RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 3, 2026

Section 230 Was Written for Content You Didn't Create. Your AI Creates It.

Two decades of internet products were built on a single sentence: a provider of an interactive computer service is not treated as the publisher or speaker of information provided by another information content provider. Every word of that sentence assumes someone else wrote the content. When your assistant composes the sentence itself, the assumption fails — and most companies shipping AI features have not noticed that they stepped outside the shelter.

Provided by another
The statutory hook that generated output does not obviously satisfy
Non-users sue too
Your terms bind customers, not the third party the output harmed
Vendor indemnity is narrow
Output claims are commonly excluded and capped at fees paid

The Sentence the Whole Consumer Internet Rests On

Section 230 of the Communications Decency Act does something narrow and enormously consequential. It says a service cannot be treated as the publisher or speaker of information provided by another information content provider, and it defines an information content provider as anyone responsible, in whole or in part, for the creation or development of information. Marketplaces, review sites, forums, social networks and comment sections all exist in the shape they do because that immunity made hosting other people's words survivable.

The load-bearing phrase is "provided by another." Courts have consistently held that a service which materially contributes to the unlawfulness of content becomes a creator of it and loses the shield for that content. That doctrine was developed for services that shaped user submissions through required dropdowns or prompted illegal choices. A system that writes the words from scratch is a considerably harder case for immunity than any of those.

Why This Is Not an Academic Question for Your Roadmap

Product teams add an assistant to a help center, a search box or a marketplace and treat it as a UI change. Legally it is a change in what the company says. Every claim your assistant makes about a product, a competitor, a person, a price, a policy or a medical or financial question is now plausibly a statement by your business, subject to the ordinary law that governs business statements. That law is not new or exotic. It is defamation, consumer protection, discrimination, professional licensure and contract — the same body of rules that has always applied to what your company says, applied to a system that now says a great deal at scale and without review.

Where Generated Output Turns Into a Claim

Statements About People and Companies
  • Confident false assertions about a named individual or business
  • Fabricated citations, cases, credentials or incidents presented as fact
  • Comparative claims about competitors the company never verified
  • Summaries of reviews that invent complaints nobody made
  • Republication at scale, so one bad pattern becomes many statements
Statements About Your Own Product
  • Assistant promises a feature, refund or SLA that does not exist
  • Pricing or eligibility answers that contradict the actual terms
  • Compliance and security claims invented mid-conversation
  • Guarantees that create contract exposure a rep could not have created
  • Instructions that lead a user into an unsafe or non-compliant action
Regulated Advice and Decisions
  • Legal, medical, tax or investment direction given as though qualified
  • Screening or eligibility guidance that steers a protected class
  • Debt, credit or housing answers that touch specific consumer statutes
  • Employment guidance that shapes a hiring or promotion outcome
  • Safety-critical instructions with no human review path
The Structural Failures
  • No log of prompts and outputs, so you cannot reconstruct any incident
  • No reporting route for bad output, so harm accumulates silently
  • No domain constraint, so the assistant answers questions you never scoped
  • Vendor indemnity never read; output claims commonly excluded
  • Insurance assumed to cover this without checking the AI exclusions

The Spectrum From Hosting to Authoring

It helps to stop asking whether "AI" is covered and start locating each feature on a spectrum. At one end sits pure hosting: a user posts, you display it, and the immunity question is the familiar one. Next comes ranking and recommendation of user material, which has been litigated hard and remains largely protected in most contexts. Then extractive features — quoting a passage with attribution and a link — where your system selects but does not compose. Then synthesis, where the model reads several sources and writes a new claim in its own words. At the far end is open generation, where output comes from model parameters with no identifiable source at all.

Immunity arguments get weaker with every step to the right, and most product teams have quietly moved several steps without revisiting anything. The design lesson is that choosing extraction with visible attribution over confident synthesis is not merely a trust-and-safety preference. It keeps a feature closer to the end of the spectrum where the law is settled and favorable.

What Actually Reduces Exposure

Constrain What It Can Say

  • Ground answers in your own documented material rather than open-ended world knowledge
  • Attribute and link sources so users can verify instead of trusting prose
  • Refuse defined categories outright rather than improvising in regulated territory
  • Keep commitments — pricing, refunds, eligibility — reading from systems of record, not from the model
  • Route high-stakes interactions to a human with a visible handoff

Build the Record and the Recovery

  • Log prompts and outputs with retention long enough to investigate a complaint
  • Give every surface a one-click route to report bad output, and track resolution
  • Evaluate against adversarial prompts before launch and after each material change
  • Read vendor indemnity for output-claim exclusions and liability caps before you rely on it
  • Check whether your insurance actually covers AI output, and what the exclusions say

Notice that none of these depend on how the immunity question is ultimately resolved. They are worth doing if generated output is protected and they are essential if it is not, which is the right profile for a decision you have to make now about a question that will take years to settle.

Frequently Asked Questions

Our chatbot only answers from our own help articles. Are we fine?

You are in the best available position, and not because of Section 230 — because the output is far more likely to be accurate and because you can trace any claim back to a document you control. The residual risk is the model stating something your articles do not say, which is why grounding needs to be paired with visible citations and evaluation rather than trusted on its own.

Does a disclaimer that answers may be inaccurate help?

Modestly, and mostly with your own users. It can support arguments about reasonable reliance in a contract dispute. It does not help against a third party defamed by the output, who never saw your interface or agreed to anything, and courts are generally unimpressed by disclaimers that a business's own system contradicts in the same screen.

What if a user's prompt is what caused the bad output?

It is a real factual argument and a weak structural one. Provocation goes to fault and damages, not to whether your system authored the statement. If your assistant can be steered into defaming someone with a paragraph of prompting, that is a product finding to fix before launch rather than a defense to raise afterward.

How is this different from the risk of hosting user reviews?

Hosting reviews puts you inside the immunity's core: someone else wrote it, you displayed it, and a notice-and-takedown process handles the rest. Generating a summary of those reviews moves you out of that core, because the summary is a new statement your system composed. Many products now do both on the same page without distinguishing them.

Should we add AI-specific terms for our customers?

Yes, and keep expectations calibrated. Clear terms on acceptable use, the limits of reliance, ownership of output and how you handle logs are genuinely useful for the customer relationship and for enterprise procurement. They do nothing for third-party claims, which is precisely where the uninsured exposure sits.

Is legislation going to resolve this?

Section 230 reform has been proposed persistently and repeatedly stalled, and AI-specific liability rules are moving unevenly across jurisdictions. Building a product strategy on an expected statutory outcome has been a losing bet for a decade. Design for the world where generated output is your statement; if a clearer safe harbor eventually arrives, nothing you built becomes waste.

Your Assistant Speaks From the Same Pages You Publish

Grounded assistants answer from your site. That makes every inaccurate claim, stale policy page and unsupported guarantee already published a live input to what your AI will tell the next customer — and to what a plaintiff will quote back.

See what your site currently says. Run a free scan and review the claims your assistant is repeating on your behalf.

Is your own site ADA compliant?

Run a free WCAG 2.1 AA scan on any public URL. Real axe-core checks in a real browser — instant report, no signup.

Need it watched instead of checked once? Starter is $29/mo for continuous monitoring, audit trails and PDF/CSV exports.