On July 31, 2026, the Munich Regional Court I ruled that six protected musical works were reproducibly contained in Suno's v3.5 and v4 models, which the court said were stored on servers in Germany. The court treated that model-side memorization as reproduction under German copyright law and separately found infringement when generated outputs made original musical features recognizable.
That is a consequential holding, but it is narrower than the slogan that "AI model weights are copyrighted copies." The judgment concerned identified works, identified Suno model versions, reproducible outputs, German acts of exploitation, and a specific evidentiary record. It was a first-instance decision and was not final when announced.
The most useful way to read the case is as a four-layer decision: training copies made in the United States, work-specific memorization inside models used in Germany, generated outputs, and the territorial rules governing jurisdiction and remedies. Collapsing those layers produces a much broader claim than the court made.
What the court actually decided
The official court press release identifies case 42 O 763/25 and six works represented by GEMA. This analysis is based primarily on that release; a full judgment with the complete reasoning and operative order was not publicly verified at publication time.
- Atemlos durch die Nacht
- Rasputin
- Big in Japan
- Forever Young
- the refrain of Mambo No. 5
- Daddy Cool
The dispute concerned musical works, not song lyrics. According to the court, simple prompts containing the original lyrics, desired style, and song title could repeatedly produce outputs whose melody, harmony, rhythm, and arrangement corresponded substantially to the originals. The court concluded that the works had been memorized and were reproducibly contained in Suno's v3.5 and v4 models.
The holding had two distinct reproduction theories:
- Model-side reproduction. The protected works were embodied in the models in a form from which they could be reproduced.
- Output-side reproduction and communication. Generated audio made protected elements recognizable and was made available through the service.
The court attributed both layers to Suno as the provider. It did not accept the idea that the user's prompt alone severed the provider's responsibility.
Layer one: training in the United States
Suno said the training process occurred in the United States, so the court applied US law to those alleged training reproductions. This territorial step matters: German copyright law did not automatically govern every technical copy simply because the resulting service was later accessible in Germany.
The court nevertheless rejected Suno's fair-use defense on the record before it. It distinguished US cases such as Bartz v. Anthropic and Kadrey v. Meta because those proceedings did not involve the same evidence of substantially similar generated outputs. The Munich court saw output similarity as evidence that weighed heavily against fair use.
This does not establish a universal US rule. A German trial court's application of US law is neither a binding US precedent nor a replacement for the fact-specific four-factor analysis performed by US courts. Its importance is practical: a European court may need to classify foreign training acts separately from domestic model deployment and output delivery.
Layer two: memorization inside the model
The novel center of the case is the court's treatment of the trained model itself. It reasoned that the six works were reproducibly contained in Suno's model because sufficiently directed prompts could repeatedly elicit recognizable musical material.
This is not the same as saying that a model stores a conventional audio file, or that every parameter can be mapped to a note. Copyright reproduction can be technologically neutral. The legal question is whether a protected work is fixed in a form from which it can be perceived or reproduced, directly or indirectly. The court inferred that condition from reproducibility.
That evidentiary route suggests a useful distinction:
| Claim | What the ruling supports | What it does not establish |
|---|---|---|
| A protected work can be reproduced from model state | Yes, for the six works and tested Suno versions | That every trained model contains every training work |
| Model parameters can qualify as a reproduction | Yes, where work-specific content is reproducibly embodied | That weights are categorically copyrighted copies |
| Similar output is evidence of memorization | Yes, on this record | That one coincidental similarity proves storage |
| Technical opacity defeats copyright analysis | No | That courts can ignore technical causation or alternative explanations |
The distinction is central for machine-learning evidence. A plaintiff still needs to connect a particular protected work to the model and exclude explanations such as commonplace musical elements, prompt injection of the work itself, post-processing, or chance. Repeatability, prompt sensitivity, similarity across protected elements, and access to the training corpus can strengthen that connection.
Layer three: generated outputs
The court also found that the generated tracks reproduced protected elements and that making them available through Suno infringed the right of communication to the public. This layer is more familiar than the model-weight theory: copyright has long compared an accused output with protectable expression in an earlier work.
Still, the prompt facts need care. The prompts were not purely generic requests such as "make a disco song." They included the original lyrics, title, and desired style, although they did not specify melody, harmony, rhythm, or arrangement. The court still characterized them as simple and open-ended. Those details help explain the attribution analysis, but they also limit how far the result can be generalized to ordinary prompting.
The court found that recognizable melody, harmony, rhythm, and arrangement mattered. It did not decide that a style alone is protected. Nor did it establish that any song sounding reminiscent of a famous artist infringes. The legal comparison remains work-specific and focuses on protected expression rather than abstract genre or mood.
Layer four: jurisdiction, remedies, and territoriality
The court accepted international jurisdiction under the special venue available to collecting societies and evaluated different acts under the law of the place where each alleged infringement occurred. It applied US law to US training and German law to model and output uses in Germany.
That separation is a template for future cross-border AI disputes. One model lifecycle can generate several legally distinct events:
corpus acquisition -> training copies -> trained model -> local inference -> generated output -> public distribution
Each arrow may occur in a different country, involve a different actor, and implicate a different exclusive right or exception. Saying "the model was trained abroad" does not automatically answer whether a locally deployed model or locally delivered output infringes. Conversely, a domestic output dispute does not automatically make all foreign training unlawful.
The judgment granted most of GEMA's requested injunctive, information, and damages relief, but it was not final. An appeal was available; no authoritative public docket source confirming a filed appeal was verified by August 12, 2026. The decision is evidence of one German trial court's approach, not a settled Europe-wide rule.
Why the text-and-data-mining exception did not resolve the case
The press release says the model-side reproductions were not covered by Germany's Section 44b text-and-data-mining exception. It does not announce that every form of generative-AI training falls outside the exception. The decisive published fact was the court's finding that the works remained memorized in the resulting model and could be reproduced from it.
The press release also records that Suno obtained the works by stream-ripping from YouTube while bypassing the platform's Rolling Cipher. It does not make clear whether the court imposed a separate anti-circumvention remedy or how that fact affected every element of the text-and-data-mining analysis. It should not be converted into a broader holding that every scraped source is unlawfully accessible.
These are separate gates:
- Does the activity fall within text and data mining?
- Was the source lawfully accessible?
- Did the rightsholder reserve rights where the statute permits reservation?
- Is the resulting model merely the product of analysis, or does it retain reproducible protected expression?
- Does a later output independently reproduce the work?
A system can pass one gate and fail another. Compliance programs need provenance and extraction testing, not just a label saying that a dataset was collected for machine learning.
What the ruling does not decide
The case does not safely support any of the following generalizations:
- All generative-AI training is copyright infringement.
- Every model trained on a song contains a legally cognizable copy of it.
- Model weights are always copies as a matter of European law.
- A style, genre, tempo, or artist reference is independently protected.
- Suno is banned everywhere, or the ruling automatically applies outside Germany.
- The decision is final or binding on other German courts, EU institutions, or US courts.
- The same result follows where outputs cannot be reproduced or do not contain recognizable protected expression.
It also did not resolve every neighboring-right issue around sound recordings, performances, or lyrics. The six claims described by the court focused on the musical works represented by GEMA.
An engineering response: test for work-specific extraction
For model developers, the ruling turns memorization from a research metric into a legal-control surface. A defensible program should connect data provenance, model evaluation, release gates, and incident response.
1. Keep training provenance at the asset level
Record the source URL or supplier, acquisition method, license, applicable territory, rightsholder reservation, transformations, and dataset versions. A declaration that a corpus was "public" is not enough. Public availability and lawful access are different questions.
2. Build canary and known-work extraction suites
Test whether prompts can recover protected sequences from high-risk or disputed works. For music, evaluation may compare melody, harmony, rhythm, structure, and arrangement across repeated generations. Include prompt variations and negative controls so the test does not confuse common musical vocabulary with memorization.
3. Measure repeatability, not one lucky output
The legal theory here depended on reproducibility. A release gate should record generation count, sampling settings, model version, prompt construction, similarity thresholds, and human review. The relevant signal is a stable extraction pathway, not an isolated resemblance.
4. Separate model and output controls
Output filters can block a recognizable song while the model still retains an extractable representation. Dataset removal or targeted unlearning can reduce model-side risk; output matching, rate limits, and prompt controls reduce delivery risk. Neither layer substitutes for the other.
5. Preserve versioned evidence
Because model behavior changes, teams need reproducible test artifacts: model hash, deployment region, prompt, seed, output, evaluator version, and decision log. This creates the temporal grounding needed to say what a particular release could reproduce at a particular date.
This resembles the broader need for machine-readable verification in AI coding harnesses. A policy claim is only as strong as the negative tests and release signals that enforce it. It also complements our EU AI Act evidence-contract checklist: product claims need versioned evidence that downstream operators can actually inspect.
A decision about evidence, not a slogan about weights
The Munich ruling matters because it gave legal significance to an empirical claim: specified works could be elicited repeatedly from specified model versions. The court then mapped that evidence onto reproduction rights at the model and output layers.
The next cases will test the boundaries. How similar must an output be? How repeatable must extraction become? Which prompts count as supplying the protected material rather than revealing it? What evidence distinguishes memorization from musical convention? How should courts treat remediation before judgment?
For now, the safe conclusion is precise. A model's opacity does not prevent it from containing a legally relevant reproduction, and work-specific reproducibility can be evidence of that containment. The judgment does not convert every parameter file into a universal archive of its training corpus.
Frequently asked questions
Does the ruling mean Suno is banned?
No. The court granted claims concerning specified works and uses, and the first-instance judgment was not final. It did not announce a worldwide ban on Suno.
Did the court rule that AI training itself is always illegal?
No. The court found that these model-side reproductions were not covered by the German text-and-data-mining exception, and it rejected US fair use for the US training acts on this record. The published summary does not declare all AI training unlawful.
Are model weights always copyrighted copies?
The ruling does not establish that categorical rule. It treated the tested Suno models as reproductions of six works because those works were found to be reproducibly contained in them.
Why did the prompts matter?
They helped establish a repeatable causal path from a model to outputs containing protected musical features. Because the prompts included lyrics, titles, and style instructions, the result should not be generalized to every generic music prompt.
Can Suno appeal?
Yes. The judgment was a first-instance decision and was open to appeal. An authoritative source confirming a formally filed appeal had not been verified by August 12, 2026.
Does the ruling control courts outside Germany?
No. Other courts may find its reasoning persuasive, but they apply their own jurisdiction, choice-of-law rules, statutes, and precedents.
References
- Munich Regional Court I, press release 16/2026, July 31, 2026
- VOSSIUS, GEMA v. Suno: AI music and copyright (secondary law-firm commentary)