How Europe Builds AI Liability (Part II): AI in Copyright
Part I of this AI Liability series mapped the three regimes of European AI liability: copyright, automated decision making under the GDPR, and the product liability rules applying to products placed on the EU market after 9 December 2026.
UPDATE TO PART I: The (European Court of Justice’s) Advocate General’s opinion in Like Company v Google Ireland (C‑250/25) will not be published today, as previously expected. The much anticipated first step toward a European Court of Justice ruling on copyright and AI in this European landmark AI case that will decide for all 27 Member States whether training AI models on protected works and reproducing them in outputs infringes copyright – is not scheduled for delivery in the Court’s calendar for the 3 to 10 September period, and no new date has been announced.
This piece stays with copyright, which is the regime where European courts have already ruled. It also sets out what a US company scaling into Europe should expect from the Court of Justice, from the national courts (that will eventually actually hear its case), and from the rightsholders. The American case law appears as comparison.
Which US companies do EU copyright rules reach?
Every company on Part I of this series. Think companies that ship or use generative features into Europe. They are affected by EU copyright rules, and the exposure can be sorted in four categories, according to which acts the company performs.
Model builders and fine tuners. Any company that trains or fine tunes an AI model on data it did not license (including its own customers’ content, open web scrapes or purchased datasets of uncertain provenance). The exposure arises at:
- the dataset stage (Kneschke, where the Hamburg courts held that scraping a photograph into a training dataset was covered by the text and data mining exception, and where Germany’s Federal Court of Justice will now decide whether that holds and what a valid opt-out looks like)
- the model (the memorization holding in GEMA v OpenAI) and
- where the company serves the EU market, possibly at training conducted abroad (GEMA v Suno reached US training from a German courtroom, and Like Company now asks Luxembourg whether training and deployment count as one process, so that EU copyright applies to training anywhere once the system is sold in Europe.).
Most companies entering the EU market are not in this group, but a company fine tuning a third party model for a European product may become a provider in its own right under the EU AI Act and inherit the Article 53 copyright policy duty described below.
Companies shipping generative features. Such as a brand using generative tools for campaign assets aimed at European audiences; a content generation tool offered to EU users; a customer service agent serving European customers; a studio shipping AI assisted work into the EU market; an e-commerce platform generating product descriptions or images for its European storefronts.
Their exposure under the European copyright regime arises at the outputs: if the vendor’s AI model reproduces protected works in what the company publishes in Europe, the company is the entity that communicated the work to the public there (whatever the vendor indemnity says). This is the largest group, and the first rightsholders will write a cease-and-desist letter to, ahead of the model developers whose training created the problem.
Companies whose products summarize or retrieve third party content. Anything that answers questions from the web, from news, reviews or documents. Such as AI search, assistants with browsing and summarization features. This is the landmark Hungarian case, Like Company’s, own fact pattern: a chatbot summarizing a press article.
Worth noting here that the press publishers’ right of Article 15 of the EUcelcece Copyright Directive (EU) 2019/790 (the CDSM Directive, created a related right for press publishers, separate from the authors’ copyright in the articles, giving publishers established in the EU their own exclusive right over the online use of their press publications by information society service providers, for two years from publication, with an exception for very short extracts.
That gives every European publisher standing of its own against a chatbot, or any online service, that reproduces its articles. A US software company with an AI summarization feature serving EU users is closer to Like Company’s defendant than it may realize.
Companies whose own content is being used. The reverse side of the above. A company that publishes, whether media, marketing content, software documentation or product data, is a rightsholder too. The same case law tells it:
- how to keep its content out of AI training (according to the Hamburg courts: the reservation must be machine readable, in a form crawlers can detect; plain language terms on a website do not count, and a ruling from Germany’s Federal Court of Justice – expected in the coming months – will settle what is enough) and
- what it can enforce against AI providers that reproduce its material. A company, whose own content is being used (such as articles, marketing copies, documentation or product data being scraped or reproduced by AI providers) has something to gain from these European rules and may use them as an asset.
Not something that a US company would expect. But its content is protected in Europe under the same rules, without any EU establishment. This is because copyright protection follows the work into every country of the Berne Union (the Berne Convention for the Protection of Literary and Artistic Works has more than 180 contracting parties and covering nearly every state in the world, including all EU Member States and the United States.) A US publisher, software company or brand whose articles, documentation or product data are scraped and reproduced by an AI provider serving the EU can enforce in a European court (the same way the German music rightsholders did against OpenAI and Suno), with the injunction and the information claim, and can post machine readable reservations that European courts will honor.
The one European right that requires EU establishment is the press publishers’ right of Article 15, which is limited to publishers established in a Member State. A US media company can get that through an EU subsidiary.
Copyright is where a US company will be challenged first
Part I of this piece covered three regimes: copyright, automated decision making claims under the GDPR, and product liability claims. Product liability claims cannot start until after 9 December 2026, and then need harm, a claim and a trial. Automated decision making claims exist today, but they arise only where a company makes decisions about individuals by automated means, which describes a minority of businesses. Copyright claims already exist for anyone shipping AI features into Europe, have already succeeded in the German courts against OpenAI and Suno, and typically begin with a cease and desist letter rather than a lawsuit.
Copyright is the regime where a US company’s European AI exposure becomes concrete first. This is because the European courts have already ruled (against providers) and the claimants are organized (collecting societies and press publishers with statutory standing, professional enforcement and, in Germany, a venue privilege that reaches conduct abroad). Furthermore, the European remedies are commercial, rather than merely financial: a European court’s first tools are the injunction and the information claim, which can stop a product and open its training records. Those remedies are not the damages award that an American business would typically expect and try to budget for.
The American comparison:
The European cases apply copyright statutes that predate generative AI: the InfoSoc Directive of 2001 and the copyright directive of 2019. The American cases do the same with the Copyright Act of 1976. No AI statute is involved in either Europe or the USA.
What differs is the legal solutions: Europe has enumerated exceptions rather than fair use, and the exception that matters (text and data mining, TDM) comes with an opt-out that rightsholders can exercise in advance. Also, Europe has no statutory damages and no opt-out class actions. Europe decides these cases in specialized judicial chambers (copyright or IP divisions within national civil courts), which can refer new questions to the Court of Justice in Luxembourg, when the question is new. Those differences are the reason the European outcomes look the way they do.
Five points where an AI product can infringe
European copyright law asks five questions about an AI system, each based on the legally distinct act that the technology involves. A company can be lawful at one step and liable at the next. The questions concern:
- assembling the training dataset,
- training the model on it,
- the trained model itself, which may retain works in its parameters,
- the outputs, and
- offering the system to the public.
Each of the decided European cases concerns a different one of these five acts, which is why they can point in different directions (without contradicting each other).
The Hungarian landmark case now pending in Luxembourg, Like Company v Google, raises four of the five: training, the exception that might cover it, and the outputs, both as a reproduction and as a communication to the public.
The case that will set the European frame: Like Company v Google
How a dolphin story reached the Grand Chamber
The facts of the case are modest (the stakes are not). In July 2023, a small Hungarian news site, balatonkornyeke.hu (a personal note: Lake Balaton is often quoted as “the Hungarian sea”; a visual gem and an ‘institution’ in Hungary: a most beautiful turquoise blue body of water that stretches as far as the eye can see, lined with lush, cultivated wine landscapes and gentle green hills), published an article reporting that a local celebrity had not abandoned his plan to bring dolphins to Lake Balaton (sic). A user asked Google’s Gemini chatbot to summarise the article.
The chatbot answered over several paragraphs, reproducing parts of the article and, according to the Hungarian court’s order, adding material that did not come from it. The publisher, Like Company, sued Google Ireland before the Budapest Környéki Törvényszék (Budapest Regional Court), alleging that between June 2023 and February 2024 Gemini systematically extracted and displayed substantial parts of its press publications, and that its content had been used to train the underlying model without authorisation or remuneration. The Hungarian court stayed the case and, on 3 April 2025, sent four questions to the Court of Justice of the European Union (EUR-Lex, C‑250/25).
The four questions
The questions of the (talented) Hungarian attorney which were referred to the Court of Justice of the EU in Luxembourg, concern multiple of the five acts above:
- Outputs as communication to the public. Whether a chatbot that displays text partly identical to a press publication, beyond the “very short extracts” the press publishers’ right already tolerates, performs a communication to the public (Article 15(1) of the 2019 directive and Article 3(2) of the InfoSoc Directive), and whether it matters that the chatbot merely predicts the next word from observed patterns.
- Training as reproduction. Whether training a chatbot’s language model, a process of observation and pattern matching, constitutes a reproduction (Article 2 InfoSoc).
- The text and data mining exception. If training is a reproduction, whether the reproduction of lawfully accessible works in this way falls within the TDM exception of Article 4 of the 2019 directive.
- Outputs as reproduction by the provider. Whether, when a user prompts the chatbot with text identical to or referring to a press publication and the answer reproduces that publication in whole or in part, the reproduction is attributable to the chatbot provider.
Questions two and three are the European version of the training debate. Questions one and four are the output side. The Hungarian reference for a preliminary ruling by the Court asks both sides of the AI copyright debate (that courts elsewhere have taken separately).
- The input side (was training on protected works lawful) and
- the output side (does what the model produces infringe).
Munich’s Suno judgment was one of the first to decide both. The American cases have mostly been input cases. In Like Company, the European Court of Justice will cover the whole chain (will consider training and outputs) together.
The German judgments
Kneschke v LAION. This case concerns the boundary of the text and data mining exception as applied to AI training. In September 2024 the Hamburg Regional Court dismissed a photographer’s claim against the nonprofit behind the LAION 5B dataset over the automated download of his photograph from a stock site whose terms prohibited automated access, holding the copying covered by the text and data mining exceptions of the German Copyright Act: Section 44b, the general exception implementing Article 4 of the CDSM Directive, which a rightsholder can switch off by a machine readable reservation under Article 4(3), and Section 60d, the research exception implementing Article 3, which cannot be switched off. Today, on 3 September 2026, the Federal Court of Justice heard oral argument in the case (I ZR 281/25), the first to test those exceptions, and the machine readability standard for opt-out reservations, against AI training dataset scraping. No judgment was announced; the court commonly reserves judgment for a later pronouncement date. The ruling will be the first from a European supreme court on the TDM exceptions as applied to AI training dataset construction and on what counts as a machine readable opt-out.
Every Member State applies the same Article 4 wording, so courts across the Union will read the German ruling as guidance.
GEMA v OpenAI. In November 2025 the Munich I Regional Court delivered the first European judgment holding a generative AI provider liable (42 O 14139/24). GEMA, the German collecting society for music authors, sued over the lyrics of nine well known German songs memorised in the language models and reproduced in chatbot outputs on simple prompts. The court rejected each limb of the American provider’s defense. The court held that where a comparison of training data and outputs shows a complete adoption of a work in the model’s parameters, that is memorisation, and memorisation is a reproduction: fixation in probability values is a fixation nonetheless, and the reproduction right covers reproductions by any means and in any form. The TDM exception covers the preparatory stage only, format conversions and working memory copies; where the work itself ends up reproduced inside the model, the exception’s premise, that only information is extracted, no longer holds, and the court declined to extend it by analogy, reasoning that the risk of memorisation originates in the provider’s sphere. On outputs, responsibility lay with the provider, which selected the training data and built the architecture. OpenAI was ordered to cease, to disclose the extent of the use and the revenue derived from it, and declared liable in damages, with the amount to be determined once disclosure is given The judgment is on appeal before the Munich Higher Regional Court.
Nothing about the provider’s US establishment mattered: the court decided infringements occurring in Germany, the memorized model made available there and the outputs served to German users, and for those acts the location of the company, its servers and its training was irrelevant. The step of reaching training conducted on US soil came eight months later, in Suno.
GEMA v Suno. On 31 July 2026 the same chamber ruled further (42 O 763/25), concerning six musical compositions. The judgment prohibits these acts: reproduction for training in the United States, reproduction through memorisation in the model on German servers, communication to the public through offering the generator, and reproduction and communication through the outputs.
The jurisdictional mechanism is directly relevant for a US company. The court took jurisdiction over the US training acts under Section 131 of the German Collecting Societies Act, a special venue rule for collecting societies, then applied US copyright law to those acts under the territoriality principle and rejected fair use. It distinguished the American decisions in Bartz v Anthropic and Kadrey v Meta on the ground that there the training data were not made accessible to users in outputs, whereas here simple, open ended prompts produced outputs substantially similar to the originals. A German court conducted a full American fair use analysis, and the American defendant lost under its own law.
Two aspects are worth noting. The court found that Suno obtained the training data by stream ripping from YouTube, circumventing technical protection measures, so a defendant with licensed or lawfully accessed data should not read the judgment as deciding its situation. The venue rule that reached the US training is a privilege of collecting societies that an individual rightsholder cannot invoke. The judgment is first instance and not final, with an appeal open to the Munich Higher Regional Court.
We may conclude that the German decisions have one organizing idea, which is that the exceptions protect the analysis of information and no longer apply where a work is reproduced. That boundary is tested at the model and at the outputs rather than at the dataset, also raised in Like Company question, now with Luxembourg.
Where in Europe: what changes from one Member State to the next
Part I made the point for product liability that the first EU market a company enters decides which national statute applies and how predictable the early years will be. Copyright is more harmonized than product liability.
The European directives (the InfoSoc Directive of 2001 (Directive 2001/29/EC) sets the exclusive rights, reproduction in Article 2 and communication to the public in Article 3, and the CDSM Directive of 2019 (Directive (EU) 2019/790) adds the text and data mining exceptions in Articles 3 and 4 and the press publishers’ right in Article 15) fix the exclusive rights and the exceptions for all 27 Member States, and a preliminary ruling binds the courts of all 27 Member States when they apply the same provisions. But the litigation is national, and what a US company will be exposed to differs materially by Member State. There are five factors to be considered:
Who can sue, and where. Germany’s collecting societies enjoy the Section 131 venue privilege that reached Suno’s US training. No other Member State’s plaintiff has yet achieved equivalent reach. The press publishers’ right of Article 15 gives publishers across the Union a right of their own against online uses, and Hungary’s Like Company shows a single small publisher can reach Luxembourg. In France, the authors’ and publishers’ organisations have sued Meta before the Paris court, with the case pending. Proceedings are also advancing in the Netherlands.
Which chamber decides. Germany channels copyright to specialized court chambers. Munich’s 42nd Civil Chamber has now decided both generative AI cases against providers. Hamburg’s courts have decided the dataset case for the defendant. But there is no contradiction, those are different aspects. What is important to note is that in Germany the act for which a company is challenged, and the court district, will shape the outcome.
How the opt-out is read. The TDM opt-out must be machine readable. The Hamburg Regional Court suggested in obiter that a reservation written in natural language could satisfy that requirement, given that modern systems can parse ordinary text. On appeal, the Higher Regional Court held that the claimant had not shown the reservation was machine readable as at the relevant use in the second half of 2021. The Federal Court of Justice’s pending ruling will settle the standard. In practice, it will also set the reference point for the other Member States, which apply the same directive language. Until then, a company honoring robots.txt style reservations is in a defensible position everywhere, and a company relying on the absence of one is in a defensible position only where courts read the requirement narrowly.
The costs of a cease-and-desist letter. German enforcement uses a formal cease and desist letter, whose costs the recipient bears if the claim is well founded, and which demands a signed undertaking not to repeat the infringement, backed by a contractual penalty for each breach. That machinery makes German rightsholders’ letters cheap to send and expensive to ignore, and it is the practical form European copyright exposure takes first.
Elsewhere in Europe the warning letter is used less. While in Germany the rightsholder recovers its lawyer’s fees for the letter from the recipient if the claim is good (which makes the letter a self-financing first step and explains why German rightsholders send so many of them), in most other Member States the sender bears its own cost of a pre-action letter, and that is why a rightsholder there would skip the letter or use it only as a courtesy before filing. There a company’s first real contact with the claimant would be typically the court summons. France and the Netherlands for example litigate instead of warning.
How fast a case reaches Luxembourg. Hungarian reporting on Like Company reveals that a Member State with little settled practice on a new technology can send a question to Luxembourg quickly, and the answer then binds the markets with the most practice.
A company entering through one Member State is exposed to the reference culture of every other Member State’s courts. Hungary, Denmark, Greece, Spain and France argued for reaching training abroad. Germany argued against. We can see those signs as the EU Member States indicating how their own courts and legislatures are likely to lean. That may be vital for a US company choosing where to establish its European operations.
The American background, briefly
Four American cases show the difference, and the Munich court engaged with two of them directly: in Suno it named Bartz and Kadrey and explained why their fair use findings did not apply.
In Bartz v Anthropic, training on lawfully acquired books was held transformative fair use in June 2025 and retaining millions of pirated books in a central library was not held as such. The pirated-library claims settled for 1.5 billion dollars, the largest copyright settlement in history, with final approval on 20 July 2026. The settlement covers only the pirated-library claims; claims over what the model produces remain open.
In Kadrey v Meta, the court granted Meta partial summary judgment on fair use in June 2025, stressing how narrow the ruling was. Certification for interlocutory appeal was refused in July 2026, and the case continues in the district court on the authors’ distribution and contributory infringement claims.
In Thomson Reuters v Ross Intelligence, the first federal appellate test of fair use in AI training, was argued in the Third Circuit on 11 June 2026 and is undecided.
On 1 September 2026, the Department of Justice filed a statement of interest in the consolidated New York Times litigation against OpenAI and Microsoft, urging a broad transformative reading of fair use for training and a separate substantial similarity analysis for outputs.
Three differences matter for a US company entering the European market:
First. Europe has no statutory damages and no opt-out class, so the European exposure will never end in a 1.5 billion dollar settlement. The central European remedy is the injunction that stops the product and the information claim that opens the training records. That consequence may hurt a Europe-faced business more than a settlement.
Second. The powerful American defense “fair use” does not exist in Europe, and the TDM exception that replaces it can be excluded by the rightsholder in advance, through a machine-readable reservation. So, a European court will examine whether the opt-out was respected, instead of whether the use was transformative.
Third. Munich distinguished the American fair use rulings on output accessibility, and the Department of Justice now argues that outputs need their own analysis. Both Europe and the US are moving toward the same rule where a model’s outputs matter more than its training data. The result is that output controls are investment worth making on both sides of the Atlantic.
The EU AI Act
The EU AI Act adds one copyright obligation. It is aimed at model providers rather than deployers. Providers of general-purpose AI (GPAI) models must maintain a copyright policy that respects TDM opt-outs and publish a summary of their training content (Article 53). Those obligations have been in force since August 2025.
A US company fine tuning a third party model for the European market should establish whether it has become a provider (in its own right) because that triggers the policy.
What a US company will want to prepare before EU-entry
Provenance. The German decisions depend on how the data was obtained (lawfully accessed or scraped past a technical barrier) and on whether machine readable opt-outs were respected. The German Federal Court of Justice is about to say what a valid European opt-out looks like. A company that can show – provide documentation on – where its training data came from and how it treated reservations, will be well positioned to answer a cease and desist letter and has the file ready that the claimant’s lawyer will most want to see and the judge will read at the outset.
Licences and indemnities. For every AI feature shipped into Europe, the company should be able to name the model, the licence behind it, and the indemnity in the vendor contract. And also to know whether that indemnity covers claims brought in a Member State under EU law, including information claims and injunctions rather than damages alone.
Outputs. Munich, London and the American authorities agree that liability concentrates where protected works appear in outputs. Output controls that stop memorized works from appearing can be the most affordable step away from potential litigation available both in the EU and the US.
The cease-and-desist letters. After the Munich judgments, rightsholders and collecting societies can send cease-and-desist letters demanding that: 1. the use stop, 2. training and revenue information be disclosed, and 3. damages be paid. We discussed the issues relevant here above.
Summary
The copyright regime runs on the same mechanism as the product liability regime described in Part I because the documentation written before EU market entry is the strongest asset that can – and will – determine AI-liability years later. In copyright, the first to read that file will be a rightsholder’s attorney.
On 9 September 2026, Holon Law Partners will take up further intriguing issues of European AI liability at our dedicated Budapest AI Breakfast, held alongside the region’s leading AI Summit 2026 Budapest on 7 to 8 September.
