Blog
Targeting the Right Question: What AG Rantos Left Open in Anne Frank Fonds
On 15 January 2026, Advocate General Rantos delivered his Opinion in Anne Frank Fonds (C-788/24), a reference from the Dutch Supreme Court. It puts a familiar problem back before the Court of Justice: how a territorially defined right of communication to the public plays out on the internet where everything is reachable from everywhere. In the case, a scholarly edition of Anne Frank’s manuscripts, still protected in the Netherlands until the end of 2036 but in the public domain elsewhere, was published in original Dutch yet on a Belgian website that excluded Dutch users through state-of-the-art geoblocking and an additional access check. Because users could nonetheless reach the site through a VPN, the rightholder argued that a communication to the public was taking place in the Netherlands after all.
The Opinion arrives at a defensible outcome: effective geoblocking keeps the publication outside of Article 3(1) InfoSoc Directive in the blocked territory, and the mere possibility of VPN circumvention does not alter that. Earlier commentary on this blog has set out the reasoning in detail and largely welcomed it. The purpose of this post is narrower: to draw attention to a question the referral raised yet the Advocate General did not really answer, namely whether the location of a communication to the public depends on the publication being targeted at the public in the state concerned. That omission is significant because the Court has consistently relied on exactly such a targeting test in adjacent areas.
A Central Question, Answered in a Footnote
The first question from the Hoge Raad was whether a communication to the public presupposes that the publication is addressed to the public in the relevant state. The Advocate General answers in the negative. He recites the established two-element test — an act of communication and a public — and concludes that, since the manuscript would not have been accessible to the online public without the defendants‘ intervention, an act of communication took place (para. 22–24). The question of targeting is then resolved in a footnote: what matters is that a sufficient number of persons can access the work, irrespective of where those persons are located (fn. 20 to para. 20).
For a question that the referring court considered central, this is surprisingly thin. It also stands in contrast with the Court’s broader case law. To locate an infringing act, the Court of Justice has repeatedly asked whether the activity was directed at the relevant territory: in trademark law (L’Oréal/eBay, para. 64), for the sui generis database right (Football Dataco/Sportradar, para. 34–43), for copyright’s own distribution right (Dimensione Direct Sales/Knoll, para. 30–33), and for the right of communication to the public under Article 8(2) of the Rental and Lending Right Directive (RAAP, para. 59). National courts have taken the same view, the German Federal Court of Justice most recently in Produktfotografien (para. 23).
Targeting Everywhere But Here?
The Opinion does not explain why Article 3(1) of the InfoSoc Directive should stand apart from this line. The objection that mere online accessibility alone can already cause harm does not distinguish the right of communication to the public, since the same is true of the database right and the distribution right. In Football Dataco, for example, the Court explicitly took the harm through the ubiquitous availability of content online into account (para. 35). And in Dimensione Direct Sales, it saw the distribution right infringed upon already by an advertisement, even where no consequential sale to an EU buyer was ever shown (para. 28, 32). Yet in both cases the Court still located the infringement by where the websites were directed, rather than by their mere accessibility.
The authorities invoked by the Advocate General also do not support a special treatment of the right of communication to the public. In VCAST, it was precisely relevant which concrete persons were targeted by the communication in question (para. 47–50). And Mircom concerned peer-to-peer filesharing, where no question of geographic or audience-specific targeting was ever at issue. The Court therefore had no occasion to consider the territorial reach of a communication.
An Obligation to Rebuild Offline Borders Online
The Advocate General does eventually narrow the large scope of the right of communication to the public, but only at a second stage. Assuming that a communication to the public occurs wherever the content can be reached, he then removes the blocked territory by way of a carve-out: only effective geoblocking ensures there is no communication there. It therefore becomes obligatory for anyone who wishes to use a work online in a way that is lawful in their home country but is subject to copyright in another Member State.
The Opinion does not really weigh the consequences. As this case shows, harmonization is imperfect, so the status of protection of a work is often unclear. Setting up geoblocking comes with costs that fall on users often unaware that their use is unlawful somewhere else — such as libraries, archives and museums dealing with material that is in the public domain where they sit. Cautious actors may simply choose not to put works online at all, even though their use might not have any effect in another Member State.
Why Targeting is the Better Route
A targeting criterion in contrast reaches the same result but without these difficulties. If a communication is not targeted at a particular territory, it is unlikely to affect the public there — therefore there is no communication to the public in that state to begin with. This strikes a better balance between the interests of the rightholder and the user: if a user orients a use towards a certain public and is therefore likely to impact the rightholder’s interests in that territory, they can reasonably be expected to observe its rules.
Of course this makes enforcement somewhat more demanding for rightholders. However, this can often be easily managed through the objective criteria for determining whether an activity is directed at a territory, such as the presentation and language of the publication. Those same criteria also make it unlikely that a use will cause relevant harm in a Member State without being targeted at its public. And in the remaining cases, any residual harm is more effectively addressed through harmonisation than by expecting users to rebuild offline borders online.
A targeting analysis also sits more comfortably within the Court’s own framework of Article 3(1) InfoSoc Directive than the geoblocking exception does. Where a communication is not directed at a certain territory, the user does not deliberately intervene, in full knowledge of the consequences of its action, to give users located there access to a protected work. The Advocate General instead relies on the “new public” criterion, which covers a different situation: it asks whether a rightholder limited the original public of a communication, so that anyone later reaching a new public becomes liable. In the geoblocking scenario, however, it is users without rights who limit the public to avoid liability. The “new public” criterion would therefore have to be reinterpreted to fit this setting.
What the Court Should Clarify
The Court of Justice now has an opportunity to settle how the right of communication to the public is to be located online, with implications well beyond VPNs and works whose protection ended unevenly across the EU. As long as terms of protection and exceptions continue to differ between Member States, the problem will persist. The Court is unlikely to take a stricter line than the Advocate General, not least because the defendants did everything that could reasonably be asked of them to respect the foreign right. The clarification worth hoping for is modest: a person who acts lawfully in their own home state should only have to deal with liability elsewhere once they direct their activity at the public there. Eventually, a more durable solution lies in harmonisation rather than in the expectation that users rebuild offline borders online.

If It Looks Like a Duck
Co-authored with Linda Kuschel. A German version of this post is available here.
The lawfulness of using copyrighted material to train generative AI models is one of copyright law’s hottest issues. The various lawsuits around the world seeking to answer this question are seen by many as fundamental for the future of both technology and cultural creations. The Munich Regional Court has now become the first court in the EU to issue an opinion on the lawfulness of AI models. The court’s ruling doesn’t only fuel the copyright debate, it can also be embedded in a larger political and social context — reinforcing a narrative of the EU as a thorough regulator, opposing the free-market US. At the same time, the decision reflects a stricter stance towards large tech companies than in previous years.
The Case at Issue
The Munich lawsuit was brought by the German collecting society GEMA, which exercises the rights to the lyrics of German classic songs such as Reinhard Mey’s “Über den Wolken” and Rolf Zuckowski’s “In der Weihnachtsbäckerei”. GEMA based its case on OpenAI’s use of these songs‘ lyrics to train the models GPT-4 and GPT-4o, and their subsequent appearance in the models’ output when prompted. The court was tasked with deciding on the lawfulness of both the act of training the AI model with copyright-protected material, as well as displaying the lyrics in the model’s output. It ruled in favor of GEMA and ordered OpenAI, inter alia, to cease and desist from reproducing the works in the model itself and from reproducing and communicating them to the public through the output.
Memorizations as Reproductions
Notably, the court bases its decision primarily on the fact that the AI model itself contained reproductions of the song lyrics that were used for training (para. 165 ff.). The phenomenon of memorization is central to this assumption: while generative AI models are not databases but consist of many parameters that represent statistical correlations in the training data, it may still be possible that training data is incorporated in the model in a way that it can be extracted as output upon a particular prompt. Such memorization occurs, for example, when certain data is included very often in the training dataset. The court treats the question of whether memorization has taken place as a question of fact, which it affirms in its assessment of the evidence (para. 168 ff.). It reaches this conclusion because the works in question (1) were indisputably included in the training dataset and (2) were reproduced in the output in a clearly recognisable manner (3) through “very simple prompts”.
On these facts, the Regional Court found that a reproduction (Section 16 German Copyright Act) had taken place (para. 176 ff.). The court applies the (usual) broad definition of the term “reproduction”, according to which any physical fixation of a work that is suitable for making the work perceptible at least indirectly is sufficient. Importantly, the court considers it irrelevant whether the song lyrics at issue were stored as-is, or merely “reflected” (OpenAI, para. 76) in the model parameters. It concludes that the works are “embodied” in the parameters of the model itself, simply because they were used as part of the dataset that trained the model, and can in turn be extracted from it as output.
Following this notion, the key question now becomes whether every instance of memorization qualifies as reproduction. After all, the phenomenon of memorization in information technology is by no means limited to cases in which training data is generated by “simple prompts”. Prompts and output merely serve to prove that training data has been memorized. Proof could only be found lacking in case of prompts that already contain the training data verbatim (“Repeat after me: ‘Wind Nord-Ost, Startbahn null-drei […]’”) or its abstract information (as in the example that OpenAI gave to the court, which uses numerous prompts to reconstruct the song lyrics word for word, para. 173 f.). Apart from such cases, it becomes irrelevant whether a prompt is simple or sophisticated, or even whether it is provocative or designed to circumvent security mechanisms: if the training data is provided in the output, we can conclude that it has been memorized in the model.
Given this broad definition of “memorization”, it is patently debatable whether it should always result in a finding of copyright-relevant reproduction. For instance, some works, while effectively memorized in the model, may rarely be perceived in the output if they are only triggered by a very specific, complex prompt. The concept of reproduction, however, does not reflect a spectrum of probability between mere possibility and actual perception. Yet, the economic interests of rightsholders arguably remain unaffected by a latent representation in the model; they are infringed only by the actual perception of the works in an output. Some scholars therefore consider a teleological reduction of the concept of reproduction, for example by limiting it to memorizations that can be made perceptible “with reasonable effort”. The Munich Regional Court helps itself along with a similar adjustment — not on the legal, but the factual level, as the court emphasises that “simple, non-provocative” prompts proved memorization.
The Text and Data Mining Exception
Copyright law permits reproductions without the permission of the rightsholder if they are carried out for the automated analysis of text and data in order to extract information (i.e., text and data mining (TDM), Section 44b German Copyright Act). The decision reveals the first path dependency in case law, with the Munich Regional Court adopting the Hamburg Regional Court’s structure of three phases (para. 166): (1) creation of the training material, (2) training of the model, (3) use of the model. Although phase 1 was not within this dispute’s scope, the Munich Regional Court — like the Hamburg Regional Court — takes a position on this and assumes as well that reproductions for the preparation of a training corpus are covered by Section 44b German Copyright Act.
The court classifies the memorization as part of phase 2 and states plainly that such reproductions cannot be carried out “for the purposes of” TDM because they do not serve to obtain any further information (para. 206). Notably, the court explicitly considers whether to interpret the provision in a manner favorable to technology and innovation, thereby disclosing a consideration that in the past may have only implicitly influenced comparable decisions on transformative technologies. At the same time, however, it clearly rejects such an interpretation, arguing that the legitimate interests of rightsholders would be prejudiced and that the risk of infringement is rooted in the way LLM models are trained.
Liability for Output Infringement
Finally, the court finds that showing the lyrics in the AI’s output amounts to acts of reproduction and making available to the public (§ 19a German Copyright Act) (para. 239 ff.). As every internet user could obtain the song lyrics at issue by prompting the AI model, they are made available to the public. Moreover, the lyrics are reproduced (again) when displayed to the user and stored in their chat history.
The court rejects OpenAI’s argument that it is the user who should be held responsible for such output infringements. Instead, it emphasizes OpenAI’s decisive role: as the operator, it selects the training data, designs the model’s architecture and ultimately decides to make a model available that carries such risk of infringement. OpenAI is thus denied the favorable treatment as intermediary, which in the past, due to its liability exemption, has benefited digital businesses.
Consequences of the Decision
The Regional Court did not issue a universal decision on the lawfulness of training generative AI on copyrighted material. While its reasoning is by no means limited to song lyrics and in fact applies to all types of works, memorization must be established on the facts of the case for each work and model concerned.
OpenAI will most likely appeal the ruling. Should it become final, OpenAI would face two injunctions and a claim for damages: the lyrics may no longer be reproduced in the models, and no outputs containing the lyrics may be generated. Damages already incurred as well as future damages would have to be compensated.
The injunction on reproducing the relevant content in the output could presumably be implemented with reasonable effort through content moderation: while it is (at least for now) virtually impossible to prevent all potentially copyright-infringing output, the display of certain word sequences such as the song lyrics in question could certainly be prevented with simple software instruction.
The injunction targeting reproductions in the models, on the other hand, could have serious consequences for OpenAI. This is because the affected works cannot be filtered out of the model. According to OpenAI, “there is no unlearning” (para. 84), at least not at present. Insofar as the use of ChatGPT involves reproductions of the model on German servers, OpenAI may therefore be forced to stop offering ChatGPT in this region altogether. Alternatively, it remains free to license the works at issue. The ruling is limited to models 4 and 4o, which are likely to be replaced by newer models with ostensibly different training data anyway. Nevertheless, it currently seems that the phenomenon of memorization is almost impossible to prevent. This means that going forward works contained in training datasets are likely to be considered reproductions in the model, and their use will therefore require permission from the rightsholders. Notably, comparable difficulties arise from a data protection perspective.
The court rejected OpenAI’s plea to refer this case to the ECJ itself or to suspend it until a ruling is issued in the Like Company referral procedure already pending. That case concerns the summarisation of an article by Google’s AI chatbot ‘Gemini’. The questions referred also deal with the training phase and the output level of the AI model. Therefore, the upcoming ECJ decision could, at least in part, supersede the ruling of the Munich Regional Court if it were to take a different view.
…Then It Probably Is a Duck
Due to their initial complexity, new technologies are inherently difficult to treat adequately in legal analysis. Taking advantage of this, AI providers describe their models as “black boxes”; it is unclear what exactly happens within them, but it is definitely not a reproduction; rather, outputs are based on a “sequential-analytical, iterative-probabilistic synthesis” (para. 80). The Munich Regional Court cuts through this technical opacity: what goes into the model as input and comes out again as output must, for copyright purposes, ultimately also be contained within the model itself.
Moreover, assigning responsibility for technology poses a problem if technology is understood as something that is predetermined. Yet, innovation is very much dependent on the choices made by innovators — making it contingent rather than inevitable. This also applies to AI models: although the operator does not know its output beforehand, the model is based on a freely chosen architecture and selected training data. Accordingly, the Munich Regional Court found that OpenAI was aware of the copyright infringements at least since GEMA had given notice and could have trained a new model or obtained a license during this time.
The decision fits snugly within the current popular narrative of a tightly regulating EU that protects rightsholders and a US that favors AI-friendly market solutions. In June, two US courts handed down copyright rulings in favor of Anthropic and Meta (although they are of little consequence due to their limited scope). Meanwhile, the EU is looking to thread the needle by maintaining a high level of copyright protection without causing competitive disadvantages for European companies. But in any case, due to intellectual property law’s principle of territoriality, AI training abroad is not subject to European copyright laws. The EU sought to address this issue in the AI Act by imposing meta-obligations on providers, such as the requirement to implement a policy to comply with EU copyright law (Art. 53(1)(c) AI Act).
The court’s reasoning now reveals a different path for holding AI providers from third countries accountable for respecting European copyright law: reproduction of the output and their making available occur in the EU and are therefore subject to European (or, in this case, German) copyright law. The court appears to take the same view regarding reproductions in the model itself — though it remains remarkably quiet on this point, merely stating, in the context of international jurisdiction, that OpenAI’s servers, on which the model is provided, are located in Germany, and referring to the lex loci protectionis principle. The fact that, in the court’s opinion, the reproductions in the model are the result of the training process and therefore — in the case of OpenAI — took place in the US is not addressed at all. Most likely, (further) reproductions of the model are considered part of its use on servers in Germany. However, the court does not elaborate on this at all.
The decision of the Munich Regional Court also reflects another trend: in the past, then young and somewhat idealised digital companies benefited from innovation-friendly regulation and jurisprudence that gave them enough freedom to become giants. This was justified by the high social benefits that their business models promised. This argument is essentially no less valid for generative AI than it was for search engines or host providers. OpenAI, in essence, seeks to draw upon such arguments from the “golden age” of platform innovation when it calls for “an assessment-based adjustment of liability” (para. 228).
However, the circumstances have changed. Trust in large tech companies has suffered greatly in recent years. The social costs associated with internet platforms are now becoming apparent. For generative AI, this is happening in light speed — the effects on the labour market, mental health and culture are already subject to intense public debate. In Kadrey v Meta Platforms, for example, it is stressed that while being “highly transformative”, generative AI may also “dramatically undermine the market” for creative works and ultimately the “incentive for human beings to create things the old-fashioned way”. Furthermore, generative AI providers do not appear to succeed in developing a positive image similar to that of, say, the early Google (“Don’t be evil”) or Facebook. OpenAI’s release of the Sora 2 video model, for example, does not give the impression that the company is making an honest effort to protect the (copy-)rights of third parties. At the same time, the social benefits of such video generators appear to be limited (“the infinite slop machine”). In addition, no monopolist has emerged from among the model providers yet, limiting the general consequences of a decision against a particular provider — as the court also recognises (para. 228).
The decision of the Munich Regional Court marks a consequential yet preliminary point of orientation. Now, we must wait to see whether other courts will pick up this line of reasoning — or whether it will prove to be an outlier in retrospect. In particular, it remains to be seen whether the court’s abductive reasoning — the “duck test” for AI models — will in fact prevail.
“If It Looks Like a Duck” © 2025 by Linda Kuschel and Darius Rostam is licensed under CC BY-SA 4.0.

Machine-Readable Opt-Outs in Kneschke vs LAION
A Fundamental Decision on AI Training?
The decision in Kneschke ./. LAION e.V. by the Hamburg Regional Court (German version) has received quite some attention in copyright circles and beyond. Contrary to some takes, however, it does not address whether Article 4 DSM Directive applies to AI training. Rather, LAION reproduced an image to check whether an existing image description (taken from the Common Crawl dataset) matched the actual content of the image when creating the dataset LAION-5B in the form of a collection of links.
The question was whether LAION can rely on the limitation concerning text and data mining for the purposes of scientific research under Article 3 DSM Directive, transposed in Section 60(d) of the German Act on Copyright and Related Rights. For this, LAION has to be a “research organisation”, which — at least regarding the court’s reasoning — is doubtful.
However, this is only a side issue here. Instead, what I find more intriguing is the court’s extensive obiter dictum on opt-outs under Article 4(3) DSM Directive and Section 44b(3) German Act on Copyright and Related Rights.
Opt-outs in Copyright
Opt-out regimes have become increasingly common in copyright. Structurally, they represent a proceduralization of the exclusive right granted under copyright law: whether exclusivity exists depends on a process initiated by the rightsholder. If the rightsholder remains inactive, use is generally permitted (some people therefore speak of copyright law “turned on its head”).
Users, such as AI companies, are therefore relieved of the transaction costs they would otherwise bear under an initially exclusive right. In the case of AI training, these are prohibitively high because of the sheer volume of content. Meanwhile, rightsholders bear additional costs for declaring an opt-out. However, this shift in the cost can be worthwhile if it enables negotiations and a market-based solution for the allocation of rights to use the content. More on this can be found here.
For online content, the DSM Directive requires that an opt-out be declared using machine-readable means. Article 4(3) states:
The exception or limitation provided for in paragraph 1 shall apply on condition that the use of works and other subject matter referred to in that paragraph has not been expressly reserved by their rightholders in an appropriate manner, such as machine-readable means in the case of content made publicly available online.
To determine the appropriateness of an opt-out, the interests of users (the easier to detect, the better) and rightsholders (the easier to declare, the better) must be balanced. Users can without further ado be required to employ all available and reasonable means to detect an opt-out. Conversely, rightsholders can reasonably be expected to declare their opt-out in a way that enables automated detection, as otherwise users would not use content — they would need to refrain from any use out of uncertainty about whether an opt-out was declared, since if they cannot license every piece of content because of the high volume, they cannot check it manually for an opt-out either. The provision on machine-readable means in Article 4(3) DSM Directive is based on this idea.
What about LAION?
In the LAION case, the reproduced image in question, hosted on a stock photo platform, was subject to a general, plain-language opt-out included in the website’s terms of use. Nonetheless, the court found that this satisfied the requirements for machine-readability. The rationale was that LAION, in analyzing the images for their correlation with the image tag, was able to “understand” the (plain-language) image tag. Whether this implies that LAION also had the means to detect and interpret entirely unknown opt-outs across the web — an entirely different technical endeavour — seems very dubious to me, but is ultimately a question of fact.
However, the court’s reasoning suffers from a more fundamental flaw: it takes only the technical means of users to detect and understand the opt-out into account, and completely ignores the range of options available to rightsholders for declaring the opt-out. This is problematic in light of the DSM Directive’s requirement for the opt-out to be appropriate: the purpose of the limitation in Article 4 is to eliminate legal uncertainty for users regarding the lawfulness of text and data mining. For this reason, the reservation must be appropriate to ensure users are not exposed to an undue risk of copyright infringement. The Directive notably does not require that the burden on rightsholders is minimized to the greatest extent possible.
Therefore, it is insufficient to consider only whether users have technical means to detect a given opt-out; it is equally important to assess what machine-readable means can reasonably be expected from rightsholders to make use of when declaring an opt-out. If rightsholders can declare an opt-out with minimal (extra) effort in a certain way that results in a significant reduction of users‘ burden (e.g., by making it especially easy or resource-efficient to detect), there would have to be good reasons why they should not be required to do so.
For the upcoming appeal, it will therefore be interesting to observe whether the arguments regarding machine-readability are upheld, should they arise at all.
Linda Kuschel and I delve into these issues in more detail in our comments on the LAION decision by the Hamburg Regional Court.