Who answers for NYT's AI-generated search summaries?
Who answers for a publisher's unedited AI search summaries? Applying the Munich 'own words' ruling, Section 230 doctrine, and NYT-commissioned accuracy data, this analysis maps why an AI-summarizing publisher becomes directly answerable for machine-written statements about third parties — the exposure in-house counsel and litigators must weigh before deploying AI summaries.
- Jurisdiction
- Germany; United States; Canada
- Court
- LG München I (Munich Regional Court)
- AI tool named
- Google AI Overviews; ChatGPT
- Ruling date
- May 28, 2026
- Source document
- View primary court order ↗
- Last verified
- Aug 26, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
The NY Times AI-generated search summaries test is easiest to misread as a product experiment. It is sharper than that. In the weeks before Aug. 23, 2026, The New York Times began showing AI-generated summaries to a subset of search users on a page that also returned excerpts and links; Semafor described it as the news arm’s first AI-written text placed before readers without mediation by a Times journalist or editor. The model, sample size, test duration, and labeling practices were not publicly disclosed in the reporting available so far. [1][2]

This is not legal advice. It is a risk analysis of what changes when a publisher commissions, displays, and benefits from machine-written statements about real people, companies, and events.
The surrounding drama matters, but only up to a point. Wirecutter’s Finder tool gave the company a prior AI-product precedent outside the core news desk. The NewsGuild’s proposals for a 22.5% AI-licensing revenue pool and mandatory human oversight show why staff would read the test as a labor issue as well as a technology issue. And there is an obvious tension in a publisher litigating against OpenAI over AI copying while deploying AI summaries of its own archive. [1][2]
But the cleanest question is neither labor nor irony. Once the summary is generated and served by the publisher’s own system, who legally speaks?
Why source links do not solve the speaker problem
The Munich Regional Court’s May 28, 2026 preliminary injunction against Google is not U.S. law, not a final merits judgment, and not a ruling against The New York Times. It is still the most useful working model now available for the risk created by AI summaries, because it refused to treat the generated answer as a neutral pointer to other people’s content. In LG München I, 26 O 869/26, the court held Google directly responsible for allegedly false AI Overview statements because the system independently compiled and summarized information into a statement presented by the operator. [3][4]

That distinction is the hinge. A search result can point. A snippet can quote. A generated overview does something more legally awkward: it assembles a new sentence in the platform’s presentation layer and asks the reader to accept that sentence as the answer. The Munich court’s reasoning treated that answer as the operator’s own communication, not merely as hosted third-party material. [3][4]
The court also rejected the defense that users could check the sources themselves. That rejection matters for publishers because it fits the way readers actually consume search answers. A linked source is useful for verification; it is not the same as retracting the claim, qualifying the claim, or proving that the operator did not publish the claim. Publication is not a scavenger hunt. If the answer card says the thing in the operator’s voice, the injured person will not begin by suing the footnote.
The Munich ruling also denied Google host-provider privileges under the Digital Services Act on that fact pattern, because the challenged AI Overview was not treated as a passive storage-and-display function. The injunction was not limited to Germany, another feature that made the decision unusually visible outside its immediate procedural setting. [3][4]
The limits are just as important. This was a first-instance Eilverfahren, a preliminary proceeding. German appellate consideration remains live, and the underlying question is expected to be revisited through the OLG Hamm track before the German Federal Court of Justice. The Munich order is therefore a warning signal, not a universal rulebook. [5]
Still, for risk officers, the warning is concrete. If an AI system writes a fresh summary, the safer assumption is that the deployer has moved from indexing speech to making speech. That assumption is especially hard to avoid for a news publisher, whose entire institutional function is to create and select information for readers.
Section 230 is a poor hiding place for a publisher’s own AI answer
U.S. law frames the same problem differently. Section 230(c)(1) protects covered services from being treated as the publisher or speaker of information “provided by another information content provider.” The statutory line is not whether a web page contains user-facing information. The line is whether the challenged content was provided by someone else or was created or developed, at least in part, by the defendant. [6]

That is why the NYT search test is not just another version of hosting comments, indexing third-party pages, or displaying article links. If the Times’ own system generates a summary from returned material, the defamatory or otherwise actionable sentence is not simply “provided by another information content provider.” It is the output of a system the publisher chose to deploy in its own reader interface.
No U.S. appellate court has squarely resolved Section 230 for publisher-operated AI summaries. That uncertainty should not be inflated into comfort. The statutory synthesis is plain enough for predeployment review: when the defendant commissions the tool, controls the presentation, and serves the generated statement as part of its own product, counsel should analyze the output as the defendant’s own speech unless and until a court says otherwise.
| Risk question | Why it matters |
|---|---|
| Did the system merely display third-party text? | That is the fact pattern Section 230 was built to protect most strongly. |
| Did the system generate a new answer from multiple sources? | That pushes the output toward the operator’s own statement. |
| Did editors review the generated sentence before publication? | Human review may not erase liability, but its absence makes the “own speech” problem harder to resist. |
| Did the answer concern an identifiable person or company? | That is where defamation, false light, trade disparagement, and related claims begin to become practical rather than abstract. |
The point is not that every AI summary is defamatory. Most will not be. The point is that the legal role changes when the organization stops delivering sources and starts delivering a machine-written answer in its own environment.
Accuracy rates do not answer the liability question
The accuracy data reported from The New York Times’ own commissioned work makes the exposure easier to see, but not because it proves that AI summaries are generally unusable. The reported numbers are more uncomfortable than that: high correctness and significant ungroundedness can coexist.
Publicly available reporting says the Times commissioned Oumi to test Google AI Overviews on SimpleQA, with 4,326 searches per round. The reported results were 85% correct for Gemini 2 and 91% correct for Gemini 3, while ungrounded answers rose from 37% to 56%. The same reporting says Google had an internal finding of 28% incorrect results. Those figures should be treated carefully because the accessible figures here come through secondary reporting of a paywalled Times article, not through a fully public test package with all methods exposed. [7][8]
Google disputed the framing of the results in its own characterization, which is also part of the evidentiary record rather than a neutral resolution of it. The missing test basics still matter: model configuration, query wording, sample composition, run dates, evaluation rules, and labeling all affect what the numbers prove. [7]
For counsel, however, the practical lesson does not depend on choosing one side’s preferred adjective. A 91% correct system can still produce a steady volume of unsupported assertions when deployed at search scale. If those assertions concern restaurants, public officials, doctors, musicians, startups, criminal accusations, product defects, sanctions, or court records, the error is not just a model-quality event. It is a statement about a third party that someone may have to defend.
That is also why source-link behavior belongs in the risk model. If users treat the generated answer as the destination rather than the beginning of research, a correction hidden in the linked material may never reach the injured person’s audience. The related problem of correction propagation is the reason our earlier analysis of AI-summary correction gaps sits beside this one rather than underneath it.
The defamation cases show variation, not safety
The U.S. and Canadian AI-defamation disputes now in the file do not point in one direction. They show how much will turn on the forum, plaintiff status, fault standard, disclaimers, publication evidence, and proof of harm.
Walters v. OpenAI is the defense-side caution against overclaiming. On May 19, 2025, a Georgia trial court granted summary judgment for OpenAI in a case involving allegedly false ChatGPT output about a radio host. The reported grounds included disclaimers, lack of negligence evidence, and the plaintiff’s public-figure actual-malice burden. It is a state trial court decision, not a national settlement of AI-output liability. [9]
Ashley MacIsaac v. Google points the other way procedurally. In May 2026, the Canadian musician filed an Ontario lawsuit seeking CAN $1.5 million after Google’s AI system allegedly identified him as a sex offender. A filed complaint is not a liability finding, but the fact pattern shows why generated biographical claims are legally volatile: the alleged error is specific, reputational, and attached to a living person. [10]
Battle v. Microsoft, filed in Maryland in 2023, belongs in the same boundary file. Together with Walters and MacIsaac, it is a reminder that AI-defamation exposure will not be answered by one magic word: not “AI,” not “beta,” not “sources,” and not “disclaimer.” Those words may matter. They may reduce reliance, affect fault, or shape damages. They do not decide whether the defendant published the challenged statement.
Publishers already understand this outside the AI setting. A newsroom would not ordinarily defend a false sentence in a staff-written search blurb by saying readers could have clicked through to see the underlying archive. Nor would it expect a court to treat a house-written summary as a reader comment. The novelty is the machine in the middle, not the reputational injury at the end.
That is an uncomfortable position for The New York Times in particular because it is not merely a platform with some publisher-like functions. It is a publisher in the ordinary sense and, for Section 230 analysis, an entity that creates and develops information content. Its own defamation exposure is not theoretical; our separate record on the Kai Spears NYT defamation verdict is a reminder that high institutional standards do not keep a publisher out of court.
The deployment decision counsel actually has to make
The hardest internal conversation is not whether AI search summaries are useful. They are useful when they work. A clean answer can spare a reader from opening five old articles to find one date, one quote, or one procedural posture. That product elegance is exactly why the legal exposure matters: the better the answer format becomes, the more readers will treat it as the publisher’s answer.
Before deployment, the responsible review is narrower and less theatrical than most AI-governance talk. It asks whether generated summaries can name or describe third parties; whether certain categories should be excluded; whether sensitive claims require editorial review; whether logs preserve the generated answer shown to the user; whether corrections propagate to cached or regenerated summaries; and whether the organization is prepared to respond as the speaker of the sentence.
Labeling still matters. So do links, disclaimers, and user education. They are evidence in later disputes, and sometimes good evidence. They are not a substitute for deciding who owns the statement when the system writes, the publisher displays, and a real person is misdescribed.
So the prelaunch question for the Times, and for any organization copying the format, is not whether the summary is labeled AI or whether the sources are linked. It is whether the organization is ready to answer directly for machine-written statements about third parties.
References
- New York Times tests out AI-generated search summaries — Semafor, Aug. 23, 2026
- New York Times AI summaries in search raise Guild concerns — The Next Web
- 26 O 869/26 begl. Abschrift Urteil v. 28.05.2026 — LG München I, May 28, 2026
- German court holds Google liable for AI hallucination: Read the full decision here — Transparency Coalition
- Who Speaks When an Algorithm Speaks? A German Ruling on AI Overviews — Oxford Business Law Blog, July 2026
- Are AI Overviews Creating New Risk of Libel for Search Engines? — Minnesota Journal of Law, Science & Technology, Oct. 7, 2024
- Google’s AI Search Overviews Frequently Provide False Information, Research Finds — Futurism
- Google AI Overviews accuracy analysis — The New York Times, Apr. 7, 2026
- Walters v. OpenAI, LLC — Loeb & Loeb, May 2025
- Canadian musician Ashley MacIsaac sues Google over AI-generated sex offender claim — The Guardian, May 5, 2026
Related records
Tool profile
How to Read Legal AI Benchmarks Ahead of the OpenAI IPOGoverning regulation
Browse the obligations tracker →Preventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →