Stop your AI chatbot from making promises you can’t keep
Transform AI guidelines into specific guardrails that shield you from legal risk.
Stephanie Nivinskus is principal at Ragan’s Center for AI Strategy.
When a chatbot on your website lies, the courts will come after you. We’ve already seen it happen in Canada and the U.S. Recently, it happened in Germany.
A chatbot on an aesthetic-medicine platform told customers its doctors were board-certified specialists. None of them were. A German regional court ordered the company to stop making the claim and treated the chatbot’s claims as the company’s claims.
A consumer group had first warned the company after its chatbot told customers the two doctors behind it, known as “Dr. Rick and Dr. Nick,” held specialist credentials that don’t exist in Germany. The company deactivated the bot, considered the matter closed and moved on, but never signed a cease-and-desist agreement with a penalty clause attached. Only that signed agreement would have stopped the company from turning the chatbot back on.
That unsigned document is the reason the case ended up in court. The judges rejected the argument that the chatbot spoke for itself. It spoke for the company, just as an employee would.
Miri Rodriguez, advisor with Ragan’s Center for AI Strategy and founder and CEO of Empressa AI, shared what this means for comms teams building chatbots today. She made an important distinction.
“A brand guideline helps people make good decisions,” she said. “A guardrail ensures AI cannot make bad ones.”
Many organizations create brand guidelines but don’t create the AI guardrails needed. Transforming a guideline into a guardrail means doing three things:
- Name what the AI can never claim.
Rodriguez’s list begins with the exact failure that landed the German company in court: claims about credentials, licenses, titles or certifications.
From there, add promises that create legal or financial commitments, including refunds, pricing, guarantees or contract terms. Also include statements about safety or regulated health outcomes, along with anything that would normally require approval before it reaches the public.
“If a human would need legal or communications to review it before saying it, the AI shouldn’t be saying it on its own,” she said.
- Decide where the conversation hands off to a person in writing.
Do not wait until the exchange gets awkward or the customer gets angry. The handoff should happen the moment the conversation moves from sharing information to making a commitment or exercising judgment. That includes money, contracts, complaints, health and safety.
Rodriguez said the ownership should be clear. “Legal and comms define where the handoff line is, and engineering builds it,” she said.
- Put a name on who reviews the transcripts and set the cadence.
“AI isn’t something you deploy once and walk away from,” Rodriguez said.
Review transcripts weekly during rollout, move to monthly once the system settles, and run another check whenever the model or its configuration changes. The bot’s behavior can shift right along with those changes, whether anyone tells you or not.
The bottom line is you should write your own guardrails, or risk letting a court write them for you.

