Summary
On 31 July 2026, the Munich Regional Court (Landgericht München I) ruled that US-based Suno Inc. infringed copyright by training its AI music generator on six protected works without a licence and by reproducing them in outputs. The 42nd Civil Chamber found the songs were memorised in model weights hosted on German servers, rejecting Suno’s fair-use and text-and-data-mining defences. The decision confirms that a rightsholder opt-out under EU law extinguishes the TDM exception and that reproduction occurs both at the training stage and when the model generates output in Germany.
The Event
GEMA, the German collecting society, filed suit in January 2025 (case ID: 42 O 763/25) seeking cease-and-desist, disclosure, and damages. The chamber, presided over by Judge Elke Schwager, heard the case in March 2026 and postponed judgment from 12 June to 31 July. The court ordered Suno to stop unauthorised reproduction of the six works, to stop using them to train its model, to disclose revenue connected with the infringement, and to pay damages in an amount not yet determined. The judgment is not yet enforceable.
The six works are ‘Daddy Cool’ (Frank Farian), ‘Rasputin’ (Farian, Fred Jay, George Reyam), ‘Forever Young’ and ‘Big in Japan’ (Marian Gold, Bernhard Lloyd, Frank Mertens), ‘Atemlos’ (Kristina Bach), and ‘Mambo No. 5’ (David Lubega, Christian Pletschacher). GEMA documented that prompting Suno produced audio matching the melodies, harmonies, and rhythms of those works. The court accepted that the similarities were too extensive and specific to be coincidental and that the works were reproducibly contained in Suno’s models v3.5 and v4, stored on servers in Germany.
The court held that Suno used “stream-ripping” techniques to extract the works from YouTube, circumventing a technical protection measure called the “rolling cipher.” It found infringement of the reproduction right under German law both for the training conducted in the US and for the reproduction in the model and communication to the public in Germany. The court asserted jurisdiction over the US training activity through a special rule in Germany’s Collecting Societies Act (VGG).
Context
Suno argued the works were not protected by copyright, that training was covered by US fair use, and that its model stored only mathematical patterns, not copies. Under EU law, it invoked the text-and-data-mining exception in the EU Copyright Directive. GEMA had exercised the directive’s opt-out mechanism, expressly excluding its repertoire from TDM use. The court ruled that the opt-out extinguished the exception, leaving Suno without a defence under German law. The ruling also rejected Suno’s characterisation of model weights: the court found that memorisation meant the works were effectively stored and could be extracted, making the model itself a vehicle for reproduction.
This is GEMA’s second AI copyright win, following a 2025 judgment against OpenAI concerning unlicensed lyrics. GEMA’s CEO, Dr Tobias Holzmüller, stated that “AI models built on stolen intellectual property have no protection under the law” and that providers must pay for licences. Suno responded that the ruling “rests on a fundamental mischaracterization of how Suno’s technology works” and is evaluating appeal.
Implications
The ruling separates the EU liability pathway from the US fair-use analysis. In the US, Suno’s pending case with Universal Music Group and Sony Music (Warner Music Group settled in November 2025) will turn on whether training is transformative. In Germany, the question is narrower: did the rightsholder opt out of TDM, and did the model memorise protected material? For IP owners, the practical consequence is that an opt-out is not a formality—it is a jurisdictional switch that can determine the entire liability outcome in the EU.
For Korean companies that operate AI training pipelines or deploy generative models in Europe, the decision carries a concrete warning. A Korean AI developer that scrapes or ingests protected content—music, images, or text—and deploys a model on EU-hosted servers faces exposure even if training occurred elsewhere. The VGG jurisdictional hook means a collecting society or rightsholder can sue in Germany for acts of reproduction that took place outside the EU, provided the model is accessible in Germany. Korean filers who are rightsholders benefit from this low jurisdictional bar; those who are AI developers must treat it as a new litigation risk.
One immediate action: a company training generative models on third-party data should run a technical audit to detect memorisation of protected works before EU deployment. If the model can regenerate identifiable fragments of training data, the risk of a successful reproduction claim in Germany is high. For rightsholders, the action is to file a formal, machine-readable opt-out under Article 4 of the EU DSM Directive and to monitor outputs from commercial AI services for evidence of memorisation. GEMA’s method—prompting with lyrics, style, and title—provides a template for evidence gathering.
In Korean practice, the added-matter bar under Article 47(2) of the Patent Act is not directly analogous, but the procedural lesson is parallel: a technical record of what entered a system and what it produces can determine liability. Korean companies managing global IP portfolios should treat EU opt-out registrations with the same formality as priority document filings—missing one can forfeit a legal position before litigation begins.
Outlook
Suno is likely to appeal. The judgment is not enforceable pending any appeal, and the damages amount remains undetermined. The US case, UMG v. Suno, is scheduled for oral argument in the coming months and will test fair use on a different legal standard. A US finding of fair use would not disturb the Munich ruling but would create a split that forces AI companies to maintain jurisdiction-specific compliance architectures.
The EU AI Act applies from August 2026 and will layer regulatory obligations on top of copyright liability. The Munich ruling gives regulators a judicial foundation to require transparency about training data. In the meantime, companies deploying generative AI in the EU should isolate training datasets and model versions by jurisdiction. If a model trained on unlicensed data cannot be replaced immediately, legal and engineering teams should prepare a disclosure and licensing position before receiving a cease-and-desist order. For Korean conglomerates with EU-facing AI products, the hedge is to commission a privileged memorisation audit now, while the appeal is pending, so that exposure is quantified before the legal framework hardens further.
Sources