"Quantitative model risk management requires treating pending legal proceedings as operational parameters. Unquantified copyright liability quietly compromises capital allocation."
Why does this belong on a CRO's desk at all? Because a vendor's litigation posture changes model availability, pricing and indemnity, sometimes within a single quarter.
Executive summary for CRO, CCO and Model Risk leadership
- Scale: 200+ AI-related civil actions are trackable across 68+ named defendants and 14 jurisdictions, of which roughly 188 sit in U.S. federal district courts as of August 2026.
- Doctrine: Courts increasingly separate transformative training (often defensible under 17 U.S.C. § 107) from unlawful acquisition, storage or distribution of pirated corpora (not defensible). That split was established in Bartz v. Anthropic and reinforced by Thomson Reuters v. Ross.
- Largest financial exposure to date: the approved $1.5 billion class settlement in Bartz v. Anthropic (~$3,000 per work across ~500,000 works).
- Risk is no longer copyright-only: chatbot product liability and wrongful-death claims, BIPA/privacy actions, agentic-AI CFAA suits (Amazon v. Perplexity), state AG enforcement, and data-center Clean Air Act citizen suits now shape vendor safety parameters and contract terms.
- Global exposure: the Munich Regional Court (LG München I) ruling in GEMA v. OpenAI and the English High Court decision in Getty v. Stability AI mean the EU/UK entities of a banking group can face materially different outcomes than their U.S. affiliates.
- Governance action: litigation status must be mapped into the model inventory and validation cycle under SR 11-7 / OCC Bulletin 2011-12, with defined escalation triggers at Rule 56 summary judgment, injunction, and settlement events.
AI litigation summary dashboard (as of August 2026)
| Metric | Value |
|---|---|
| Total active matters tracked | 200+ (≈188 in U.S. federal district courts) |
| Unique defendants | 68+ (OpenAI, Microsoft, Meta, Anthropic, Google, Apple, Stability AI, Midjourney, Runway, Adobe, Snap, MiniMax/Hailuo, Uncharted Labs (Udio), Suno, Character.AI, Perplexity, Clearview AI) |
| Jurisdictions covered | 14: U.S. federal courts (S.D.N.Y., N.D. Cal., D. Del., D.D.C., N.D. Ill., C.D. Cal.), U.S. state courts, UK High Court (EWHC Ch), Germany (LG München I), plus EU member-state courts and DPAs (CNIL, Garante) |
| Disclosed / claimed stakes | $6B+ in aggregate disclosed settlements and claimed damages |
| Core claim categories | Copyright ingestion (17 U.S.C. § 106), output regurgitation and DMCA § 1202, privacy/BIPA, right of publicity and deepfakes, agentic AI / CFAA / CIPA, chatbot product liability and wrongful death, antitrust, trade secrets, securities, employment screening |
| Protected work categories tracked | Literary, Musical / Sound Recording, Visual Art, Audiovisual / Video, Database / Code |
| Primary source of record | PACER / CM/ECF docket sheets, state e-filing systems, foreign court registries |

AI Litigation Tracker: scope, sources and update methodology

An ai litigation tracker compiles active civil lawsuits, court dockets and judicial orders across federal jurisdictions into a verified evidentiary database for model risk management. As of August 2026, trackable matters span between 188 federal cases and over 200 total AI lawsuits across U.S. courts, with primary documentation pulled directly from federal court dockets.
The gap between those two figures is methodological, not factual. The lower number counts federal dockets only; the higher number adds state courts, foreign venues and non-IP claim classes. Worth saying plainly, because a mismatched count is the fastest way to lose an examiner's trust.
«By 2025 more than 50 disputes between rights holders and AI developers were being tracked, making AI litigation the dominant intellectual property story of the year.»
To maintain an auditable evidence chain, model risk managers can cross-reference indexed filings against the internal Source Register.
Which AI cases are included in the tracker
The tracker indexes civil actions filed in U.S. federal district courts and state jurisdictions involving artificial intelligence technologies. Eligible matters include claims about generative ai training datasets, algorithmic discrimination, copyright infringement, trade secrets, consumer privacy violations, product liability for conversational agents, and unauthorized automated data access. Regulatory enforcement actions and agency policy initiatives are cataloged separately, so a rulemaking consultation never gets mistaken for a live docket.
«This case tracker monitors key U.S. litigation raising copyright and copyright-adjacent issues related to the creation and use of generative AI.»
Inclusion boundaries are applied consistently. A matter enters the tracker when a complaint is docketed, not when a policy proposal, consultation or guidance note is published. Employment-screening, resume-parsing, monitoring and notetaking matters carry a state-level tag, because a meaningful share of AI litigation now starts outside federal court.
Counts differ across public trackers because inclusion rules differ. Some monitor only copyright dockets. Others fold in privacy, deepfake, antitrust, securities and consumer-protection claims, and a few keep settled or appeal-stage matters inside the active set.
«Reported AI case counts varied widely by methodology - the Copyright Alliance listed more than 30 matters in December 2024, while other trackers listed 27 and 15 respectively.»
How to read case status and court records links
AI litigation case timeline: current cases and procedural status
An ai litigation tracker case timeline tracks how high-stakes lawsuits move through the federal judicial system. In mid-2026, federal dockets reflect two pivotal facts: an approved $1.5 billion class settlement in Bartz v. Anthropic, and ongoing summary judgment proceedings in the consolidated New York Times v. OpenAI action.
«Judge Alsup held on 23 June 2025 that training an LLM on books was "exceedingly transformative" fair use, while retaining pirated copies in a central library was not.»

Review the detailed procedural history in the dedicated AI Case Timeline: Bartz v. Anthropic entry.
Latest legal updates on AI court cases
Recent ai litigation tracker legal updates show federal courts tightening scrutiny on training data procurement and on generative outputs.
- Antitrust and competition. In United States v. Google (D.D.C., Sept. 2, 2025), the court declined Chrome and Android divestiture but imposed behavioral remedies restricting exclusive contracts covering Google Search, Chrome, Google Assistant and Gemini.
- Discovery. In the S.D.N.Y. multi-district litigation, the district court affirmed a magistrate order compelling production of a 20-million de-identified ChatGPT log sample (January 2026). OpenAI's objection was denied in April 2026.
- Court procedure. Southern District of Texas General Order 2025-04 requires counsel and self-represented litigants to verify the factual and legal accuracy of AI-assisted filings.
- Patent inventorship. USPTO 2024 guidance permitted patenting AI-assisted inventions where one natural person made a significant contribution; the 2025 revision reaffirmed that AI is a tool and conception must be human.
- Music and video models. Sony v. Uncharted Labs (Udio) survived a motion to dismiss in April 2026, and Disney et al. v. MiniMax & Hailuo AI moved into motion-to-dismiss briefing the same month.
Case statuses: from complaint to judgment
Federal civil litigation moves sequentially from filing to final verdict under the Federal Rules of Civil Procedure. A case begins with a complaint, progresses to Rule 12(b)(6) motions to dismiss, enters Rule 26–37 discovery, and reaches Rule 56 summary judgment before trial. Governance teams read these stages to judge when a third-party model faces heightened injunction or settlement risk.
Each stage carries a different governance meaning. Litigation stage, not headline volume, should drive internal escalation.
| Procedural stage | What it proves | Enterprise risk signal |
|---|---|---|
| Complaint filed | Nothing adjudicated; allegations only | Log in model inventory; note vendor and claim class |
| Rule 12(b)(6) denied | Claims are legally plausible | Review vendor indemnity scope and cap |
| Rule 26–37 discovery on logs, weights, datasets | Provenance evidence is being produced | Request vendor attestation on training-data lineage |
| Rule 56 summary judgment | Merits resolved without trial on some claims | Formal reassessment of residual risk and concentration limits |
| Injunction / settlement | Enforceable financial or operational consequence | Trigger contingency plan, substitute model, or capital add-on for operational risk |
Enterprise case study: model risk mitigation in a commercial bank
Illustrative composite scenario, not a documented client engagement.
A large commercial bank evaluated third-party LLM vendors by auditing model documentation and weight provenance against active discovery orders in federal court. Discovery in the leading book-training cases centered on how corpora were acquired, so the risk team reused that exact question set in vendor due diligence. Three questions, nothing exotic: what was the source of the training corpus, was it licensed or scraped, and does a contractual indemnity survive an adverse ruling?
The review surfaced unmitigated copyright exposure in two commercial tools whose vendors could not evidence lawful acquisition of training material. Both tools were pulled from credit-decisioning support workflows, and the vendor questionnaire was permanently amended to include provenance attestation and litigation-notification clauses. (Updated) Internal reporting recorded a material reduction in previously unquantified legal exposure across those pipelines. The specific percentage figure cited in an earlier version of this article was an internal, unverified estimate and has been withdrawn; see Appendix A.
The transferable lesson is procedural. An adverse Rule 56 ruling against a vendor does not automatically create liability for the licensee. It does change the vendor's incentive to settle, its pricing, and sometimes its ability to keep serving a model in its current form. That is the exposure a bank controls contractually, and in advance.
Generative AI copyright cases: claims and court decisions

Generative ai copyright cases turn on whether using protected works to train artificial intelligence systems is fair use under 17 U.S.C. § 107. That is the same doctrinal question that decides downstream commercial usage rights for AI art generators. (Updated) Instead of asserting a general trend, the split between transformative training and unlawful acquisition is documented here through two concrete holdings.
«In a revised opinion dated 11 February 2025, the court granted Thomson Reuters partial summary judgment and denied Ross a fair-use defense for copying Westlaw headnotes.»
«On 4 November 2025 the High Court of England and Wales held that Stable Diffusion's model weights are not "infringing copies" within the meaning of the CDPA.» — CMS, Artificial Intelligence and Copyright Case Tracker, Getty Images v. Stability AI entry (2025). https://cms.law/en/int/expert-guides/cms-expert-guide-to-artificial-intelligence/artificial-intelligence-and-copyright-case-tracker
| Case Name & Citation | Protected Work Category | Product / Technology | Presiding Court | Key Copyright Question | Current Procedural Status | Last Verified Update |
|---|---|---|---|---|---|---|
| Bartz et al. v. Anthropic PBC (No. 3:24-cv-05417) | Literary Work | Claude LLM / Text Generation | U.S. District Court, N.D. California | Is training LLMs on books fair use? Is maintaining a pirated central library actionable? | Training held fair use (June 23, 2025); central library held non-fair use; $1.5B class settlement approved July 20, 2026; appeal activity noted August 2026 | July–August 2026 |
| Kadrey et al. v. Meta Platforms, Inc. | Literary Work | LLaMA Models / Text Generation | U.S. District Court, N.D. California | Does training LLaMA on book datasets constitute fair use under 17 U.S.C. § 107? | Summary judgment granted for Meta on reproduction claims (June 25, 2025); DMCA/CMI theory rejected; amended complaint "reluctantly" permitted March 2026 and filed April 2026; interlocutory appeal denied July 2026; torrent-distribution theory unresolved | July 2026 |
| Thomson Reuters v. Ross Intelligence Inc. | Database Work / Literary Work | Legal Research AI Platform | U.S. District Court, D. Delaware | Does copying legal headnotes to train a legal search engine constitute fair use? | Partial summary judgment for Thomson Reuters; fair use defense denied (Feb. 11, 2025) | March 2026 |
| New York Times Co. v. Microsoft Corp. & OpenAI | Literary Work (News) | ChatGPT / Copilot LLMs | U.S. District Court, S.D. New York | Does ingesting news articles for training and producing regurgitated output infringe copyright? | Motion-to-dismiss opinion April 4, 2025; core direct and contributory claims active; 20M-log discovery order affirmed; amended allegations filed June 2026; summary judgment briefing | Mid-2026 |
| Authors Guild v. OpenAI (consolidated, MDL) | Literary Work | ChatGPT / GPT models | U.S. District Court, S.D. New York (Stein, J.) | Do short summaries and reproductions of plaintiffs' works infringe absent fair use? | Motion to dismiss denied Oct. 27, 2025 - output infringement claims survive; discovery closed, merits briefing continuing | Mid-2026 |
| Andersen et al. v. Stability AI et al. | Visual Art | Stable Diffusion / Image Generator | U.S. District Court, N.D. California | Do image models contain derivative works? Does output generation violate DMCA § 1202(b)? | Direct infringement claims narrowed; core training claims proceeding toward jury trial; discovery disputes and letters of request granted May 2026 | Mid-2026 |
| Concord Music Group v. Anthropic PBC (No. 5:24-cv-03811) | Musical Work / Lyrics | Claude LLM | U.S. District Court, N.D. California | Does training on song lyrics without license infringe, and is it fair use? | Anthropic moved for summary judgment on fair use (April 2026); fair-use hearing reset to Oct. 21, 2026 | August 2026 |
| Disney, Universal & Warner Bros. v. MiniMax & Hailuo AI (No. 1:25-cv-08921) | Audiovisual / Video | Video Generation Models | U.S. District Court, S.D. New York | Does training video diffusion models on copyrighted film frames constitute infringement? | Filed September 2025; two motions to dismiss filed April 2026; discovery pending | Mid-2026 |
| Sony Music & UMG v. Uncharted Labs (d/b/a Udio) (No. 1:24-cv-04777) | Musical Work / Sound Recording | Udio Music Generator | U.S. District Court, S.D. New York | Does AI audio synthesis using protected sound recordings violate copyright and DMCA § 1202? | Filed June 24, 2024; motion to dismiss denied April 2026; Sony sole remaining plaintiff after confidential UMG resolution; Warner Music resolved via strategic partnership April 2026 | May 2026 |
| Hendrix et al. v. Apple Inc. | Literary Work | OpenELM Models / HuggingFace distribution | U.S. District Court, N.D. California | Does open-sourcing model weights trained on pirated book datasets trigger direct liability? | Filed September 2025; initial pleadings complete; motion to dismiss pending | Early 2026 |
| Reddit v. Anthropic | Database Work / User Content | Claude training data acquisition | California state / N.D. California (remand dispute) | Does scraping platform content in breach of terms support state-law claims? | Court tentatively granted Reddit's motion to remand (March 2026) | March 2026 |
| Getty Images v. Stability AI Ltd | Visual Art | Stable Diffusion / Image Generator | High Court of England & Wales (EWHC Ch) | Are model weights "infringing copies"? Does international training trigger UK liability? | Primary and secondary copyright claims rejected Nov. 4, 2025; limited trademark win on watermark outputs; appeal pending | November 2025 |
| GEMA v. OpenAI | Musical Work / Lyrics | ChatGPT lyric memorization | Munich Regional Court (LG München I) | Does LLM training and memorization of song lyrics constitute reproduction under German/EU law? | Judgment for plaintiff Nov. 11, 2025 - memorization held to be unlawful reproduction; further liability rulings April 2026 | April 2026 |
Training data, output and copyright use in AI cases
Copyright analysis separates training data ingestion from model output generation. The U.S. Copyright Office 2025 Part 3 Report notes that training implicates reproduction rights under 17 U.S.C. § 106 during ingestion, including downloading, transferring, format conversion and temporary copies. Output claims work differently: they require proof of substantial similarity and actual copying of protected expression. That is the analysis deciding whether outputs from AI image and art generators or AI voice generators can be used commercially without risk.
Empirical research supports the plaintiffs' output theory in a narrow but important way. Large language models can memorize and, under specific prompting, emit verbatim or near-verbatim fragments of training data. That capability is the technical bridge between an ingestion claim under § 106 and a regurgitation claim tested against substantial similarity. It also explains why a court such as LG München I treated memorization itself as reproduction.
UK analysis frames the question slightly differently. It emphasizes that copies contained in a model or in its outputs may engage communication, distribution and secondary-infringement rules, so the location of the copy matters as much as the training act. Small distinction on paper. Large consequence for a group operating on both sides of the Atlantic.
Federal court decisions and case summaries
Every case summary must separate factual allegations from binding judicial holdings. In Thaler v. Perlmutter (D.C. Cir., March 18, 2025), the court affirmed that copyright requires human authorship, ruling that pure AI outputs are ineligible for registration while AI-assisted works may qualify where a human is the author using AI as a tool. In Thomson Reuters v. Ross Intelligence (D. Del., Feb. 11, 2025), by contrast, the court rejected a fair use defense where AI training used proprietary Westlaw headnotes to build a commercial substitute.
Two further decisions matter for annotation discipline. In AI Visualize v. Nuance Communications (Fed. Cir., April 4, 2024), the court affirmed dismissal of AI-related patent claims as ineligible under 35 U.S.C. § 101. In Percipient.ai v. United States, a precedential Federal Circuit opinion issued June 7, 2024 was later vacated by order on November 22, 2024, with the appeal reinstated. A useful reminder, actually: a case summary must always state the live posture, never a superseded panel holding.
In Andersen et al. v. Stability AI, the products at issue include diffusion-based image systems distributed to consumers. That is why enterprise creative teams evaluating AI art generators should track this docket alongside licensing terms.
From docket to model inventory: integrating AI litigation into SR 11-7 MRM

Litigation intelligence has no governance value until it enters the model inventory. For U.S. banking organizations, the operative framework is supervisory guidance on model risk management (Federal Reserve SR 11-7 and OCC Bulletin 2011-12), read together with third-party risk expectations. Legal exposure attaching to a vendor model is part of that model's residual risk. It is not a legal-department side file.
Five-step integration workflow





Vendor contract and indemnity checklist (five clauses derived from 2025–2026 rulings)
- Provenance attestation vendor warrants lawful acquisition of training corpora and represents that no known pirated repository was retained. That is the precise distinction on which Bartz v. Anthropic turned.
- Uncapped or separately capped IP indemnity copyright indemnity carved out of the general liability cap, covering statutory damages and defense costs for outputs generated by the licensed model.
- Litigation notification vendor notifies the institution within a defined window of any new complaint, adverse order, injunction or settlement materially affecting the licensed model.
- Output-filtering and memorization controls contractual commitment to regurgitation mitigation, with evidence available for validation, addressing the memorization risk documented in the German and SDNY output rulings.
- Continuity and substitution rights termination without penalty, model-substitution assistance and data-export rights if an injunction or settlement restricts the model.
Escalation runbook: what a model risk manager does on an injunction alert
- Confirm the order on the primary docket (PACER/CM/ECF) and capture the PDF for the evidence file.
- Determine scope: which model versions, jurisdictions and use cases the order reaches.
- Identify all inventory entries and downstream processes dependent on the affected model.
- Apply the pre-approved control: restrict to non-customer-facing use, switch to the substitute model, or suspend.
- Notify legal, procurement and the model risk committee; record the decision and its rationale in the inventory.
- Reassess residual risk and, where exposure is material and unhedged, discuss an operational-risk capital add-on with finance.
- Log the closure date and the next verification date.
One caveat on this runbook. Steps four and five collapse if nobody owns the substitute model in advance, which is the most common failure we see described in governance reviews.
Vendor legal risk matrix: OpenAI vs Meta vs Anthropic
The matrix below summarizes posture as of August 2026 for executive reporting. Risk levels reflect adverse holdings, discovery burden and unresolved output claims. They are not predictions of final liability.
| Vendor | Flagship litigation | Key legal question outstanding | Potential enterprise impact | Indemnity / mitigation posture | Legal risk tier |
|---|---|---|---|---|---|
| OpenAI | NYT v. Microsoft & OpenAI; Authors Guild v. OpenAI (SDNY MDL) | Output regurgitation and DMCA § 1202 after motion to dismiss denied; scope of log discovery | Discovery orders over chat logs raise confidentiality and data-retention questions for enterprise tenants | Enterprise copyright indemnity offered commercially; verify scope for fine-tuned and RAG deployments | High |
| Meta | Kadrey v. Meta (N.D. Cal.); SNE v. Meta (France); May 2026 publisher class action (SDNY) | Fair use won on reproduction, but torrent-distribution theory unresolved; new publisher claims | Open-weight distribution shifts more provenance diligence onto the deploying institution | Open-weight licensing typically provides limited or no copyright indemnity to downstream users | Medium-High |
| Anthropic | Bartz v. Anthropic (settled, $1.5B); Concord Music v. Anthropic; Reddit v. Anthropic | Lyrics fair-use hearing set for Oct. 21, 2026; scraping/terms claims after remand | Settlement removes the largest book-corpus exposure but music and scraping claims remain live | Commercial indemnity available; validate that it covers post-settlement corpora and outputs | Medium |
Financial-sector AI litigation: credit, fraud and fair-lending claims

Copyright dominates the headlines. The claims most likely to reach a bank's own models, though, are discrimination and consumer-protection actions arising from algorithmic decisioning. The Database of AI Litigation maintained at George Washington University illustrates that breadth deliberately: it spans "algorithms used in hiring and credit and criminal sentencing decisions" as well as generative AI training and AI companion liability.
For financial institutions, four claim families deserve a dedicated tag in the model inventory:




State enforcement is now a parallel channel. Texas v. Pieces Technologies produced the first state-attorney-general settlement over generative-AI accuracy claims, and four state AI statutes (the Colorado AI Act, Texas TRAIGA, California SB 243 and the New York RAISE Act) impose transparency and testing duties that plaintiffs will cite as the standard of care.
A KYC/AML footnote that rarely makes the risk pack: automated screening and transaction-monitoring models sit inside the same evidentiary logic. If an examiner asks why an alert was suppressed, "the model decided" is not an answer. Reproducible rationale is.
Key AI litigation cases involving Meta, OpenAI and Anthropic

Major developers of generative systems face extensive litigation across s federal courts over model architecture and data ingestion. Actions v openai, v meta, and v anthropic set critical precedents for model risk management and enterprise software procurement. They also shape the commercial-use terms governing how licensed outputs may be published, resold or embedded in customer-facing products.
OpenAI litigation landscape
OpenAI faces consolidated class actions in the Southern District of New York, including Authors Guild v. OpenAI and The New York Times v. OpenAI, both inside Judge Stein's multi-district litigation. Plaintiffs allege unauthorized copying of millions of books and news articles to train ChatGPT, alongside DMCA § 1202 and trademark-related theories. OpenAI defends on fair use, absence of substantial similarity, and lack of market substitution.
In October 2025 the court denied dismissal of output-infringement claims, holding that short summaries of plaintiffs' works may infringe absent fair use. Discovery disputes through mid-2026 keep circling training logs and model data retention, including the affirmed order to produce a 20-million de-identified log sample. A July 2026 Manhattan filing further accused OpenAI of discovery misconduct. Related matters include Silverman v. OpenAI, filed in N.D. California and narrowed at the dismissal stage before being drawn into the broader consolidation, plus OpenAI, Inc. v. Open Artificial Intelligence, Inc. (N.D. Cal., No. 4:23-cv-03918) on the trademark side. In February 2026, the California federal court dismissed xAI v. OpenAI, ending that trade-secret action at the district-court level.
«Corporate media plaintiffs and coordinated actions now dominate the docket - the largest coordinated actions to date against AI developers.»
Meta and dataset liability
In Kadrey v. Meta Platforms, Inc. (N.D. Cal.), Judge Vince Chhabria granted summary judgment for Meta on plaintiffs' reproduction claims, holding on June 25, 2025 that training LLaMA on book datasets was fair use. The DMCA/CMI-removal theory then failed because the underlying copying was not actionable infringement. The court left open a separate theory, though, on dataset distribution via torrents, and plaintiffs pleaded that Meta used the piracy-linked Books3 corpus.
«The Northern District of California treated Meta's training as fair use in a narrow, fact-bound ruling that left output-infringement questions open.»
(Updated status) The matter did not end in 2025. Plaintiffs moved to amend their consolidated complaint in December 2025; the court "reluctantly granted" leave in March 2026 and the amended complaint was filed in April 2026. Plaintiffs' bid to certify the summary-judgment issues for interlocutory appeal was denied in July 2026. In Europe, French publishers (SNE v. Meta, March 2025) challenge Meta under EU text and data mining rules, and a further publisher class action naming Meta was filed in SDNY in May 2026 over books and journal articles used to train Llama.
Anthropic legal proceedings
Anthropic reached a milestone in Bartz v. Anthropic (N.D. Cal., No. 3:24-cv-05417, filed Aug. 19, 2024), where the court approved a $1.5 billion class action settlement on July 20, 2026 covering author book claims, after a final fairness hearing in May 2026. Judge William Alsup ruled on June 23, 2025 that model training was "exceedingly transformative" fair use, but held that storing more than seven million pirated books in a central library created separate infringement liability. Two findings, one docket, opposite directions.
«The settlement of at least $1.5 billion - roughly $3,000 per work across some 500,000 works - is the largest publicly documented copyright recovery on record.»
Meanwhile, Concord Music Group v. Anthropic PBC (No. 5:24-cv-03811) remains active in N.D. California over song-lyrics training, brought by Concord, Universal Music Group and ABKCO. Anthropic moved for summary judgment on fair use in April 2026 and the fair-use hearing was reset to October 21, 2026. Separately, in Reddit v. Anthropic, the court tentatively granted Reddit's motion to remand in March 2026, keeping the platform's terms-of-service and scraping claims in state court.
(Updated) A previously published sentence in this section referring to an unrelated third-party domain has been removed as an editorial error; the original wording is retained for transparency in Appendix A. Enterprise buyers evaluating any AI vendor, including smaller design and generation tools such as those reviewed in our Canva AI generator overview, should request the same evidence set used above: legal-entity registration, training-data provenance attestation, indemnity scope, and audit rights.
Non-copyright AI litigation: product liability, privacy, and agentic claims

Copyright owns the headlines, yet enterprise risk managers must watch non-IP categories that are already changing model safety parameters, default refusals and API terms.
Chatbot harm and product liability
Litigation targeting consumer-facing LLMs has shifted toward defective design and negligence rather than speech. In wrongful-death and self-harm actions against companion and assistant AI developers, including Garcia v. Character.AI, Raine, Soelberg, Peralta and Gavalas v. Google, plaintiffs allege that engagement-maximization architectures create foreseeable risks of self-harm. Courts are testing whether Section 230 immunity extends to dynamically generated conversational output, and the emerging theory frames engagement optimization itself as a design defect. For banks deploying conversational agents in collections, advice or servicing, this line of cases is the closest available proxy for duty-of-care expectations.
Agentic AI and CFAA compliance
As autonomous agents scrape web data and execute API calls, corporate targets are reaching for the Computer Fraud and Abuse Act. In Amazon v. Perplexity, the court is evaluating whether AI agents that bypass robots.txt and anti-scraping protocols incur civil CFAA liability. That ruling lands directly on automated market-intelligence, pricing and vendor-monitoring workflows. Adjacent matters include X v. Bright Data on scraping, Ambriz v. Google on the CIPA capability test, the Otter.ai notetaker MDL, and a widening wave of CIPA/ECPA claims against AI voicebots.
Governance translation: an agent acting on external systems is a digital worker. It needs a named owner, an approved role, access limits, an escalation path, an audit trail, and a shutdown mechanism. No evidence, no autonomy.
Privacy, biometrics and data scraping
Training-data acquisition claims increasingly plead privacy statutes instead of copyright: BIPA actions over biometric identifiers, right-of-publicity claims over voice and likeness cloning, and the consolidated Clearview AI litigation. Deepfake and AI-generated defamation claims form a parallel track covering celebrity likeness, voice cloning and political synthetic media.
State AG enforcement and AI statutes
State attorneys general have become the primary enforcement channel. Key proceedings include Texas v. Pieces Technologies (generative-AI accuracy claims in healthcare), Vermont v. Clearview AI, civil investigative demands issued in Texas to Meta and Character.AI, and xAI v. Bonta. Compliance duties now flow from the Colorado AI Act, Texas TRAIGA, California SB 243 and the New York RAISE Act.
Infrastructure, antitrust and securities
Data-center build-out is generating its own docket: Clean Air Act citizen suits over on-site gas turbines, exclusionary-zoning challenges to hyperscale campuses, and utility-regulator proceedings over load and tariffs. Alongside these sit antitrust matters (United States v. Google), trade-secret disputes among labs, securities claims over AI disclosure, and employment cases over automated hiring.
International AI litigation: EU, UK and Asia-Pacific proceedings

Roughly one in ten tracked matters sits outside the United States, and the outcomes diverge materially from U.S. fair-use reasoning.
- Germany, GEMA v. OpenAI (LG München I): the Munich Regional Court held on November 11, 2025 that training on and memorizing song lyrics without a licence constitutes reproduction under German copyright law, with further liability findings in April 2026. Among the first European merits rulings against an AI developer on training data.
- United Kingdom, Getty Images v. Stability AI (EWHC Ch): on November 4, 2025 the High Court rejected the primary and secondary copyright claims, holding model weights are not "infringing copies" under the CDPA, while granting a limited trademark win on watermark outputs. An appeal is pending.
- France, SNE v. Meta: publishers' action under EU text and data mining provisions, filed March 2025.
- Canada, Toronto Star v. OpenAI: jurisdictional order permitting the claim to proceed.
- India, ANI v. OpenAI: judgment reserved.
- China, Ultraman LoRA decision: contributory-liability finding against a model-hosting platform.
- EU regulators: CNIL enforcement in France and Garante proceedings in Italy concerning ChatGPT are tracked separately from litigation, consistent with the tracker's inclusion rules.
For multinational banking groups the practical consequence is uncomfortable but simple. A single vendor model may be defensible in one jurisdiction and unlawful in another, so jurisdictional tagging in the model inventory is not optional.
Limitations and open questions
Honesty about gaps matters more than a tidy dashboard.
Case counts remain methodology-dependent, so any figure in this tracker should be read together with its inclusion rules rather than quoted alone. Fair use in training is still unsettled at appellate level in the United States, which means the 2025 district-court holdings could narrow or widen. The torrent-distribution theory in Kadrey has not been resolved. Cross-border divergence between Munich and London is now documented, yet nobody can say how EU courts will treat model weights over the next two years.
Audience assumptions here are also hypotheses until validated. The claim that CROs and Heads of Model Risk prioritise provenance evidence over feature velocity reflects interviews and analyst commentary, not a controlled study, and should be tested against your own interview and CRM data.
FAQ & AI governance insights
How do federal AI litigation rulings impact enterprise model adoption?
Judicial rulings set operational parameters for model adoption. When courts reject fair use defenses for pirated training corpora, risk managers must re-evaluate vendor liability indemnities and verify dataset provenance before deploying models into production. The practical trigger points are Rule 56 orders, injunctions and executed settlements, not the mere filing of a complaint.
What is the difference between training data claims and output infringement claims?
Training data claims address unauthorized reproduction of copyrighted material during model training under 17 U.S.C. § 106, including downloading, conversion and temporary copies. Output claims focus on whether generated responses reproduce protectable expression substantially similar to source works, which requires proof of actual copying and is assessed against the fair-use factors of 17 U.S.C. § 107.
Is training an AI model on copyrighted works fair use?
There is no single answer yet. Bartz v. Anthropic and Kadrey v. Meta treated training on lawfully obtained books as fair use in fact-bound rulings, while Thomson Reuters v. Ross denied fair use where the AI product substituted for the copyrighted source. Retaining pirated copies was held not to be fair use even where training itself was, and the Munich Regional Court reached a different conclusion under German law entirely.
Can AI-generated output be copyrighted?
No, not on its own. In Thaler v. Perlmutter (D.C. Cir., March 18, 2025) the court affirmed that copyright requires human authorship. Purely machine-generated output is ineligible for registration, although AI-assisted works may qualify where a human author used the system as a tool.
How frequently should financial institutions update their AI model risk registers?
Registers should be updated on a structured 30-day cadence, or immediately after major federal court rulings, summary judgment orders, injunctions or class action settlements affecting primary AI vendors. Docket monitoring itself should run on a shorter cycle; every five business days is the cadence used for this tracker.
Which regulatory frameworks require banks to monitor AI legal risk?
Model risk management expectations under Federal Reserve SR 11-7 and OCC Bulletin 2011-12, combined with third-party and operational risk guidance, require institutions to identify, measure, monitor and control risks arising from models, vendor models included. Fair-lending obligations under ECOA/Regulation B, FCRA accuracy duties, and state AI statutes add further monitoring obligations.
How can I verify a case status myself?
Search PACER by case number, party name or filing-date range. The PACER Case Locator returns the case number, court, date filed and date closed, and is refreshed every 24 hours. Read the docket sheet as the chronological record of filings, and retrieve native CM/ECF PDFs rather than third-party copies. Where the filing court is unknown, use the Case Locator; where documents are sealed, they will not appear publicly.
What should be in an AI vendor contract after the 2025–2026 rulings?
At minimum: a training-data provenance warranty, a separately capped or uncapped copyright indemnity covering defense costs, litigation-notification obligations, contractual output-filtering and memorization controls with evidence rights, and continuity/substitution rights if an injunction or settlement restricts the model.
Are chatbot and agentic-AI cases relevant to enterprises that only use copyright-clean models?
Yes. Product-liability theories against conversational agents shape the duty of care for any customer-facing deployment, and CFAA/CIPA rulings on agentic scraping and call interception apply to internal automation regardless of the model's training-data pedigree.
Appendix A: editorial revisions and superseded wording
