
While a lot of the attention in the AI and copyright space has gone to the hundreds of ongoing cases in the US, courts around the world have been tackling the question of copyright infringement already, with several landmark decisions taking place in Germany. We’ve had the LAION saga, but most importantly, the German collective society GEMA has been extremely busy litigating in this space, leading to a couple of landmark decisions, last year’s GEMA v OpenAI, and the latest one is GEMA v Suno, in which the copyright holders have once again obtained a resounding success.
In many ways this was a foreseeable and unsurprising result given the fact that Munich is home territory for GEMA. The Bavarian city is arguably the IP capital of Europe with the European Patent Office there, as well as having a long IP tradition in academic institutions such as the Max Planck Institute. If I were a betting man, which I am not, I would have put money on GEMA winning their all of cases there. And yet, this decision managed to surprise me in ways that I did not think were possible, as it has produced an eye-opening and far-reaching (literally) ruling that has brought the question of jurisdiction to the forefront of the AI copyright debate. Reading this together with the Delhi court decision we covered recently here at Llama Towers, it is clear that jurisdiction is back on the menu.
The facts
GEMA sued the US music AI developer Suno regarding copyright infringement in six musical works: Atemlos durch die Nacht, Rasputin, Daddy Cool, Big in Japan, Forever Young, and the chorus of Mambo No. 5 (sorry, not providing a link, I hate that song). GEMA alleged that these works had been reproduced during the training of two of Suno’s AI models ( versions 3.5 and 4). They also argued that the models had stored these copies through memorisation, and that these had been later reproduced as outputs from prompts that included the lyrics to the songs, and that these outputs amounted to reproduction without authorisation.
The claimants argued that the defendants had trained their models in the US by using millions of complete audio recordings, including the works cited above. GEMA then argued that these recordings had been obtained from YouTube using what is known as “stream ripping“, where you can create a copy of a streamed work, and that this circumvented YouTube’s own copy protection features. The recordings then were pre-processed and tokenised to train Suno’s models. GEMA did not argue that these recordings were stored as full audio files in the model, which is in itself an interesting shift from previous cases, but they did argue that the musical works remained embedded in the model parameters through memorisation, and that this enabled the model to reproduce the works in a substantial manner.

In order to demonstrate the memorisation, the claimants repeatedly prompted Suno using the original song titles, the complete lyrics, and a broad genre description for each song (for example, “80s synth pop”). Suno generated outputs that the plaintiff claimed closely reproduced protected musical expression. GEMA argued that these outputs showed that the original works had been memorised during training and that the model itself contained unlawful reproductions of the works.
GEMA also argued that the model itself was a communication to the public of the works by the defendants, as the model was able to be used to make adaptations of the work available to the public.
Suno argued that the trained model did not contain copies of works, only mathematical relationships and statistical correlations. They then argued that any similarities in the outputs resulted from the claimant’s highly specific adversarial prompting, which had included the addition of the full original lyrics. The defendants also argued that training constituted fair use under US copyright law, and that any temporary copies made in Germany were covered by existing exceptions, including temporary copies and the TDM exception. Suno also argued that any potentially infringing outputs were attributable to users rather than to Suno itself. Finally, the defendants also challenged GEMA´s standing, as German courts do not have any jurisdiction over training activities that took place in the US.
The decision
The Munich Regional Court largely found in favour of GEMA on the copyright infringement front, particularly on the reproduction and memorisation arguments. The court held that it had jurisdiction over both the alleged infringements occurring in Germany and the training carried out in the US.
An interesting part is that the court identifies three different stages of training, somewhat matching what had happened with the OpenAI case. These stages are i) pre-training, ii) training, and iii) inference (outputs). Following the old input-output dichotomy, the input phase is i) and ii), while the output phase is iii). An addition to the existing debates regarding this question is that the TDM exceptions do cover the first stage, but they do not cover the training itself if the model has memorised the works. The third phase is evidently not covered by any exception if there has been a reproduction. This is for all intents and purposes a similar argument to that presented in GEMA v OpenAI, and it fits many of the arguments we have been making here. Training falls under the TDM exceptions, but outputs that are substantially similar to the inputs are reproductions, in other words, the proof is in the output.
Although the court agreed that some part of the input phase could fall under the TDM exception, in this particular case they concluded that Suno’s use of the works for AI training infringed the reproduction right. It rejected the argument that the trained Suno models merely contained abstract statistical information, holding instead that the copyrighted works had been reproduced within the model in a legally relevant manner because they remained stored in the model’s parameters in a form capable of generating substantially similar outputs. The court argues that it is irrelevant if the model is holding actual copies of the work, as long as it is capable of producing an output that resembles the work in a substantial manner. The defendants asked for expert opinion to be sought here, and the court denied it.
So the court held that the TDM exception under German law did not apply here, mostly because the works had not been lawfully obtained, as there had been and because valid rights reservations had been made, in other words, the authors had opted out of training. With respect to the US training, the court further concluded that the defendant could not rely on the US fair use doctrine (more on that later).
The ruling contains a very detailed and lengthy musical analysis of each of the outputs presented by the claimants, an analysis that I will not comment on because I lack the musical knowledge. The court was satisfied that the outputs were substantially similar to the original works, and not being able to listen to the outputs, it’s not possible to argue with that.
So far, so normal, but then the most interesting headline of the case dropped. The court devotes almost ten pages to a detailed analysis of US fair use law and jurisprudence. Rather than simply asking whether AI training is “transformative”, it analyses modern SCOTUS framework and then explains why, on the facts before it, Suno cannot rely on fair use. The main issue is that it admits that in Bartz v Anthropic Judge Alsup had argued that AI training was transformative, the ruling argues that this is not applicable here, as there are actual infringing outputs that are too similar (citing also Campbell and Warhol). The argument is that if AI training merely extracts statistical relationships and the model does not reproduce the protected works, then Bartz may apply. But if the model memorises works and later reproduces them in outputs, then the use ceases to be sufficiently transformative. This then becomes a commercial substitution, and the fair use balance shifts against the AI developer.
However, GEMA did not win all of its claims as the court rejected their separate claim that the defendant had infringed the right of communication to the public by merely offering the model itself. This is the right way of looking at a model, one would not go to Suno if one wanted to hear “Forever Young” for free, one would go to YouTube or Spotify.
As a remedy, the court granted injunctions prohibiting (i) the use of the works for AI training, (ii) storage of the works within the AI model, (iii) offering the model in Germany insofar as it embodied those works, and (iv) the creation of infringing adaptations through the outputs, and damages will be calculated afterwards, and here the judge uses some very strong language, citing that the damage to the musicians is “irreparable”. This seems standard, until you notice that the injunction is ordering something that will have an effect in training, in other words, it will have extra-territorial effect, the ruling says Suno must stop copying the works belonging to the authors “within the territory of the United States of America for the purpose of training an artificial intelligence (AI) model to generate music”.
Wow.
Discussion
In some ways, this is a perfect companion to the GEMA v OpenAI ruling, although I think that it is better argued. As mentioned, I do not think that is is a very surprising ruling given the context and the court, this is a ruling that is very willing to look at the arguments from the claimants favourably, particularly citing useful experts and academic commentary (great to see Lee/Cooper/Grimmelmann make a repeated appearance here).
This is a pretty good ruling, at least in the less-controversial parts. I think that it follows GEMA v OpenAI in its analysis of memorisation, and I agree that if a model is capable of producing an output that is a substantial reproduction of a work in the training data, then that is copyright infringement. I cannot judge whether the outputs were similar to the copyright works in question, I will take the court’s word and analysis as a given. I also think that the TDM analysis is mostly spot-on, although I continue to argue that in OpenAI training is covered under the TDM exception (lengthier analysis here), although that argument is less prevalent here. I know some colleagues disagree with this, but I’m not going to re-open that argument.
But two things bother me about the ruling. The first one is the prevalence of adversarial prompting used to generate actionable outputs. Just as what occurred with the initial New York Times complaint, and as it has been happening in many other cases such as the recent Delhi decision, it is becoming evident that being able to produce an infringing output has become the most important part of ongoing copyright litigation, particularly if we assume that training itself falls under fair use in the US (still a big assumption I know). I think that this is understandable, if a model can reproduce a work in a substantial manner, then it doesn’t matter how it was able to do it, be it through keeping stored copies of the work, or through memorisation (more on that in the article that I’m currently writing).
But I strongly believe that courts should be suspicious of adversarial prompting, and we should really be looking at how the public uses models. I can’t imagine that there are many people out there who go “you know, I really want to listen to ‘Rasputin’ today, let’s fire up Suno and make a copy”. However, one thing that is happening, and that we can definitely look as potential copyright infringement, is the existence of so-called AI covers. This is a real thing, if you search YouTube for “AI cover” of a popular song, it is likely that you will find it. This was part of the argument against fair use, and it is a big element of the court’s discussion regarding fair use… until you notice what the covers are. So you can get AI covers of Billie Jean as a heavy metal song, or as a country song. Infringing? Possibly. Transformative? Possibly. We don’t know. I strongly suspect that many of those covers are not memorised, and are obtained by users uploading copies of the songs to have them modified, but I digress…
However, I think that if the outputs presented here are substantial reproductions, then the ruling is accurate. But that brings us to the second part that bothers me about the decision, and that is the glaring issue of extra-territoriality. While I would argue that courts in Germany have clear jurisdiction with regards to the infringing outputs in their territory, I’m less willing to concede that the court can order an AI company in the US to do something that may be fair use there. I found the court’s fair use argument well made, but to then use that to state that Suno has to comply with this in the US is interesting to say the least. I will have to sit down and work out the jurisdiction question in more detail, but I can’t see a US court enforcing this ruling there.
Concluding
Another fascinating decision, and one that is unsurprising and very reasonable in some parts, while entirely in new territory in others. On the one hand I really think that the way forward with memorisation is to look at outputs as we are not capable of knowing in advance whether a model has memorised a work or not.
But the jurisdiction argument is a bit strange, even if it relies on the special ways in which collecting music societies work. I do not think this part of the ruling will survive scrutiny, but it’s early days.
On the meantime, I keep wondering about the music taste of these models. If you’re going to memorise a German artist, why Helene Fischer, and not Rammstein? Discerning minds want to know.
0 Comments