On 31 July 2026, the Munich District Court (Landgericht München I) decided the first European case on a generative AI music tool (case no. 42 O 763/25). The court largely followed the claims of the German collecting society GEMA against the US provider Suno Inc. It prohibited four acts in relation to six musical compositions: reproduction for training purposes in the United States, reproduction through memorisation in the model in Germany, communication to the public through the offering of the model, and reproduction and communication to the public through the outputs. It based its jurisdiction over the US training on a venue rule for collecting societies, applied US copyright law to those acts and rejected fair use. It also ordered Suno to disclose the scale of its use and found it liable in damages. The judgment builds on the reasoning the same chamber developed in GEMA v OpenAI in November 2025 in relation to a text-to-text tool, now applying it in a song lyrics to music context. Suno can appeal to the Munich Court of Appeal.
What was the case about?
GEMA is the German collecting society for musical works. It sued Suno, the Delaware-based provider of a music generator that turns short text prompts into playable audio, after a licensing request went unanswered.
Six compositions from its repertoire were at issue: “Atemlos durch die Nacht”, “Daddy Cool”, “Rasputin”, “Big in Japan”, “Forever Young” and the refrain of “Mambo No. 5”. Unlike in GEMA v OpenAI, the lyrics were not part of the claim, and no performers’ or phonogram producers’ rights were asserted. GEMA sought injunctive relief against four types of copyright-relevant act, plus information and damages, both limited from the outset to four of the six works.
Much of the technical background was undisputed: Suno trained its models in the United States on millions of complete recordings, including the six works, obtained from YouTube by stream-ripping (circumventing the platform’s “Rolling Cipher”, a download restriction). Suno combined the audio files with metadata (i.e., title, genre, lyrics) into bundles, tokenised them (broke them into small, purely numeric units) and trained the model’s parameters on them. This encoding involves quantisation: the values are rounded to a limited set of levels, a deliberate compression that makes the data compact enough to train on. Because that step discards fine detail, the recordings themselves are not contained in the finished model, which holds only its trained parameters (the weights).
That model is stored on servers in Germany (Suno’s later denial was disregarded as filed out of time) and outputs are cached only briefly on edge servers, kept close to users for fast streaming. GEMA’s exhibits used only the lyrics, a style tag and the title – nothing on melody, harmony, rhythm or arrangement – with each identical prompt repeated between 4 and 176 times.
GEMA argued that the outputs proved the fixation of the six works in the model itself: neither chance nor steering prompts explained the resemblance, and the lyrics shaped only the syllable stress, not the music. Suno denied any storage: the parameters held only mathematically learned patterns and could not hold even 1% of the training data. Any resemblance was the user’s doing (GEMA’s 338 prompts, entered with full lyrics), so responsibility lay with the user. Suno further relied on the EU text and data mining exception and US fair use and challenged the court’s jurisdiction over its US activities.
The court largely sided with GEMA. In detail:
Is a work memorised in an AI model a reproduction?
The court found: Yes. Following the computer-science literature in evidence, it held that a model memorises a work where its parameters take over more than the patterns and correlations a model normally extracts — at least part of the content itself (para. 243 et seq.). An exact copy is not required, because audio models discard detail by design: what matters is not how much of a work is taken over, but what. That relaxes GEMA v OpenAI, where lyrics had been described as taken over “completely” (GRUR-RS 2025, 30204, para. 183 et seq.). Suno’s capacity argument did not persuade the court: GEMA never claimed the model stores all training data, only these six works, and memorisation research links retention to how often a work appears in the training set – a mechanism Suno itself had described for popular songs.
According to the court, the comparison of works with outputs proved memorisation. GEMA’s prompts were simple and open-ended: lyrics, style and title only, leaving melody, harmony, rhythm and tempo to the model. A text requires prosodic compatibility (a stressed syllable must fall on a stressed beat), but that governs how notes are allotted to syllables, not the shape of the melody – the same text could be set to entirely different music. If the output nevertheless reproduced the melody of the original, that music could only have come from the model itself. Suno countered that GEMA had provoked the outputs. Steering, in the court’s view, means evaluative or suggestive prompts that push the model towards a particular result; repeating an identical prompt does not steer, it reasoned, because input, parameters and the resulting probabilities stay the same. With chance and steering both excluded, one output per work sufficed, and the court refused an expert opinion, since Suno had neither engaged with the studies in evidence nor offered an alternative explanation.
On the law, the court applied its OpenAI reasoning from text to music and confirmed an act of reproduction. The works are embodied in the specified parameters, which sit on servers, and fixation in probability values is a reproduction “in any form” under Article 2 of Directive 2001/29/EC on the harmonisation of certain aspects of copyright and related rights in the information society (“InfoSoc Directive”) and Sec. 16 German Copyright Act (Urheberrechtsgesetz, “UrhG“). The court compared the model to a progressively stored JPEG file, in which information is scattered, and the lossy character of the storage to an MP3 file, which also retains only what human senses perceive (para. 268 et seq.). It also rejected Suno’s objection that a reproduction presupposes a stable, addressable storage state, accessible independently of context and repeatable — a condition it found satisfied given full access to the model’s parameters. Repeatable rendering is in any event not a condition of the reproduction right (para. 279).
Did the text and data mining exception cover Suno’s training?
The court said: In principle yes, in this case no. The court first held Sec. 44b UrhG applicable to (Gen)AI training at all, relying on Recitals 18(1) of Directive (EU) 2019/790 on copyright and related rights in the Digital Single Market (“DSM Directive”), which call for the exception to accommodate new technologies, on the CJEU’s technology-neutral approach (C-433/20, para. 26 – Austro-Mechana) and on the German legislator’s reference to machine learning as a base technology for AI (BT-Drs. 19/27426, p. 60). The court also ruled on how far the exception reaches: Analysis itself is not copyright-relevant; what it covers are the copies that analysis requires, e.g., format conversion and back-ups made in assembling the training corpus (para. 285 et seq.). However, GEMA’s memorisation claim did not cover these preparatory acts, which were carried out in the United States.
The text and data mining exception, the court found, did not cover reproductions inside the model (para. 294 et seq.). Text and data mining aims at the evaluation of information, it explained, and the statistical patterns a model learns are exactly that. Memorisation went further: the works were not merely analysed but taken over into the parameters, so the premise the exception rests on – that analysis leaves the author’s own exploitation untouched – no longer holds. The court also rejected applying the exception to memorisation by analogy. It reasoned that since the exception offers no remuneration, such an extension would leave authors unprotected – contrary to Recital 17 of the DSM Directive – and the memorisation risk falls solely on the provider. The court added a point with wide reach: if current technology cannot prevent memorisation, training on protected works is entirely excluded from the exception. A business model that helps itself to the intellectual property of others free of charge is, in the court’s words, unknown to both EU and German law (para. 304 et seq.).
Furthermore, the court found the text and data mining exception also failed for lack of lawful access: access is lawful where a work is freely available online or licensed, under Recital 18(2) sentence 1 of the DSM Directive, not where access barriers are overcome. On YouTube the six works could be listened to, but the Rolling Cipher exists precisely to prevent the downloading that goes beyond listening. It is therefore an effective technical measure under Sec. 95a UrhG, and by defeating it Suno obtained access to download the works unlawfully (para. 308 et seq.).
Finally, the court rejected Suno’s argument that compliance with the AI Act (Regulation (EU) 2024/1689) could serve as a justification: AI Act compliance and copyright compliance are strictly separate. Article 53(1)(c) refers to copyright law rather than defining its scope (Recital 108), and the training-data summary under Article 53(1)(d) exists to help rightsholders enforce their rights, not to replace licences (Recital 107) — Suno’s reading, the court noted, would turn a transparency duty into an immunity (para. 300 et seq.). The Code of Practice itself states that adherence “does not constitute compliance with Union law on copyright” (para. 303).
Does offering the model itself infringe?
The court confirmed an infringement and held Suno directly liable for it.
First, the making-available-to-the-public right (Sec. 19a UrhG) failed on the evidence: where up to 176 identical prompts precede a matching output, users do not access the work at a time of their choosing (para. 315 et seq.). GEMA had asserted further infringing outputs, the court noted but did not put them in evidence. The claim succeeded instead on the unnamed right of communication to the public (Sec. 15(2) UrhG, Article 3(1) InfoSoc Directive), the statutory list of exploitation rights being illustrative, not exhaustive. Offering the model holds the memorised works ready for retrieval through the user interface, and the act is complete once access is enabled; actual retrieval is unnecessary (para. 369 et seq.).
On attribution, the court rejected Suno’s argument that it merely acts as an intermediary. Doctrinally, criteria like ‘central role’ or ‘intent’ merely extend liability to indirect infringers; once direct use is established, it explained, they need not be examined at all (para. 372 et seq.). Suno crossed that line because it is responsible for content emerging from open-ended prompts and exercises decisive influence over outputs through its training and infrastructure (CJEU C-426/21, para. 66 – Ocilion). Alternatively, the court examined the platform criteria and found them satisfied: a ‘central role’ stems from Suno’s control over model functionality, training data and design; ‘intent’ derives from algorithmic control, requiring no knowledge of specific works (CJEU C-188/24 & C-190/24, para. 109 et seq. – WebGroup Czech Republic), reinforced by established memorisation research and public cover-generation tutorials (para. 381 et seq.).
Read together, these findings leave a door open. The finding of a direct infringement rests on two cumulative conditions: the works are memorised and they surface on open-ended prompts. A provider whose model does not memorise, or whose infringing outputs appear only on steering prompts, would fall outside this reasoning and would have to be assessed under the intermediary framework instead, with central role and intent established separately. Whether that route is practically available depends on circumstances a provider can barely control in advance, and the same judgment places the risk of memorisation squarely in the provider’s sphere. The line between open-ended and steering prompts looks set to become the field on which future cases are fought.
Finally, neither did Article 6 of the Digital Services Act (Regulation (EU) 2022/2065) (“DSA”) shield Suno. The privilege covers only user-stored content, not a provider’s own, and turns on whether the provider’s role is purely passive or active (CJEU C-682/18 and C-683/18, para. 106 – YouTube and Cyando). Suno failed that test: it offers the model and the application together and created the outputs itself on simple, open-ended prompts, so they count as its own information rather than third-party content it merely conveys (para. 408 et seq.).
Who is responsible for infringing outputs: provider or user?
The court held the AI provider responsible for the output, which was reproduced and communicated to the public in Germany.
First, the court held the outputs recognisably reproduce the works, applying the CJEU’s Mio standard: comparing the details but not the overall impressions (CJEU C-580/23 and C-795/23, paras. 85–87 – Mio). Judging from an average listener’s perspective, the chamber refused an expert opinion and compared the works note-by-note (para. 321 et seq.). For ‘Atemlos durch die Nacht’, it found the output appropriated both the melody and the defining compositional dramaturgy, with the other five works following the same pattern.
The outputs also infringed the unnamed right of communication to the public (Sec. 15(2) UrhG), and here too the court found that Suno acted directly: the outputs trace back to systemic causes, and their content is attributable to it as provider of the models. The audience was public in both the quantitative and the qualitative sense — the generator is open to anyone who registers, drawing 2.2 million visitors in a single month of 2024, and its users are a new public. The repeated prompts did not defeat that: even if only every fourth or 176th input yields a substantially similar track, a public is still reached (para. 389 et seq.).
Regarding reproduction, the court held Suno retains control over the copy. It reasoned that users merely trigger outputs via open-ended prompts, which does not shift authorship. Suno is neither a mere recording device where the user makes the copy (BGH I ZR 14/21, para. 29 – Internet-Radiorecorder II), nor a passive sales platform (BGH I ZR 112/23, para. 72 – Manhattan Bridge). The court added this aligns with the EU attribution standard (CJEU C-426/21, para. 46 – Ocilion). Consequently, it concluded the private copying exception is wholly inapplicable, as the provider itself (commercially) produces the copy (para. 399 et seq.).
Finally, the court found temporary copies on edge servers and in working memory failed under Sec. 44a UrhG for two independent reasons. First, they hold independent economic significance by enabling profit-increasing instant playback. Second, they lacked a lawful statutory purpose, as the copies circumvented a Rolling Cipher and accompanied infringing outputs (Recital 33 InfoSoc Directive).
Why could a German court rule on training in the US?
The extraterritorial limb of the injunction has no direct precedent, and the court reached it in two steps: First, jurisdiction for the domestic acts followed from Sec. 131(1) of the German Collecting Societies Act (Verwertungsgesellschaftengesetz, “VGG“) with Sec. 32 of the German Code of Civil Procedure (Zivilprozessordnung, “ZPO“), read as conferring international jurisdiction under the principle of double functionality. Second, the concentration rule of Sec. 131(2) VGG then drew the US training into that same court: a collecting society may bring all claims against one infringer before any court competent for them. That rule is double-functional, the court held – it confers international jurisdiction rather than presupposing it. A sufficient domestic connection existed anyway: GEMA’s seat, mostly German authors, and a close link between the domestic and foreign acts.
Three limits deserve attention: (1) The gateway only serves collecting societies. (2) At least one place of infringement must lie in Germany. (3) Recognition and enforcement of the German title in the United States remain open questions which the judgment does not address.
Did the training in the United States infringe under US law?
The court applied US law, affirmed the protection of the works, and found an infringement.
For the US training, Article 8(1) Rome II pointed to US law under the country of protection principle (Schutzlandprinzip); GEMA’s standing, by contrast, rests on its contracts with the authors and so on German law (Article 4(2) Rome I). Evidence was assessed under the German lex fori, and the court refused Suno’s application for an expert on US law, researching the Copyright Act and the US case law itself — German courts establish foreign law of their own motion, much like a question of fact (para. 420 et seq.).
On that footing it affirmed the basics: the works are original under the low threshold of 17 U.S.C. § 102(a), no higher than under EU law, so the earlier findings carried over (para. 430 et seq.). Suno’s downloads, format conversions and back-ups are reproductions under 17 U.S.C. §§ 106(1) and 101, including intermediate copies (Sega v. Accolade). The court left open whether the model weights encode further reproductions, rejected the de minimis defence, and found the US substantial-similarity test and the CJEU’s recognisability standard to reach the same result (para. 488 et seq.).
With reproduction established, everything turned on Suno’s fair use defence, which the court dismissed. Under 17 U.S.C. § 107 four statutory factors are weighed together, with the burden on the defendant. The decisive comparison, the court held, was with Bartz v Anthropic and Kadrey v Meta (both N.D. Cal. 2025), where the training material never reappeared in the outputs — as Bartz put it, “if the outputs seen by users had been infringing, Authors would have a different case” (para. 463 et seq.). The court found that no factor favoured Suno.
Purpose and character: the use was not transformative, since a model that memorises a work and regenerates it transforms nothing; it was commercial; and circumventing the Rolling Cipher breached 17 U.S.C. § 1201(a), which the court weighed as bad faith. It may be fair use to copy from a book to write a review, it observed, but not to steal the book to make the copy (para. 483 et seq.).
Nature of the work: this factor favours a user who takes mainly facts or ideas, as in reverse engineering; the six songs, however, sit at the creative core of copyright, and what Suno took was their expression.
Amount used: it copied them in full, and the outputs reached the public, unlike the internal snippets in Google Books.
Market effect: Suno argued GEMA first had to show actual losses; the court held the opposite — the burden of disproving market harm lay with Suno, and it rejected any German-style secondary burden requiring GEMA to disclose revenue figures. Substantially similar outputs, free on the entry tier, substitute for the originals (para. 519 et seq.).
What comes next?
The judgment is not final. An appeal looks likely, focused on the extraterritorial limb, the memorisation standard and the 176 prompts. The text and data mining exception is also pending before the BGH (LAION, I ZR 281/25) and the CJEU (Like Company v Google, C-250/25, AG opinion due 3 September 2026), though Munich saw no need to refer its own case. Meanwhile, the US proceedings continue and licensing deals are reshaping the market. Whether Suno versions beyond v3.5 and v4 fall within the injunction is left for enforcement.
Annex – At a Glance:
Four Acts of Use:
| Infringing act | Granted on | Rejected / not reached | Defences — all rejected | Law (Motion) |
| ①TRAININGReproduction for training — USA | 17 U.S.C. §§ 106(1), 101Downloads, conversions, back-ups — including intermediate copies (para. 427 et seq.) | Weights as reproductions: left open. | ✗ Fair use — all 4 factors fail (para. 479 et seq.)✗ Rolling-Cipher circumvention = 17 U.S.C. § 1201(a), bad faith (para. 509 f.)✗ No jurisdiction (§ 131 VGG) | US lawArt. 8(1) Rome II (para. 420 et seq.)(Motion 1 a) aa)) |
| ② MODELReproduction by memorisation — Germany | Sec. 16 UrhG / Art. 2 InfoSoc DirectiveWorks fixed in the parameters (para. 263 et seq.) | ✗ Sec. 44b TDM — corpus yes, specific model no (para. 285 et seq., 294 et seq.); no lawful access (para. 308 et seq.)✗ AI Act Art. 53 — transparency ≠ licence (para. 300 et seq.) | German law(Motion 1 a) bb)) | |
| ③ OFFERINGCommunication to the public — Germany | Sec. 15(2) UrhG / Art. 3(1) InfoSoc DirectiveUnnamed right — offer complete once access enabled (para. 369 et seq.) | Sec. 19a UrhG fails | ✗ “Mere intermediary” — acts directly (para. 372 et seq.); central role + intent anyway (para. 381 et seq.)✗ Art. 6 DSA — own content (para. 408 et seq.) | German law(Motion 1 b)) |
| ④OUTPUTSReproduction & communication — Germany | Sec. 16, 15(2), 23 UrhGWorks recognisable in outputs — CJEU “Mio”, average listener (para. 321 et seq.) | Expert refused — the chamber is the average listener. | ✗ Sec. 53 private copying (para. 399 et seq.)✗ Sec. 44a temporary copies — own economic value (para. 403 et seq.)✗ “User did it” | German law(Motion 1 c)) |
Error! Filename not specified.Memorisation and Lawful Access under Sec. 44b UrhG: The court held that fixing a work within a model’s parameters constitutes a reproduction under Sec. 16 UrhG. It substantiated this finding by comparing the original works with outputs generated from open-ended prompts. Furthermore, the court ruled that the text and data mining exception under Sec. 44b UrhG covers the training, but not the memorisation of works in the specific model itself. Crucially, it determined that if memorisation cannot be prevented, the exception does not apply at all. Because the works were stream-ripped in circumvention of YouTube’s Rolling Cipher, the court found that lawful access was absent.
Direct Liability and the DSA Hosting Privilege: The court found the AI provider to be a direct infringer. It reasoned that because the memorised works surface in response to simple, open-ended prompts, the outputs must be legally attributed as the provider’s own content, precluding any reliance on the DSA hosting privilege. The court noted that these conditions are cumulative; its reasoning implies that a model that does not memorise and that solely infringes based on highly specific steering prompts, could instead be assessed under the intermediary liability framework.
Rejection of the US Fair Use Defence: Applying US copyright law directly, the chamber rejected the fair use defence across all four factors. The court distinguished this scenario from US precedents like Bartz and Kadrey based on a single factual distinction: unlike in those cases, the training material here resurfaced in the generated outputs.




