Client Alert 23 Jul. 2026

Generative AI and copyright under the EU AI Act: compliance and practical implications for businesses

What businesses using AI tools need to know – and do – right now

If your business develops, deploys or simply uses artificial intelligence tools – from contract drafting software to customer service chatbots, from AI-generated marketing content to data analytics platforms – compliance with EU and Italian AI regulation is no longer a future issue. While new obligations are already in force and others will shortly become applicable, businesses should now assess how AI is used across their organization and what governance measures should be implemented. 

Against this backdrop, Regulation (EU) 2024/1689 of 13 June 2024 (the “AI Act”), which entered into force on 1 August 2024, establishes the first comprehensive legal framework governing artificial intelligence within the European Union, and is expected to play an increasingly important role in shaping the interaction between generative AI, copyright law and the broader regulatory framework applicable to AI developers, providers and deployers.

Here we examine the interaction between the existing EU copyright framework and the AI Act, highlighting the key compliance obligations, enforcement mechanisms and practical implications for businesses using AI systems.

Generative AI and copyright under the existing EU Framework

The relationship between generative AI and copyright has rapidly emerged as one of the most debated legal issues in the AI ecosystem. The legal debate primarily revolves around two closely connected issues: the legal treatment of AI-generated outputs and the use of copyright-protected content for the training of AI models.

While EU copyright law does not contain specific rules on AI-generated content, copyright protection has traditionally been linked to human authorship and creative choices. Consistent with the case law of the Court of Justice of the European Union1, outputs generated entirely by AI systems are generally considered unlikely to benefit from copyright protection, whereas the position remains less clear where a meaningful human contribution is involved. A broadly similar approach has also been adopted outside the European Union. Specifically, the U.S. Copyright Office2 has clarified that copyright protection requires human authorship and that the mere provision of prompts to a generative AI system is not, in itself, sufficient to qualify a person as the author of the resulting work, given the inherently unpredictable nature of AI-generated outputs.

With respect to the use of copyright-protected content for the training of AI models, before the adoption of the EU AI Act, the relationship between artificial intelligence and copyright was already partially addressed under the existing EU copyright framework, most notably through Directive (EU) 2019/790 on Copyright in the Digital Single Market (the “DSM Directive”).

Notably, the DSM Directive introduced specific exceptions for text and data mining (“TDM”) – the automated process of extracting and analysing large volumes of text and data, widely used to train AI models – permitting the reproduction and extraction of protected works for training purposes under Articles 3 and 4. While the framework allows the use of protected content for scientific research and, in certain circumstances, commercial purposes, rightsholders retain the ability to opt out and expressly reserve their rights, preventing their content from being used for commercial AI training without prior authorisation.

Although the DSM Directive provides a starting point for addressing some of the copyright issues raised by generative AI, it is important to note that it was adopted before the widespread deployment of large language models and other generative AI systems. Consequently, significant legal uncertainty remained, particularly in relation to the scope of the TDM exceptions, the operation of the opt-out mechanism, and the treatment of AI-generated outputs.


The AI Act: Key Developments and Compliance Obligations

The uncertainties surrounding the use of copyright-protected content for AI training emerged alongside a broader regulatory concern regarding the development and deployment of increasingly powerful AI systems. It is in this context that the EU legislator adopted the AI Act, establishing the first comprehensive legal framework governing artificial intelligence within the European Union.

The AI Act follows a phased implementation timeline. Following its entry into force on 1 August 2024, the provisions relating to prohibited AI practices and AI literacy became applicable on 2 February 2025. The rules governing general-purpose AI models (“GPAI”), including the obligations applicable to GPAI providers, entered into application on 2 August 2025. Following the amendments introduced by the Digital Omnibus package, the application of the obligations relating to high-risk AI systems has been postponed to 2 December 2027 for stand-alone high-risk AI systems and to 2 August 2028 for high-risk AI systems embedded in regulated products.

Who does the AI Act apply to?

The AI Act introduces a layered system of obligations that varies depending on the role performed within the AI value chain and the type of AI system concerned.

Specifically, the Regulation distinguishes between deployers – broadly, organisations using an AI system under their authority in the course of a professional activity – and end users who interact with AI systems without assuming compliance obligations. In practice, the boundary between these categories must be assessed case by case, and businesses should not assume they fall outside the Regulation’s scope without first mapping their actual AI use. Indeed, many organisations incorrectly assume that the AI Act only applies to technology companies. In reality, businesses using third-party AI tools will often qualify as deployers and should therefore assess their own compliance obligations. The Regulation also imposes specific obligations on providers of general-purpose AI models (GPAI) – large, versatile models capable of performing a wide range of distinct tasks – as well as on providers of applications built on such models (for instance, AI agents, chatbots, integrated customer service systems and HR recruitment tools).

Copyright-specific obligations for GPAI providers

The copyright-related obligations introduced by Article 53 of the AI Act apply specifically to GPAI providers. They are required, inter alia, to implement a copyright compliance policy, respect opt-outs expressed by rightsholders pursuant to Article 4(3) of the DSM Directive and make publicly available a sufficiently detailed summary of the content used for training purposes.

AI Literacy obligations for all AI users

Article 4 of the AI Act requires providers and deployers of AI systems to take measures, to the best of their ability, to ensure that their personnel, as well as any other persons operating or using AI systems on their behalf, possess a sufficient level of AI literacy. The measures adopted should be proportionate and take into account the technical knowledge, experience, education and training of the individuals concerned, the intended use of the AI system, and the context in which it is deployed. Although the AI Act does not prescribe specific training programmes or certification requirements, organisations should implement appropriate governance measures to support compliance with this obligation, such as tailored training, awareness initiatives and internal policies.

Transparency requirements for all AI systems

In addition to these copyright-specific requirements, the AI Act introduces transparency obligations for certain AI systems under Article 50. These obligations require providers and deployers, among other things, to inform users when they are interacting with an AI system and, in certain circumstances, to clearly disclose when content has been artificially generated or manipulated. Specific transparency requirements also apply to deepfakes and certain biometric and emotion-recognition systems.

Enhanced obligations for the most powerful AI models

The Regulation also establishes a stricter regime for GPAI providers presenting systemic risk, i.e. highly capable models whose deployment may generate significant risks on a large scale. Pursuant to Article 55, such providers are subject to additional obligations relating to risk assessment and mitigation, cybersecurity, incident reporting and ongoing monitoring. These requirements are intended to address the potential impact that highly capable AI models may have on public safety, fundamental rights and the broader economy.

AI Act and Data Protection

The AI Act complements, and does not replace, the existing EU data protection framework, including the General Data Protection Regulation (GDPR). Organisations developing, deploying or using AI systems that involve the processing of personal data must ensure compliance with both regulatory regimes. In practice, this requires organisations to assess the lawfulness of personal data processing, implement appropriate technical and organisational measures, ensure transparency towards data subjects, and, where required, carry out Data Protection Impact Assessments (DPIAs). Particular attention should be paid to high-risk AI systems and other AI use cases involving significant processing of personal data, which may require a coordinated legal assessment under both the AI Act and the GDPR. Organisations should therefore adopt an integrated compliance approach, aligning AI governance with existing data protection policies, procedures and risk management frameworks.

Most recent legislative developments

Most recently, the AI Act has already undergone its first substantive amendments following the adoption of the Digital Omnibus package by the Council of the European Union on 29 June 20263.

In addition to revising the implementation timeline discussed above, the Digital Omnibus package introduces a number of further modifications to the AI Act. Among the most significant, there is the introduction of a new prohibited AI practice covering systems designed to generate or manipulate non-consensual intimate content and child sexual abuse material. The amendments also clarify the allocation of supervisory powers between the AI Office and national authorities by confirming the AI Office’s exclusive competence to supervise GPAI models and systems developed by the same provider, while preserving the competence of national regulators in specific sectors such as law enforcement, border management and financial services. Furthermore, the amendments shorten the transitional period for compliance with the transparency obligations relating to AI-generated content and introduce mechanisms aimed at avoiding duplicative compliance requirements where equivalent AI-specific obligations already exist under sector-specific EU legislation.

Compliance and Enforcement of the AI Act

The AI Act is supported by a dedicated compliance and enforcement framework.

In this instance, the AI Office, established within the European Commission, plays a central role in the implementation and supervision of the rules applicable to GPAI providers. In addition to monitoring compliance by the latter, the AI Office is responsible for developing guidance and codes of practice, coordinating enforcement activities across Member States and assessing systemic risks associated with advanced AI models. It also serves as a key point of coordination between national authorities, the AI Board and the broader EU AI governance framework. For businesses, this also means that regulatory expectations will continue to evolve through guidance, codes of practice and enforcement decisions, making ongoing monitoring an essential part of AI governance.

Compliance with the AI Act is reinforced by a significant sanctions regime. Pursuant to Article 99 of the AI Act, Member States are required to adopt national rules on penalties and designate competent authorities responsible for supervision and enforcement.

The Regulation provides for a tiered system of administrative fines depending on the nature of the infringement. The most severe penalties apply to prohibited AI practices under Article 5 of the AI Act, and may reach up to EUR 35 million or 7% of the undertaking’s total worldwide annual turnover, whichever is higher. Other infringements, including breaches of obligations applicable to providers, deployers and notified bodies, may result in fines of up to EUR 15 million or 3% of worldwide annual turnover, while the provision of incorrect, incomplete or misleading information to competent authorities may trigger fines of up to EUR 7.5 million or 1% of worldwide annual turnover.

Italy: Law No. 132 of 23 September 2025

At national level, Italy enacted Law No. 132 of 23 September 2025 (the “AI Law”), establishing the domestic governance and enforcement framework. The Italian approach adopts a multi-authority model: the Italian Digital Agency (AgID) serves as the national innovation and notifying authority, while the National Cybersecurity Agency (ACN) acts as the market surveillance authority and single point of contact with EU institutions. The Bank of Italy, CONSOB and IVASS retain sector-specific supervisory roles for high-risk AI systems used by financial intermediaries, while the Data Protection Authority (Garante) intervenes on high-risk AI systems used in law enforcement, border management, justice and democratic processes. On 10 June 2026, the Council of Ministers adopted in a first preliminary examination two implementing legislative decrees under the AI Law, making Italy the first EU Member State to have established a comprehensive national AI regulatory framework fully aligned with the EU AI Act. The decrees are still subject to parliamentary committee review, the Conference of Regions, and scrutiny by the competent authorities before final adoption. The following aspects of the Italian framework are of particular practical relevance to businesses. 

(i)    Copyright

First, it amends the Italian Copyright Law (Law No. 633/1941) to require explicit human authorship for copyright protection – meaning AI-generated outputs without a meaningful human creative contribution will not enjoy copyright protection in Italy – and introduces a new provision expressly regulating TDM for AI purposes in conformity with the DSM Directive.

(ii)    Criminal Liability

Second, the Italian framework introduces criminal sanctions for two categories of conduct. A provision enacted by the AI Law criminalises the unlawful dissemination, without the subject’s consent, of images, videos or audio falsified or altered by AI systems (so-called deepfakes), punishable by one to five years’ imprisonment. The 10 June 2026 implementing decree goes further, introducing a new criminal offence sanctioning the failure to adopt required security measures for high-risk AI systems, or their alteration, where such omission or conduct creates a concrete danger to human life, public safety or national security. Critically, corporate liability under Legislative Decree No. 231/2001 also applies: companies – not only the individuals responsible – may be held criminally liable for AI-related offences committed in their interest or to their benefit.

(iii)    Employment

Third, the AI Law and the 10 June 2026 implementing decree establish rules for AI use in the workplace. Decisions concerning the establishment, modification or termination of employment relationships – including disciplinary measures and dismissals – may not be adopted exclusively on the basis of automated processing: the final decision must always be reserved to a human decision-maker. Workers are entitled, upon request, to an intelligible explanation of any AI-assisted decision affecting them, including disclosure of how the AI system influenced the outcome. A dismissal issued in violation of the prohibition on fully automated decisions is null and void. Employers must also comply with applicable information obligations before activating AI-based data processing affecting workers.

(iv)    Professional services

Fourth, and of direct relevance to professional service providers, the AI Law provides that intellectual professions – including legal services – may only use AI systems as a supporting tool, with the core intellectual activity remaining with the professional, and requires that clients be informed of AI use in clear and accessible language.

(v)    Civil liability for AI-related harm

Fifth, the 10 June 2026 implementing decree introduces a dedicated civil liability regime for damage caused by AI systems, directly addressing the regulatory gap created by the EU’s withdrawal of its proposed AI Liability Directive. The decree provides AI-damaged parties with enhanced procedural tools: (i) the right to access the AI system’s technical documentation; (ii) a presumption of causation, which eases the claimant’s burden of proof without eliminating it entirely; (iii) the option to bring proceedings before a court close to the claimant’s residence; and (iv) the right to bring a direct action against the AI operator’s insurer. For businesses deploying AI systems, these provisions directly increase civil litigation exposure and underscore the importance of robust AI governance, adequate contractual protections and appropriate insurance coverage.

Key Takeaways for Businesses

Businesses should not wait until regulatory scrutiny arises. The period leading up to the full application of the AI Act offers an important opportunity to review AI governance, contractual arrangements and internal policies. In particular, businesses developing, deploying or using generative AI systems should consider:

  • mapping their AI footprint: identify the AI tools currently in use across the organisation (chatbots, contract review software, data analytics tools, automated communications, generative content platforms, etc.) and determine whether their business acts as a provider building AI systems or a deployer using them – the two roles carry very different obligations and the distinction should not be assumed without a thorough assessment;
  • reviewing copyright exposure: assess how the AI tools your business uses were trained and whether AI-generated content may infringe third-party rights. Also, consider whether outputs produced with AI assistance can qualify for copyright protection under the EU and Italian framework, which now explicitly requires a meaningful human creative contribution;
  • adopting internal AI governance policies: introduce clear rules on which AI tools may be used, for which purposes and by whom, and – in particular for professional service firms – ensure that AI outputs are always reviewed and validated by a human professional before being used or disclosed to clients;
  • ensuring transparency: where organisations use AI systems that interact with clients or the public, put in place appropriate disclosure mechanisms in line with Article 50 of the AI Act; if operating a regulated profession in Italy, also comply with the obligations under the Italian AI Law to inform clients of any AI use, in clear and accessible language;
  • monitoring the evolving regulatory landscape: businesses should assess their compliance status, review ongoing projects and ensure internal governance structures are in place. Track the Italian implementing decrees adopted by the Council of Ministers on 10 June 2026 (currently in preliminary examination, pending parliamentary and regulatory review) and their final adoption;
  • assessing litigation and liability exposure under Italy’s new civil liability regime for AI-related damage and the new criminal offences applicable to high-risk AI systems – including corporate liability under Legislative Decree No. 231/2001.

The AI Act is more than a technology regulation. It establishes a governance framework that affects businesses across virtually every sector. Organisations that assess their AI use early, implement appropriate governance measures and monitor regulatory developments will be better positioned to manage legal risk while continuing to benefit from AI-driven innovation.

 

[1] See, inter alia, Infopaq International A/S v Danske Dagblades Forening (C-5/08), Eva-Maria Painer v Standard VerlagsGmbH and Others (C-145/10) and Football Dataco Ltd and Others v Yahoo! UK Ltd and Others (C-604/10). Outside of the European Union, a different approach was initially adopted by the Australian Federal Court in Thaler v Commissioner of Patents [2021] FCA 879, which recognized an AI system as an inventor for patent purposes (but not as the owner). However, that decision was subsequently overturned by the Full Court of the Federal Court of Australia, which held that an AI system cannot qualify as an inventor under Australian patent law.

[2] U.S. Copyright Office, Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence, Federal Register / Vol. 88, No. 51, 16190, 16 March 2023.

[3] The Digital Omnibus on AI is part of the broader Digital Omnibus package published on 19 November 2025, which includes two legislative proposals aimed at simplifying the EU digital regulatory framework. The AI-related amendments were formally adopted by the Council of the European Union on 29 June 2026. See Council of the European Union, Press Release, Artificial Intelligence: Council Gives Final Green Light to Simplify and Streamline Rules, 29 June 2026.

Related resources

client alert

Generative AI and copyright under the EU AI Act: compliance and practical implications for businesses

Read

client alert

FinCEN’s updated information sharing rules and the growing complexity of international AML compliance

Read

news

Curtis Ranked in Legal 500 USA 2026 Guide

Read