Civil Law And Ai-Generated Defamation And Reputation Damage Claims In Europe .
Civil Law and AI-Generated Defamation and Reputation Damage Claims in Europe
1. Introduction
AI-generated defamation occurs when an artificial-intelligence system produces or reproduces false, misleading, insulting, or reputation-damaging information about an identifiable person or organisation.
Examples include:
a chatbot falsely stating that a person committed a crime;
an AI search assistant generating a false biography;
an AI-generated article falsely accusing a company of fraud;
an AI system inventing a criminal conviction;
an AI-generated image falsely depicting a person committing misconduct;
an AI voice clone making defamatory statements;
an AI search engine repeatedly displaying a false allegation;
an AI platform automatically republishing a defamatory statement;
an AI system combining true facts in a misleading way that seriously harms reputation.
There is currently no substantial European case-law body specifically deciding liability for a generative-AI hallucination as defamation. Therefore, existing European defamation, personality-rights, intermediary-liability, privacy and data-protection cases provide the principal legal framework.
This distinction is important: the cases below should not be presented as if they were already decisions about ChatGPT-style generative AI.
2. Meaning of Defamation in the European Context
European countries do not have one completely harmonised law of defamation.
National systems use concepts such as:
defamation;
libel;
insult;
personality rights;
protection of honour;
protection of reputation;
private-life protection;
non-material damage;
unlawful interference with personal rights.
Therefore, an AI-generated statement may give rise to different causes of action depending upon the country.
The common structure is generally:
Identifiable claimant → defamatory statement → publication → unlawfulness → fault/attribution where required → reputational harm → causation → remedy.
3. Why AI Creates a New Defamation Problem
Traditional defamation normally has a relatively identifiable publisher:
Journalist → writes article → newspaper publishes it.
Generative AI creates a much more complicated chain:
User asks question → AI processes prompt → model generates statement → platform displays answer → user may copy it → search engine may index it → third parties may read it.
Therefore, several potential actors may become relevant:
AI developer;
AI deployer;
chatbot operator;
platform;
search engine;
user who prompted the AI;
publisher who republishes the output;
data provider;
website containing the underlying information.
The central legal question becomes:
Who legally “published” the defamatory statement?
4. Core Civil-Law Issues
An AI-defamation claim generally requires examination of:
1. Identification
Is the person identifiable?
2. Falsity
Is the statement factually false?
3. Defamatory character
Does it damage honour, reputation or personality rights?
4. Publication
Was it communicated to someone other than the claimant?
5. Attribution
Who caused or controlled publication?
6. Fault
Was there negligence, knowledge, recklessness or another legally relevant form of responsibility?
7. Causation
Did the AI statement actually cause the claimed damage?
8. Damage
Was there:
financial loss;
professional damage;
emotional/non-material damage;
loss of business;
loss of employment;
social harm?
9. Freedom of expression
Does Article 10 ECHR protect the publication?
10. Privacy/data protection
Does GDPR provide additional remedies?
5. Case Law 1 — Google Spain SL and Google Inc. v AEPD and Mario Costeja González, C-131/12
This is one of the most important European cases for AI-generated reputation problems.
The CJEU considered the responsibility of search engines for personal information appearing on third-party webpages. It held that the operator of a search engine can be responsible for processing personal data appearing on webpages published by others. It also recognised the possibility of requesting removal of certain search results under the data-protection framework. (Infocuria)
Importance
This case is not a defamation case in the narrow sense.
Its importance for AI lies in reputation amplification.
Imagine:
An AI system generates a false statement about a person.
Even if the original source disappears, an AI search engine may continue to associate that person with the false allegation.
The legal problem therefore becomes:
publication + indexing + AI synthesis + continued accessibility.
AI application
A person may potentially seek:
correction;
removal;
de-indexing;
cessation of processing;
damages where the requirements of the applicable regime are satisfied.
The case established that search-engine processing can have a significant independent impact on a person's privacy because search results make information substantially more accessible. (curia)
Nature of authority: Foundational digital-reputation authority, not an AI-generation case.
6. Case Law 2 — Google LLC v CNIL, C-507/17
The CJEU subsequently considered the territorial scope of the right to de-reference.
The Court held that a search-engine operator is not generally required to remove links from every version of its worldwide search engine, although EU Member State versions must be addressed and appropriate measures must be taken against access from the EU to non-EU versions. (Infocuria)
Importance for AI-generated defamation
AI systems are global.
A false AI-generated statement could appear:
in France;
Germany;
Italy;
Spain;
outside the EU.
The claimant may therefore face a territorial-remedy problem.
Example
An AI-generated false biography is removed from an EU-facing service but remains accessible through a non-EU version.
The question becomes:
How far should the European remedy extend?
Google v CNIL provides an important framework for thinking about the territorial limits of reputation-related digital remedies.
Nature of authority: Digital reputation/data-removal authority.
7. Case Law 3 — Delfi AS v Estonia, ECtHR
The Grand Chamber of the European Court of Human Rights considered liability of a large commercial online news portal for offensive comments posted by users.
The Court accepted the Estonian courts' finding of liability in the particular circumstances, taking account of factors including the extreme nature of the comments, the professional/commercial nature of the portal and the steps taken to remove the comments. (HUDOC)
Importance for AI
This case is important because AI platforms may argue:
“We did not personally write the defamatory statement.”
But the legal question may instead be:
What role did the platform play in creating, displaying, controlling or distributing the harmful content?
For an AI platform, relevant factors could include:
whether the system autonomously generated the statement;
whether the operator controls the model;
whether the platform knows about recurring false outputs;
whether complaints were received;
whether correction mechanisms exist;
whether the platform can technically prevent recurrence.
Important limitation
Delfi concerned user-generated comments, not generative AI. It therefore cannot automatically be transferred to AI.
Nature of authority: Important intermediary-liability analogy.
8. Case Law 4 — Magyar Tartalomszolgáltatók Egyesülete and Index.hu Zrt v Hungary
The ECtHR subsequently distinguished the circumstances in Delfi.
Anonymous users had posted offensive comments on websites criticising the business practices of a real-estate company. The ECtHR found that holding the websites liable in the circumstances violated Article 10 freedom of expression. (Merlin)
The Court considered factors including:
nature of the comments;
context;
responsibility of the portal;
consequences of liability;
availability of less restrictive measures.
Relevance to AI
This case is extremely useful because it demonstrates that intermediary liability is context-sensitive.
An AI provider should not necessarily be treated identically to:
an original author;
a newspaper;
a passive hosting provider;
a social-media platform.
The technological and legal role of the defendant matters.
AI example
A user asks:
“Tell me about Person X.”
The AI accidentally generates:
“Person X was convicted of financial fraud.”
If the system has simply reproduced an identified source, the legal analysis may differ from a system that independently fabricates the allegation.
9. Case Law 5 — Sanchez v France, ECtHR Grand Chamber
In Sanchez v France, the Grand Chamber considered the responsibility of a politician for failing to remove hateful comments posted by third parties on his Facebook page.
The Court upheld the domestic finding in the circumstances and considered the duties and responsibilities associated with maintaining an online communication space. (Global Freedom of Expression)
Relevance to AI
The case demonstrates that liability may sometimes arise from failure to act after becoming aware of unlawful content, rather than from being the original author.
For AI systems, this raises a different question:
What happens after an AI provider is notified that its system repeatedly generates a false defamatory allegation?
Potential facts could include:
repeated complaints;
known hallucination pattern;
failure to correct a known false biography;
failure to implement an available technical fix;
continued publication after notice.
The analogy is therefore particularly relevant to post-notice responsibility.
Nature of authority: Online-content intermediary analogy; not generative AI.
10. Case Law 6 — Pihl v Sweden, ECtHR
Pihl v Sweden concerned allegedly defamatory comments posted by a third party on a blog.
The ECtHR considered whether the State had adequately protected the claimant's reputation while also respecting freedom of expression.
The Court did not require automatic liability for the blog operator in the circumstances, recognising that imposing excessive intermediary liability could have a chilling effect on Internet expression. This case is discussed alongside Delfi and subsequent intermediary-liability authorities. (DOI)
AI significance
This is important for a generative-AI platform because automatic liability for every erroneous output could create significant incentives to:
suppress legitimate answers;
refuse controversial subjects;
prevent users from discussing real people;
over-filter factual criticism.
Therefore, courts may need to balance:
reputation protection ↔ freedom of expression ↔ technological intermediary responsibility.
11. Case Law 7 — Axel Springer AG v Germany, ECtHR Grand Chamber
The ECtHR examined the conflict between freedom of expression and protection of reputation/private life.
The Court recognised that reputation can fall within Article 8 where an attack reaches a sufficient level of seriousness, while Article 10 protects freedom of expression. It identified factors relevant to the balancing exercise, including contribution to public debate, how information was obtained, its veracity, content, form, consequences and severity of sanctions. (HUDOC)
Application to AI-generated statements
This provides a useful framework for determining whether an AI-generated statement is protected expression or unlawfully harmful.
Important questions include:
Was it presented as fact?
Compare:
“There are allegations that X committed fraud.”
with:
“X committed fraud.”
The second is much more readily understood as a factual assertion.
Was there public interest?
A statement concerning:
public safety;
corruption;
consumer fraud;
professional misconduct
may receive different treatment from an entirely private allegation.
Was the information verified?
Generative AI creates a major difficulty because a language model may produce an apparently confident factual statement without having verified it.
Therefore:
AI confidence is not the same thing as factual verification.
12. Case Law 8 — Magyar Jeti Zrt v Hungary, ECtHR
This case concerned an Internet news portal that included a hyperlink to material later considered defamatory.
The ECtHR rejected automatic liability merely because a hyperlink had been provided. It considered whether the journalist endorsed or repeated the content, whether the journalist knew or could reasonably have known it was unlawful, and whether due diligence and good faith were exercised. (BAILII)
AI relevance
This is particularly useful for AI-generated aggregation.
Suppose an AI system responds:
“According to several reports, Person X committed fraud.”
The system may not itself be the original source.
A court could potentially need to distinguish:
AI repeating a source;
AI summarising a source;
AI endorsing a source;
AI inventing a claim;
AI combining several sources into a new false allegation.
These are legally different factual situations.
13. Case Law 9 — Shevill v Presse Alliance, C-68/93
The CJEU considered cross-border defamation and jurisdiction.
The Court held that, in cross-border publication cases, jurisdiction could lie in the place where the publisher was established for the harm caused generally, while courts in places where the publication was distributed could have jurisdiction concerning damage occurring there. (Infocuria)
AI significance
AI-generated defamation is inherently capable of being cross-border.
A single AI answer can be displayed simultaneously in:
France;
Germany;
Italy;
Spain;
Netherlands.
Therefore, jurisdiction becomes a major issue.
Example
A German resident receives a defamatory AI-generated answer from a company established in Ireland and suffers professional harm in Germany.
Potential questions include:
Which court has jurisdiction?
Which country's defamation law applies?
Where did the damage occur?
Can the claimant obtain EU-wide relief?
Shevill is an important starting point.
14. Case Law 10 — eDate Advertising GmbH v X and Martinez v MGN, Joined Cases C-509/09 and C-161/10
The CJEU developed the jurisdictional rules for Internet-based personality-rights violations.
The case concerned publication of information online and damage to personality rights. The Court recognised the particular nature of Internet dissemination and allowed jurisdictional approaches reflecting the location of the claimant's centre of interests. (Infocuria)
Relevance to AI
This is extremely important because AI-generated defamation is usually:
instantaneous;
borderless;
searchable;
reproducible;
potentially persistent.
A claimant's centre of interests may therefore become important in deciding where proceedings can be brought.
15. Case Law 11 — Glawischnig-Piesczek v Facebook Ireland, C-18/18
The CJEU dealt with defamatory content on Facebook.
The Court considered the ability of a national court to require a hosting provider to remove or prevent access to content that had been found unlawful. The case also addressed the prohibition on imposing a general monitoring obligation under the then-applicable e-Commerce Directive framework. (Infocuria)
Importance for AI
AI systems create a new form of content moderation problem.
Imagine that an AI repeatedly produces:
“Person X was convicted of fraud.”
After a court determines that the statement is false and unlawful, the question may become:
Can the provider be required to prevent substantially identical AI-generated statements from recurring?
Glawischnig-Piesczek is important by analogy because it demonstrates that European law can permit targeted preventive measures while distinguishing them from an unlimited general monitoring obligation.
16. GDPR and AI-Generated Defamation
Defamation and data protection are separate legal concepts, but they can overlap.
Suppose an AI generates:
“John Smith was convicted of corruption.”
That statement potentially involves personal data.
If false, it may create both:
Reputation problem
The statement damages John's honour/reputation.
Data-protection problem
The AI system may be processing inaccurate personal data.
17. Article 5 GDPR — Accuracy
The GDPR contains an accuracy principle for personal data.
For AI systems, this is especially significant because generative AI may produce:
invented names;
invented criminal records;
incorrect employment histories;
false professional qualifications;
fabricated quotations.
An AI provider handling personal data therefore faces an additional regulatory dimension beyond ordinary defamation law.
18. Article 17 GDPR — Erasure
The GDPR provides a right to obtain erasure in specified circumstances, subject to exceptions.
This can be particularly relevant when false personal information has been generated or stored.
However, Article 17 is not an automatic right to erase every defamatory statement.
Freedom of expression and information must also be considered. The GDPR itself requires Member States to reconcile data protection with freedom of expression and information. (EUR-Lex)
19. Article 82 GDPR — Compensation
Article 82 provides a right to compensation for material or non-material damage caused by infringement of the GDPR. (EUR-Lex)
The CJEU has clarified that GDPR compensation is compensatory rather than punitive.
Importantly, a GDPR infringement by itself does not automatically establish compensable damage; the claimant must establish the required elements, including actual damage and causal connection. (EUR-Lex)
AI example
If an AI system stores and disseminates false personal information:
GDPR infringement
actual non-material/material damage
causal link
may potentially support an Article 82 claim.
20. AI Hallucination and Defamation
The most distinctive problem is the AI hallucination.
Example:
User asks:
“Who is Professor X?”
AI answers:
“Professor X was dismissed from university after committing research fraud.”
But no such dismissal occurred.
Traditional legal analysis
The statement potentially has:
identifiable victim;
factual assertion;
publication;
falsity;
reputational significance.
The difficult question is:
Who is legally responsible for the generated statement?
21. Who Could Be Responsible?
A. The AI user
If a person deliberately prompts an AI to generate defamatory content and publishes it, the user may potentially become the publisher.
Example:
User asks AI to create a false article accusing competitor X of fraud.
The user then publishes it.
The fact that AI generated the words does not necessarily remove the user's responsibility.
B. The AI provider
A claim against the provider may depend upon:
applicable intermediary rules;
knowledge;
control;
contractual relationship;
negligence;
data protection;
product/service liability;
specific national law.
C. The platform
A platform that hosts AI-generated content may have separate responsibilities under applicable digital-services rules.
D. The search engine
A search engine that indexes or generates an AI summary of false information may have distinct responsibilities from the original publisher.
Google Spain and Google v CNIL are especially relevant here. (Infocuria)
22. Digital Services Act
The EU Digital Services Act is relevant to online platforms and hosting services.
Article 16 establishes notice-and-action mechanisms for allegedly illegal content. Notices must be sufficiently precise and substantiated, and providers must process them according to the DSA framework. (EUR-Lex)
The DSA also stresses the need to protect freedom of expression while addressing illegal content. (EUR-Lex)
AI application
Suppose an AI-generated defamatory statement is displayed on an online platform.
A sufficiently substantiated notice may trigger the platform's applicable DSA procedures.
But:
DSA compliance and civil liability are not the same thing.
A platform's failure to follow a DSA obligation may create regulatory consequences, while a civil defamation claim depends on the applicable national law and facts.
23. AI-Generated Images and Deepfakes
Defamation is not limited to text.
An AI-generated image may falsely depict:
a politician accepting a bribe;
a doctor harming a patient;
a company executive committing fraud;
a professor engaging in misconduct.
A deepfake may therefore combine:
false representation + visual evidence appearance + widespread dissemination.
This may create:
defamation;
personality-rights claims;
privacy claims;
image-right claims;
data-protection claims;
copyright issues;
potentially criminal-law consequences depending on the jurisdiction.
24. AI Voice and Audio Defamation
An AI-generated voice clone could falsely state:
“I stole money from my employer.”
If listeners believe the voice belongs to the claimant, the claimant may suffer:
professional damage;
loss of clients;
employment consequences;
social harm.
The evidence becomes particularly important.
The claimant may need to establish:
the recording was AI-generated;
the voice was sufficiently identifiable;
the statement was attributed to the claimant;
the statement was false;
third parties heard it;
actual damage resulted.
25. Causation
Causation is especially difficult in AI defamation.
Suppose:
AI generates false allegation → 10 people see it → one person republishes it → newspaper publishes it → employer terminates claimant.
Who caused the damage?
Potential causal links include:
AI provider → user → social platform → newspaper → employer.
A court may need to determine:
whether the AI output was a factual cause;
whether republication was foreseeable;
whether later conduct constituted an intervening cause;
whether the claimant can prove actual loss.
26. Damage
Possible forms of damage include:
Economic
lost employment;
lost customers;
lost contracts;
reduced business;
professional opportunities lost.
Non-economic
humiliation;
distress;
damage to dignity;
damage to social standing;
emotional suffering.
Professional
Particularly serious allegations may affect:
lawyers;
doctors;
academics;
directors;
accountants;
public officials;
regulated professionals.
27. Truth Versus Opinion
A central defamation distinction is:
Statement of fact
“Dr X stole €100,000.”
This can ordinarily be tested for truth or falsity.
Opinion
“I think Dr X is dishonest.”
This is more likely to receive protection as an opinion, although context and factual basis remain important.
AI systems create problems because they frequently present uncertain information in declarative factual language.
Thus:
“I believe there may have been misconduct”
is legally different from:
“X committed misconduct.”
28. AI Confidence Is Not Legal Truth
A particularly important principle is:
The probability assigned internally by an AI model is not equivalent to proof of a factual allegation.
For example, an AI may generate:
“X was arrested in 2022.”
because that sentence is statistically plausible.
But statistical plausibility does not establish:
truth;
source reliability;
legal proof;
reasonable publication.
This distinction may become central to negligence and causation arguments.
29. Notice and Correction
A responsible AI system should ideally have mechanisms allowing:
complaint;
verification;
correction;
deletion where legally appropriate;
prevention of recurrence;
explanation of the correction.
This is particularly important for persistent hallucinations.
Suppose a person repeatedly asks:
“Was X convicted of fraud?”
The AI repeatedly gives the same false answer.
After the provider receives reliable evidence that the statement is false, continued repetition may become legally more significant than the initial accidental output.
30. Defences
A defendant may raise several arguments.
1. Truth
The statement was substantially true.
2. Opinion
The statement was an opinion rather than a factual allegation.
3. Public interest
The statement concerned a legitimate public-interest issue.
4. Lack of identification
The statement did not reasonably identify the claimant.
5. Lack of publication
The output was not communicated to a third party.
6. Lack of causation
The claimant cannot establish that the AI output caused the alleged damage.
7. Lack of knowledge
The provider did not know and could not reasonably have known of the unlawful content, depending on the applicable regime.
8. Freedom of expression
Article 10 ECHR may protect certain expression.
9. Intermediary protections
Applicable EU/national intermediary rules may restrict automatic liability.
31. Freedom of Expression
European courts generally require a balance between:
Article 8 — reputation/private life
and
Article 10 — freedom of expression.
The Axel Springer line of cases illustrates factors such as:
contribution to public debate;
status of the person concerned;
subject matter;
method of obtaining information;
truth/accuracy;
content and consequences;
severity of sanction. (5RB)
This balance becomes particularly important for AI because AI tools are used for:
journalism;
research;
political discussion;
criticism;
satire;
creative work;
factual information retrieval.
32. Special Problem: Public Figures
A public figure generally has to tolerate a wider degree of criticism than a private individual, particularly concerning matters of public interest.
But that does not mean:
“Anything said about a public figure is lawful.”
False factual allegations can still raise serious reputation issues.
The Axel Springer and Magyar Jeti cases demonstrate the importance of context, factual basis and public-interest considerations. (5RB)
33. Cross-Border AI Defamation
Suppose:
AI provider — Ireland
Claimant — France
User — Germany
Output — available throughout Europe
Business damage — Netherlands
This creates several questions:
Jurisdiction
Which country's courts can hear the claim?
Applicable law
Which national defamation law applies?
Territorial remedy
Should an injunction operate:
nationally;
across the EU;
globally?
Enforcement
Can a judgment be enforced against a provider established in another Member State?
Shevill and eDate provide important foundations for these cross-border Internet personality-right disputes. (Infocuria)
34. Important Difference: Defamation and GDPR
These claims should not be confused.
| Defamation | GDPR |
|---|---|
| Protects reputation/honour | Protects personal data |
| Primarily national law | EU-wide regulation |
| Focuses on harmful statements | Focuses on processing of personal data |
| Truth/falsity often central | Lawfulness, accuracy, purpose etc. |
| Damages/injunction/correction possible | Erasure, restriction, objection, compensation etc. |
| Article 10 ECHR relevant | Articles 7 and 8 Charter relevant |
The same AI output can potentially engage both regimes.
35. Important Difference: AI Provider vs Publisher
A court may distinguish:
Original publication
AI system independently generates:
“Person X committed fraud.”
User publication
User asks AI for defamatory content and publishes it.
Reproduction
AI retrieves and reproduces an existing defamatory article.
Search result
Search engine merely indexes the underlying article.
AI summary
AI generates a new summary combining several sources.
These five situations may produce materially different liability questions.
36. Evidence in an AI-Defamation Case
A claimant should preserve:
exact AI prompt;
exact AI response;
date and time;
model/version;
screenshots;
conversation logs;
URL or service identification;
number of repetitions;
correction requests;
provider responses;
source material used by the AI;
evidence proving falsity;
evidence of publication;
evidence of financial loss;
evidence of professional consequences.
Particularly important
The claimant should preserve the original AI output, because generative systems can change their answers after updates.
37. Technical Forensic Evidence
Experts may need to determine:
whether the content was actually generated by AI;
which model generated it;
whether retrieval augmentation was used;
what sources were supplied;
whether the output resulted from hallucination;
whether the system had a known defect;
whether safeguards were functioning;
whether the provider received previous complaints.
This makes AI-defamation litigation partly a technical evidence case.
38. Liability Model
A simplified model is:
Stage 1
AI developer
↓
Creates model
Stage 2
AI provider
↓
Deploys model
Stage 3
User
↓
Requests information
Stage 4
AI system
↓
Generates statement
Stage 5
Platform/search engine
↓
Distributes or indexes statement
Stage 6
Third parties
↓
Read/repeat statement
Stage 7
Claimant
↓
Suffers reputational/economic damage
The court must determine which link constitutes the legally relevant publication or wrongful act.
39. Possible Remedies
Depending on national law and the applicable EU framework, remedies may include:
1. Damages
For:
financial loss;
non-material harm;
professional harm.
2. Injunction
Preventing further publication.
3. Correction
Requiring clarification or correction.
4. Removal
Removing unlawful content.
5. De-indexing
Removing search results.
6. Erasure
Where GDPR Article 17 applies.
7. Restriction of processing
Where GDPR conditions are satisfied.
8. Declaration
Judicial declaration that the statement is unlawful or false.
40. DSA and AI-Generated Defamation
The Digital Services Act is especially relevant where AI-generated defamatory material appears through an intermediary or hosting service.
The DSA requires hosting services to maintain notice-and-action mechanisms for allegedly illegal content and provides procedural safeguards for affected parties. (EUR-Lex)
However:
The DSA does not replace national defamation law.
Instead, it creates an additional digital-governance layer.
Therefore:
National defamation law
GDPR
DSA
ECHR
may all become relevant to the same AI-generated statement.
41. Case-Law Comparison
| Case | Main principle | AI-defamation relevance |
|---|---|---|
| Google Spain, C-131/12 | Search-engine responsibility for personal-data processing | AI search/reputation |
| Google v CNIL, C-507/17 | Territorial limits of de-referencing | Cross-border AI reputation |
| Delfi v Estonia | Intermediary responsibility for user content | AI platform responsibility |
| MTE & Index.hu v Hungary | Limits on intermediary liability | Preventing overbroad AI liability |
| Sanchez v France | Responsibility after awareness of unlawful online comments | Notice/continued AI output |
| Pihl v Sweden | Balance between reputation and intermediary freedom | AI platform liability |
| Axel Springer v Germany | Reputation versus freedom of expression | AI factual allegations |
| Magyar Jeti v Hungary | Hyperlink liability and endorsement/knowledge | AI aggregation/reproduction |
| Shevill v Presse Alliance | Cross-border defamation jurisdiction | International AI publication |
| eDate Advertising, C-509/09 | Internet personality-right jurisdiction | AI-generated cross-border harm |
| Glawischnig-Piesczek, C-18/18 | Removal/prevention of unlawful online content | Repeated AI-generated defamation |
42. Six Most Important Principles
Principle 1 — AI is not automatically the legal publisher
The legal responsibility must be attributed to an identifiable natural or legal actor under the applicable law.
Principle 2 — False factual statements are particularly important
An AI-generated factual allegation is different from protected opinion or satire.
Principle 3 — Reputation and freedom of expression must be balanced
Axel Springer provides an important European framework. (5RB)
Principle 4 — Intermediary liability depends on circumstances
Delfi, MTE, Pihl and Sanchez demonstrate different outcomes depending on the nature of the content, intermediary and circumstances. (Merlin)
Principle 5 — GDPR can provide an additional route
Where false AI output constitutes processing of personal data, GDPR accuracy, erasure and compensation provisions may become relevant. (EUR-Lex)
Principle 6 — Cross-border AI claims create jurisdictional problems
Shevill and eDate remain important starting points for Internet-based personality-right disputes. (Infocuria)
43. Hypothetical Example
Assume an AI chatbot is asked:
“Who is Dr A?”
It answers:
“Dr A was convicted of medical fraud and lost his medical licence.”
The statement is completely false.
Dr A loses several patients after the answer is shared online.
Legal analysis
Step 1 — Identification
Dr A is clearly identifiable.
Step 2 — Factual allegation
The statement alleges a specific conviction and professional sanction.
Step 3 — Falsity
Court records establish that no such conviction exists.
Step 4 — Publication
The answer was displayed to the user.
Step 5 — Repetition
The user publishes the answer on social media.
Step 6 — Causation
Patients demonstrate that they relied upon the statement when cancelling appointments.
Step 7 — Potential claims
Potentially:
national defamation/personality-right claim;
GDPR claim if personal data was unlawfully processed;
DSA procedures if distributed through a covered platform;
injunction/removal;
compensation.
Step 8 — Defendant analysis
The court must separately analyse:
user responsibility;
AI provider responsibility;
platform responsibility;
search-engine responsibility.
There is no automatic rule making all four liable.
44. Special Problem of Repeated AI Hallucination
Suppose the provider is notified:
“Your AI falsely states that I was convicted of fraud.”
The provider investigates and confirms that the allegation is false.
Yet the model continues producing:
“X was convicted of fraud.”
This fact could become important in assessing the provider's knowledge, response, reasonable precautions and subsequent conduct, depending on the applicable national and EU legal regime.
It is potentially very different from a single unforeseeable generation error.
45. Future European AI-Defamation Litigation
Future courts may need to answer questions such as:
Is an AI provider a publisher?
Is AI output a “communication” by the provider?
Does autonomous generation alter publication liability?
What constitutes reasonable AI verification?
Does repeated hallucination amount to negligence?
What happens after notice of a false allegation?
Can an injunction require prevention of substantially identical AI output?
Can a claimant demand model correction?
Can GDPR accuracy principles apply to generated statements?
Who bears the burden of proving causation?
How should damages from AI-generated reputational harm be calculated?
Which country's law governs cross-border AI defamation?
46. Key Legal Formula
For examination purposes, remember:
AI Output
↓
Identifiable Person
↓
False/Factually Harmful Statement
↓
Publication
↓
Attribution
↓
Unlawfulness / Fault
↓
Reputation or Personality-Rights Injury
↓
Causation
↓
Material + Non-Material Damage
↓
Defamation + GDPR + DSA + ECHR
↓
Removal / Correction / Injunction / Damages
47. Ultra-Short Revision Notes
Important cases
Google Spain — C-131/12
Search-engine processing and reputation/privacy.
Google v CNIL — C-507/17
Territorial limits of de-referencing.
Delfi AS v Estonia
Online intermediary liability.
MTE & Index.hu v Hungary
Limits on intermediary liability and protection of expression.
Sanchez v France
Responsibility after awareness of unlawful third-party comments.
Pihl v Sweden
Reputation protection versus Internet intermediary freedom.
Axel Springer v Germany
Reputation versus freedom of expression.
Magyar Jeti v Hungary
Hyperlinks, endorsement and knowledge.
Shevill v Presse Alliance — C-68/93
Cross-border defamation jurisdiction.
eDate Advertising — C-509/09 and C-161/10
Internet personality-rights jurisdiction.
Glawischnig-Piesczek — C-18/18
Removal and prevention of unlawful online content.
Conclusion
AI-generated defamation in Europe is presently best understood as an intersection of traditional civil defamation/personality-rights law, Internet intermediary liability, GDPR, the Digital Services Act and Article 8/Article 10 ECHR jurisprudence.
The decisive legal questions are not simply “Did AI hallucinate?” but:
Who caused the publication? Was the statement presented as fact? Was it false? Who knew or should have known? What was done after notice? Did the statement cause actual reputational or economic harm? And how should reputation be balanced against freedom of expression?
The existing European authorities—particularly Google Spain, Delfi, MTE & Index.hu, Sanchez, Axel Springer, Magyar Jeti, Shevill, eDate and Glawischnig-Piesczek—provide the principal doctrinal building blocks. None should be treated as a direct ruling that a generative-AI provider is automatically liable for hallucinated defamation; that precise question remains substantially dependent on future cases and the applicable national law. (Infocuria)

comments