view all news & events
09/29/2026

AI Flash: What AI start-ups could still clarify before their next review in light of Suno, LAION and the AI Act

Since this summer, several legal questions have become more tangible for AI start-ups. On 31 July 2026, the Munich Regional Court (Landgericht München I) held that the music generator Suno infringes copyright in works from GEMA’s repertoire (case no. 42 O 763/25, not yet final). On 3 September 2026, the German Federal Court of Justice (Bundesgerichtshof) heard the case concerning the creation of the LAION training dataset and intends to deliver its judgment on 17 December 2026 (case no. I ZR 281/25). The transparency obligations under Art. 50 AI Act have applied since 2 August 2026. Products placed on the market from 9 December 2026 are subject to new product liability rules that expressly cover software.

Such topics are therefore likely to come up in due diligence for a financing round, in a customer audit, in a procurement review by a large company or in an exit. We have compiled six questions that an AI start-up should ask itself in advance in order to be prepared for such reviews and negotiations.

 

Were the training data lawfully obtained and licensed?

In the Suno case, the Munich Regional Court did not apply the text and data mining exception in Section 44b of the German Copyright Act (UrhG) to the extent that works had been memorised in the model. According to the judgment, there was also no lawful access, because Suno had downloaded the works from YouTube by circumventing technical protection measures. In the LAION proceedings, the Federal Court of Justice has to decide, among other things, when a reservation of rights is machine-readable. Anyone training on third-party data might therefore be well advised to keep a traceable record of where the data come from and how they were accessed.

Helpful documentation: a register of data sources with access route, licences and terms of use, and documentation of how reservations of rights are observed.

 

Can the model reproduce protected content, and who is liable if it does?

In the Suno case, the court inferred from reproducible outputs that the works were stored in the model and treated this as reproduction under Section 16 UrhG. According to the judgment, simple, open-ended user prompts do not break the attribution to the provider; the position might be different for prompts that deliberately steer the output. The same chamber had already found copyright infringement in November 2025 in GEMA v OpenAI concerning song lyrics (judgment of 11 November 2025, case no. 42 O 14139/24). Whether the higher courts will follow is open. Until then, it might even make sense to test one’s own model specifically for such outputs and to document the results.

Helpful documentation: test logs on the reproduction of training content, a description of the output filters and a procedure for complaints from rights holders.

 

Does the company hold the rights to its code, data and model?

For employees, the economic rights in computer programs generally vest in the employer under Section 69b UrhG. This rule does not, however, apply to code written by founders before incorporation or to work by freelancers and agencies. Here it would need to be checked whether, and to what extent, rights of use were granted. Since a grant of rights is, in case of doubt, limited to the purpose of the contract (Section 31(5) UrhG), express provisions could avoid later doubts. Open-source components and open model weights may bring further licence conditions, for example on redistribution, purpose of use and attribution. Most commentators deny copyright protection for model weights as such; to our knowledge, the courts have not yet decided the question. Contracts and protection as trade secrets under the German Trade Secrets Act (GeschGehG), which requires appropriate confidentiality measures, are therefore likely to carry all the more weight.

Helpful documentation: founder and employment contracts with IP clauses, freelancer agreements, a list of open-source components and models with their licences, and a description of the confidentiality measures.

 

What role and which obligations does the company have under the AI Act?

The obligations depend on whether the company is a provider or a deployer, whether it develops or modifies a general-purpose AI model and which risk category its system falls into. Art. 50 has applied since 2 August 2026. Providers of generative systems placed on the market before that date must implement the machine-readable marking under Art. 50(2) by 2 December 2026. Following the Digital Omnibus, the obligations for high-risk systems under Annex III apply from 2 December 2027. Providers established outside the EU may also need to appoint an authorised representative in the Union: for general-purpose AI models already now (Art. 54), for high-risk systems under Annex III from December 2027 (Art. 22).

Helpful documentation: a classification of role and risk category, evidence of the marking and, where applicable, the technical documentation and the summary of training content.

 

Is the processing of personal data in training and operation secured?

If training data contain personal data, training requires a legal basis. Which one is available depends on where the data come from. For publicly available data, legitimate interests under Art. 6(1)(f) GDPR are likely to be the main option; the European Data Protection Board set out criteria for the balancing test in its Opinion 28/2024. Where the data come from the company’s own users, consent under point (a) or, again, legitimate interests may also be considered. The contract with the user under point (b) is likely to cover training only to the extent that it serves the service for that particular user, not the general improvement of the model. Consent can be withdrawn, and as things stand, individual data can hardly be removed from a trained model in a targeted way. In operation, the contract with the user can cover the processing to the extent that the AI service forms part of the contract. If the start-up processes data on behalf of its customers, the question of the legal basis lies primarily with them. If it also uses the same data for its own training, it pursues, according to a widely held view, a purpose of its own and to that extent acts outside the scope of processing on behalf of its customers.

Helpful documentation: records of processing activities with the legal bases chosen, depending on the basis a legitimate interests assessment or the consent texts, a data protection impact assessment and data processing agreements with clear rules on the use of customer data for training.

 

What do the contracts with customers and model providers provide, and what changes for liability from December?

Many AI products are built on a model from a large provider whose terms largely determine use, liability and changes unilaterally. It might be worth checking whether one’s own customer contracts fit these terms, for example regarding indemnities for infringements caused by outputs, liability caps and commitments on data use. Under Directive (EU) 2024/2853, manufacturers are strictly liable for products placed on the market from 9 December 2026, including defective software and AI systems. This liability cannot be excluded or limited by contract vis-à-vis injured persons. Between businesses, on the other hand, liability arrangements remain possible, for example for recourse within the supply chain. The German implementing act has not yet been adopted.

Helpful documentation: the model providers’ terms of use, template customer contracts and an overview of liability provisions and insurance.

The main open question is whether, on 17 December, the Federal Court of Justice will treat the creation of training datasets as covered by the text and data mining exception or refer questions to the Court of Justice of the European Union. This could determine how robust datasets based on publicly available content are. In a review, the key question is therefore likely to be whether a start-up knows its risks and can show how it deals with them, regardless of whether every legal question has been settled. Compiling the documents listed above now could pay off, also as a basis for negotiations on warranties and indemnities. We are happy to help with questions on individual points.

    Share

  • LinkedIn
  • XING