GEMA v Suno: What the Munich AI Judgment Means for the Four Phases of AI Model Use

GEMA v Suno: What the Munich AI Judgment Means for the Four Phases of AI Model Use

Author
Dr. Ursula Feindor-Schmidt, LL.M.
Dr. Ursula Feindor-Schmidt, LL.M. Lawyer, Partner
Specialised Lawyer for Copyright and Media Law
View profile

Share blog post via

On 31 July 2026, the Munich Regional Court I (Landgericht München I) handed down its second landmark AI judgment in GEMA v Suno (Case No. 42 O 763/25). Following GEMA v OpenAI (judgment of 11 November 2025, Case No. 42 O 14139/24), which concerned song lyrics, the 42nd Civil Chamber now had to rule on an AI music generator. The outcome is clear: without a licence, Suno may not reproduce six works from the GEMA repertoire – including “Atemlos durch die Nacht”, “Forever Young” and “Daddy Cool” – for training, store them in its model, offer them via the model or reproduce them in outputs. Remarkably, the Chamber also prohibited the training that took place in the United States – applying US law and expressly rejecting the fair use defence. The judgment is not final; an appeal is pending before the Munich Higher Regional Court (OLG München, Case No. 6 U 2314/26 e).

Together with the LAION decisions of the Hamburg Regional Court and Higher Regional Court and the GEMA v OpenAI judgment, a largely coherent picture of German case law now emerges for the first time. The courts do not assess “the AI” as a whole but distinguish four consecutive phases of use: creating the dataset, training, offering the model and the output. In each phase separate acts of use have to be considered and require their own justification. This article first presents the decision and then shows what currently applies in each of these phases.

What did the Munich Regional Court decide?

Suno is a US-based company operating an AI music generator. Users enter lyrics or a description and a musical style and receive two finished recordings within seconds. The proceedings concerned versions v3.5 and v4, which are also available in Germany; technically, the system combines a transformer model with a diffusion model.

Training took place in the United States using millions of complete sound recordings. Suno obtained the works at issue by stream-ripping them from YouTube, circumventing the so-called rolling cipher, a technological measure designed to prevent downloads. For users in Germany, the trained model was held on edge servers located in Germany.

Staff of GEMA and its counsel entered only the original lyrics, the title and a general style indication, such as “Schlager” or “80s, synth pop, male voices”. The prompts contained no specifications as to melody, harmony, rhythm or arrangement. The same prompt was entered between 4 and 176 times per work. The outputs submitted reproduced the melodies, harmonies and arrangements of the originals in a recognisable manner; the Chamber played them at the oral hearing and compared them on the basis of musical transcriptions.

The court prohibited four acts of exploitation:

  1. reproducing the works for training purposes in the United States,
  2. reproducing them by storing them in the form of parameters in the model in Germany (memorisation),
  3. communicating them to the public by offering the model and the music application in Germany,
  4. reproducing and communicating to the public adaptations of the works in the outputs.

In addition, GEMA was granted claims for information and for damages on the merits, as well as the right to publish the operative part of the judgment in the Süddeutsche Zeitung at Suno’s expense once it becomes final. The Chamber dismissed the action only insofar as GEMA had relied on the right of making available to the public under Section 19a of the German Copyright Act (UrhG) (see Phase 3 below).

The special feature: a Munich court rules on AI training in the United States

What is new compared with GEMA v OpenAI is above all that the Chamber also ruled on the training carried out in the United States (paras. 118 et seq.). Three steps support this result:

  • Jurisdiction: Section 131(1) of the German Collecting Societies Act (VGG) gives collecting societies a venue at the place where the infringement was committed. Under Section 131(2) VGG, they may bundle all claims against the same infringer before one of these courts. The Chamber applies the provision “double-functionally” to international jurisdiction as well. Because Suno offers its music generator throughout Germany and thus also in Munich, GEMA could also sue there for the acts committed in the United States. Under public international law, the Chamber relies on the protective principle; in the alternative, it finds a sufficient link to Germany (GEMA’s seat, predominantly German authors, close factual connection).
  • Applicable law: Under the principle of the law of the protecting country (Art. 8(1) Rome II Regulation), training in the United States is governed by US law, while the model and the outputs in Germany are governed by the German Copyright Act.
  • Fair use: The Chamber examined 17 U.S.C. § 107 itself and rejected fair use; all four factors weigh against Suno (paras. 447 et seq.).

Particularly instructive is the distinction drawn from the US decisions Bartz v. Anthropic and Kadrey v. Meta, on which Suno had relied. In those cases, the training data were not, or not substantially, accessible in the outputs. Here, by contrast, the music generator produced recordings substantially similar to the originals in response to simple prompts (para. 480). Training a music generator may well be transformative in general. But where the works are memorised and reproduced, original and output serve the same purpose – listening to music (paras. 484, 494). In addition, the Chamber regarded the circumvention of the rolling cipher as bad faith and as a violation of 17 U.S.C. § 1201. Under the fourth factor, it considered the outputs a substitute for the originals on the market for entertainment music (paras. 519 et seq.). It granted the injunction under the eBay standard, taking into account that GEMA had declared its willingness to license (para. 543).

Assessment: For collecting societies, training abroad is therefore no longer a safe harbour. Whether a venue that is available only to collecting societies can actually support the review of acts committed in the United States will have to be clarified by the Munich Higher Regional Court. Individual rights holders cannot rely on Section 131 VGG.

The four-phase model: how German courts assess AI uses

The courts break down the life cycle of an AI model into consecutive phases. The Hamburg Regional Court developed this distinction in the LAION case (judgment of 27 September 2024, Case No. 310 O 227/23, para. 46); the Munich Regional Court I has adopted it (GEMA v Suno, para. 240): creating the training dataset, training the model, and using the trained model through prompts and outputs. GEMA v Suno adds a separate phase: offering the model, which the Chamber treats as an act of exploitation even before any prompt is entered.

The four phases of use of AI models and how German courts assess them

The value of this approach lies in its precision. Each phase is a separate act of use that requires its own justification; an exception that applies in Phase 1 does not automatically carry over into Phase 2. The hinge is memorisation: only once a work is fixed in the model is there a reproduction in the model – and that infringement then continues through the offering of the model into the output.

Phase 1: Creating the training dataset

In brief: Collecting and preparing works for an AI dataset is text and data mining and is in principle permitted under Sections 44b and 60d UrhG – but only with lawful access and provided there is no effective, machine-readable reservation of rights.

The leading case for this phase is LAION. The non-profit association LAION had downloaded a photograph from a picture agency’s website in order to match image and image description for a public training dataset. The Hamburg Regional Court dismissed the photographer’s action (judgment of 27 September 2024, Case No. 310 O 227/23). Section 44a UrhG did not apply, as a targeted download is neither transient nor incidental. However, the reproduction was permitted as text and data mining for the purposes of scientific research under Section 60d UrhG. The court left open whether Section 44b UrhG also applied, but indicated that a reservation expressed in natural language could suffice.

The Hamburg Higher Regional Court dismissed the appeal (judgment of 10 December 2025, Case No. 5 U 104/24) and now also applied Section 44b UrhG in addition to Section 60d. Timing was decisive: what matters is whether the reservation was machine-readable at the time of use – here, the download in the second half of 2021. This could not be established. The court takes a technology-neutral view of machine readability: terms and conditions or a legal notice may suffice if the text can be captured and interpreted by machines in such a way that automated processes exclude the content. Whether natural language is sufficient, and what role robots.txt or the TDM Reservation Protocol play, remains disputed. An appeal on points of law is pending before the Federal Court of Justice (BGH, Case No. I ZR 281/25) – it will be the first ruling of Germany’s highest civil court on Sections 44b and 60d UrhG in the run-up to AI training.

GEMA v Suno confirms this line in principle: Section 44b UrhG and Art. 4 of the DSM Directive apply to AI training and cover reproductions made to prepare the training corpus, such as format conversions or copies in working memory (paras. 284 et seq.). What is new is an important limit: the exception requires lawful access to the work (Section 44b(2) UrhG). Suno lacked such access because it had circumvented YouTube’s rolling cipher. The Chamber classifies the rolling cipher as an effective technological measure within the meaning of Section 95a UrhG – even though Suno succeeded in circumventing it. If a measure were one hundred per cent effective, legal protection against circumvention would not be needed (paras. 308 et seq.). The Chamber therefore did not have to decide whether effective reservations of rights had been declared.

In practice: Phase 1 is the domain of the TDM exceptions. Anyone who obtains training data by stream-ripping, from shadow libraries or by circumventing technological measures cannot rely on them. Rights holders should declare their reservation in machine-readable form and document when they did so.

Phase 2: Training and memorisation in the model

In brief: Where works are memorised in the model, there is a reproduction under Section 16 UrhG. Section 44b UrhG covers the analysis of works, but not their incorporation into the model – that requires a licence.

The Chamber laid the foundations in GEMA v OpenAI. In response to simple prompts such as “What are the lyrics of …?”, ChatGPT reproduced nine song lyrics, including “Atemlos”, “Männer” and “Über den Wolken”, largely verbatim. From this, the court concluded that the lyrics were fixed in the GPT-4 and GPT-4o models. It is irrelevant that the work is present only as probability values distributed across the parameters: Art. 2 of the InfoSoc Directive covers reproduction “by any means and in any form”. The Chamber compares the model to a progressively stored JPEG file or an MP3 file, in which no discrete copy is identifiable either.

In GEMA v Suno, the Chamber transfers this line to music and refines it (paras. 240 et seq.):

  • What memorisation is: The parameters do not merely extract information such as patterns and correlations from the training data, but take over at least part of its content. An exact, one hundred per cent copy is not required (paras. 243, 245).
  • How it is proven: By comparing the original with an output generated in response to a simple, open-ended prompt. For sufficiently complex works, chance can be ruled out as the cause (paras. 247 et seq., 258). The Chamber did not consider an expert opinion necessary.
  • What a simple prompt is: Lyrics, title and genre do not determine melody, harmony, rhythm or tempo; they are therefore not a steering prompt (paras. 253 et seq.). Nor does entering the same prompt repeatedly steer the result, since input and parameters remain the same (para. 252).
  • What does not work: The objection that the model could not, mathematically, store even 1% of the training data is irrelevant – only the six works at issue matter (para. 260). Nor is a “parameter player” needed for indirect perceptibility; the music generator itself makes the works audible (para. 277).

This reproduction in the model is not covered by Section 44b UrhG (paras. 280 et seq.). Text and data mining aims at obtaining information; the exception permits only reproductions made “for the purposes of” that analysis. The copy remaining in the model does not serve any further data analysis but interferes with the authors’ exploitation interests. An analogous application is ruled out, not least because the risk of memorisation stems solely from the model provider’s sphere (para. 299). The Chamber puts it clearly: if memorisation cannot be avoided according to the state of the art, training with protected works is not covered by the TDM exception at all (para. 304). The legal order knows no business model that helps itself to third parties’ intellectual property free of charge (para. 305).

The AI Act does not change this either. The obligations under Art. 53(1)(c) and (d) of the AI Act – a copyright policy and a summary of training content – are intended to facilitate enforcement, not to replace a licence. The Code of Practice itself states that adherence to it does not constitute compliance with copyright law (paras. 300 et seq.).

In practice: The decisive question is no longer whether a model was trained on a work, but whether the work is memorised in the model. If it is, storing it in the model requires a licence wherever the model is stored. Nor did it help Suno to argue, after the close of the oral hearing, that the model weights were no longer held on servers in Germany: the risk of repetition can only be removed by a cease-and-desist declaration backed by a contractual penalty (para. 312).

Phase 3: Offering the model on the German market

In brief: Anyone who offers a model containing memorised works in Germany communicates those works to the public (Section 15(2) UrhG) – regardless of whether a user actually retrieves them.

This phase is the real innovation of GEMA v Suno. GEMA had primarily relied on the right of making available to the public under Section 19a UrhG. The Chamber rejected this: Section 19a requires access “at a time individually chosen”. Where up to 176 identical prompts are needed to obtain a work, that is not the case. GEMA had stated that it had obtained further infringing outputs, but did not submit them (para. 316).

The alternative claim, however, succeeded. The Chamber found an interference with the unnamed right of communication to the public under Section 15(2) UrhG, which it derives from Art. 3(1) of the InfoSoc Directive in conformity with EU law (paras. 369 et seq.):

  • Act of communication: By offering the model and the application, Suno opens up access to the memorised works. The mere possibility of retrieval is sufficient. As with the right of making available online under Art. 8 of the WIPO Copyright Treaty, what matters is the prior offering, not the actual retrieval (paras. 376 et seq.).
  • Direct, not as an intermediary: Suno does not merely provide infrastructure; through its choice of training data, its training and its architecture, it determines the content of the outputs. The criteria for indirect communication – central role and deliberate intervention – therefore need not be examined; they would in any event be met (paras. 378 et seq.).
  • Knowledge: Memorisation has been known in expert circles at the latest since the 2021 study by Carlini et al. Tutorials explaining how to create cover versions of well-known songs with Suno circulate publicly (para. 382).
  • Public: The service is open to anyone who registers; in 2024 it recorded 2.2 million visitors in a single month. Even if only every fourth or every 176th input produces a substantially similar piece, a large number of persons is reached (paras. 386, 394).

In practice: The infringement thus lies in the offering of the model itself, not only in an individual prompt. The model becomes a publicly accessible repository of works. For enforcement, the decision also points to an evidential line: repeated prompts suffice to prove memorisation (Section 16 UrhG), but not for Section 19a UrhG. Rights holders should therefore document and submit all outputs, not just the most striking one.

Phase 4: Prompt and output

In brief: Outputs in which protected works are recognisable infringe the authors’ rights (Sections 16 and 23 UrhG and Section 19a or Section 15(2) UrhG). For simple prompts, the provider is liable as the perpetrator; only with heavily steering prompts may the user become the perpetrator.

Recognisability: The test is not the overall impression but whether creative elements of the work have been adopted in a recognisable form – even a small part may suffice if it expresses the author’s own intellectual creation (CJEU, Mio; CJEU, Pelham II). For music, what counts is the perception of an average music listener. Since the members of the Chamber themselves belong to this group, the court dispensed with an expert opinion (para. 323). It listened to the recordings and compared transcriptions: in the output for “Atemlos durch die Nacht”, for example, tempo and key are identical, and the entire compositional dramaturgy from pre-chorus to post-chorus is adopted (paras. 326 et seq.).

Liability: For the right of reproduction, the Chamber follows the Federal Court of Justice (Manhattan Bridge, I ZR 112/23) and asks who has control over the act. For simple, open-ended prompts, this is the provider: it selects the training data, trains the model and is responsible for its architecture and for memorisation. The user merely triggers the output (paras. 399 et seq.). Unlike an internet radio recorder, the model is not a mere recording device, and unlike a marketplace operator, the provider bears responsibility for the content. In GEMA v OpenAI, the Chamber had indicated the opposite scenario: where complex steering leads away from the meaning of the works – the example was a 13-part word puzzle – the user may be the perpetrator. Exactly where the line lies remains open.

No exception, no liability privilege:

  • Section 44a UrhG does not apply: temporary storage on edge servers has independent economic significance, because users can listen to the output while it is still being generated (paras. 403 et seq.).
  • 6 DSA does not help: outputs generated by simple prompts are the provider’s own information, not third-party information provided by users (paras. 408 et seq.).
  • Quotation, pastiche, private copying: In GEMA v OpenAI, the Chamber had already rejected Sections 51, 51a and 53 UrhG.

In practice: Output filters and takedown procedures may reduce infringements in the output; they leave memorisation in the model (Phase 2) and the offering of the model (Phase 3) untouched. Whether a prompt was “simple” or “provoking” depends on its content – not on the number of repetitions.

What questions remain open?

None of the decisions discussed is final. The line may still shift in the coming months:

Proceedings Court Case No. Key issue
LAION Federal Court of Justice (BGH) I ZR 281/25 Requirements for a machine-readable reservation; scope of Sections 44b, 60d UrhG
GEMA v OpenAI Munich Higher Regional Court 6 U 3662/25 e Memorisation as reproduction; liability for outputs
GEMA v Suno Munich Higher Regional Court 6 U 2314/26 e In addition: offering as communication to the public; jurisdiction over US training
Like Company v Google CJEU C-250/25 Output, training, TDM and reproduction by the provider (Gemini)
Manchester United Fanatics Klub v Google CJEU C-806/26 In addition: prompt input, consent and opt-out

The two Hungarian references concern the press publishers’ right. However, the interpretation of Arts. 2 and 3 of the InfoSoc Directive and Art. 4 of the DSM Directive at issue there applies to all categories of works. In Like Company, the Grand Chamber held its hearing on 10 March 2026. The Munich Regional Court I considered a reference of its own unnecessary, as the CJEU’s case law on reproduction and communication to the public is settled and the case did not even fall within the scope of the TDM exception (paras. 555 et seq.).

Four points in particular remain open:

  1. Can a venue available only to collecting societies (Section 131 VGG) support the review of training acts in the United States?
  2. Where exactly is the line between a simple and a provoking prompt?
  3. What form must a reservation of rights take to be “machine-readable”?
  4. How many attempts are compatible with making available to the public under Section 19a UrhG?

The next cases are already under way: two children’s book publishers are suing OpenAI before the 42nd Civil Chamber of the Munich Regional Court I – PRH Verlagsgruppe together with Ingo Siegner over “Der kleine Drache Kokosnuss”, and Carlsen Verlag together with Marc-Uwe Kling and Astrid Henn over “Das NEINhorn”. Besides texts, these cases also concern characters and covers.

Frequently asked questions (FAQ)

Is AI training with protected works now prohibited in Germany?

Not all the steps of a training. Collecting and analysing works for a training dataset remains permitted as text and data mining, provided access is lawful and no effective reservation of rights exists. What is not permitted without a licence, according to the Munich case law, is for works to be memorised in the model and to be retrievable again via the model and its outputs.

Does training abroad protect against claims under German law?

Not reliably. If the model is offered in Germany or stored on servers in Germany, memorisation, offering and output are governed by the German Copyright Act. For collecting societies, the Munich Regional Court I has moreover ruled on the training in the United States – under US law and without fair use.

Is a reservation of rights in the legal notice (Impressum) sufficient?

This has not been conclusively settled. According to the Hamburg Higher Regional Court, what matters is that the reservation can be captured and evaluated by machines at the time of use. Until the Federal Court of Justice rules, a combination is advisable: robots.txt, the TDM Reservation Protocol and a clear statement in the terms of use or legal notice, each with a documented date.

Who is liable if a user generates a protected work with a prompt?

For simple, open-ended prompts – such as lyrics, title and genre – the model provider is liable as the perpetrator. If the user steers the result with complex, provoking instructions, the user may become the perpetrator. Anyone who further uses outputs, for example by publishing them, is in any case responsible for doing so.

Is it enough to comply with the AI Act?

No. The copyright policy and the training data summary under Art. 53 of the AI Act are transparency and compliance obligations. They replace neither a licence nor an exception.

Does this only apply to music and lyrics?

No. The standards on reproduction, communication to the public and the TDM exception apply to all categories of works – books, photographs, illustrations, films and software as well as music. The pending actions by the children’s book publishers will show how the courts treat characters and artistic works.

Practical note for rights holders and AI providers

The four-phase model gives both sides a clear framework for assessment: for each phase, it must be asked separately which act is involved and what justifies it.

For rights holders – music publishers, book publishers, picture agencies, film and media companies:

  • Declare reservations of rights in machine-readable form and document the date of the declaration.
  • Test AI models with simple, open-ended prompts and secure all prompts and outputs with date and model version – not just the most striking hit.
  • Consider whether enforcement through a collecting society, which can use the venue under Section 131 VGG, makes sense.
  • Develop licensing models for training and output; as GEMA v Suno shows, a willingness to license can also have procedural effects.

For AI providers and companies deploying models:

  • Check and document the provenance of training data; do not obtain data by circumventing technological measures.
  • Read and respect reservations of rights technically.
  • Take and document measures against memorisation, such as deduplicating training data and testing for regurgitation before rollout.
  • Do not assume that training abroad or compliance with the AI Act replaces a copyright assessment.
  • When procuring AI solutions, agree on contractual indemnities and warranties regarding the chain of rights.

We advise rights holders, publishers, media companies and providers of AI systems on all questions of AI and copyright – from the declaration of reservations of rights, Audits and evidence collection regarding current (and past) models to enforcement and licensing. Please do not hesitate to contact us.

More posts

FOCUS Business recommends LAUSEN as a Top Commercial Law Firm for 2026 in the Media and Press Sector

FOCUS Business recommends LAUSEN as a Top Commercial Law Firm for 2026 in the Media and Press Sector

Re-named a Top Commercial Law Firm We are pleased to have once again been recommended by FOCUS Business: LAUSEN is once again among Germany’s top commercial law firms in the media and press sector for 2026. The survey considers commercial law firms based in Germany. Respondents can recommend up to 20 firms in each of …

Read more
LAUSEN in the Handelsblatt ranking “Germany’s Best Lawyers 2026”

LAUSEN in the Handelsblatt ranking “Germany’s Best Lawyers 2026”

We are pleased to announce that three attorneys from LAUSEN have been recommended in the latest Handelsblatt ranking, “Germany’s Best Lawyers 2026.” The ranking is compiled annually in collaboration with Best Lawyers and is considered one of the most prestigious accolades in the German legal market. These recommendations confirm our firm’s exceptional expertise in the …

Read more
Identifiability in reporting – Objection to the Federal Court of Justice’s overly lenient approach

Identifiability in reporting – Objection to the Federal Court of Justice’s overly lenient approach

In many disputes involving defamation, the question arises: Is the person in question identifiable or not? And: To whom are they identifiable? There are many ways this can manifest: mentioning age, occupation, place of residence, or the name of the company where the person works; using altered names or initials; or publishing a photo showing …

Read more