Your government contracts just got more transparent
The UK Government’s new mandatory AI governance framework means any communications support you deliver now requires explicit disclosure of AI use, documented review cycles, and audit trails before publication. Service agreements need urgent updating, liability flows to you.
The UK Government published mandatory departmental guidance on 30 July 2026 establishing risk-assessment protocols for generative AI use across government communications. Service providers delivering to government bodies now face explicit liability for AI-generated outputs, and a general disclaimer will not help.
The organisational test (not technical)
The chatbot’s statements are attributable to the company as its own commercial communication. The system is not a third party.
On 12 May 2026, the Higher Regional Court of Hamm held a cosmetic treatment provider liable for statements its AI chatbot made about the doctors who ran the business. The chatbot invented qualifications they did not hold, and the court held the company responsible.
The company’s position was the position most businesses instinctively reach: the chatbot said it, not us. The system’s output was not drafted by a human, not signed off, and emerged from probabilistic behaviour nobody specified.
The court rejected this. The test is not technical. It is organisational. The chatbot’s statements were attributable to the company because the system forms part of the company’s own business organisation. The chatbot is not a third party whose misconduct relieves the operator of responsibility.
It is an organisational test about whose business the system sits inside, not a technical test about who built the model.
This matters commercially because it disposes of the second defence as well: “We did not build the model, we licensed it.” That is a statement about your supply chain, not about whose business the system was operating inside when it spoke to your customer. A government contractor using Government Assist cannot escape liability by saying the system belongs to DSIT.
Why disclaimers fail
A general disclaimer does not defeat liability for a concretely misleading statement. What is required is actual technical and organisational control over the system.
Most businesses running a customer-facing chatbot have a line of text somewhere near it: Answers without guarantee. May produce inaccurate information. Please verify independently.
The court addressed this directly. A general disclaimer of that kind does not defeat liability. What is required instead is actual technical and organisational control over the system.
This is not unique to German law. The Committee of Advertising Practice has stated that the UK Advertising Codes apply regardless of how advertising content is generated, and that disclosure is very unlikely to mitigate the harm caused by a fundamentally misleading message.
Two regulators, two jurisdictions, no coordination, same answer: a disclaimer sitting next to a false statement does not convert it into a true one. The disclaimer may manage customer expectations. It will not manage your exposure.
The UK position is stricter
Under the Digital Markets, Competition and Consumers Act 2024, your state of mind is irrelevant, and the CMA no longer needs a court.
The temptation is to file this as a German case and move on. That would be a mistake. The equivalent UK analysis is less forgiving, not more.
Unfair commercial practices offences under the Digital Markets, Competition and Consumers Act 2024, in force since 6 April 2025, are strict liability, apart from the professional diligence limb. The trader’s state of mind at the time of the offence is irrelevant.
Separately, the CMA can now impose penalties of up to 10 per cent of global turnover without going to court.
“The model hallucinated and we did not intend to mislead anyone” is entirely true and entirely irrelevant under strict liability.
So a UK business whose chatbot invents a qualification, a price, an accreditation, a delivery window, an eligibility criterion or a warranty term is exposed on the same attribution logic Hamm applied, without needing a German court to get there, and against a regulator that no longer needs a court either.
What actually reduces risk
None of them is a disclaimer. All of them are load-bearing for compliance with the DSIT framework.
The court pointed toward the answer when it said technical and organisational control is what is required. In practice that means five things:
- Log and retain the outputs, so that when a complaint arrives you can establish what was actually said rather than reconstructing it.
- Test before release against the questions that carry regulatory weight, qualifications, accreditations, warranties, delivery windows, eligibility criteria, rather than the ones about opening hours.
- Apply version control to prompts and models, with a record of what changed and when, because a model update you did not initiate can change behaviour you had already tested.
- Build a working escalation route to a human for the categories where a wrong answer is expensive.
- Name an owner, because a control nobody is accountable for is a policy, not a control.
The contract problem
You are carrying a strict liability exposure created by a system you did not build and cannot fully inspect or prevent from changing.
Here is the position most businesses are in without having noticed.
Almost every conversational AI vendor agreement currently in the market excludes liability for model output. It is close to standard. The result is that the operator carries the whole of a strict liability consumer law exposure, created by a system it did not build, cannot fully inspect, and cannot prevent from changing.
That is a risk allocation nobody would accept if it were written down in those terms. It usually is written down, in the exclusions, and it usually is accepted, because the exclusions get less attention than the price.
For government contractors, this matters acutely. You are delivering to a client whose own regulatory obligations now flow through to you, and your vendor agreement passes the risk straight back to you.
What to negotiate
Service agreements with government clients should explicitly allocate responsibility for AI disclosure and liability. Vendor agreements should shift risk appropriately.
In your government client agreements:
- Allocate responsibility for AI disclosure explicitly, specifying who confirms AI use and who ensures disclosure before publication.
- Specify review timelines before publication, not after. The client carries liability for content it approves; you carry liability for content you deliver.
- Include indemnities covering reputational harm from undisclosed or inadequately reviewed AI-generated content, because a false statement attributed to the government becomes your liability if you knew or should have known.
- Establish data-protection protocols for sensitive materials processed through third-party AI systems. The DSIT framework does not displace data protection obligations.
In your vendor agreements:
- Output logging should be a contractual deliverable with a defined retention period and your right of access, not a feature the vendor may deprecate.
- You should have advance notice of material model or prompt changes, because otherwise your pre-release testing has a shelf life you cannot see.
- There should be a testing obligation before any material change is pushed to production.
- And the indemnity needs to reach regulatory and consumer law claims arising from model output.
Questions this raises
Six questions the Government Assist framework and the Hamm judgment tend to prompt, answered directly.
Is my business liable for what its AI chatbot says?
On the reasoning of the Higher Regional Court of Hamm, yes. The chatbot’s statements are attributable to your business as its own commercial communication, because the system forms part of your business organisation. Under UK strict liability law, your state of mind is irrelevant.
Does a chatbot disclaimer limit my liability?
Not for a concretely misleading statement. A general disclaimer does not defeat liability. What is required is actual technical and organisational control over the system.
Does it help that we licensed the model rather than built it?
No. The test is organisational, not technical. The question is whose business the system was operating inside when it spoke to your customer, not who built the model.
What controls actually reduce Government Assist liability risk?
Five things: log and retain outputs, test before release against high-risk questions, apply version control to prompts and models, build a working escalation route to a human, and name an owner accountable for each control.
Should we update our communications retainer fees to account for AI governance?
Yes. Communications retainer fees should be adjusted to account for mandatory review cycles and audit-trail documentation. The DSIT framework is binding government-wide and sets the standard for the market.
What if a vendor refuses to give us the indemnity and audit rights we need?
That is useful information rather than a dead end. It tells you what your residual exposure is, and it lets you price it, insure it, or narrow deployment to the categories where a wrong answer is survivable.
Sources
- UK Digital, Science and Innovation Team (DSIT), Departmental Guidance on Generative AI in Government Communications, 30 July 2026.
- Higher Regional Court of Hamm, judgment of 12 May 2026, case 4 UKl 3/25 (revision to Bundesgerichtshof permitted).
- Digital Markets, Competition and Consumers Act 2024, unfair commercial practices provisions in force 6 April 2025.
- Committee of Advertising Practice guidance on AI-generated advertising content.
Renegotiating government and vendor agreements?
Eliga provides embedded commercial and technology counsel to scaling businesses. If you are delivering communications services to government and want your agreements reviewed before publication rather than after a regulatory complaint, we should talk.
This page is general information about UK commercial law and artificial intelligence. It is not legal advice and does not create a solicitor-client relationship. Take specific advice on anything you are about to negotiate or sign.
