harbor
Ask Google whether a Munich publishing house runs scams, and early this year its AI Overview would have answered yes—about that publisher and its subsidiary. It would have described subscription traps and dubious business practices, and linked the companies to fraudulent firms they had no connection to. None of it appeared in the sources the Overview cited; the system had generated the connection itself. In May 2026, the Regional Court of Munich ordered Google to stop serving that AI Overview about the publishers on the theory that the overview is Google’s own statement, and not someone else’s falsehood, so Google must answer for it.
The ruling is provisional, and Google said it will appeal. If its reasoning holds and spreads, though, it marks the point where the liability regime that has protected search engine results for more than two decades is stopped from protecting the generative AI features built on top of them. That protection was always conditioned on the provider being a conduit for content that other people wrote, not generating the entirely new content themselves. European courts are beginning to say that a system that composes new text is not just a conduit, and to hold it liable for what it produces.
The AI Statement Belongs to Google
German law, like EU law, treats a search engine that points users to third-party pages as an intermediary, liable for another party’s unlawful content only after it has been put on notice and fails to act. But in LG München I, Case 26 O 869/26 (May 28, 2026), the regional court argued that AI Overviews are different in kind. By evaluating and combining material from various sources into a new answer, the system produces what the court called independent and substantive statements, some of which appear on none of the underlying pages. Because Google offers the feature and controls the model, the output it produces is independent content.
Google’s defense was that users can check the cited sources and that people know not to trust AI answers without verifying them. The court, as expected, rejected this argument. The ability to fact-check or disprove a statement through research does not excuse making the statement. So the court reasoned analogously to press law, where a publisher answers for a headline that defames even if readers never read the article beneath it.
The decision is a preliminary injunction from a court of first instance, issued in expedited proceedings and subject to the appeal Google said it will bring. Germany’s civil law system gives it no binding force over other courts. This is also the first court to enjoin an AI Overview on this reasoning; so holding the protective search engine rulings inapplicable to them is a distinction higher courts will test. The Regional Court of Frankfurt, though, had previously taken the underlying principle in September 2025, stating that Google can answer for an objectively false overview, dismissing a competition law case before it only because the summary there turned out not to be false.
The Court of Justice of the EU Is Also Narrowing the Exemption
The Regional Court of Munich did not invent the distinction it applied. EU law has, for a while, conditioned intermediaries’ protection on their neutrality to the content, meaning their status as a passive host (Google France, Joined Cases C‑236/08 to C‑238/08, 2010; L’Oréal v. eBay, Case C‑324/09, 2011). Under the e-Commerce Directive of 2000, and the Digital Services Act (the EU’s platform-liability regime, which now carries the distinction between neutral hosting and active involvement), a hosting provider escapes liability for user content only while it plays a technical, passive role and neither knows about nor controls the material it hosts. But a provider that takes an active hand in creating the content loses that protection. AI Overviews raise a prior question: whether a system that generates the content ever had the protection to begin with. The regional court’s reasoning is that it did not because no third-party content is being hosted in the first place. A search engine can still be a host, but the point made is that when the system composes a statement of its own, it is not hosting someone else’s words, so it answers as an author.
The Court of Justice of the European Union (CJEU) has been narrowing the exemption from a different direction than the Munich court, which makes it less likely that a German higher court, on appeal, will stretch the safe harbor to rescue generative output. This June, in a case that concerned when a member state may impose age-verification and content rules on services based in another (WebGroup Czech Republic; Coyote System, Joined Cases C‑188/24 and C‑190/24), the CJEU also held that a provider that decides through an algorithm whether, how, and in what order user-supplied information is passed on does exercise control over that information and cannot claim the hosting exemption. In July, ruling on an Italian fine for gambling ads on YouTube (AGCOM v. Google Ireland, Case C‑421/24), the CJEU said that when Google reviewed a creator’s channel to enter a commercial partnership, it acquired specific knowledge of that content and could not claim the exemption for those videos. Neither case is about artificial intelligence. In both, the content came from a third party; what cost the provider its shield was its own involvement in that content—controlling how it was ranked in the first case, and knowing what it said in the second.
The regional court and the CJEU narrowed the exemption for different reasons. The regional court did not extend it to a provider whose system produces the content, while the CJEU took it away from providers too closely involved with the third-party content, with arguments that might apply if those of the regional court fail on appeal. The common thread is that both the Munich court and the CJEU read the exemption as protecting only a passive conduit, and both place an algorithmic service that ranks or generates on the other side of it.
The Web-Surfacing Defense Is Shrinking
In response, AI companies are likely to argue that the output merely surfaces what is already online. In the EU, this defense is becoming unavailable for the generative layer, including AI Overviews, while it remains available for ordinary search. A search results page can still return a list of links to content someone else wrote and answers for, so the provider acts only as a conduit for those links. But an AI summary that states, in “its own” generated language, that a company runs subscription traps makes a claim no one else stands behind, and the farther the output travels from the sources it cites, the weaker the intermediary framing becomes.
That leaves providers of generative search with a narrow set of options, none of them costless. They can try to bind the output so closely to the cited sources that the summary asserts nothing the underlying pages do not. That constrains the product significantly, though. For publishers of sites that once received click-throughs from Google Search and have recently complained that AI Overviews strip their traffic, it may be the outcome they prefer. They can otherwise absorb liability exposure for the errors a generative system produces at scale. Or they can withdraw the feature in jurisdictions that adopt this view, which is workable for an overview bolted onto search but much harder for a chatbot whose entire product is generated text.
There is no good reason why the characterization this ruling adopted (that generated output is the provider’s own content) would stay confined to defamation. Once a system’s statements count as the provider’s own, the same starting point feeds any regime that turns on who made a claim: data protection rules on accuracy when an AI states false facts about a person, consumer protection rules when it misdescribes a product, and the product liability regime arriving in Europe. Each regime keeps its own elements and defenses, so a company that authors a statement for one purpose is not automatically liable under all of them. But that characterization is a necessary first step. That is why anyone deploying generative AI in Europe should be following a preliminary injunction at a German court about two publishers.
Legislation Points the Same Way
The statutory picture, which does not depend on the characterization adopted by the regional court, points that way. From December 2026, the revised Product Liability Directive treats software, including AI systems, as products and applies strict liability to them. A claimant harmed by a defective AI product need not prove that the provider was negligent, only that the product was defective and caused the harm, with disclosure rules and presumptions that ease that burden. Defamation and product liability are separate actions with separate elements, but the Munich court’s reasoning hints at a single underlying principle for cases in which they overlap in AI products: The provider can be held to answer without showing fault.
The AI Act could be mistaken for the instrument that resolves the questions raised by the regional court’s ruling. The AI Act regulates AI systems as products to be made safe, through risk classification, transparency, and documentation obligations. A person harmed by a particular output gets only the ability to complain to an authority, while claims for the harm fall to other law. For that reason, the claim in the regional court went under German personality and press law (the reputation and image protections that stand in for a U.S. defamation and right of publicity claim). The General Data Protection Regulation (GDPR) did not apply either, since the GDPR protects individuals and the plaintiffs in that case were companies. The EU also stepped back from the instrument that would have addressed AI liability head-on. The proposed AI Liability Directive, which would have addressed AI liability, was withdrawn in 2025, leaving fault-based claims to national tort law. The reclassification the legislature declined to enact is being worked out, case by case, in national courts.
Three Doctrines Are Converging
Three bodies of law that developed separately are converging on one question: whether a system’s output can be attributed to the entity that ran it. Generative AI puts all three in play because a system that produces statements can be an intermediary that hosts, a service that ranks, and something close to a publisher that speaks at the same time—three states that trigger three different types of liability.
These threads run separately, but a shared practical understanding is starting to surface. The Munich injunction is one court’s early and provisional answer to where that leaves the usual safe harbor. It will not be the last, and the direction it points is not toward the provider. It may look forgettable, and it may not survive appeal, but its reasoning is a sign, in flashing lights, of where the law is heading.
