The Regional Court of Munich has found AI music company Suno liable for using six songs, including “Forever Young” and “Rasputin”, to train its music generator. It reached that result by reasoning that a model which can be prompted into producing a near-copy of a song must hold a copy of it. Lutz Riede and Oliver Talhoff of Freshfields, writing on 7 September, describe the court’s approach as “novel and experimental in many respects”. For the UK, the interesting part is the evidence rather than the verdict. The UK government’s March 2026 copyright report says a model trained abroad could, in principle, be an infringing copy when brought into the UK, but only if the model actually holds a copy of the work in question. Getty Images’ secondary infringement claim against Stability AI failed in the UK for want of exactly that evidence. Munich has now shown one way a court can be persuaded that the evidence exists.
Strategic Insight: UK law does not care where a model was trained if the model itself holds infringing copies and is imported. The open question is proof. A test that infers copies from outputs, if any UK court ever adopted it, would turn a territorial defence into a question about what the model can be made to sing.
What did the Munich court decide?
Filed as 42 O 763/25, the case was brought by GEMA, the German performing rights society, over six works: “Atemlos durch die Nacht”, “Rasputin”, “Big in Japan”, “Forever Young”, “Daddy Cool” and the refrain of “Mambo No. 5”. According to Freshfields, GEMA succeeded on almost every claim it brought under German law, and on the US-law claims concerning training done in America. We reported the ruling in August.
The remedies are broad. Freshfields lists an injunction that covers reproduction during training in the US, “storage” inside the model in Germany, and the public playing of outputs and adaptations there. Suno must account for the infringements and the revenue linked to them, owes damages mostly dating back to 1 July 2023, and must pay for the judgment’s operative part to be printed by the Süddeutsche Zeitung.
| What the judgment involved | Figure |
|---|---|
| Works in dispute | 6 songs |
| Length of the judgment | 137 pages |
| Identical-prompt attempts GEMA needed before the output it relied on | 4 (“Mambo No. 5”) to 176 (“Atemlos”) |
| Damages liability runs from | largely 1 July 2023 |
| Further cases already pending, per Freshfields | at least 2 (children’s book series) |
The court made four findings that Freshfields singles out as contested:
- Jurisdiction over US training. German courts can rule on training that took place only in the US, under US copyright, and can order it stopped.
- US law applies, and it is not fair use. Training in the US is governed by US law, and it is not fair use where copies of the training data end up stored in the model weights.
- Proof by output. A model contains copies of works if those works were in the training data and can be pulled back out through user prompts.
- The provider owns the output. Suno, not the user, answers for infringing songs generated from simple prompts.
The court also held that the EU’s exception for text and data mining did not cover the copies it found inside the model. Those copies served no further analysis, and Suno lacked lawful access to the songs. The court treated getting round YouTube’s “rolling cipher” as getting round a technical protection measure.
Critical Context: This is a first-instance judgment. Freshfields expects the questions to travel up to Munich’s appeal court, Germany’s Federal Court of Justice (BGH) and the EU’s top court, the CJEU. Suno has been ordered to stop; the legal principle is a long way from settled.
Where is the reasoning weakest?
Freshfields’ critique centres on evidence. The judges never commissioned an independent technical expert to examine Suno’s models. It relied on academic literature and on the two parties’ own technical submissions, which the authors say ignores how differently AI model types are trained and run.
The “simple prompt” finding gets the hardest treatment. GEMA prompted with complete song lyrics and, for “Forever Young”, added a style instruction: ”80s, Synth Pop, male voices”. Even so, GEMA needed anywhere from 4 to 176 runs of the same prompt to get the output it relied on. GEMA said the other attempts also infringed but, according to the authors, declined to put them on file. If one prompt can return as many as 176 different outputs, the authors ask, how strong is the inference that a fixed copy sits within the model? The court appears to treat the underlying network as “deterministic”, with the variation introduced afterwards; in their view that finding is thinly supported technically.
The same facts weaken the finding on who is responsible. Detailed prompts, repeated attempts and an apparent intent to produce infringing material point, Freshfields argues, towards a process steered by the user, which would make the user rather than Suno directly liable.
Two other expert gaps follow. The judges declined to appoint a musicologist, reasoning that they belong to the musically informed public, and then wrote detailed passages on arpeggios and chord resolution. Nor did the court appoint an expert on US law before rejecting fair use. It set aside Bartz and Kadrey, the US decisions that treated training as fair use, saying neither involved copies held inside the model.
Reality Check: The authors point out that the UK High Court in Getty Images heard extensive technical expert evidence and concluded the opposite: the model held no copies. The two courts reached different answers on the same factual question, and they reached them by different routes.
The jurisdiction point is the most unusual. Training happened entirely in the US. The court claimed jurisdiction anyway through a German provision that lets collecting societies bundle claims against one infringer before a single court. Freshfields says that rule was written for “travelling infringers” such as touring concert promoters inside Germany, and that the court’s reliance on GEMA’s seat and the mainly German nationality of its authors is weak. Crucially for anyone outside GEMA, the authors note that the provision is not available to other rights holders.
Why does a German case matter to UK rights holders?
Because UK law already contains the hook, and the Getty case showed where it catches.
Copyright is territorial. The UK government’s Report on Copyright and Artificial Intelligence, published on 18 March 2026, notes that large AI firms told the consultation their foundation models are trained abroad, mostly in America. Copies made during that training fall under US law, not UK law.
But the report also sets out the secondary infringement route. Importing an article that is an infringing copy can itself infringe, and an article made abroad counts if making it in the UK would have infringed. In Getty Images v Stability AI, the report says, the High Court accepted that a trained model is capable of being such an article, including one trained overseas. Getty’s secondary infringement claim failed because there was no evidence that Stable Diffusion held any of the works in issue. The report is explicit that “the outcome may be different in other cases, if there is evidence that a model does contain copies of a work”, and that the ruling is under appeal.
The report itself links the two jurisdictions. It cites Munich’s earlier GEMA v OpenAI ruling as finding that a large language model had retained copies of song lyrics, and uses it to underline that the Getty finding turned on its facts.
Strategic Reality: For a UK rights holder, the legal question is already framed: does this model contain a copy of my work? Munich answers it from outputs. The UK High Court answered it from expert evidence on how the model works. Whether a UK court ever accepts output-based proof matters more to UK music publishers than anything Munich decides about US fair use.
There is a caution. Munich’s output test needed 137 pages for six songs. Freshfields argues it will be hard to generate that kind of evidence across a large catalogue, and harder still if providers deploy more reliable output filters. A UK catalogue owner hoping to use the approach would be looking at work by work proof, not a class-wide claim.
What does it mean for UK developers working across both regimes?
The UK’s own data-mining exception does not stretch to commercial training. Section 29A of the Copyright, Designs and Patents Act 1988 permits copies for computational analysis by someone with lawful access, but only “for the sole purpose of research for a non-commercial purpose”. The government’s March report dropped its earlier preferred option, a wide exception that rights holders could opt out of, and said it will not reform copyright law until it is confident any change meets its objectives. We covered that shift in March.
Munich adds three practical exposures for a UK business whose model reaches German users:
- Hosting and output location. Jurisdiction over output and “storage” was straightforward, Freshfields says, because outputs were created in Germany and the model ran on German servers.
- Lawful access. The court refused to apply the EU’s data-mining exception partly because access to the works was not lawful. How training data was collected, not only what it was, now carries legal weight.
- Output liability. The court placed responsibility for infringing output on the provider where prompts were simple and open-ended.
The UK report also reminds UK providers of general-purpose AI that access to the EU market means complying with the EU AI Act, whose transparency rules bind anyone seeking access to that market.
| Stakeholder | What Munich changes | What to watch |
|---|---|---|
| UK music rights holders and collecting societies | A court has accepted output-based proof of copies in a model | Whether the Getty appeal adopts or rejects that kind of evidence |
| UK-based model developers serving EU users | Hosting location, data collection method and output controls all bear on liability | Appeals in Munich and any reference to the CJEU |
| UK businesses using generative music tools | The court placed liability for simple-prompt output on the provider, not the user | Vendor terms on indemnities and output filtering |
| UK policymakers | Another court has found copies retained in a model | The government’s next step after its March report |
How should UK organisations respond now?
💡 Implementation Framework: Preparing for a copy-in-the-model test
Phase 1: Know your exposure (next month)
- Rights holders: list the works most likely to be memorised, such as heavily streamed or widely licensed tracks
- Developers: record where each model is trained, hosted and served, and which users it reaches
- Users: check vendor terms for who carries liability for infringing output
Phase 2: Build the evidence (next quarter)
- Rights holders: if you test models, log every prompt and every attempt, not only the hits
- Developers: document how training data was obtained, including any access controls bypassed
- Both: keep technical evidence that an independent expert could assess
Phase 3: Plan for either outcome (next 12 months)
- Rights holders: prepare licensing offers alongside any enforcement plan
- Developers: test output filters against regurgitation of known works
- Both: revisit positions when the Getty appeal is decided
The logging advice follows directly from Freshfields’ critique. The weakest part of GEMA’s evidence was the gap between 176 attempts and the one output put before the court. A UK claimant would be wise not to repeat that gap.
Priority actions by position
For rights holders and publishers
- Test methodically: Use the simplest prompts that work and keep the full record. Complex, repeated prompting invites the argument that the user, not the provider, caused the output.
- Consider licensing first: The UK report records PRS for Music’s point that AI developers passed on a licensing offer from GEMA, and litigation followed.
- Follow Getty closely: The appeal is the next UK ruling in this area, and the government describes the Getty finding as fact specific.
For UK model developers
- Map your footprint: Treat where you host and serve as a legal decision, not only an engineering one.
- Audit acquisition: The Munich court’s lawful-access finding makes scraping methods a live issue.
- Measure memorisation: Testing for overfitting on well-known works is worth treating as a legal control as well as a quality one.
For businesses deploying AI music and media tools
- Read the indemnity: Check whether your provider accepts liability for infringing output.
- Control prompts: Avoid workflows that feed full lyrics or copyrighted text into generators.
- Keep records: Know which tool produced which asset.
Four problems that remain open
Challenge 1: The ruling may not survive appeal
Freshfields expects the appeal court in Munich, the BGH and the CJEU all to consider these questions. As a lower court, Munich had no obligation to send questions to the CJEU, and the authors suggest it may have missed a chance to add legal certainty by doing so.
Mitigation strategy: Treat Munich as a signal of litigation risk in Germany, not as settled European law.
Challenge 2: Output evidence cuts both ways
The more attempts and detail it takes to extract a song, the easier it is to argue the user caused the infringement.
Mitigation strategy: Rights holders should record the minimum prompt that reproduces a work; developers should record how much effort extraction takes.
Challenge 3: The UK evidence question is unresolved
The first UK ruling on copyright and AI training found no copies in the model, and the government describes that finding as fact specific and under appeal.
Mitigation strategy: Avoid building a UK strategy on either Getty or Munich until the Court of Appeal has ruled.
Challenge 4: UK reform is on hold
The government has dropped its preferred opt-out exception and says it needs more evidence before any reform.
Mitigation strategy: Plan around current law: licences for commercial training done in Britain, and local law wherever training actually happens.
⚠️ Warning: The jurisdiction route that let GEMA reach US training is a German rule for collecting societies. Freshfields says it is not open to other rights holders, so UK claimants should not assume the same route to training done elsewhere is open to them.
The takeaway: the fight is moving to evidence
Munich has not settled whether AI training infringes copyright. It has shown that a court willing to infer copies from outputs can reach training done in another country and impose wide remedies, and Freshfields makes a strong case that the inference was drawn on thin evidence. For the UK the lesson is narrower and more useful. UK law already treats an imported model that contains infringing copies as a problem, wherever it was trained. Whether anyone can prove a model contains copies is the question on which UK exposure now turns.
Three things matter most:
- Proof is the battleground: Output-based evidence persuaded Munich; expert evidence on model internals persuaded the UK High Court.
- Location still matters: Where a model is hosted and where outputs appear shaped jurisdiction in Munich.
- UK policy is waiting: The government has shelved its preferred reform and is watching litigation.
Your next steps
Immediate actions (this week):
- Identify which of your models, or your vendors’ models, serve users in Germany
- Check vendor contracts for output indemnities
- Rights holders: list the works you would test first
Strategic priorities (this quarter):
- Document training data sources and how they were accessed
- Set up a logged, repeatable memorisation test
- Review licensing options alongside enforcement
Long-term considerations (this year):
- Track the Getty appeal in the Court of Appeal
- Monitor the Suno appeal and any CJEU reference
- Watch for the government’s next copyright and AI proposals
Source: AI Training & Copyright Part 3: Recent Case Law by the Regional Court of Munich (“GEMA vs. Suno”) (Freshfields, Technology Quotient blog, 7 September 2026), by Lutz Riede and Oliver Talhoff. UK context draws on the government’s Report on Copyright and Artificial Intelligence (18 March 2026) and section 29A of the Copyright, Designs and Patents Act 1988.
This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching how the Court of Appeal handles the evidence question in the Getty appeal, and whether Suno’s appeal reaches the CJEU. Read more analysis at Insights, or get in touch.