Who owns AI ad copyright risk after GEMA v. OpenAI?
The GEMA v. OpenAI ruling turns copyright risk on AI-generated ad creative into a brand-level problem: the advertiser who publishes an unchecked asset is the likelier enforcement target than the tool vendor. Here's what the Munich court actually held — and the verification steps media buyers should run before an AI asset goes to paid media.
- Platform
- Cross-platform
- Creative type
- AI image and text ads
- Failure type
- copyright clearance risk
- Last reviewed
- 0-08-26
The uncomfortable moment comes before upload, not after the legal memo arrives. A growth lead has an AI-assisted headline, a generated image, maybe a few variants from a creative tool, and the campaign is waiting in a paid media account. The question is practical: if this asset contains protected material, does the risk sit with the model provider, the creative-tool vendor, or the brand about to publish it?
The narrow answer after the GEMA v. OpenAI copyright case is this: the Munich ruling does not directly decide AI ad tools risk. It concerned nine German song lyrics and OpenAI’s GPT-4 and GPT-4o models, not Performance Max, Advantage+, third-party ad creative generators, or ChatGPT-assisted ad copy workflows. But the ruling makes one assumption harder to defend: that generated output is automatically “the vendor’s problem.” Once the brand publishes the asset into paid media, the brand becomes the visible party in market and the more obvious enforcement target.

That is analysis, not a holding from the court. The holding itself is narrower, and it matters to keep it narrow. If a team turns this case into a blanket claim that every AI ad generator now creates direct brand liability in Germany, it has gone further than the materials support. If a vendor tells the buyer there is nothing to check because the platform generated it, that is also too casual.
What the Munich court actually decided
The case record is concrete. GEMA filed the action on Nov. 13, 2024, before the Munich Regional Court I, 42nd Civil Chamber, under docket 42 O 14139/24. The court decided the case on Nov. 11, 2025. The works at issue were nine German lyrics, including “Atemlos,” “Männer,” and “Über den Wolken,” and the models discussed were GPT-4 and GPT-4o. The court largely upheld claims for injunctive relief, disclosure, and damages, while dismissing personality-right claims. [1]
For ad teams, the useful part is not a grand theory of AI. It is the court’s treatment of two different points in the chain: what happens inside the model during training and memorization, and what happens when a user gets output that closely tracks protected work.
| Issue in the case | What the ruling summary says | Why media buyers should care |
|---|---|---|
| Training and memorization | Model weights could themselves be treated as copyright reproductions under §16 UrhG and Article 2 of the InfoSoc Directive when protected lyrics were durably memorized. | The court did not treat the AI system as a liability-free black box merely because the copying was embedded in model operation. |
| Output | Near-verbatim lyrics produced through simple prompts were treated as reproduction, adaptation, and communication to the public. | The legally sensitive moment is not only model training. A user-facing output can create a separate publication problem. |
| Text and data mining defense | The TDM exception failed where durable memorization went beyond analysis. | A workflow cannot assume that “the model was trained under an exception” clears later output. |
| Personality-right claims | Those claims were dismissed. | They are not the useful center of gravity for an ad-upload copyright workflow. |
The output point is the one that travels most easily into a media-buying workflow, even though the case was about lyrics. The court’s concern was not that GPT-4 or GPT-4o generated something vaguely inspired by familiar songs. The case summary describes near-verbatim output reached through simple prompts. That distinction matters. A paid social image that merely uses a common visual convention is not the same fact pattern as an AI-generated line of copy that closely reproduces a protected lyric, script, slogan, or product description.
The training point still matters, but in a different way. If model weights can be analyzed as reproductions where protected works have been durably memorized, the court is not accepting a clean separation between “the system learned” and “nothing was copied.” For buyers, that does not mean they can audit model weights. They usually cannot. It does mean that a vendor’s assurance that generation is automated does not answer the narrower launch question: what exactly are we about to put in public?
The ruling is not about ad tools, but it changes the risk conversation
A media buyer should not read GEMA v. OpenAI as if the Munich court had reviewed a campaign built inside an ad platform. It did not. The court did not rule on a retail media banner, a Meta Advantage+ creative variant, a Google Performance Max asset, or a third-party generator connected to a creative approval queue. Those are different tools, different fact patterns, and potentially different contracts.
The useful extrapolation is narrower: the ruling gives plaintiffs and advisers a stronger way to look at unchecked AI output. If a model can produce near-verbatim protected material through ordinary prompting, and if that output can be treated as a legally relevant reproduction or communication when shown to the public, then the last-mile publisher cannot treat the tool as a complete shield.

This is where the risk transfer becomes operational. The model provider may be upstream. The AI creative vendor may sit inside a production chain. The agency may have generated the asset. But the published ad is easy to find, screenshot, archive, and attach to a demand letter. The advertiser or retailer whose name appears in market is easier to identify than the technical service that helped create the asset.
CMS and Hunton guidance points in that direction: when an advertiser or retailer publishes unchecked AI-generated output, that publishing party is the practical enforcement target, rather than the third-party tool vendor buried upstream. [2][3]
That does not mean the vendor has no responsibility. Contracts, indemnities, platform terms, and local law can matter. But none of those documents are the asset currently being delivered to users. At launch time, the person pushing the campaign live needs a yes-or-no answer about the creative in front of them, not a theory that someone else may be brought into the dispute later.
Who carries the risk after publication?
Before publication, the risk is distributed across the production chain. A model provider controls the underlying system. A tool vendor controls the interface, guardrails, and commercial promises. An agency or internal team controls prompts, edits, approvals, and upload. After publication, the risk becomes easier to aim at the brand because the allegedly infringing material is no longer a private generation event. It is an ad.
That is the part many AI creative workflows underprice. The output may have passed through a chat interface, a design tool, a feed generator, and a media platform before anyone outside the company saw it. The claimant does not need to understand that chain to notice a protected lyric, a near-verbatim paragraph, or a copied visual element in a public placement. The public asset gives them the first target.
For a small agency, this also affects client service. If the agency uses AI to create variations and the client publishes them, the client may still ask why the agency delivered an unchecked asset. If the client generated the asset internally and asks the agency only to traffic it, the agency still needs a record of what it reviewed and what it did not review. The launch checklist is where these responsibilities become visible.
The Munich ruling supports a cautious mental model: treat AI output as unverified material until it has been checked. Not because every AI asset is infringing, and not because this lyrics case directly governs every ad tool. The reason is simpler. The court took near-verbatim machine output seriously, and paid media publication is the step that turns an internal draft into a public communication.
What to add before the paid media upload
A verification gate does not need to become a legal department inside the media team. It needs to create a documented pause between generation and publication. The point is to make sure someone checked the asset that will actually run, not just the prompt idea or the first draft.

For AI-assisted ad creative, the gate should sit after final edits and before upload or campaign activation. Earlier review is useful, but the last version is the one that matters. A headline changed during trafficking, a regenerated image, or an automatically suggested variant can be the version that creates the problem.
- Keep the generation record: tool used, date, prompt or creative instruction where available, output version, and the final asset name.
- Check text for near-verbatim matches: distinctive phrases, lyrics, long copied sentences, recognizable taglines, or unusually familiar product language should be searched and escalated.
- Check images for obvious source dependence: if the output resembles a known campaign, character, artwork, album cover, celebrity image, or stock asset, do not treat “AI-generated” as clearance.
- Separate inspiration from reproduction in the approval note: “generated from campaign brief and edited by team” is more useful than “AI made it.”
- Assign a named approver before launch: the media buyer should not be the only person discovering copyright concerns five minutes before activation.
- Preserve the approved version: store the reviewed file, ad ID or asset ID, approval timestamp, and any escalation outcome.
The check should be proportionate to the asset. A generic sale badge may need little more than ordinary brand review. A music-adjacent campaign line, a parody lyric, a generated illustration of a recognizable entertainment property, or copy prompted from a competitor’s landing page needs more scrutiny. The GEMA facts are a useful reminder of why: the problem was not that output existed, but that protected expression allegedly came back in a form close enough for the court to treat it as legally significant.
The approval note can stay plain. For example: “AI-assisted copy reviewed for distinctive third-party text; no near-verbatim match found in final headline and primary text; approved for campaign upload.” If something was changed because it looked too close to a source, say that. If legal reviewed it, note that. If the vendor supplied a clearance representation, attach it, but do not let that replace review of the final ad.
This is not a promise that documentation prevents a claim. It is a way to avoid the weakest position: a public AI-generated ad with no record of who checked it, what version was checked, or why anyone believed it was safe to publish.
The launch rule
After GEMA v. OpenAI, the safest working rule for media buyers is limited but firm: AI-generated creative is unverified until someone has checked, documented, and approved the final asset before it goes live. The case does not turn every AI ad tool into the same legal fact pattern as memorized song lyrics. It does make the vendor-side shrug less useful when the brand is the one putting the output into market.
References
- Landmark ruling of the Munich Regional Court (GEMA v OpenAI) on copyright and AI training — Bird & Bird
- Guidance on AI-generated advertising and copyright risk — CMS
- Guidance on AI-generated advertising and copyright risk — Hunton
This is a record of what happened and what was tested, not legal advice. Compliance determinations require qualified counsel.