Skip to content

AI litigation and enforcement

What courts and regulators have actually decided about AI so far, each case stated with its posture and its date, and what the ruling does and does not settle.

Most writing about AI and the law describes a direction of travel. That is the least useful thing to know when you have to decide something. A complaint is not a holding, a denied motion to dismiss decides only that a claim was pleaded well enough to continue, and a summary-judgment ruling on one set of facts can be flatly inconsistent with another judge reasoning about a nearly identical dataset three days later. All of that happened in 2025, and the difference between those things is the whole content of the question “is training on copyrighted work lawful?”

These pages state posture. Each one says what was filed or enacted, on what date, at what stage it now sits, what has actually been decided, and — usually the longest section — what the decision does not reach. Where the position is genuinely unresolved they say so and name who disagrees, because a page that guesses at an outcome is worth less than one that tells you which docket to read. Nothing here is legal advice, and the instruments are linked so you can check the wording against the summary.

Authors Guild v OpenAI: Case Status and What Has Been Decided

Where the consolidated authors' copyright litigation against OpenAI actually stands procedurally, and which questions no ruling in it has yet reached.

9 min read

The Four-Factor Fair Use Test Applied to AI Training

How US courts have actually weighed purpose, nature, amount and market effect in the AI training cases decided so far, and where the decided cases disagree.

11 min read

The GPAI Copyright Policy Obligation in Practice

What Article 53(1)(c) of the EU AI Act actually requires a general-purpose model provider to have in place, what the Code of Practice adds, and where to find each provider's published artefacts.

10 min read

Output Copyrightability: the Zarya of the Dawn and Thaler Decisions

The two decisions that fixed the US position on AI output — a registration cancelled in part, and a registration refused entirely — with what each actually held.

10 min read

Database Rights and AI Training on EU Databases

The sui generis database right is a separate obstacle to training on EU data, with its own subsistence test and its own relationship to the TDM exceptions.

10 min read

Singapore's Computational Data Analysis Copyright Exception

What sections 243 and 244 of Singapore's Copyright Act 2021 permit for AI training, the lawful-access condition they turn on, and the fact that contract cannot override them.

9 min read

Australian Copyright Law and AI Training: the Current Status

Australia has no text-and-data-mining exception and a closed list of fair dealing purposes, so training on protected works needs a licence or an existing defence.

9 min read

Canada's AI and Copyright Consultation: the Outcome So Far

What the 2023-24 federal consultation on generative AI and copyright asked, what it has produced, and why Canadian law on training is still unamended.

9 min read

The EU AI Act's Machine-Readable Marking Duty for Synthetic Content

Article 50(2) puts a technical marking duty on the provider of a generative system, which is a different obligation from the deployer-side labelling duty it is confused with.

10 min read

China's AI-Generated Content Labelling Measures

The Measures effective 1 September 2025 require both a visible label and metadata inside the file, and place duties on generators, platforms, app stores and users.

10 min read

California SB 942: the Free Provenance Detection Tool

What the California AI Transparency Act requires a covered provider to build and publish as a detection tool, and why that duty is harder than the disclosure duty next to it.

9 min read

Does C2PA Adoption Satisfy the EU AI Act's Labelling Duty?

Why adopting Content Credentials is evidence towards Article 50(2) compliance and not a safe harbour, and what the gap between the two looks like in practice.

9 min read

South Korea's AI Framework Act: the Generative Content Labelling Duty

The transparency and labelling obligations the AI Framework Act places on generative AI output, in force since 22 January 2026, and what the Enforcement Decree still controls.

8 min read

FTC Rules on AI-Generated Endorsements and Testimonials

How the revised Endorsement Guides and the 2024 rule on consumer reviews treat a testimonial that no customer ever wrote, including liability for supplying the tool.

9 min read

Deployer Due Diligence Before Buying a High-Risk AI System

A pre-purchase checklist built from Articles 26 and 13: the documents and capabilities to demand from a provider while you still have commercial leverage.

10 min read

Model Cards and Datasheets as Regulatory Evidence

Which fields in a model card or datasheet map onto an actual legal requirement, which are supporting evidence, and which are simply good practice with no legal counterpart.

9 min read

The Questions a DPIA Requires You to Ask an AI Vendor

A vendor question list derived limb by limb from Article 35(7) GDPR, phrased as what to send during procurement rather than as an internal template.

10 min read

Right-to-Audit Clauses in AI Vendor Contracts

What an audit clause needs — scope, trigger, sub-processor reach, evidence and remedy — to be worth invoking against an AI vendor, and the standard carve-outs that hollow one out.

10 min read

Approving an AI Sub-Processor Under GDPR Article 28

How to turn Article 28(1)'s 'sufficient guarantees' standard into a documented approval process for an AI sub-processor, including the flow-down and objection mechanics.

10 min read

When Integrating a GPAI Model Makes You the Provider

Article 25's three triggers that turn a distributor, deployer or integrator into the provider of a high-risk AI system, and what happens to the original provider when one fires.

10 min read

The Minimum Log Retention Period for High-Risk AI Under the AI Act

Where the six-month floor for high-risk AI logs actually comes from, why it is not in Article 12, and how it differs from the ten-year documentation period.

9 min read

What a High-Risk AI System's Automatic Log Must Capture

Article 12 sets one enumerated field list and one purpose test, and only the field list is a build spec you can implement directly.

9 min read

AI Audit Logs in an EU Market Surveillance Investigation

What a market surveillance authority can demand under Articles 21 and 74, in what order, and what your logs are actually doing once a file is open.

10 min read

Colorado's AI Act: the Documentation Deployers Must Keep

The deployer record-keeping regime SB 24-205 would have imposed, why it never took effect, and the narrower documentation duty that replaced it from 2027.

9 min read

Italy's Garante and Replika: the 2023 Order and the 2025 Fine

The scope and grounds of the Garante's 2 February 2023 urgent measure against Luka Inc., and the €5 million fine that followed it in 2025.

9 min read

Italy's Garante and ChatGPT: the Full Dated Timeline

Every dated step from the March 2023 suspension to the Rome court's 2026 annulment of the €15 million fine, and what each one did and did not decide.

10 min read

Clearview AI's GDPR Fines: a Dated, Multi-Country Tally

Each European penalty against Clearview AI with its amount, date and issuing authority, plus the enforcement problem that means almost none of it has been paid.

9 min read

FTC v Rite Aid: What the Facial Recognition Order Requires

The terms of the stipulated order in the FTC's 2023 Rite Aid case: a five-year ban, deletion of models built on the collected images, and an ongoing algorithmic safeguards programme.

9 min read

iTutorGroup: the EEOC's First AI Hiring Settlement

The $365,000 consent decree the EEOC obtained in 2023, the date-of-birth screening rule behind it, and why the case is thinner on AI than its reputation.

8 min read

The Workday AI Hiring Lawsuit: Where the Case Stands

A dated posture summary of Mobley v. Workday, including the agent ruling, the ADEA collective, and the long list of things no court has decided.

10 min read

SafeRent Tenant Screening: What the Settlement Actually Says

The terms of the 2024 Louis v. SafeRent settlement over an algorithmic tenant-screening score, and why it was a private class action rather than an FTC or HUD enforcement action.

9 min read

The Air Canada Chatbot Ruling: What the Tribunal Actually Decided

The actual holding in Moffatt v. Air Canada, the sum awarded, and why the widely repeated version of the decision overstates what a small-claims tribunal established.

9 min read

Amazon's Abandoned AI Recruiting Tool: What Was Actually Reported

What Reuters reported in October 2018 about Amazon's internal resume-screening model, attributed properly, and which parts of the story have never been confirmed.

9 min read

Ireland's DPC and Meta's AI Training: What Was Actually Decided

A dated account of the Irish Data Protection Commission's engagement with Meta over training on EU users' public posts, and why it is not the legitimate-interest ruling it is described as.

9 min read

Why the EU Withdrew Its AI Liability Directive

The Commission's stated reason for dropping the AI Liability Directive proposal in its 2025 work programme, and what it left behind.

8 min read

The Revised EU Product Liability Directive and Defective AI Software

How Directive (EU) 2024/2853 brings software and AI systems inside strict product liability, who counts as liable, and the evidential presumptions it introduces.

11 min read

The General Product Safety Regulation and AI-Enabled Consumer Products

How Regulation (EU) 2023/988 applies to a consumer product with an embedded AI feature, including the learning-functionality limb of the safety assessment and the recall duties.

10 min read

Who Is Liable When a High-Risk AI System Causes Harm: the Current EU Answer

An argument that the EU's compensation route for AI harm is far narrower than the regulatory conversation suggests, and that its gaps fall on exactly the harms AI systems most often cause.

11 min read

The Digital Services Act's AI-Generated Content Duties

What the DSA specifically requires very large platforms to do about synthetic media, and how those duties differ from its general content moderation obligations.

10 min read

The Cyber Resilience Act's Security Requirements for AI-Enabled Products

Which AI-enabled products fall under Regulation (EU) 2024/2847, what its essential requirements demand, and how its staged timeline lines up with the AI Act's.

10 min read

Does NIS2 Apply to an AI Infrastructure Provider?

How NIS2's sector list and size thresholds land on a company that hosts models or sells inference, and what falls due if they land on you.

10 min read

The DSA's Recommender System Transparency Rules and AI

What Article 27 of the Digital Services Act requires you to explain about an AI-driven ranking system, and why the non-profiling opt-out is a different article that binds fewer people.

9 min read

The EU AI Pact: What Signatories Actually Commit To

The specific voluntary pledges a company makes by signing the Commission's AI Pact, and the precise legal weight they carry, which is none.

8 min read

The EU AI Office's Role and Powers Over GPAI Providers

The specific enforcement powers the Commission exercises through the AI Office over general-purpose AI models, and why they sit outside the national market surveillance system.

10 min read

The EU AI Act's Regulatory Sandbox Requirement (Articles 57 and 58)

What member states are obliged to establish by 2 August 2026, and what participating in a sandbox actually changes about a provider's exposure.

9 min read

Real-World Testing of High-Risk AI Outside a Sandbox (Article 60)

The conditions Article 60 attaches to testing a high-risk AI system on real people before it is placed on the market, including the informed-consent regime in Article 61.

10 min read

When a Product Manufacturer Becomes the "Provider" Under the EU AI Act

How Article 25(3) transfers provider status to the manufacturer of a product that embeds a high-risk AI system, and what the AI supplier still owes under Article 25(4).

9 min read

The EU AI Act's Authorised Representative Requirement for Non-EU Providers

What Article 22's written mandate must empower a representative to do, why Article 54 imposes a separate one for GPAI model providers, and what the role is not.

9 min read

Subject to Both: Reconciling Colorado's AI Act With the EU AI Act

An argument that a company subject to both regimes should build to the EU's evidence requirements and to Colorado's discrimination theory, because neither subsumes the other.

11 min read

The EU AI Act's Definition of "Substantial Modification"

What Article 3(23) actually says, why continuously learning systems can change without triggering it, and why the concept does not apply to fine-tuning a general-purpose model.

10 min read

Other topics