AI Copyright Litigation in 2026: Implications for Companies That Use AI

September 10, 2026

The Anthropic settlement, a district court split on fair use, and the Supreme Court’s decision not to revisit the human-authorship rule have reshaped AI copyright risk. The effects reach companies that use AI in products, content, and code, not only the companies that build models.

The most prominent copyright development of the past year carried a very large number. Anthropic agreed to pay roughly $1.5 billion to settle claims that it trained AI models on pirated books, approximately $3,000 per work, and agreed to destroy the pirated dataset. The settlement received final court approval in July 2026. 

It is tempting to categorize that as a problem for AI companies alone. The settlement, and the rulings around it, are also changing what acquirers, investors, and enterprise customers ask of companies that use AI, embed it in products, or ship work that AI helped create. That includes a large share of growing companies. 

Where the law currently stands 

Three developments frame the landscape. 

First, the district courts have split, in an instructive way. In the Anthropic case, the court found that training an AI model on books was transformative, but that acquiring and storing pirated copies was not fair use. In a parallel case against Meta, another court granted summary judgment for the company on fair use, declining to treat the pirated source of the books as decisive, while emphasizing that those plaintiffs had failed to prove market harm and that training may well infringe in other cases. The practical direction of both rulings: the dispute is shifting from whether AI training is lawful to how the training data was obtained and what the training does to the market for the underlying works. Provenance is becoming much of the game. 

Second, the settlement put a price on the risk. Approximately $3,000 per work, across hundreds of thousands of works, for the training inputs alone. Notably, the settlement covered only past training, not model outputs. Whether an AI system’s outputs can infringe remains in active litigation, so the output side of the risk remains open. 

Third, the Supreme Court declined in March to revisit the rule that copyright requires a human author. Under current U.S. law, purely AI-generated work is not copyrightable. Work created by a human with AI assistance can be, but the human contribution carries the protection, and how much contribution is enough remains an open question the courts are still working out. 

Why this reaches companies that use, rather than build, AI 

For a company that will never train a model, three threads still apply. 

Ownership of the company’s own assets. Where a team uses AI heavily in producing code, content, or designs, the human-authorship rule bears directly on how much of that output the company owns. Work with no meaningful human contribution may be protectable by no one, which is an uncomfortable discovery to make during diligence when an acquirer asks what stands behind a core asset. 

Provenance of what the company builds on. For companies that fine-tune on third-party content, scrape data, or build products on top of licensed databases, the emerging case law suggests the source of the data matters as much as the use. Where the data came from, and what the company was permitted to do with it, is becoming a first-order question. 

Discoverability of AI usage. In the consolidated litigation against OpenAI, the court has ordered production of a sample of 20 million de-identified user conversations. Prompts and outputs are business records: they can be demanded in litigation, and they are beginning to be requested in diligence. 

The diligence questions are changing 

In CGL’s experience, versions of the same questions now appear in acquirers’ and investors’ request lists: which AI tools the company uses and under what terms, whether AI-generated material sits inside the codebase or key content, what human review and contribution look like, and where training or fine-tuning data came from. 

Companies that can answer cleanly tend to move through diligence without drama. Companies that cannot may find themselves negotiating special indemnities and escrows constructed for the occasion. The difference between the two is usually not the technology; it is documentation that was either kept or not kept well before the deal. 

Practices worth putting in place 

The defensible position is built from ordinary habits: a current inventory of AI tools in use and the terms that govern them, a policy on where AI can and cannot be used in building product, documentation of human contribution to AI-assisted work that matters, records of where training and fine-tuning data came from, and a retention approach that treats prompts and outputs as the business records they are. 

None of this requires predicting how the litigation ends. It requires being able to show the work when someone with leverage asks. 

The rulings described above are current as of August 17, 2026. Several of these cases are on appeal or still in progress, and the legal landscape could look different within months. 

How CGL can help 

CGL advises companies on putting AI usage on a defensible footing before a financing or sale makes the question urgent, from IP ownership hygiene to the diligence questions acquirers are now asking. To discuss how these developments apply to a particular product, codebase, or content operation, a 20-minute call can be scheduled HERE.

 

Disclaimer

The materials available at this website are for informational purposes only and not for the purpose of providing legal advice. You should contact your attorney to obtain advice with respect to any particular issue or problem. Use of and access to this website or any of the e-mail links contained within the site do not create an attorney-client relationship between CGL and the user or browser. The opinions expressed at or through this site are the opinions of the individual author and may not reflect the opinions of the firm or any individual attorney.

Other Articles

External Privacy Policy with hand hovering above it and reading glasses sitting on it Is an External Privacy Policy Enough?
GDPR Explained: A Quick Guide for U.S. Businesses
Children’s Data Privacy: Five Takeaways from the FTC’s Recent Workshop

    Please take a moment to tell us a few things about your needs and someone from our team will reach out to you as soon as possible.

    We would to hear from you

    Thank you for reaching out!

    Someone from our team will get back to you shortly

    We would to hear from you