News 05 Dec. 2024
Partner Dr. Alexandra G. Maier Recognized Again in Lexology Client Choice Award 2025, Mining Experts Category 2025
more
Event 23 Oct. 2024
Counsel Mohannad El Murtadi Suleiman to Speak at the 2nd Annual Africa Arbitration Day in New York
Event 18 Aug. 2023
Partner Borzu Sabahi Speaks at FDI Moot Shenzhen
News 25 Jul. 2023
Partner Eric Gilioli Ranked in Top 10 Influential Energy & Natural Resources Lawyers in Kazakhstan in Business Today
Client Alert 20 Apr. 2026
Italy Implements the EU's “Breakfast Directive”: New Rules for honey, Juices, Jams and Milk
News 09 Apr. 2024
Curtis Announces New Partners and Counsels Across Offices in Spring 2024
News 22 Oct. 2025
Curtis Named Leading Firm in Legal 500: Latin America 2026
News 21 Oct. 2025
Elisa Botero Recognized as Top 100 Female Lawyer in Latin America 2025
News 17 Jun. 2025
Curtis Announces Dual Promotion to Partner and Counsel in Dubai
News 02 Jun. 2025
Curtis advises Al Ain Farms on two strategic acquisitions, making it the largest integrated dairy and poultry producer in United Arab Emirates
Client Alert 28 Dec. 2023
U.S. to Impose Secondary Sanctions on Non-U.S. Banks For Financing Russia’s Defense Industry
News 24 Aug. 2023
Curtis Attorneys Quoted in CoinDesk on FTX Founder Sam Bankman-Fried’s Strategy Ahead of His Criminal Trial
Client Alert 10 Jul. 2024
EU Adopts New Restrictive Measures Against Belarus
Client Alert 26 Jun. 2024
The EU Adopts its 14th Sanctions Package Against Russia
client alert
Generative AI and copyright under the EU AI Act: compliance and practical implications for businesses
FinCEN’s updated information sharing rules and the growing complexity of international AML compliance
Client Alert 23 Jul. 2026
If your business develops, deploys or simply uses artificial intelligence tools – from contract drafting software to customer service chatbots, from AI-generated marketing content to data analytics platforms – compliance with EU and Italian AI regulation is no longer a future issue. While new obligations are already in force and others will shortly become applicable, businesses should now assess how AI is used across their organization and what governance measures should be implemented.
Against this backdrop, Regulation (EU) 2024/1689 of 13 June 2024 (the “AI Act”), which entered into force on 1 August 2024, establishes the first comprehensive legal framework governing artificial intelligence within the European Union, and is expected to play an increasingly important role in shaping the interaction between generative AI, copyright law and the broader regulatory framework applicable to AI developers, providers and deployers.
Here we examine the interaction between the existing EU copyright framework and the AI Act, highlighting the key compliance obligations, enforcement mechanisms and practical implications for businesses using AI systems.
The relationship between generative AI and copyright has rapidly emerged as one of the most debated legal issues in the AI ecosystem. The legal debate primarily revolves around two closely connected issues: the legal treatment of AI-generated outputs and the use of copyright-protected content for the training of AI models.
While EU copyright law does not contain specific rules on AI-generated content, copyright protection has traditionally been linked to human authorship and creative choices. Consistent with the case law of the Court of Justice of the European Union1, outputs generated entirely by AI systems are generally considered unlikely to benefit from copyright protection, whereas the position remains less clear where a meaningful human contribution is involved. A broadly similar approach has also been adopted outside the European Union. Specifically, the U.S. Copyright Office2 has clarified that copyright protection requires human authorship and that the mere provision of prompts to a generative AI system is not, in itself, sufficient to qualify a person as the author of the resulting work, given the inherently unpredictable nature of AI-generated outputs.
With respect to the use of copyright-protected content for the training of AI models, before the adoption of the EU AI Act, the relationship between artificial intelligence and copyright was already partially addressed under the existing EU copyright framework, most notably through Directive (EU) 2019/790 on Copyright in the Digital Single Market (the “DSM Directive”).
Notably, the DSM Directive introduced specific exceptions for text and data mining (“TDM”) – the automated process of extracting and analysing large volumes of text and data, widely used to train AI models – permitting the reproduction and extraction of protected works for training purposes under Articles 3 and 4. While the framework allows the use of protected content for scientific research and, in certain circumstances, commercial purposes, rightsholders retain the ability to opt out and expressly reserve their rights, preventing their content from being used for commercial AI training without prior authorisation.
Although the DSM Directive provides a starting point for addressing some of the copyright issues raised by generative AI, it is important to note that it was adopted before the widespread deployment of large language models and other generative AI systems. Consequently, significant legal uncertainty remained, particularly in relation to the scope of the TDM exceptions, the operation of the opt-out mechanism, and the treatment of AI-generated outputs.
The uncertainties surrounding the use of copyright-protected content for AI training emerged alongside a broader regulatory concern regarding the development and deployment of increasingly powerful AI systems. It is in this context that the EU legislator adopted the AI Act, establishing the first comprehensive legal framework governing artificial intelligence within the European Union.
The AI Act follows a phased implementation timeline. Following its entry into force on 1 August 2024, the provisions relating to prohibited AI practices and AI literacy became applicable on 2 February 2025. The rules governing general-purpose AI models (“GPAI”), including the obligations applicable to GPAI providers, entered into application on 2 August 2025. Following the amendments introduced by the Digital Omnibus package, the application of the obligations relating to high-risk AI systems has been postponed to 2 December 2027 for stand-alone high-risk AI systems and to 2 August 2028 for high-risk AI systems embedded in regulated products.
The AI Act introduces a layered system of obligations that varies depending on the role performed within the AI value chain and the type of AI system concerned.
Specifically, the Regulation distinguishes between deployers – broadly, organisations using an AI system under their authority in the course of a professional activity – and end users who interact with AI systems without assuming compliance obligations. In practice, the boundary between these categories must be assessed case by case, and businesses should not assume they fall outside the Regulation’s scope without first mapping their actual AI use. Indeed, many organisations incorrectly assume that the AI Act only applies to technology companies. In reality, businesses using third-party AI tools will often qualify as deployers and should therefore assess their own compliance obligations. The Regulation also imposes specific obligations on providers of general-purpose AI models (GPAI) – large, versatile models capable of performing a wide range of distinct tasks – as well as on providers of applications built on such models (for instance, AI agents, chatbots, integrated customer service systems and HR recruitment tools).
The copyright-related obligations introduced by Article 53 of the AI Act apply specifically to GPAI providers. They are required, inter alia, to implement a copyright compliance policy, respect opt-outs expressed by rightsholders pursuant to Article 4(3) of the DSM Directive and make publicly available a sufficiently detailed summary of the content used for training purposes.
Article 4 of the AI Act requires providers and deployers of AI systems to take measures, to the best of their ability, to ensure that their personnel, as well as any other persons operating or using AI systems on their behalf, possess a sufficient level of AI literacy. The measures adopted should be proportionate and take into account the technical knowledge, experience, education and training of the individuals concerned, the intended use of the AI system, and the context in which it is deployed. Although the AI Act does not prescribe specific training programmes or certification requirements, organisations should implement appropriate governance measures to support compliance with this obligation, such as tailored training, awareness initiatives and internal policies.
In addition to these copyright-specific requirements, the AI Act introduces transparency obligations for certain AI systems under Article 50. These obligations require providers and deployers, among other things, to inform users when they are interacting with an AI system and, in certain circumstances, to clearly disclose when content has been artificially generated or manipulated. Specific transparency requirements also apply to deepfakes and certain biometric and emotion-recognition systems.
The Regulation also establishes a stricter regime for GPAI providers presenting systemic risk, i.e. highly capable models whose deployment may generate significant risks on a large scale. Pursuant to Article 55, such providers are subject to additional obligations relating to risk assessment and mitigation, cybersecurity, incident reporting and ongoing monitoring. These requirements are intended to address the potential impact that highly capable AI models may have on public safety, fundamental rights and the broader economy.
The AI Act complements, and does not replace, the existing EU data protection framework, including the General Data Protection Regulation (GDPR). Organisations developing, deploying or using AI systems that involve the processing of personal data must ensure compliance with both regulatory regimes. In practice, this requires organisations to assess the lawfulness of personal data processing, implement appropriate technical and organisational measures, ensure transparency towards data subjects, and, where required, carry out Data Protection Impact Assessments (DPIAs). Particular attention should be paid to high-risk AI systems and other AI use cases involving significant processing of personal data, which may require a coordinated legal assessment under both the AI Act and the GDPR. Organisations should therefore adopt an integrated compliance approach, aligning AI governance with existing data protection policies, procedures and risk management frameworks.
Most recently, the AI Act has already undergone its first substantive amendments following the adoption of the Digital Omnibus package by the Council of the European Union on 29 June 20263.
In addition to revising the implementation timeline discussed above, the Digital Omnibus package introduces a number of further modifications to the AI Act. Among the most significant, there is the introduction of a new prohibited AI practice covering systems designed to generate or manipulate non-consensual intimate content and child sexual abuse material. The amendments also clarify the allocation of supervisory powers between the AI Office and national authorities by confirming the AI Office’s exclusive competence to supervise GPAI models and systems developed by the same provider, while preserving the competence of national regulators in specific sectors such as law enforcement, border management and financial services. Furthermore, the amendments shorten the transitional period for compliance with the transparency obligations relating to AI-generated content and introduce mechanisms aimed at avoiding duplicative compliance requirements where equivalent AI-specific obligations already exist under sector-specific EU legislation.
The AI Act is supported by a dedicated compliance and enforcement framework.
In this instance, the AI Office, established within the European Commission, plays a central role in the implementation and supervision of the rules applicable to GPAI providers. In addition to monitoring compliance by the latter, the AI Office is responsible for developing guidance and codes of practice, coordinating enforcement activities across Member States and assessing systemic risks associated with advanced AI models. It also serves as a key point of coordination between national authorities, the AI Board and the broader EU AI governance framework. For businesses, this also means that regulatory expectations will continue to evolve through guidance, codes of practice and enforcement decisions, making ongoing monitoring an essential part of AI governance.
Compliance with the AI Act is reinforced by a significant sanctions regime. Pursuant to Article 99 of the AI Act, Member States are required to adopt national rules on penalties and designate competent authorities responsible for supervision and enforcement.
The Regulation provides for a tiered system of administrative fines depending on the nature of the infringement. The most severe penalties apply to prohibited AI practices under Article 5 of the AI Act, and may reach up to EUR 35 million or 7% of the undertaking’s total worldwide annual turnover, whichever is higher. Other infringements, including breaches of obligations applicable to providers, deployers and notified bodies, may result in fines of up to EUR 15 million or 3% of worldwide annual turnover, while the provision of incorrect, incomplete or misleading information to competent authorities may trigger fines of up to EUR 7.5 million or 1% of worldwide annual turnover.
At national level, Italy enacted Law No. 132 of 23 September 2025 (the “AI Law”), establishing the domestic governance and enforcement framework. The Italian approach adopts a multi-authority model: the Italian Digital Agency (AgID) serves as the national innovation and notifying authority, while the National Cybersecurity Agency (ACN) acts as the market surveillance authority and single point of contact with EU institutions. The Bank of Italy, CONSOB and IVASS retain sector-specific supervisory roles for high-risk AI systems used by financial intermediaries, while the Data Protection Authority (Garante) intervenes on high-risk AI systems used in law enforcement, border management, justice and democratic processes. On 10 June 2026, the Council of Ministers adopted in a first preliminary examination two implementing legislative decrees under the AI Law, making Italy the first EU Member State to have established a comprehensive national AI regulatory framework fully aligned with the EU AI Act. The decrees are still subject to parliamentary committee review, the Conference of Regions, and scrutiny by the competent authorities before final adoption. The following aspects of the Italian framework are of particular practical relevance to businesses.
First, it amends the Italian Copyright Law (Law No. 633/1941) to require explicit human authorship for copyright protection – meaning AI-generated outputs without a meaningful human creative contribution will not enjoy copyright protection in Italy – and introduces a new provision expressly regulating TDM for AI purposes in conformity with the DSM Directive.
Second, the Italian framework introduces criminal sanctions for two categories of conduct. A provision enacted by the AI Law criminalises the unlawful dissemination, without the subject’s consent, of images, videos or audio falsified or altered by AI systems (so-called deepfakes), punishable by one to five years’ imprisonment. The 10 June 2026 implementing decree goes further, introducing a new criminal offence sanctioning the failure to adopt required security measures for high-risk AI systems, or their alteration, where such omission or conduct creates a concrete danger to human life, public safety or national security. Critically, corporate liability under Legislative Decree No. 231/2001 also applies: companies – not only the individuals responsible – may be held criminally liable for AI-related offences committed in their interest or to their benefit.
Third, the AI Law and the 10 June 2026 implementing decree establish rules for AI use in the workplace. Decisions concerning the establishment, modification or termination of employment relationships – including disciplinary measures and dismissals – may not be adopted exclusively on the basis of automated processing: the final decision must always be reserved to a human decision-maker. Workers are entitled, upon request, to an intelligible explanation of any AI-assisted decision affecting them, including disclosure of how the AI system influenced the outcome. A dismissal issued in violation of the prohibition on fully automated decisions is null and void. Employers must also comply with applicable information obligations before activating AI-based data processing affecting workers.
Fourth, and of direct relevance to professional service providers, the AI Law provides that intellectual professions – including legal services – may only use AI systems as a supporting tool, with the core intellectual activity remaining with the professional, and requires that clients be informed of AI use in clear and accessible language.
Fifth, the 10 June 2026 implementing decree introduces a dedicated civil liability regime for damage caused by AI systems, directly addressing the regulatory gap created by the EU’s withdrawal of its proposed AI Liability Directive. The decree provides AI-damaged parties with enhanced procedural tools: (i) the right to access the AI system’s technical documentation; (ii) a presumption of causation, which eases the claimant’s burden of proof without eliminating it entirely; (iii) the option to bring proceedings before a court close to the claimant’s residence; and (iv) the right to bring a direct action against the AI operator’s insurer. For businesses deploying AI systems, these provisions directly increase civil litigation exposure and underscore the importance of robust AI governance, adequate contractual protections and appropriate insurance coverage.
Businesses should not wait until regulatory scrutiny arises. The period leading up to the full application of the AI Act offers an important opportunity to review AI governance, contractual arrangements and internal policies. In particular, businesses developing, deploying or using generative AI systems should consider:
The AI Act is more than a technology regulation. It establishes a governance framework that affects businesses across virtually every sector. Organisations that assess their AI use early, implement appropriate governance measures and monitor regulatory developments will be better positioned to manage legal risk while continuing to benefit from AI-driven innovation.
[1] See, inter alia, Infopaq International A/S v Danske Dagblades Forening (C-5/08), Eva-Maria Painer v Standard VerlagsGmbH and Others (C-145/10) and Football Dataco Ltd and Others v Yahoo! UK Ltd and Others (C-604/10). Outside of the European Union, a different approach was initially adopted by the Australian Federal Court in Thaler v Commissioner of Patents [2021] FCA 879, which recognized an AI system as an inventor for patent purposes (but not as the owner). However, that decision was subsequently overturned by the Full Court of the Federal Court of Australia, which held that an AI system cannot qualify as an inventor under Australian patent law.
[2] U.S. Copyright Office, Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence, Federal Register / Vol. 88, No. 51, 16190, 16 March 2023.
[3] The Digital Omnibus on AI is part of the broader Digital Omnibus package published on 19 November 2025, which includes two legislative proposals aimed at simplifying the EU digital regulatory framework. The AI-related amendments were formally adopted by the Council of the European Union on 29 June 2026. See Council of the European Union, Press Release, Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules, 29 June 2026.
Corporate
Data Protection and Privacy Law
Media, Technology and Entertainment
Daniela Della Rosa
Partner
Gaia Morelli
Maria Elena Sarvia
Associate
Milan
+39 02 7623 2001
Rome
+39 06 6758 2201
news
Curtis Ranked in Legal 500 USA 2026 Guide