Not without a license, once the model can remember those hits and reproduce them in a recognizable way. That was the ruling of the Munich I Regional Court on July 31, 2026, in the case brought by the German collecting society GEMA (the Belgian counterpart to SABAM) against Suno, the American provider of a popular AI music generator (LG Munich I, July 31, 2026, 42 O 763/25). According to the court, Suno is infringing copyright during model training, through the storage of the songs in the model itself, and through the generated outputs. Furthermore, the ruling has remarkably far-reaching implications: the German court also prohibits Suno from copying the songs in the United States for training purposes.
The facts
GEMA manages the rights of composers, lyricists, and music publishers. It took six well-known songs to court: "Atemlos durch die Nacht," "Daddy Cool," "Rasputin," "Big in Japan," "Forever Young," and the chorus of "Mambo No. 5.".
Suno offers a music generator that, at the user’s request, produces two complete songs in just a few seconds. By May 2024, the service had more than 10 million users; in October 2024 alone, it had 2.21 million visitors. Free users can generate 10 songs per day. A $10-per-month subscription entitles users to 500 songs, and a $30 subscription to 2,000, each with commercial usage rights.
Suno trained its models in the United States using millions of full-length audio recordings, including the six songs. It obtained those recordings from YouTube through a process known as “stream ripping,” thereby circumventing the Rolling Cipher, a technical measure implemented by the platform to prevent the downloading of audio.
To demonstrate the infringement, GEMA employees entered the original song lyrics as a prompt, along with the title and a general style description such as “Schlager” or “80s synth pop.” In total, there were 338 prompts for the six songs: 176 for “Atemlos durch die Nacht,” 124 for “Big in Japan,” and 4 to 14 for the others. The generator produced outputs that closely resembled the originals; GEMA made the audio clips public. She sought an injunction, information, and damages, including for the training activities conducted on U.S. soil.
The ruling
The court granted GEMA virtually everything it sought. Only the claim based on the right of availability was dismissed. The reasoning follows a four-step process.
The reproduction of musical works within the AI model itself
The court first ruled that the six numbers in the design itself were reproduced within the meaning of § 16 of the German Copyright Act (Urheberrechtsgesetz), the implementation of Article 2 of the InfoSoc Directive. The key is memorization: the phenomenon in which a model not only analyzes training data but also encodes it in its parameters so that it can reproduce that data in its output later on.
According to the court, proof of this was provided by comparing the training data with the outputs. Since, in the judge’s view, GEMA’s prompts were simple and open-ended, and since coincidence is ruled out with such complex musical pieces, the similarity could only have come from the model itself. After all, the court held that while lyrics do determine the rhythm of the syllables, they do not determine the melody, harmony, or tempo.
The judge considered it irrelevant that the model does not contain audio files but only parameters and probabilities. He compared the situation to an MP3 file or a progressively saved JPEG: in those cases as well, detailed information is lost and the work is distributed across data structures, and yet a reproduction exists. It is sufficient that the work can be made indirectly perceptible using technical means—in this case, the generator itself. The judge rejected the defense’s argument that a reproduction requires a precisely delimitable, identifiable object: that requirement stems from the Levola Hengelo ruling The Court of Justice's ruling concerns the question of whether a work exists, not whether that work has been reproduced.
The exception for text and data mining does not cover caching
Suno invoked the exception for text and data mining (TDM) under § 44b UrhG, the implementation of Article 4 of the DSM Directive. The court identified three phases: collecting and preparing the training data, actually training the model, and using it through prompts and outputs.
For the first phase, the judge accepted that the TDM exception applies in principle, including to AI training. However, in his view, the reproductions within the model fall outside its scope: the exception covers only copies that serve the automated analysis of information, whereas a memorized work no longer serves the analysis but rather its subsequent reproduction. The judge put it bluntly: if, given the current state of the art, memorization cannot be prevented, then training a model using protected works does not fall under the TDM exception.
A second ground was added. The TDM exception requires lawful access to the work, and that was lacking: Suno obtained the numbers by circumventing YouTube’s Rolling Cipher, an effective technical measure. The transparency policy set forth in Article 53 of the AI Regulation does not grant, according to the judge, a free pass: simply publishing a summary of one’s training data does not constitute a license.
Public communication through the music generator's offerings and outputs
Suno was correct on one point. The making available right presupposes that the public can access the work at a time of its choosing. Anyone who needs up to 176 identical prompts to obtain a single song does not have that freedom of choice, according to the judge. The claim based on that ground was dismissed.
The alternative claim was, however, upheld: according to the court, the availability of the model—which is hosted on edge servers in Germany—and the outputs themselves constitute a public communication under the right of communication set forth in § 15 UrhG, interpreted in light of Article 3 of the InfoSoc Directive. In this regard, Suno acts directly and as the infringer, not the user who enters the prompt: the provider selected the training data, determined the architecture, and was aware of the memorization problem at least since the high-profile study by Carlini et al. from 2021. Regarding the hosting exemption under Article 6 of the Digital Services Act (DSA) Suno cannot invoke this defense, because the outputs are its own content and not information provided by users.
Training in the United States and the fair use test under U.S. law
The most notable part of the ruling concerns the training itself, which took place entirely in the United States. The court also found that it had jurisdiction over this matter, based on the concentration rule in § 131(2) of the German CMO Act (Verwertungsgesellschaftengesetz (VGG)): If multiple courts have jurisdiction over several disputes involving a management company against the same infringer, the company may consolidate all of its claims in one of those courts.
Under the applicable U.S. law, which the court itself examined on the basis of the U.S. Copyright Act, the case law cited by the parties, and the library of the Max Planck Institute in Munich, the downloads and training copies constitute reproductions. The judge rejected the fair use defense on all four factors. In doing so, he explicitly distinguished the U.S. rulings in the cases Bartz vs. Anthropic (N.D. Cal. June 23, 2025, No. 3:24-cv-05417) and Kadrey vs. Meta (N.D. Cal. June 25, 2025, No. 3:23-cv-03417): In that case, no infringing outputs were presented; here, they were. A model that recognizably reproduces the training works is not transformative but provides a commercial substitute. Furthermore, circumventing the Rolling Cipher violates 17 U.S.C. § 1201(a)(1)(A) and weighed heavily as evidence of bad faith.
The judgement is clear. Suno must cease reproduction for training purposes within the United States, subject to a penalty of up to 250,000 euros per violation. In addition, the judgment includes a ban on storing the design and on distributing it in Germany, a duty to provide information effective July 1, 2023, a declaration of liability for damages, the publication of the judgment in a quarter-page notice in the weekend edition of the Süddeutsche Zeitung, and 5,049.70 euros in out-of-court attorney’s fees. The judgment is provisionally enforceable upon posting security of 150,000 euros per prohibited act. Suno has announced that it will appeal, so the judgment is not yet final.
Legal analysis and interpretation
The proof is in the results
GEMA did not have to specify exactly where in the billions of parameters the songs were located. For each song, it presented a single output generated using the lyrics and a style description as a prompt, and the court compared that output note by note with the original. From that similarity, the court inferred that the model had memorized the lyrics. This line of reasoning is at the heart of the judgement and it is consistent with what the same chamber decided late last year regarding song lyrics in ChatGPT (LG Munich I, November 11, 2025, 42 O 14139/24), the case we previously analyzed in our article on the question of whether an AI model itself is an illegal copy.
The German approach remains functional: if the model can reproduce the work in a recognizable way, then the model incorporates the work. The British High Court chosed in Getty Images v. Stability AI Ruling (High Court of Justice, November 4, 2025, [2025] EWHC 2863 (Ch)) the opposite, technical perspective: a model does not store works, only mathematical relationships, and is therefore not itself an infringing copy. This judgement has not bridged the divide in Europe but has deepened it. It is noteworthy, however, that the Munich chamber has provided a more robust foundation for its reasoning this time, including a comparison with lossy compression formats and its own fifty-page musicological analysis of each track, conducted without the assistance of an expert. As long as the Court of Justice has not ruled on the matter, the question of which approach the Belgian court will follow remains open.
A German judge applying U.S. law to U.S. training
The second issue that is raising eyebrows internationally is jurisdiction. The court inferred from a national merger control rule for collective management organisations that it was also authorized to rule on actions that took place entirely within the United States, and then proceeded to apply the U.S. fair use doctrine itself in a ten-page ruling, without consulting a U.S. legal expert. The result is a German ban on copying on U.S. territory.
That is a defensible interpretation, but it is vulnerable. Private international law links the question of infringement to the law of the country in which protection is sought; the question of jurisdiction is distinct from that, and it is precisely that leap from a domestic rule of concentration to global jurisdiction over a foreign defendant that can certainly be called into question. Enforceability is also uncertain: a U.S. judge will not simply enforce a German order regarding conduct in the United States. In practice, the lesson is more modest but realistic: anyone who trains their model outside Europe but offers it in Europe cannot keep European courts at bay.
The bridge between the European and American debates
It is interesting to note how the court does not ignore U.S. case law but rather incorporates it. In the case of Bartz v. Anthropic, the judge described the training of a language model as “spectacularly transformative,” and that case has since been settled with a $1.5 billion settlement approved on July 20, 2026. In the Kadrey v. Meta case, the service provider prevailed because the outputs reproduced no more than fifty words from the books. The Munich court has reversed those findings: as soon as the output substantially resembles the training material, the transformative nature of the work ceases, and the fair use balance shifts.
Thus, both legal systems converge on one point: the dispute is resolved based on the output, not on the abstract question of whether training is permitted. From now on, the same practical test applies to the TDM exception in the European Union and to fair use in the United States: if the model can recognizably reproduce the works on which it was trained, a license is required. The directive to developers, therefore, is not “do not train,” but “ensure that your model does not mimic its sources.”.
Specifically, what does this mean?
For AI developers. Anyone who trains generative models on protected content cannot comfortably rely on the TDM exception in the EU once the model is capable of memorizing information. In Belgium, this exception is set forth in Article XI.190, 20° of the Code of Economic Law (CEL), with the same requirements for lawful access and respect for a machine-readable opt-out. The origin of the training data is a sticking point in itself: anyone who circumvents technical measures such as the Rolling Cipher forfeits both the European exception and, according to this ruling, any goodwill in the fair use assessment. Those who wish to manage this risk should obtain licenses or incorporate demonstrable caching filters and document them.
For authors, publishers, and copyright management organizations. GEMA’s evidence strategy is replicable: simple, open-ended prompts, a systematic comparison of the output and the original, and the publication of the excerpts. Anyone wishing to protect their repertoire must also formulate an explicit and machine-readable reservation under Article XI.190, 20° of the WIPO Copyright Treaty, because without a valid opt-out, the first training phase remains, in principle, permitted. The negotiating position for licenses regarding AI and copyright has been reinforced once again by this ruling; GEMA now offers its own paid music database that models are permitted to use for training.
For businesses that use AI-generated music. The output of a music generator may constitute an infringing adaptation of an existing song, even if that was not the user’s intention. The commercial usage rights granted by the provider under the contract do not protect against the rights of third parties. Anyone using AI-generated music in advertisements, videos, or podcasts would be wise to verify its origin and any similarities, negotiate contractual indemnities, and, when in doubt, seek assistance from a attorney specializing in copyright law.
Frequently asked questions (FAQ)
Does training an AI model using music fall under the exception for text and data mining?
Partially. According to the Munich I Regional Court, the TDM exception does cover the copies necessary to collect and analyze the training data, but not the permanent storage (memorization) of the works in the model itself. Furthermore, the exception does not apply if the training data was obtained without lawful access—for example, by circumventing technical protection measures—or if the rights holder has provided a machine-readable opt-out.
Does this German ruling also apply in Belgium?
Not directly, but it does carry weight. The court applies European directives (the InfoSoc Directive and the DSM Directive) that have been transposed into Belgian law in the WER, including in Article XI.165, § 1 (right of reproduction) and Article XI.190, 20° (TDM exception). A Belgian judge is not bound by this reasoning but will take it into account, just as the opposing British ruling in Getty Images v. Stability AI was considered. Furthermore, the judgment is not final: Suno has filed an appeal.
Can I use music created by an AI generator for commercial purposes?
The provider’s license grants you rights only with respect to the provider itself. If the output bears a recognizable resemblance to an existing protected song, the copyright holder of that song may take action for infringement, including against the user who is exploiting the excerpt. Therefore, check for similarities with existing repertoire and request contractual indemnities from the provider.
Conclusion
The ruling by the Munich I Regional Court reaffirms the German legal position following the case against OpenAI and extends it to music: an AI model that memorizes and recognizably reproduces protected songs is itself a reproduction, falls outside the TDM exception, and requires the provider to obtain licenses. A new and controversial development is the transatlantic reach of the ruling, in which the German court also prohibits the U.S. training after conducting its own fair use analysis. For Belgium and the rest of the EU, where the same harmonized copyright law applies, the message—pending the appeal and the ruling of the Court of Justice—is already clear: anyone who trains or feeds generative AI with protected repertoire would be wise to rely on licenses rather than exceptions.



