Dear Reader,
On Friday 28 August Sony Music Publishing and Warner Chappell sued Anthropic in the US District Court for the Northern District of California. The complaint names the company, its chief executive Dario Amodei and its co-founder Benjamin Mann. It says Anthropic trained Claude on “tens of thousands” of copyrighted songs by “torrenting, scraping and downloading” the lyrics, and that Claude repeats those lyrics when users ask for them. The publishers want statutory damages of up to $150,000 per work (Music Business Worldwide, complaint).
The next day the European Commission sent the AI labs its first formal questions under the AI Act. Four days after that the US government told a New York judge that training a model on copyrighted text is legal.
Anthropic has already paid $1.5bn to avoid the answer
The Sony and Warner suit is the fifth music case against Anthropic. Universal Music Publishing, Concord and ABKCO sued in October 2023 over about 500 songs and filed a second case in January 2026 covering more than 20,000 works, with damages above $3bn. BMG sued in March 2026 over 493 works. Round Hill Music sued on 17 August 2026. The publishing arms of all three major music companies are now in court against the same defendant.
The book case shows what these cases cost. In June 2025 Judge William Alsup ruled in Bartz v Anthropic that training a model on books is fair use, because the use is “exceedingly transformative”. He also ruled that downloading seven million pirated books to build a permanent library is not fair use. Anthropic settled in September 2025 for at least $1.5bn, about $3,000 for each of roughly 500,000 books (Norton Rose Fulbright). The company paid rather than wait for an appeals court to rule on the training question. The Sony and Warner complaint cites the same seven million pirated books.
So, three years after the first suits were filed, two district judges have said training is fair use, though they treated the role of pirated source material differently. Neither case has yet produced an answer from an appeals court.
Brussels asked the labs what is in the models
On Saturday 29 August Henna Virkkunen, the Commission’s Executive Vice-President for Tech Sovereignty, announced that the AI Office had sent formal requests for information to general-purpose AI providers “based in different regions of the world”. Euractiv reported the recipients include OpenAI, Anthropic and Google (Euractiv).
There were two sets of questions. The first asks how the models are secured, whether independent external evaluations exist, and how the models are monitored once on the market. The second went to providers that have not published a summary of the content they trained on. The AI Act requires that summary so that rights-holders can see whether their work was used. The Commission’s enforcement powers over these providers started on 2 August 2026. An incorrect or misleading reply can be fined up to €15 million or 3% of global turnover.
The Commission did not say whether training on copyrighted text is legal in the EU. It only required the labs to publish what they used.
Washington told the judge training is fair use
On Wednesday 2 September the US Department of Justice filed a statement of interest in The New York Times v OpenAI. The brief supports OpenAI’s argument that training a language model on copyrighted articles is fair use. It says “the United States has a strong interest in continuing to develop a robust and competitive artificial intelligence industry” and that “constraining LLM development under a misunderstanding of fair use doctrine would thwart such creative and scientific progress” (TechCrunch, WIRED).
The Times case has been running since December 2023. The complaint asks the court to destroy every GPT model and training set that contains Times articles. Judge Stein refused to dismiss the case in March 2025. In June this year the Times dropped its trademark claims and one of its secondary claims. In July it accused OpenAI of withholding evidence about training and asked for sanctions. There is still no trial date.
The brief does not bind the court. It shows which side the administration is on, and why.
The training fight starts with the supplier
Nobody knows yet whether training on copyrighted text is legal. Two district courts in California have said yes, though they differed on the role of pirated sources. The Times case has no trial date. The EU has not ruled on legality at all; it required the labs to disclose what they trained on. And this week the US government said the answer should be yes because the industry matters to the country. Governments are settling the question, and each settles it the way that suits its own interest.
For the labs this is a large problem. For a company that uses a model it is mostly not.
The leading models were trained on vast datasets containing the same kinds of protected material. Choosing between OpenAI, Anthropic, Google and Meta does not remove the dispute over whether that training was legal. A contract can, however, determine who pays for the consequences. Anthropic’s terms also cover claims tied to data the company used to train its model (Anthropic Commercial Terms). The protection differs by vendor. Claims about what the model puts out work differently, and they come later in this issue.
The most likely outcome is settlements and licences. Anthropic paid $3,000 a book. The music publishers want up to $150,000 a song. The cost goes into the price of the API. For a buyer that means a higher line in next year’s budget and nothing more.
The other ending is withdrawal of a model. The Times asked for it in 2023. No court has ordered it in three years. A lab that lost that badly would retrain on licensed data and raise prices. The service would continue.
The claim that reaches a buyer is about outputs
One part of the Sony and Warner complaint is different. It says Claude reproduces the lyrics of protected songs in its answers. That is a claim about what the model produces, and the same output inside a company’s own product is the company’s problem.
Vendor contracts do change who pays when a claim arrives. Anthropic’s protection covers paid use of its service, including the data on which it trained the model, as well as Claude’s outputs. OpenAI and Microsoft separately describe protection against claims concerning model outputs.
Each promise has conditions. Microsoft requires an appropriate metaprompt, tests with a retained report, and enabled protected-material and jailbreak filters (Microsoft Learn). OpenAI excludes, among other cases, customers who ignored safeguards, modified the output, or lacked rights to the input or fine-tuning files (OpenAI Service Terms). Fine-tuning alone does not remove the protection.
A company should therefore check three things: its contract, its safeguards and the behaviour of its own product. Asking for the lyrics of a well-known song will show whether the safeguards work. It will not replace reading the contract.
Briefing
OpenAI released GPT-6 Astra on 3 September and its president Greg Brockman said “it’s not unreasonable to feel that we are now in the AGI era”. The model went first to companies in OpenAI’s Daybreak cyber programme, then to paid ChatGPT tiers, the API, Azure and AWS (Fortune). API price is $10 per million input tokens and $50 per million output tokens. ARC Prize scored it 62.7% on ARC-AGI-3 with the standard harness and 99.9% with a harness that lets the provider’s own tooling in, and wrote: “we are not claiming that it is AGI” (ARC Prize). The two numbers are 37 points apart. In Microsoft Foundry the model is so far available only in the Global and US data zones; there was no EU zone at launch (Microsoft Azure).
Anthropic dropped the 30-day retention rule for enterprise customers on 1 September. Issue 62 covered the rule. The replacement, Enterprise Frontier Safeguards, keeps the monitoring data in the customer’s own cloud storage under the customer’s keys, at no charge, rolling out this autumn by invitation. Claude Mythos 5, the model for vetted cybersecurity partners, is not covered by the change. When the monitoring flags something, the alert goes to the customer to review (The Register). The review work that Anthropic used to do now sits with the customer’s own team.
Nvidia is buying Hugging Face for $12.9bn; the deal was announced on 3 September. The price is $11.9bn to shareholders plus $1bn to retain staff, closing in the first half of 2027. Hugging Face hosts 3 million models used by 18 million developers and 200,000 companies (TechCrunch). The main distribution point for open-weight models will belong to the main seller of the chips that run them.
In summary
For the next few years every company will be using models whose legal basis is unsettled. The courts will not settle it soon, because the defendants prefer to pay, and governments will decide the way their own economies’ interests point. That is a cost of using the technology, the same for everyone, and built into the price.
A company has little control over whether the base model’s training was legal. It does control the data it adds, its safeguards and the answers shown to customers. Those are the three things it can check.
Stay balanced, Krzysztof
Krzysztof Goworek is founder of Quintant — AI advisory that gets enterprises from experiment to production value.