Generative AI and Copyright in the European Union: Transparency, Copyright Compliance, and the AI Act
This study explores the relationship between generative artificial intelligence and copyright law in the European Union (EU), focusing on the Artificial Intelligence (AI) Act (Regulation (EU) 2024/1689) and its interplay with the existing EU copyright acquis. It distinguishes between two questions that are often conflated: whether AI-generated or AI-assisted content deserves copyright protection, and whether the providers and deployers of AI systems that produce such content bear regulatory responsibilities. Applying doctrinal legal research to the AI Act, the study examines the treatment of general-purpose AI models, copyright-compliance policies, training-content summaries, synthetic-content transparency, documentation, institutional supervision and adaptive codes of practice. It also places these obligations alongside the Court of Justice’s originality standard, which has so far been tied to the author’s own intellectual creation expressed through free and creative choices. The study concludes that the EU framework works best in relation to provider accountability, provenance and transparency, but that some important output-side copyright issues remain to be addressed by the existing copyright framework. In that light, it suggests strengthening the links between AI law and copyright law without turning the AI Act into a copyright-specific law.
Introduction
Generative AI poses two types of copyright issues. On the output side, the questions concern originality, authorship and the protectability of outputs produced with differing degrees of human involvement. On the input and system side, the questions are what rights-protected material is used for training, which rights have been reserved by rightsholders, how transparent training is, and who bears responsibility when general-purpose AI models are placed on the European Union market.
What is distinctive about the European Union (EU) response is that the AI Act is not a copyright law. Rather, it is a horizontal instrument of AI governance that integrates copyright-relevant obligations into a larger framework covering safety, fundamental rights, transparency, market access and systemic risk. It is therefore essential to consider separately the copyrightability of outputs and the compliance obligations of providers, and to examine how the two function within the same legal context.
Research problem
Although the AI Act neither sets out rules on the copyrightability of AI-generated content nor allocates authorship of such content, the European Union has established specific regulatory requirements for general-purpose AI models, such as copyright-compliance policies and public summaries of training content. This creates a gap between copyright doctrine and the governance of AI. The key research question is how the Union’s transparency and provider-accountability measures interact with the existing copyright acquis, namely the rules on originality, text and data mining, rights reservations and the protection of human creative expression.
Objective
This paper examines the structure of the EU AI Act and its relationship with copyright, and explores how the Union can bring greater clarity to the treatment of generative-AI training and AI-assisted creative production without introducing a de facto AI-specific copyright regime.
Research questions
This study addresses the following research questions:
1. How does the EU AI Act regulate copyright-relevant conduct by providers of general-purpose AI models?
2. How do the transparency obligations of the AI Act relate to the current European Union copyright acquis, including rights reservations for text and data mining?
3. How do EU originality principles apply to AI-assisted and substantially AI-generated output?
4. What legal and institutional clarifications would improve coherence between generative-AI governance and copyright protection in the European Union?
Research methodology
The paper adopts a doctrinal method, gathering and synthesising the relevant legal materials. It examines Regulation (EU) 2024/1689, the EU copyright directives, the case law of the Court of Justice of the European Union on originality, the institutional regulatory framework and the academic literature. The analysis treats the AI Act as a horizontal regulatory framework and considers copyright subsistence, with its implications for authorship and originality, separately from the transparency and compliance requirements imposed on providers.
Literature review
In the literature on the European Union AI Act, Martin Senftleben examines whether exceptions permitting text and data mining for the training of generative AI are compatible with the copyright three-step test, questioning whether the international test applies to such copies at all and arguing that rules permitting text and data mining for AI training, combined with an opt-out for copyright owners, can satisfy its criteria. Adam Buick argues that the AI Act’s transparency requirements, which are designed to facilitate enforcement of the text-and-data-mining opt-out under the Directive on Copyright in the Digital Single Market (CDSM Directive), cannot on their own resolve the challenges that generative AI training poses to copyright, because their effect depends on the adequacy of the underlying copyright rules. In his analysis of the copyright-adjacent provisions of the Act, Andres Guadamuz considers the transparency requirements placed on providers of general-purpose AI models under Article 53 in the context of the broader EU copyright acquis.1
The key issue illustrated by this literature is not merely whether generative AI should be regulated, but how new obligations bear on model providers and on copyright laws that were forged before large-scale generative models acquired economic importance. Of special interest in the resulting scholarship are the AI Act’s effect on text and data mining, rights reservations and transparency, and the extent to which it can genuinely help rightsholders enforce existing copyright.
Research gap
Much of the current discussion treats training-data compliance and the copyrightability of outputs as a single AI-copyright question. But the regulatory instruments involved serve different legal functions. The AI Act addresses systems, providers, deployers, transparency, documentation and market accountability, while copyright subsistence remains governed by the copyright acquis and the doctrine of originality. The research gap lies in the need to explain this separation clearly, while identifying where coordination is needed so that transparency obligations support, rather than supplant or obscure, copyright analysis.
Copyrightability, originality, and human creative choice
The AI Act does not assign ownership of AI-generated content; copyrightability remains governed by the ordinary criteria of EU copyright law. The crux of the matter is whether a work created with the use of AI, where the AI is not the sole contributor, can still qualify as protected expression, or whether the human free and creative choices in the final work have been displaced. If the AI system does no more than implement a human conception, protection may attach to the human-created elements; if virtually nothing of the expressive work can be regarded as a human intellectual creation, the case for copyright protection is correspondingly weaker.2
Although the EU AI Act does not settle the question of output copyrightability, the case law of the Court of Justice of the European Union (CJEU) provides a valuable reference point. In Painer (C-145/10), the Court held that a work is original where the author has made free and creative choices that reflect his or her personality, and in Cofemel (C-683/17) it confirmed that classification as a work is reserved to the elements that are the expression of the author’s own intellectual creation. Although these cases do not involve generative AI, they are directly relevant to this paper’s inquiry because they place human creative choice at the centre of the EU notion of originality.3
This distinction is a key feature of the EU legal architecture. The obligations placed on providers under the AI Act can increase transparency about training practices or about whether content is synthetic, but they do not make machine-generated expression a protected work. Equally, the absence of an AI-specific output rule does not mean that copyright protection is now confined to AI-generated outputs that, in and of themselves, meet the originality standard.4
The European Union Artificial Intelligence Act
A. Legislative rationale and regulatory philosophy
The Artificial Intelligence Act (Regulation (EU) 2024/1689) establishes a harmonised, horizontal regulatory regime for AI in the EU. It is important at the outset to be clear about what kind of instrument the AI Act is. The European Union’s approach to regulating AI does not involve drafting a new copyright regime for AI-generated content; it takes the form of a horizontal framework for regulating AI, in which copyright is one of several interests to be respected in the development of AI, alongside health, safety, fundamental rights, democracy and the rule of law. For a copyright analysis this distinction is crucial: the AI Act does not itself determine whether an AI-generated output is protected by copyright, but it imposes obligations relating to copyright compliance, transparency and documentation within the broader framework of AI governance.5
The rationale of the Act can be summarised in four related concerns. First, AI is a fast-evolving family of technologies that is making its way into nearly every sector of the economy. Secondly, alongside its benefits, AI can cause serious harm. Thirdly, without a common framework, individual Member States risked enacting diverging national laws on AI, fragmenting the internal market and creating uncertainty for companies active in several Member States. Fourthly, the European Union wanted to ensure that the development of AI within its borders accords with Union values. The harmonisation rationale is stated directly in recital 3: “Diverging national rules may lead to the fragmentation of the internal market and may decrease legal certainty for operators that develop, import or use AI systems.” Recitals 4 and 5 lay the foundations of the Act’s overall approach, recognising that AI can bring a wide array of economic, environmental and societal benefits but can also cause material or immaterial harm; recital 6 sets out the human-centric principle that AI “should serve as a tool for people, with the ultimate aim of increasing human well-being”; and recitals 7 and 8 explain the need for common rules, including rules specific to high-risk AI systems.6
This orientation towards the internal market and fundamental rights is reflected in the Act’s legal bases, Articles 16 and 114 of the Treaty on the Functioning of the European Union. For the purposes of this paper, the AI Act is best seen as an instrument of internal-market harmonisation coupled with the Union’s competence over the protection of personal data, rather than as legislation designed specifically for the field of copyright. It does not create a copyright regime of its own but embeds copyright-related obligations in a much larger framework of AI governance, whose aim is to improve the functioning of the internal market and support innovation while safeguarding health, safety, fundamental rights, democracy, the rule of law and environmental protection.7
This broader approach is reflected in recital 96, which explains the fundamental rights impact assessment that Article 27 requires of deployers of high-risk AI systems that are bodies governed by public law or private entities providing public services, and of deployers of certain high-risk AI systems listed in an annex to the Act, such as banking or insurance entities. The assessment identifies the specific risks to the rights of the individuals or groups likely to be affected and the measures to be taken should those risks materialise, and recital 96 links such public services to tasks in the public interest in areas such as education, healthcare, social services, housing and the administration of justice. The assessment must be performed before the system is deployed and updated when relevant factors change, reflecting the Act’s general preventive, rights-based regulatory approach.8
B. Scope and regulated actors
The scope of the Act is defined by Article 2, which deserves close attention because it sets the geographical and subject-matter reach of the Union framework. The Regulation applies to a wide range of actors: not only providers placing AI systems or general-purpose AI models on the Union market, wherever they are established, deployers established or located in the Union, importers, distributors, product manufacturers and authorised representatives, but also providers and deployers established in third countries where the output produced by the AI system is used in the Union. This matters for copyright compliance because the Act’s reach is not territorial but is based on the market and on use: a provider may have obligations in the Union even if the model was developed or trained outside the European Union.9
The Act contains a list of exclusions. Only specified provisions apply to certain categories of high-risk AI systems, and other matters fall entirely outside the Act: public authorities of third countries acting in certain capacities; existing legal frameworks with which the Act does not interfere; AI systems or models developed and put into service solely for scientific research and development; and research, testing or development activity regarding AI systems or models before they are placed on the market. The Act also does not preclude the Union or Member States from maintaining or introducing rules more favourable to workers on the use of AI by employers, so that in this respect it represents a floor, and it does not apply to AI systems released under free and open-source licences unless they are placed on the market or put into service as high-risk AI systems or as systems falling under Article 5 or Article 50.10
C. Foundational definitions
Article 3 provides a technology-centred vocabulary for analysing the actors, systems, data and deployment relationships governed by the AI Act.11
Of particular interest is the definition of an “AI system”, which turns on autonomy, inference and the ability to generate outputs, including content: an AI system is “a machine-based system that is designed to operate with varying levels of autonomy” and that “infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions”. The definition provides a technological basis for regulating AI-generated content, but not for determining whether content generated by an AI system is copyrightable. Separating the technological definition from the copyrightability question is a useful structural choice: it allows the regulatory scheme to identify and regulate systems and their outputs without prejudging the distinct legal question whether those outputs are protected by copyright.12
Several further definitions concern the regulated actors and mechanisms. A “provider” is a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts the AI system into service under its own name or trademark; a “deployer” is a natural or legal person, public authority, agency or other body using an AI system under its authority, except in the course of a personal, non-professional activity; an “authorised representative” is a person located or established in the EU who has received and accepted a written mandate from a provider to carry out the obligations under the Act on the provider’s behalf; and “operator” is an umbrella term covering providers, product manufacturers, deployers, authorised representatives, importers and distributors. The Act also defines “placing on the market”, meaning the first making available of an AI system or general-purpose AI model on the Union market, and “making available on the market”, meaning the supply of an AI system or general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, together with “putting into service”, “intended purpose” and “reasonably foreseeable misuse”. The definition of “substantial modification” is particularly relevant: it covers an unplanned change to an AI system after it has been placed on the market or put into service that affects its compliance or modifies its intended purpose, a notion that matters when considering how regulatory responsibility shifts where a system has been meaningfully altered.13
The notion of “training data”, meaning data used for training an AI system through fitting its learnable parameters, is particularly important to the subject of this paper. Its importance lies in the fact that training data may be protected by copyright, which makes it one of the key points of interaction between AI development and copyright. Together with the definitions of “validation data”, “validation data set”, “testing data” and “input data” (data provided to or directly acquired by an AI system on the basis of which the system produces an output), it supplies a vocabulary for describing precisely which stage of an AI system’s data pipeline is at stake in a particular legal or regulatory question, where the source and function of data can matter for copyright.14
Collectively, the institutional definitions set the architecture within which the Regulation is implemented and supervised: the “AI Office”, the Commission’s function of contributing to the implementation, monitoring and supervision of AI systems, general-purpose AI models and AI governance; the national “notifying authority” and “market surveillance authority”; and the concepts of a “real-world testing plan”, a “sandbox plan” and an “AI regulatory sandbox”, a controlled framework set up by a competent authority in which providers can develop, train, validate and test innovative AI systems for a limited time under regulatory supervision. The term “AI literacy” (the skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems and to gain awareness of the opportunities, risks and possible harms of AI) is also relevant, since effective compliance presupposes that providers, deployers and affected persons understand the technology and its risks.15
Two further definitions relate directly to the subject of this paper. A “deep fake” is “AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”. This is a key concept for transparency regulation, as explained below, and is also relevant to the disclosure of AI involvement in creative works. The definition of a “general-purpose AI model” (a model that “displays significant generality and is capable of competently performing a wide range of distinct tasks”), together with the concepts of “high-impact capabilities” (capabilities that match or exceed those recorded in the most advanced general-purpose AI models) and “systemic risk” (a risk specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market because of their reach or of actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights or society as a whole, that can be propagated at scale across the value chain), is fundamental to the copyright-specific obligations discussed in the next section, as are the definitions of a “general-purpose AI system” (an AI system based on a general-purpose AI model) and a “downstream provider” (a provider of an AI system that integrates an AI model, whether provided by itself or by another entity).16
D. General-purpose AI models and copyright-specific obligations
For the purposes of this section, the most relevant structural distinction in the Act is that between general-purpose AI models and AI systems. General-purpose AI models are characterised by their generality and their capability to perform a wide range of distinct tasks, and they are usually trained on large amounts of data; although AI models are essential components of AI systems, they do not constitute AI systems on their own, and the Act’s specific obligations for providers of general-purpose AI models continue to apply when those models are integrated into AI systems. Recital 98 offers a more concrete way of identifying significant generality: models with at least a billion parameters, trained with a large amount of data using self-supervision at scale, should be considered to display significant generality and to perform a wide range of distinctive tasks competently. Of particular interest for this paper, recital 99 states that large generative AI models are a typical example of general-purpose AI models, since they allow flexible generation of content such as text, audio, images or video. It should be noted, however, that the one-billion-parameter consideration is not the only legal test of generality but an indication of significant generality. Recital 100 then distinguishes general-purpose AI models from general-purpose AI systems: when a general-purpose AI model is integrated into an AI system that, as a result, can serve a variety of purposes, that system is a general-purpose AI system, which can be used directly or integrated into other AI systems.17
Recognising the key role of general-purpose AI model providers in the AI value chain, since their models may form the basis for many downstream AI systems, the Act lays down proportionate transparency and documentation obligations for them, including drawing up and keeping up to date technical documentation, making it available on request to the AI Office and national competent authorities, and providing information on the model to the downstream providers that integrate it. Recital 102 acknowledges that software, data and models released under a free and open-source licence can contribute to research and innovation and provide significant growth opportunities, and that general-purpose AI models released under such licences should be considered to ensure high levels of transparency and openness if their parameters, including the weights, the information on the model architecture and the information on model usage are made publicly available, the licence allowing users to run, copy, distribute, study, change and improve them. Under recital 103, however, the free and open-source treatment is limited: making AI components available through open repositories does not in itself constitute monetisation, but components provided against a price or otherwise monetised, including through technical support or other related services, through a software platform, or through the use of personal data for reasons other than exclusively improving the security, compatibility or interoperability of the software, do not benefit from the free and open-source exceptions.18
Recital 104 is particularly relevant to this paper: it makes clear that open-source release does not free a general-purpose AI model provider from copyright-related duties. Whether or not the model is open source, its provider remains subject to two copyright-related obligations: producing a summary of the content used for training the model, and putting in place a policy to comply with Union copyright law, in particular to identify and comply with reservations of rights under Article 4(3) of Directive (EU) 2019/790. Free and open-source general-purpose AI models whose parameters, architecture and usage information are public benefit only from exceptions to the other transparency requirements, and not at all where they present a systemic risk.19
These obligations sit within the European Union’s existing copyright framework, as recital 105 explains. Generative AI presents unique innovation opportunities but also challenges for artists, authors and other creators; the training of such models requires access to vast amounts of data, which may be protected by copyright and related rights; any use of protected content requires the rightsholder’s authorisation unless a relevant exception or limitation applies; and, under Directive (EU) 2019/790, rightsholders may reserve their rights against text and data mining (except where it is carried out for the purposes of scientific research), so that where such a reservation has been expressly made in an appropriate manner, providers need the rightsholder’s authorisation to mine the works concerned. Under recital 106, every provider placing a general-purpose AI model on the Union market should put in place a policy to comply with Union copyright law, including rights reservations under Article 4(3), regardless of the jurisdiction in which the copyright-relevant acts underpinning the training take place. The obligation therefore applies even where training was carried out outside the European Union, so that no provider can gain a competitive advantage in the Union market by applying lower copyright standards than those provided in the Union.20
Recital 107 elaborates the transparency obligation: to increase transparency on the data used in the pre-training and training of general-purpose AI models, including text and data protected by copyright, providers must draw up and make publicly available a sufficiently detailed summary of the content used for training. Taking due account of the need to protect trade secrets and confidential business information, the summary should be generally comprehensive in its scope rather than technically detailed, so as to help parties with legitimate interests, including copyright holders, to exercise and enforce their rights under Union law. Recital 108 clarifies the legal reach of the resulting oversight: the Regulation does not affect the enforcement of copyright rules under Union law, and the AI Office monitors whether providers have fulfilled their obligations to put in place a copyright policy and to publish a training-content summary without verifying or proceeding to a work-by-work assessment of the training data in terms of copyright compliance. Recital 109 further moderates these obligations by proportionality: they should be commensurate with the type and size of the provider, and where a model is modified or fine-tuned, the obligations should be limited to that modification or fine-tuning, for example by complementing the existing technical documentation with information on the modifications, including new training data sources.21
Taken together, recitals 97 to 109 are among the most significant copyright-adjacent passages in the Act, because they link copyright to the technical mechanics of general-purpose model training, documentation and placement on the Union market.22
E. Transparency, disclosure, and the regulation of AI-generated content
Recital 132 notes the specific risks of impersonation and deception posed by AI systems that interact with natural persons or generate content, and supports appropriate transparency requirements, such as informing persons that they are interacting with an AI system. Recital 134 turns to deep fakes specifically: deployers who use an AI system to generate or manipulate image, audio or video content that appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful should clearly and distinguishably disclose that the content has been artificially created or manipulated. Where the content forms part of an evidently creative, satirical, artistic, fictional or analogous work or programme, the obligation is limited to disclosing the existence of such content in an appropriate manner that does not hamper the display or enjoyment of the work, including its normal exploitation and use, a proportionality safeguard that keeps disclosure requirements from unduly discouraging legitimate creative and artistic activity. A similar disclosure obligation applies to AI-generated or manipulated text published to inform the public on matters of public interest, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication.23
These provisions are given force in Article 50 of the Act. Under Article 50(2), providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content must ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, robust and reliable as far as this is technically feasible; the obligation does not apply to systems that perform an assistive function for standard editing or do not substantially alter the input data. This provision is not designed to give AI-generated content copyright protection; rather, it provides a separate, new layer of provenance and identification that may assist copyright enforcement and evidentiary determinations where the origin of synthetic content is relevant. Article 50(4) requires deployers to disclose deep fakes and AI-generated or manipulated text published to inform the public on matters of public interest, with a lighter obligation for evidently artistic, creative, satirical and fictional content and no disclosure requirement for such text where it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it. Article 50(7), as replaced by the Digital Omnibus on AI (Regulation (EU) 2026/1744), provides that the Commission “shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content”, and allows it to adopt an implementing act laying down common rules if it deems a code inadequate. Article 4, which as amended by the same Regulation requires providers and deployers to “take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”, is of comparatively secondary relevance to copyright but supports the overall compliance environment in which copyright-related obligations operate.24
Combined, these provisions provide a strong basis for proportionate transparency, detectability and provenance of synthetic content, with specific safeguards for artistic and creative expression in the Union.25
F. Systemic risk, enforcement, and institutions
Articles 51 and 52 set out the Act’s process for classifying general-purpose AI models as models with systemic risk, including notification, rebuttal, designation and reassessment procedures, which allow the classification to evolve over time as technology advances. The systemic-risk thresholds are not directly relevant to copyrightability; the provisions are nonetheless representative of a broader regulatory framework that is adaptable, evidence-based and periodically reviewed, and that by design can keep pace with technological change to some extent without relying solely on fixed statutory thresholds, a design characteristic of significant value to the present analysis and suggestions.26
Article 53 sets out the core obligations of general-purpose AI model providers and is directly relevant to the topic of this paper. As anticipated in the recitals discussed above, Article 53(1)(c) requires providers to put in place a policy to comply with Union law on copyright and related rights, including identifying and complying with rights reservations under Article 4(3) of the Digital Single Market Directive, while Article 53(1)(d) requires them to draw up and make publicly available a sufficiently detailed summary of the content used for training, according to a template provided by the AI Office. Article 53(4) allows providers to rely on codes of practice to demonstrate compliance with these obligations until a harmonised standard is published, and Article 53(5) and (6) empower the Commission to detail measurement and calculation methodologies and to amend the annexes that underpin these obligations as technology advances. Article 54 requires providers established in third countries to appoint, by written mandate, an authorised representative established in the Union, with specified verification, documentation and cooperation tasks, which makes the practical accountability of third-country providers placing general-purpose AI models on the Union market more visible than the question of copyrightability. Article 55 adds obligations for providers of general-purpose AI models with systemic risk, namely model evaluation including adversarial testing, assessment and mitigation of systemic risks, serious-incident reporting and cybersecurity, with Article 55(2) offering the same flexible route to compliance through codes of practice and Article 55(3) protecting trade secrets and confidential information. Under Article 56, codes of practice serve as an adaptive mechanism for meeting the obligations in Articles 53 and 55: they are drawn up with the participation of providers, monitored and assessed by the Commission and the Board, and reviewed and adapted as technology and regulation develop.27
Articles 88 and 89 establish the enforcement and monitoring system for the general-purpose AI obligations, conferring exclusive supervisory and enforcement powers on the Commission, which entrusts their implementation to the AI Office. Of particular interest for this paper is Article 89(2), which gives downstream providers, that is, providers of AI systems that integrate a general-purpose AI model, the right to lodge a complaint alleging that the provider of that model has infringed the Regulation. This mechanism offers a route to enforcement that does not depend solely on the regulator’s own initiative: downstream providers have a specified procedure for bringing an upstream provider’s non-compliance to the AI Office’s attention.28
Article 90 allows the scientific panel of independent experts to issue a qualified alert to the AI Office where it suspects that a general-purpose AI model poses a concrete identifiable risk at Union level or meets the conditions for classification as a model with systemic risk; upon such an alert the Commission, through the AI Office, may exercise its powers to assess the matter, but the alert does not in itself impose a ban or penalty. Although Article 90 addresses systemic risk rather than the allocation of copyright, its expert-based alert model is a good example of the incorporation of technical expertise into an adaptive regulatory system.29
The remaining articles (91 to 96) complete the Act’s enforcement cycle for general-purpose AI. Article 91 empowers the Commission to request documentation and information from providers in order to assess compliance, the request stating its legal basis and purpose, the information required and the period for supplying it; Article 92 empowers the AI Office to evaluate a model where the information obtained is insufficient or in order to investigate systemic risks, including through independent experts with access to the model; Article 93 enables the Commission to request providers to comply with their obligations, to implement mitigation measures, or to restrict, withdraw or recall a model, and, after a structured dialogue, to make binding the commitments a provider offers; Article 94 extends procedural rights to providers of general-purpose AI models; Article 95 encourages codes of conduct for the voluntary application of requirements, drawn up with the involvement of interested stakeholders; and Article 96 requires the Commission to develop guidelines on the practical implementation of the Act, including the transparency obligations in Article 50, and to update them when necessary. Article 92’s independent technical evaluation and Article 93’s corrective powers show that documentation, copyright-compliance and transparency duties can be backed by expert verification and by coercive supervisory action.30
Finally, Annex XI sets out the technical documentation that general-purpose AI model providers must draw up, including a general description of the model and details of its development and training and, importantly here, information on the data used for training, testing and validation, covering the type and provenance of the data, curation methodologies, and how the data was obtained and selected; this documentation underpins the transparency and copyright-compliance requirements of Article 53. Annex XII defines the corresponding minimum information that providers must make available to downstream providers integrating the model into their AI systems, again including the type and provenance of training, testing and validation data and the curation methodologies used. Both annexes are highly relevant to training-data transparency and value-chain accountability in AI, but only marginally relevant to the distinct question of the copyrightability of AI output.31
Critical evaluation
The EU model is among the strongest when it comes to separating functions. The AI Act does not attempt to resolve every copyright issue through a single set of rules. Instead, it imposes upstream duties concerning copyright compliance, transparency of training content, technical documentation, detectability and institutional supervision, while leaving copyright subsistence and enforcement to the existing copyright system. This reduces the risk that copyright’s fundamental notions will be redefined through a wide-ranging AI law.32
At the same time, the separation creates practical uncertainties. Rightsholders may receive more information about training practices without learning whether a specific output is protected, who its author or source is, or how much human contribution is required. Likewise, training-content summaries can help with enforcement but need not identify every protected work used in training. The EU framework should therefore be seen as an accountability mechanism that complements, rather than replaces, substantive copyright doctrine.33
A second strength is flexibility. Implementation is supported by codes of practice, harmonised standards, technical documentation, authorised representatives, independent evaluation and obligations that can be reviewed and adjusted as general-purpose AI develops. The corresponding risk is complexity: obligations under the AI Act and the copyright directives are spread across several instruments and, unless clearly explained, can create difficulties for creators, small companies and users further down the value chain.
Suggestions
1. Clarify the output-side copyright position: Provide coordinated guidance on how the existing principles of originality and authorship apply to works made with AI, making clear that compliance with the AI Act does not imply that an output is protected by copyright.
2. Coordinate the AI Act with the copyright acquis: Provide practical guidance on how the copyright-compliance obligation in Article 53 relates to rights reservations and the text-and-data-mining provisions of the Digital Single Market framework.
3. Standardise training-content transparency: Build on the Commission’s July 2025 template so that training-content summaries are clear, proportionate and sufficiently detailed for rightsholders to exercise their rights, without requiring providers to disclose protected trade secrets.34
4. Strengthen provenance mechanisms: Encourage interoperable metadata, labelling and machine-readable provenance standards for synthetic content, as far as technically feasible and proportionate.
5. Improve stakeholder access to enforcement: Provide clear and fair avenues for creators, downstream providers and other legitimate complainants to raise concerns about non-compliance and to obtain regulatory action.
6. Maintain adaptive implementation: Maintain codes of practice, harmonised standards, expert evaluation and periodic review so that copyright-related duties keep pace with generative-AI technology.
Conclusion
There is no distinct copyright framework for AI-generated works in the EU, and that is not where the AI Act’s main novelty lies. Instead, the Act secures the copyright accountability of general-purpose AI providers through copyright-compliance policies, transparency about training content, technical documentation, disclosure of synthetic content, institutional supervision and adaptive implementation. These are steps towards greater accountability in the creation and use of generative artificial intelligence, but they do not answer the question whether an individual AI-generated work is protected by copyright.
The copyrightability of outputs therefore remains firmly within the EU copyright acquis and the concept of originality developed by the CJEU. What matters in law is whether the output is the author’s own intellectual creation, reflecting the author’s personality through free and creative choices. Where prompting, selection, arrangement, editing and human-authored content combine in a single creative process, generative AI makes that question more fact-sensitive.
A coherent EU approach should maintain this separation while improving coordination between the two layers. The transparency and accountability of AI providers should be maintained, and copyright law should be guided by clarification of originality and human authorship in works that involve AI. This can safeguard human creative expression, help rightsholders enforce their rights and remain flexible, without requiring a horizontal AI regulation to perform the role of copyright law.
*****
Footnotes
1. Martin Senftleben, Text and Data Mining, Generative AI, and the Copyright Three-Step Test, 57 IIC Int’l Rev. Intell. Prop. & Competition L. 67 (2026), https://doi.org/10.1007/s40319-026-01680-2; Adam Buick, Copyright and AI Training Data: Transparency to the Rescue?, 20 J. Intell. Prop. L. & Prac. 182 (2025), https://doi.org/10.1093/jiplp/jpae102; Andres Guadamuz, The EU’s Artificial Intelligence Act and Copyright, 28 J. World Intell. Prop. 213 (2025), https://doi.org/10.1111/jwip.12330.
2. Eleonora Rosati, Copyright and the Court of Justice of the European Union 82 (2d ed. 2023).
3. Case C-683/17, Cofemel – Sociedade de Vestuário SA v. G-Star Raw CV, ECLI:EU:C:2019:721, ¶¶ 29–30 (Sept. 12, 2019); Case C-145/10, Painer v. Standard VerlagsGmbH, ECLI:EU:C:2011:798, ¶¶ 87–90 (Dec. 1, 2011).
4. Rosati, Copyright and the Court of Justice, supra note 2, at 115.
5. Regulation 2024/1689, of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence and Amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act), art. 1(1), recital 1, 2024 O.J. (L 2024/1689), https://data.europa.eu/eli/reg/2024/1689/oj [hereinafter AI Act], amended by Regulation 2026/1744, of the European Parliament and of the Council of 8 July 2026 Amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as Regards the Simplification of the Implementation of Harmonised Rules on Artificial Intelligence (Digital Omnibus on AI), 2026 O.J. (L 2026/1744), https://data.europa.eu/eli/reg/2026/1744/oj [hereinafter Digital Omnibus on AI]; cf. Irini Stamatoudi & Paul Torremans, EU Copyright Law: A Commentary 54 (2d ed. 2021) (on the general principles of EU copyright law).
6. AI Act, supra note 5, recitals 3–8.
7. AI Act, supra note 5, pmbl., art. 1(1), recitals 3, 8; Consolidated Version of the Treaty on the Functioning of the European Union arts. 16, 114, 2016 O.J. (C 202) 47; cf. Stamatoudi & Torremans, supra note 5, at 312 (on the Information Society Directive).
8. AI Act, supra note 5, art. 27(1), recital 96.
9. AI Act, supra note 5, art. 2(1); cf. Paul Goldstein & P. Bernt Hugenholtz, International Copyright: Principles, Law, and Practice 124 (4th ed. 2019) (on the territoriality of copyright).
10. AI Act, supra note 5, art. 2(2)–(12); Digital Omnibus on AI, supra note 5, art. 1(2)(a) (replacing AI Act art. 2(2)); see also Eur. Comm’n, Guidelines on Obligations for General-Purpose AI Providers, Shaping Europe’s Digital Future (last updated Nov. 11, 2025), https://digital-strategy.ec.europa.eu/en/faqs/guidelines-obligations-general-purpose-ai-providers.
11. AI Act, supra note 5, art. 3; see generally Le Cheng, Copyright Issues Related to Generative Artificial Intelligence (AI) 37 (2026), https://doi.org/10.1007/978-981-95-8781-0.
12. AI Act, supra note 5, art. 3(1); Cheng, supra note 11, at 69.
13. AI Act, supra note 5, art. 3(3)–(5), (8)–(13), (23); see also Eur. Comm’n, Guidelines on Obligations for General-Purpose AI Providers, supra note 10.
14. AI Act, supra note 5, art. 3(29)–(33); World Intell. Prop. Org., Generative AI: Navigating Intellectual Property (2024), https://www.wipo.int/export/sites/www/about-ip/en/frontier_technologies/pdf/generative-ai-factsheet.pdf.
15. AI Act, supra note 5, art. 3(19), (26), (47), (53)–(56).
16. AI Act, supra note 5, art. 3(60), (63)–(66), (68); see also Kateryna Militsyna, Can Copyright Law Benefit from the Marking Requirement of the AI Act?, 56 IIC Int’l Rev. Intell. Prop. & Competition L. 1734 (2025), https://doi.org/10.1007/s40319-025-01624-2.
17. AI Act, supra note 5, recitals 97–100; Eur. Comm’n, General-Purpose AI Obligations Under the AI Act, Shaping Europe’s Digital Future (last updated Aug. 1, 2025), https://digital-strategy.ec.europa.eu/en/factpages/general-purpose-ai-obligations-under-ai-act (noting that the Commission’s guidelines treat a model as general-purpose where it is trained with more than 10²³ FLOP and can generate language).
18. AI Act, supra note 5, recitals 101–103; see also Buick, supra note 1.
19. AI Act, supra note 5, art. 53(2), recital 104; Directive 2019/790, of the European Parliament and of the Council of 17 April 2019 on Copyright and Related Rights in the Digital Single Market and Amending Directives 96/9/EC and 2001/29/EC, art. 4(3), 2019 O.J. (L 130) 92 [hereinafter DSM Directive]; see also Senftleben, supra note 1 (discussing the rightholder opt-out in rules permitting text and data mining for AI training).
20. AI Act, supra note 5, recitals 105–106; DSM Directive, supra note 19, arts. 3, 4; Eleonora Rosati, Copyright in the Digital Single Market: Article-by-Article Commentary to the Provisions of Directive 2019/790 45 (2021); see also Goldstein & Hugenholtz, supra note 9, at 305 (on economic rights).
21. AI Act, supra note 5, recitals 107–109; Eur. Union Intell. Prop. Off., The Development of Generative Artificial Intelligence from a Copyright Perspective (2025), https://doi.org/10.2814/3893780.
22. AI Act, supra note 5, recitals 97–109; cf. Rosati, Copyright in the Digital Single Market, supra note 20, at 66 (discussing Article 4 of the DSM Directive).
23. AI Act, supra note 5, recitals 132, 134; Militsyna, supra note 16, at 1742.
24. AI Act, supra note 5, arts. 4, 50(2), (4), (7), as amended by Digital Omnibus on AI, supra note 5, art. 1(5), (20). Article 50 applies from Aug. 2, 2026, and providers of generative AI systems placed on the market before that date have until Dec. 2, 2026 to comply with Article 50(2). AI Act, supra note 5, arts. 111(4), 113, as amended by Digital Omnibus on AI, supra note 5, art. 1(39)(b); cf. Johannes Fritz, Understanding Authorship in Artificial Intelligence-Assisted Works, 20 J. Intell. Prop. L. & Prac. 354 (2025), https://doi.org/10.1093/jiplp/jpae119 (on authorship in AI-assisted works).
25. AI Act, supra note 5, art. 50; Axel Brando, Technological Aspects of Generative AI in the Context of Copyright: Attribution and Novelty in Generative AI Hypersurfaces (Eur. Parl., Pol’y Dep’t for Just., Civ. Liberties & Institutional Affs., Briefing PE 776.529, July 30, 2025), https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/776529/IUST_BRI(2025)776529_EN.pdf.
26. AI Act, supra note 5, arts. 51–52; Eur. Comm’n, Guidelines on the Scope of Obligations for Providers of General-Purpose AI Models Under the AI Act, Shaping Europe’s Digital Future (last visited Sept. 14, 2026), https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act.
27. AI Act, supra note 5, arts. 53–56, as amended by Digital Omnibus on AI, supra note 5, art. 1(21) (replacing AI Act art. 56(6)). Chapter V has applied since Aug. 2, 2025, and providers of models placed on the market before that date must comply by Aug. 2, 2027. AI Act, supra note 5, arts. 111(3), 113(b). The General-Purpose AI Code of Practice was published on July 10, 2025, with chapters on transparency, copyright, and safety and security. Eur. Comm’n, The General-Purpose AI Code of Practice, Shaping Europe’s Digital Future (last updated July 31, 2026), https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai; see also Kalpana Tyagi, Copyright, Text & Data Mining and the Innovation Dimension of Generative AI, 19 J. Intell. Prop. L. & Prac. 557 (2024), https://doi.org/10.1093/jiplp/jpae028.
28. AI Act, supra note 5, arts. 88–89; see also Guadamuz, supra note 1.
29. AI Act, supra note 5, arts. 68, 90.
30. AI Act, supra note 5, arts. 91–96; cf. Buick, supra note 1, at 186.
31. AI Act, supra note 5, art. 53(1)(a)–(b), annex XI, § 1, pt. 2(c), annex XII, pt. 2(c).
32. Tyagi, supra note 27, at 563.
33. Fritz, supra note 24, at 360.
34. AI Act, supra note 5, art. 53(1)(d); Eur. Comm’n, Explanatory Notice and Template for the Public Summary of Training Content for General-Purpose AI Models (July 24, 2025), https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models.