Germany has no standalone AI-specific IP rules. Existing IP laws, especially copyright, patent and trade mark law, are instead applied to deal with AI-related questions, supplemented by EU-wide obligations. This is most visible in the following areas.
Copyright
No dedicated statute governs AI-generated works. Authorship remains reserved to natural persons, so purely AI-generated content without relevant human input falls outside protection. A genuine human creative contribution, through selection, arrangement or editing, can still gain copyright protection.
Patents
The same pattern applies to inventions. Courts have confirmed that only a natural person can be named as inventor, including in proceedings concerning an AI system named as sole inventor. AI-assisted inventions remain patentable if a human inventive contribution can be identified.
Text and Data Mining
Statutory exceptions permit the reproduction of lawfully accessible works for text and data mining, reversing the usual consent requirement: mining is allowed unless rightsholders opt out through a machine-readable reservation. Recent case law is testing this exception’s boundaries, including whether it covers a model retaining and reproducing protected content, or only the training process.
EU legislation is the decisive driver of Germany’s AI and IP framework.
The AI Act is the most significant instrument, setting out a broad range of obligations spanning from transparency and training-data disclosure duties for providers of general-purpose AI models to labelling requirements for AI-generated or manipulated content aimed at end users. Patent examination follows the European Patent Convention, under which the European Patent Office (EPO) has likewise refused to recognise an AI system as inventor. Non-binding initiatives, including the WIPO Conversation on IP and AI and the OECD AI Principles, inform policy debate without creating enforceable rights.
Foreign Rightsholders and AI Developers
Foreign rightsholders benefit from the same protection as domestic ones. Foreign AI developers, by contrast, face no lighter regime for a different reason: the AI Act itself applies to any provider placing a model on the EU market, regardless of where it is established, and non-EU providers must appoint an EU-based authorised representative.
German IP statutes contain no definitions for AI-related terms such as AI system, generative AI, foundation model or training data. Copyright, patent, trade mark and design law all use general, technology-neutral terms, such as work, invention or reproduction, that pre-date AI and have not been expanded to cover AI-specific terminology.
The AI Act does define several of these terms, but within a regulatory framework aimed at safety, transparency and market oversight, not at IP law. Nothing prevents a court from looking to such a definition for orientation when interpreting a matter at the intersection of IP and AI, but it is not bound to do so, and no IP statute formally adopts any of them. More fundamentally, IP law has not needed dedicated AI definitions in the first place, since its existing, technology-neutral concepts are broad enough to capture AI-related facts without any AI-specific vocabulary. This has not made the underlying interpretative work disappear, however, only relocated it: rather than a legislative definition, the concretisation now happens mainly through case law resolving open questions, sometimes only at the highest court level.
AI-related IP matters in Germany are handled by the same institutions responsible for IP law generally.
Patent and trade mark examination remains with the German Patent and Trade Mark Office (DPMA) and, for European patents, the EPO. The EPO has issued specific examination guidance for AI and machine-learning inventions, treating them as a subcategory of computer-implemented inventions subject to the usual technical-character requirements.
Disputes are heard by the ordinary civil courts, particularly the specialised copyright, trade mark and patent chambers of the regional courts, with the Federal Court of Justice as final instance. These courts apply existing procedures to AI-related questions.
A separate regulatory track has emerged under the AI Act: the “Bundesnetzagentur” acts as Germany’s national market surveillance authority, while the European Commission’s AI Office oversees compliance by providers of general-purpose AI models. Their remit concerns AI safety and transparency rather than IP rights as such, though it intersects with copyright compliance obligations.
No single regime covers an AI system as a whole; different elements attract different, sometimes overlapping, forms of protection.
Source code, documentation and sufficiently original prompts may fall within copyright protection, while training datasets and benchmarks are typically protected as compilations under the sui generis database right regardless of creativity. Database protection under copyright law applies only in exceptional circumstances. Model architecture, weights, embeddings and purely functional elements such as application programming interfaces may fall outside both regimes and are instead protected, if at all, through confidentiality as trade secrets or, in the narrow circumstances where the AI functions as software embedded within a technical solution to a concrete technical problem, through patents.
Copyright protection for AI-related software follows the general regime for computer programs: protection requires only that the code constitutes the author’s own intellectual creation, a comparatively low threshold that most non-trivial source and object code will meet. No additional qualitative or aesthetic criteria apply, and protection does not extend to the underlying ideas or principles, including those underlying interfaces.
The trained model, ie, its weights, raises particular difficulties. Only natural persons can be authors, so protection requires that the result be shaped by human creative effort rather than merely produced by technical tools. This may still be argued for supervised or reinforcement learning, where concrete outputs can be attributed to human choices, but it is excluded for unsupervised learning. Separately, weights typically do not issue control commands to a computer by themselves, which is the key characteristic of a computer program as opposed to mere data. They only become part of an executable program once embedded in a broader AI system. For both reasons, the trained model as such potentially falls outside copyright protection.
AI-related inventions made by the model creator, such as improvements to architecture or training methods, are assessed under the ordinary rules for computer-implemented inventions rather than any AI-specific regime.
Mathematical methods and computer programs are excluded from patentability “as such”. An invention must therefore make a technical contribution, solving a technical problem by technical means, rather than merely producing a better algorithm in the abstract. Following the EPO’s Enlarged Board of Appeal (G 1/19), a neural network or training method is patentable only where it has a demonstrable link to a technical purpose or physical process.
Sufficiency of disclosure raises a genuinely AI-specific difficulty: because a model’s behaviour depends heavily on its training data and hyperparameters, an application must disclose enough about the training method, and where relevant the datasets used, to allow a skilled person to reproduce the claimed effect. Claims are typically drafted as computer-implemented method or system claims defining concrete technical steps, rather than claims to the underlying model itself.
AI models, weights, datasets, prompts, system instructions, evaluation data and deployment know-how can all be protected as trade secrets under the German Trade Secrets Act, which implements the EU Trade Secrets Directive. Protection requires the information to be secret, to have commercial value because of that secrecy, and to be subject to reasonable measures to keep it confidential.
What counts as reasonable varies with the value of the information and the size of the organisation, but typically includes access controls, encryption, contractual confidentiality obligations with staff and contractors, and internal classification policies. Such measures become especially important where the model itself, including its algorithm and weights, is handed over to a third party for use, as the holder must actively safeguard secrecy to avoid losing protection.
Regulatory transparency obligations under the AI Act create a tension with secrecy, particularly for providers of general-purpose AI models. Requirements to share technical documentation, such as details on model architecture, parameters and training methods, with regulators and in part with downstream providers risk requiring disclosure of information. How this tension is resolved in practice, including through the Act’s confidentiality safeguards, remains to be seen. By contrast, the obligation to publish a training-data summary appears less problematic: even where the underlying data has trade secret quality, a summary is not expected to reveal the actual data, which would in any event be impractical given its volume.
Datasets, databases and other data compilations used or created by a model creator can be protected under several regimes, which may apply next to each other.
The sui generis database right protects a database against extraction or reuse of a substantial part where its compilation requires substantial investment, regardless of originality. This makes it the most relevant regime for training datasets and benchmarks. In exceptional cases, copyright can also arise where the selection or arrangement of a database’s contents is itself an original creation, protecting that structure rather than the content itself.
One key limit applies to data generated rather than sourced by the model creator: only investment in gathering existing material counts towards the substantial investment required for the sui generis right, not investment in creating new data. This raises the question of whether synthetic datasets generated by the model creator’s own systems can be protected as a database at all.
Whether the trained model itself counts as a database is also unclear. This depends on whether individual weights can be seen as independent elements, given that their value lies in the trained network as a whole, and on whether the investment involved is substantial and aimed at obtaining data rather than generating it. Views differ, and the answer likely depends on the specific model.
Beyond IP, contractual restrictions on access and use and trade secret protection provide additional and often more practically significant layers of protection for data and datasets. Unfair competition law may also provide protection, although this route is doctrinally uncertain and rarely provable in practice.
So far, first-instance decisions suggest that copying, scraping, ingesting, tokenising or otherwise processing a copyright work to build or operate an AI system is treated as a copyright-relevant act of reproduction (“memorisation”), regardless of whether the work is freely accessible online; public availability does not amount to a licence for this kind of use. This applies across the entire pipeline: from initial dataset compilation, through fine-tuning, to retrieval-augmented generation and evaluation.
The clearest area of legal certainty is that using unlawfully sourced material falls outside any available justification altogether. The main uncertainty concerns how far any applicable exception reaches once training is complete: whether it covers only the initial copying step or also extends to the fact that a trained model can retain and later reproduce elements of a work.
Several exceptions can justify copying works for AI development and training, though none was designed with AI specifically in mind (which some dispute) and each has real limits. A general text and data mining exception (§ 44b UrhG – German Act on Copyright and Related Rights) permits automated analysis of lawfully accessible works to extract patterns, trends or information, available for both commercial and non-commercial use, but the works must be deleted once no longer needed and rightsholders may opt out. A narrower research exception (§ 60d UrhG) applies without an opt-out where a qualifying non-profit research organisation is involved, but not to ordinary commercial product development. Other exceptions for temporary or incidental copying, quotation or private use can occasionally be argued for narrow, specific steps, but rarely justify (commercial) AI trainings as a whole process.
Lawful access to the source material is a strict requirement throughout; content obtained unlawfully cannot be brought within any of these exceptions regardless of the purpose. The central uncertainty is less about the exceptions’ wording than about how far they extend once training moves from mere analysis to building the retained capabilities of a model.
A specialised copyright chamber of the Munich Regional Court has twice taken the narrower view, against OpenAI (LG München I, 11 November 2025, 42 O 14139/24) and, more recently, against the music-AI provider Suno (LG München I, 31 July 2026, 42 O 763/25). It held in both cases that permanent retention and reproduction of works within a model goes beyond mere analysis. Neither ruling is yet final, an appeal in the OpenAI case is pending before the Federal Court of Justice (BGH – I ZR 281/25), and a related CJEU proceeding (C-250/25, Like Company v Google Ireland) is ongoing, so the underlying question is not yet settled.
Formal licensing markets for AI training content are still emerging rather than settled. No general statutory or compulsory licence exists for AI training under German law, and there is no established extended collective licensing scheme for this purpose either.
In practice, licensing is developing primarily through collecting societies. The German music rights organisation GEMA launched a bundled dataset product in July 2026, combining audio files, metadata, and both authorship and master rights from several partner publishers, with a specialist music-technology company as its first paying licensee, and other collecting societies are pursuing comparable collective licensing models for their own repertoires. The general orphan-works and out-of-commerce-works mechanisms available to libraries, archives and cultural heritage institutions exist under German law but were designed for preservation and access purposes, not commercial AI training, and are not a realistic route for developers.
Overall, the market remains fragmented, with collecting-society models now emerging as the most concrete form of licensing infrastructure to date, alongside continued bilateral negotiation and litigation pressure.
A machine-readable rights reservation is recognised and enforceable under the general text and data mining exception, removing the exception’s protection once validly made. What counts as machine-readable remains genuinely unsettled, however, since neither the statute nor a binding technical standard defines the term. Courts have begun refining rather than resolving the test: recent guidance from the court requires that a notice be machine-interpretable, not merely machine-detectable, a particularly high bar for natural-language wording that does not explicitly mention mining. Natural-language notices, robots.txt entries, and emerging protocols such as the TDM Reservation Protocol or content-provenance metadata all remain competing, unconfirmed options. None of these technical markers carries independent legal status in itself; they matter only as the vehicle through which a valid reservation is expressed. Private licensing registers and similar contractual arrangements sit outside this framework entirely, operating as voluntary market tools rather than as sources of statutory rights, though the European Commission is currently exploring the feasibility of an EU-level opt-out registry.
This legal effect does not depend on how the content was accessed: where an autonomous agent encounters a valid reservation during browsing, retrieval or tool use, the exception is unavailable regardless of whether the agent detects, ignores or fails to process the notice, since validity is assessed objectively.
Documentation and logging duties primarily result from the AI Act rather than any free-standing German statute. Providers of general-purpose AI models must publish a summary of training content, maintain a copyright compliance policy honouring rights reservations, and keep technical documentation available to the AI Office.
Stricter requirements, including data governance, technical documentation and behavioural logging, apply wherever a system is used in one of the sectors the AI Act treats as high-risk.
Cross-border infringement is a separate question governed by ordinary copyright rules: what matters is simply where the infringing act, whether a reproduction or a later communication of output to the public, actually takes effect or is directed at Germany, not where the underlying system is operated. The AI Act’s own territorial scope operates independently on the same logic, catching any provider or deployer whose system or output reaches the EU market.
To succeed with a direct infringement claim, a rightsholder must establish that a protected subject matter was used at some stage of the AI training or development process, and that this use falls within one of the acts reserved exclusively to the relevant IP rightsholder.
If the developer or provider can rely on an exception, the claim will fail. If not, the claimant needs to establish a credible link between its specific work and what the system produced. A German court has so far not required proof that specific, identifiable data corresponding to that work exists within the model itself (LG München I, 42 O 14139/24, Gema/Open AI, currently on appeal).
A first-instance decision in Germany indicates that model weights and parameters can themselves constitute an infringing reproduction, even where no single, discrete dataset within the model corresponds to a particular work. The Munich Regional Court held that a work’s content can be reproducibly embedded across a model’s parameters in a dispersed form, drawing an analogy to progressively encoded file formats in which information is spread across the file rather than stored as a contiguous block, and that the ability to retrieve this content indirectly through prompting was sufficient to make it perceptible for the purposes of the reproduction right (LG München I, 42 O 14139/24, Gema/Open AI).
The court distinguished “memorisation”, understood as a property of the trained model itself, from regurgitation, understood as the appearance of memorised content in a specific output, treating the latter as strong evidence of the former without treating the two as legally identical.
On substantial similarity, the court applied a recognisability standard rather than an overall-impression test: infringement takes place when a work’s original, creative elements remain identifiable in the output, irrespective of surrounding alterations. On this basis, outputs that reproduce song lyrics with variations, including partial hallucinated passages, were still found to infringe where the protectable core of the work remained recognisable, indicating a comparatively low threshold before de minimis copying is excluded.
Where a user relies on an AI tool to commit an infringement, the model provider cannot simply point to the user as the party that carried out the act in order to exclude its own liability. The safe harbours that do exist under German law are narrow: they were designed for intermediaries that merely host or transmit third-party content, not for systems that actively generate new content of their own. So far, courts have not extended these safe harbours to providers of (generative) AI. It remains unresolved under German law, however, whether the provider can additionally be held liable alongside the user in cases where the user is found to be the direct infringer. Indeed, in the context of ordinary prompting, the GEMA/OpenAI decision held that the provider retains control over the output and remains liable for it, unless the user has specifically provoked the infringing content through an elaborate or targeted prompt; a simple, open-ended prompt does not shift control, and therefore liability, to the user.
Where the AI system itself effectively “acts” (eg, an autonomous agent, or similar automated content generation), German case law suggests a trend towards direct liability of the provider. In a recent, not yet final, decision, the Munich Regional Court (LG München I, 28 May 2026 – 26 O 869/26) held Google directly liable for AI-generated content summarising search results, since the output went beyond a mere link to third-party material and amounted to Google’s own statement. The court rejected reliance on the intermediary safe harbours under the Digital Services Act and German law, as these only protect providers that merely store or relay third-party content. The decision concerned personality rights rather than IP, but the reasoning appears transferable.
Confidentiality issues arise wherever confidential material from a third party is introduced into an AI system, whether through training, fine-tuning, prompting, being retained in memory, retrieved by an agent, accessed via a tool call, or used for evaluation. The starting point is that a trade secret only remains protected for as long as it has not been disclosed, has not been made public with the consent of the rightsholder and remains subject to reasonable safeguards. Disclosing it to a system outside the rightsholder’s control can compromise both.
Liability typically depends on authorisation. If a business or individual was not permitted to disclose the material in that way, they may be liable to the rightsholder, particularly where they were bound by a confidentiality obligation. The AI provider, meanwhile, is unlikely to be directly liable for using or storing such material, since liability under the German Trade Secrets Act requires that the provider knew or ought to have known that the information had been unlawfully disclosed. This threshold is typically only met once the provider has been put on notice.
Separate issues arise once a model reproduces, infers, or reveals such information to another user.
The main exceptions and defences, text and data mining and the narrow intermediary safe harbours, have already been discussed above. German law has no general fair-use doctrine.
Providers have raised several further defence strategies, generally without success. Arguments such as independent creation, that outputs are an autonomous act of creation rather than a reproduction, was rejected where the output was causally traceable to memorised training data. The argument of an implied licence, based on the work having been freely available online, was rejected, since ordinary online availability does not imply consent to AI training use. Abuse of rights, framed as an attempt to force a licensing model through litigation, was rejected in the absence of evidence that the claim went beyond the specific infringement.
So far, courts have applied these defences strictly and shown little willingness to treat AI training or output generation as a special case.
AI-generated output is assessed under the ordinary copyright rules like any other content: where it reproduces the protected, original features of a work, it can infringe copyright unless covered by an exception, regardless of whether a human or an AI system produced it. The Munich Regional Court has held that close reproduction of training content in output can indicate that the work was effectively stored and reproduced within the model (LG München I, 42 O 14139/24, Gema/Open AI). Output that reproduces protected content supplied by the user, through the prompt or a reference image, is judged the same way as any derivative work. Style, genre or technique alone is not protected, only concrete expression, so an output that merely evokes a recognisable style without copying specific protected features generally does not infringe.
A user or deployer can infringe without knowing it, since awareness is not required for an infringing act to occur, only for a damages claim. In practice, it is difficult to hold the AI provider liable for the generation step itself, so liability towards third parties tends to fall on whoever publishes, distributes or commercially uses the output. Careful prompting and human review reduce practical risk but do not change the underlying infringement analysis. Reliance on provider terms of service offers little protection either way: such terms cannot bind third-party rightsholders, and many providers’ terms go further still, placing responsibility for the output on the user and requiring the (business) user to indemnify the provider against third-party claims. The scale of use mainly affects the level of damages and enforcement priorities rather than whether an infringement has occurred.
Trade mark and unfair competition law apply to AI output the same way as to any other content, once the output is put to commercial use, for example in advertising. There is no AI-specific carve-out. As with copyright, holding the AI provider liable for the generation step itself is generally difficult in practice, so responsibility tends to rest with whoever commercially exploits the output, such as by using it in marketing material.
Patent and design infringement is assessed objectively, by comparing the resulting product, process or design against the protected right, regardless of how it was created. Unlike copyright, independent creation is no defence, so an AI-generated design, code or process that happens to fall within an existing patent or design right infringes even without copying or awareness of the earlier right. The party that manufactures, markets or otherwise commercially uses such AI-generated output bears the same exposure as for any conventionally developed product; a damages claim additionally requires fault. Indirect infringement rules apply in the same way where AI-generated instructions or parameters are supplied to a third party that then practises the invention.
Since German law gives AI systems no separate legal personality, responsibility for an infringing act carried out autonomously by an agent, be it scraping content, calling external tools, generating material, publishing output, or making product or design choices, falls on whoever deployed, configured or benefited from that agent. Which regime applies to the retrieval or analysis step itself depends on the right in question: copyright offers a text and data mining privilege for mere analysis of lawfully accessible works, but trade mark and patent law know no equivalent exception, so an agent that reproduces a protected mark or technical content while gathering material can implicate those rights regardless of purpose. Much as with single-turn AI use, exposure tends to arise not at the point of internal decision-making, but once the agent’s output is actually published, commercially deployed, or embodied in a product.
German copyright protection applies when a work reflects a personal intellectual creation, meaning recognisable human creative choices in the concrete final expression, not merely in the idea or instruction behind it.
Prompt engineering usually does not always meet this bar. Because a model’s output is not fully determined by the prompt, and the same prompt can produce materially different results, a court is unlikely to treat the act of prompting as the kind of shaping control over the final expression that authorship requires. Selection and arrangement of multiple generated outputs, substantial editing, and iterative direction across several rounds stand on firmer ground, since these involve concrete human choices about the final form; protection then attaches to that human layer rather than to the underlying generated material as such. Where a protected reference work supplies the starting point, ordinary derivative-work principles apply to the extent its protected features carry through into the output.
Agentic workflows tend to weaken rather than strengthen the case for authorship. Prompt chaining, decomposition, meta-prompting and autonomous task planning all push creative decision-making further into the system and further from direct human control over the final expression, and automated selection of intermediate outputs by the system itself, rather than by a person, removes one of the clearest bases on which human authorship is usually established.
German law recognises no separate right in works that lack a human author altogether. Copyright requires a personal intellectual creation by a natural person; using AI merely as a tool to realise a human creative conception is already covered by ordinary authorship, provided the person’s own creative choices, rather than the AI’s, shape the concrete final expression, essentially the same threshold discussed above for prompt-based and AI-assisted works. Where that threshold is not met, the output simply falls outside copyright protection rather than triggering an alternative, lower threshold right of the kind some other jurisdictions grant to computer-generated works.
Joint authorship requires multiple human contributors whose combined creative input cannot be separately exploited; an AI system cannot hold this status, so joint authorship in an AI-assisted project can only arise between the human participants who together direct, edit or curate the process, not between a person and the AI itself.
Where an output is based on an existing protected work, whether a reference image, a dataset-derived element or earlier drafts, and it carries through that work’s protected expression while adding new creative material, ordinary adaptation rules apply: the resulting work is treated as a derivative work requiring the underlying rightsholder’s consent to exploit, exactly as it would for a human-made adaptation. Ownership shares among multiple human contributors, and permissions needed to use third-party input material, are determined by the same contractual and statutory rules that apply outside the AI context.
Copyright in Germany arises automatically on creation and is not subject to registration, so no disclosure obligation is built into a formal application process as it would be for a registered right. Separately, under certain conditions, the AI Act itself requires AI-generated or manipulated output to be labelled as such towards end users, independent of any copyright registration or enforcement context.
For patents and designs, there is no general duty to disclose that AI was merely used as a tool in developing the subject matter, though the inventor-designation requirement indirectly forces the issue, since only a natural person can be named regardless of how heavily AI assisted. A narrower obligation applies where the invention is itself an AI or machine-learning system: EPO guidelines require enough detail on the underlying methods and training data to let a skilled person reproduce the claimed technical effect. Overstating the human contribution to inventorship carries real risk to validity and entitlement, and in copyright enforcement, claimants increasingly need to prove the human creative process behind an AI-assisted work before protection is accepted.
An AI system cannot be named as inventor, co-inventor or creator. The Federal Court of Justice confirmed in the DABUS proceedings (BGH, 11 June 2024, X ZB 5/22) that only a natural person qualifies as inventor under the Patent Act.
Where an AI agent proposes experiments, selects parameters or generates candidate solutions, the human who directed that process and can be credited with the inventive concept must still be named; practice favours describing that person as having used a named AI system as a tool, rather than treating the AI as a co-creator. Entitlement for employees, contractors, researchers or collaborators using AI tools follows the ordinary rules unchanged, whether under the employee invention framework or the relevant engagement terms. Where an agent generates many candidates with minimal human curation, identifying who meets the inventorship threshold becomes a genuinely harder factual question, resolved case by case rather than by any AI-specific test.
The notional skilled person remains a fictional average practitioner. There is no doctrine yet assuming AI tools as standard equipment. Whether AI methods count as common general knowledge depends on whether such tools were already routine in a given field at the relevant date, for example computational screening in pharma or AI-driven simulations in materials science. Where that is so, applying an established AI tool to find a solution tends to be treated as obvious to try, lowering the inventive-step threshold, unless a surprising technical effect beyond the expected outcome is shown. For enablement, applications relying on machine learning must describe the essential characteristics of training data sufficiently for the claimed technical effect to be reproducible, without needing to disclose the datasets themselves. Regarding prior art, published AI-generated technical documents or reports count as novelty-destroying if they contain an enabling, comprehensible technical teaching. Synthetic datasets can evidence existing knowledge. Meaningless machine-generated text without a reproducible teaching does not qualify.
Design law is open to AI-generated subject matter without qualification. Unlike a patent application, a design application requires no designer to be named, so nothing excludes AI-generated designs from registration. Protection requires novelty, assessed objectively rather than by reference to how the design was produced, and individual character, meaning the overall impression on an informed user differs from existing designs; there is no creative-achievement or authorship threshold as in copyright. Following the recent modernisation of EU design law, protectable products now expressly include graphical user interfaces, icons and other digital or virtual subject matter, including animated features, so avatars and virtual goods fall within the same registrable categories as physical products. Features dictated solely by technical function remain excluded regardless of how they were generated.
Trade dress and product appearance can be protected in Germany cumulatively as a registered or unregistered design, as a trade mark (esp. as a three-dimensional trade mark) or, in the absence of any registration, under unfair competition law against unfair imitation.
Trade mark protection does not depend on a sign’s origin: names, logos, slogans, sounds and motion marks are all recognised categories of registrable sign, regardless of whether a human or an AI system created them.
Ownership follows registration rather than authorship: a trade mark can be held by a legal person, with no natural human rightsholder required at all, unlike copyright or patent law. For AI-assisted brand generation, this means the party that files and owns the registration is the owner, however heavily AI contributed to designing the sign.
Moral rights under German law (rights of disclosure, attribution and integrity) can only be held by natural persons and only attach to material that itself qualifies as a protected work. Where a human makes a sufficiently creative contribution to an AI-assisted output, that person holds full moral rights in it; a wholly AI-generated output attracts no moral rights at all, since there is no human author.
Style imitation raises no moral rights issue as such: style, technique and genre are unprotected ideas rather than protected expression, so an output that merely imitates a creator’s style does not by itself infringe that creator’s rights, unless the output reproduces recognisable protected elements from a specific work, in which case ordinary infringement and integrity-right analysis applies as for any adaptation. This is a separate question from whether training the underlying model on that creator’s works itself constituted an infringement.
Wrongly crediting someone with a work they did not create at all, including AI-generated or AI-altered content falsely presented as theirs, is addressed under the general personality right, which protects against this “identity confusion”.
A person’s name, image, voice and likeness are protected in Germany through the general personality right, derived from the constitutional guarantees of human dignity and free personal development, and applied case by case against competing interests such as freedom of expression.
Several specific aspects of this right are relevant to AI use. The right to one’s own image is protected under the Art Copyright Act and general principles of tort law, requiring consent before a likeness is published or used, subject to narrow exceptions. The right to one’s own voice is treated as a further expression of the same general personality right and has recently been confirmed to extend to AI-cloned voices, with courts awarding a notional licence fee for unauthorised use (LG Berlin II, 20 August 2025, 2 O 202/24). Name is separately protected under the Civil Code, and a performer’s actual recorded performance can additionally engage the neighbouring right for performing artists under copyright law. A entirely synthetic recreation not derived from an existing recording falls under the personality right instead.
German courts also recognise a commercial dimension to personality rights, alongside their non-material, dignity-based core, allowing licensing and damages by analogy. Unfair competition law offers a further, independent basis where AI output falsely suggests a celebrity’s endorsement.
AI and IP disputes go through the same forums as any other IP dispute, with no dedicated AI court, tribunal or office. Infringement claims are heard by the ordinary civil courts, regardless of the right at issue. Registration, opposition and invalidity proceedings, by contrast, run through the relevant office: the DPMA for national patents, trade marks and designs; the EPO Boards of Appeal for European patents; and the European Union Intellectual Property Office for EU trade marks and designs. Arbitration and mediation remain available on the usual contractual basis, with no AI-specific mechanism in place.
Claimants cannot enforce broad disclosure of training data, model weights, source code or internal logs as a matter of course. A statutory information claim obliges an infringer to disclose the scope of the infringing use and resulting revenues once infringement is established, mainly to quantify damages rather than investigate liability.
In practice, claimants rely on indirect evidence, comparing outputs against known training material, combined with a shifted burden: once a plausible case is shown, the defendant bears a secondary burden of explanation, since the relevant technical processes lie entirely within its own sphere. Courts can also classify sensitive information as confidential on request, limiting access to it during proceedings to protect trade secrets.
The first German decisions on AI model training followed this pattern, finding infringement through output-to-training-data comparison and a secondary burden on the provider, without ordering disclosure of training data, source code or model weights.
Recent German case law involving AI models has granted final injunctions prohibiting the specific infringing acts identified, reproduction during training, reproduction within the model itself, and reproduction or communication to the public via outputs, together with an information claim, a declaration of liability for damages, and a right to publish the judgment. The courts did not elaborate on how compliance should be achieved.
A stop to training or deployment is achievable indirectly, since prohibiting the underlying act of reproduction or communication effectively forces the defendant to stop training on or offering the infringing content, though the order targets the act rather than the process itself. Removing works from a training dataset, deleting or quarantining a model version, or requiring filters would in principle fall within the general destruction, recall and corrective-measures provisions available under German IP law, but this has not yet been tested for a trained model; the technical means of compliance – retraining, filtering or deletion – have so far been left to the defendant.
Interim relief is available in principle where urgency can be shown and could in theory be used to preserve evidence or to stop an ongoing infringement pending final judgment, but claimants in the reported cases have not sought it, relying instead on final relief.
Damages across German IP regimes follow a parallel structure: the rightsholder may claim its actual loss, an account of the infringer’s profits, or a reasonable royalty by analogy to a hypothetical licence, choosing whichever yields the highest figure.
Non-monetary remedies include injunctions, information/accounting claims and a right to publish the judgment at the defendant’s cost. Destruction or recall claims exist in principle, but have not been raised in an AI case so far, so how they would apply to a trained model, whether requiring full deletion, selective “unlearning” of specific content or retraining, remains untested.
Territoriality follows the principle of territoriality (Schutzlandprinzip): infringement claims are governed by the law of the state for which protection is sought, so cross-border training can trigger parallel claims under different laws. The GEMA/Suno decision (LG München I, 31 July 2026 – 42 O 763/25) shows that German courts are willing to apply foreign IP law where jurisdiction over the foreign-law claim can be established, and that a single judgment can cover acts and remedies under different legal systems.
Licences for the use of content, data or databases in AI creation could define datasets or live access, and which specific uses are covered. Remuneration can be structured as flat fees, usage-based payments, or royalties tied to output generation rather than training alone, avoiding the difficulty of proving which content was actually used. Since individual training use is hard to verify, licences should require transparency and logging obligations rather than relying solely on audit rights. Opt-out mechanisms and sublicensing terms remain essential; given that removing specific content from an already-trained model is technically difficult, output-side filtering to prevent reproduction of withdrawn or restricted content is often more realistic than deletion guarantees. For high-volume rightsholder scenarios, extended collective licensing can cut transaction costs versus individual deals.
At the national level, there are currently no concrete plans to amend existing IP statutes or introduce new substantive AI-specific legislation. Open questions are instead being resolved through case law applying existing law to AI-related cases. The AI framework is shaped almost entirely at EU level, through the directly applicable Acts and accompanying guidance instruments, already published and still evolving.
Germany’s engagement with international AI and IP harmonisation efforts runs almost entirely through the EU, since the relevant IP rights derive from EU law and since AI-specific rules, such as the AI Act, are likewise adopted at EU level rather than nationally.
At multilateral level, Germany participates, through the EU and as a WIPO member state, in the WIPO Conversation on IP and AI, which has addressed AI inventorship, authorship of AI-generated works and training data.
The most significant divergence from other jurisdictions concerns training data: the EU’s opt-out model (DSM Directive, AI Act) permits text and data mining by default unless rightsholders object. Compared to other jurisdictions, such as the US legal system, German courts have so far tended to apply a stricter standard when it comes to the reproduction of copyrighted works in connection with AI systems, in contrast to the more flexible fair-use framework applied in the United States.
Widenmayerstr. 10
80538 Munich
Germany
+49 89 212 3683 00
office@teal.de www.teal.de