The Ninth Circuit dismissed DMCA copyright-management claims against Copilot on Sept 16, 2026. License-obligation risk was left untouched.
On September 16, 2026, the Ninth Circuit affirmed dismissal of the DMCA Section 1202(b) claims in Doe v. GitHub, holding that Copilot, which the complaint itself describes as relying on a "complex probabilistic process" to predict likely code, produces a new work rather than a copy stripped of copyright-management information (CMI). That closes off one specific legal theory against AI coding tools. It says nothing about whether code an AI agent generates still carries license obligations from whatever it was trained on, and it leaves a separate set of contract claims in the same lawsuit very much alive.
Several outlets covering the decision, including Orrick, the firm that argued it for Microsoft and GitHub, described it as the nation's first appellate ruling to squarely address how the DMCA's CMI provision applies to generative AI output. That framing matters for how far the ruling actually reaches: it resolves one narrow statutory question, not the broader one engineering teams actually care about, which is whether AI-generated code is safe to merge without checking what it resembles.
Sources: Gibson Dunn: Ninth Circuit Clarifies Limits of DMCA Liability for AI-Generated Code, Orrick: Orrick secures Ninth Circuit win in nation's first appellate decision on generative AI
What the Ninth Circuit actually held
Doe v. GitHub, Inc. (No. 24-7700) is a putative class action brought by anonymous programmers against GitHub, Microsoft, and OpenAI, on interlocutory appeal from the Northern District of California. The plaintiffs argued that Copilot violates 17 U.S.C. § 1202(b), the DMCA provision that bars removing or altering CMI such as author names, copyright notices, and license terms, because Copilot generates code that lacks the attribution and license text that appeared on the training examples it drew on. The district court dismissed that theory with prejudice and certified it for appeal; a unanimous three-judge panel, in an opinion by Judge Eric Miller, affirmed, but on its own reasoning rather than simply rubber-stamping the lower court.
Sources: Gibson Dunn: Ninth Circuit Clarifies Limits of DMCA Liability for AI-Generated Code
The panel's core holding is that Section 1202(b) reaches affirmative acts against CMI attached to a work that already exists. It does not reach a tool that generates a new work that never carried that information in the first place. As the opinion put it, "one who creates a new work and fails to include CMI cannot be said to have 'removed' or 'altered' anything." Because the complaint described Copilot generating code through a probabilistic process rather than copying a specific file and stripping its header, the court held there was no "removal" or "alteration" for the statute to reach, and the DMCA claim failed on the pleadings.
Sources: PPC Land: GitHub and OpenAI win Ninth Circuit appeal over $9bn Copilot code claim
The nuance worth sitting with: the panel did not adopt a blanket rule that AI output can never violate Section 1202(b), and it corrected the district court's reasoning along the way without changing the result. The district court had framed Section 1202(b) as requiring the plaintiffs' code and Copilot's output to be "identical." The Ninth Circuit called that framing "something of a misnomer": identicality isn't a standalone requirement, just one way to show CMI was removed from a copy of a work that already exists. Minor cosmetic changes won't protect a defendant who substantially or entirely reproduces a protected work and strips its CMI, and substantial reproduction without CMI can still count as strong circumstantial evidence of removal. None of that changed the outcome here. Plaintiffs didn't allege that Copilot reproduced a copy of their specific code with the CMI stripped out; they alleged it generates new code through a probabilistic process. A plaintiff who instead pleads that a model output substantially reproduces an identifiable original work, with its CMI gone, is arguing a materially different case than the one the Ninth Circuit just closed.
Sources: Gibson Dunn: Ninth Circuit Clarifies Limits of DMCA Liability for AI-Generated Code
What's still alive in the same lawsuit
Dismissal of the DMCA theory did not end Doe v. GitHub. Two contract claims remain pending before the district court, built on allegations that GitHub and OpenAI breached the attribution and license-notice terms of the open-source licenses under which the training code was originally published. Those claims rest on contract and license law, not the DMCA, and the Ninth Circuit's ruling does not touch them one way or the other. Reporting on the case has also referenced statutory damages exposure as high as $9 billion under the DMCA's per-violation penalty structure before the claim was dismissed, a figure specific to the now-closed DMCA count rather than to what remains in the case.
Sources: PPC Land: GitHub and OpenAI win Ninth Circuit appeal over $9bn Copilot code claim
- Resolved: a DMCA Section 1202(b) claim premised on AI-generated output lacking attribution, where the complaint describes generation rather than reproduction of an identifiable original
- Not resolved: a CMI claim premised on an output that substantially reproduces a specific, identifiable original work and strips that work's attribution
- Not resolved: the contract claims in this same case over breach of open-source license and attribution terms, still pending in the district court
- Not addressed at all: whether code an engineering team merges carries license obligations because it was influenced by, or closely resembles, copyleft-licensed training data
A Ninth Circuit ruling binds one circuit, not the whole question
A circuit court opinion also doesn't travel as far as a headline suggests. Doe v. GitHub binds courts inside the Ninth Circuit, which covers California and the rest of the west coast, meaning a sizable share of where AI coding companies are headquartered and sued. It is persuasive, not binding, everywhere else. A plaintiff in a different circuit, arguing a CMI claim built around a specific reproduced file rather than generation in the abstract, is not bound by this outcome, and nothing stops another circuit from reading Section 1202(b) differently on different facts. Treating one appellate win in one circuit as a settled, nationwide answer to "is AI-generated code a DMCA problem" overstates what a single opinion, even a precedential one, actually locks in.
Why "not a DMCA violation" is not the same as "license-clean"
Section 1202(b) is a narrow statute about a specific act: removing or altering CMI that is attached to a work. It was never the vehicle for the question most engineering teams actually have, which is whether the code a model just produced is substantially similar to a specific licensed original, and if so, what that similarity obligates them to do. Those are different legal questions, decided under different doctrines, specifically direct copyright infringement and the terms of whatever license governed the original. The Ninth Circuit's ruling that generation is not "removal" under the DMCA has no bearing on either of those. A court could hold, in a different case, that a given output is a copy for infringement purposes, or that a license's attribution and share-alike terms were triggered, and none of that would conflict with what this panel decided.
A DMCA dismissal tells you one specific liability theory did not survive on one specific set of facts. It does not tell you the code is safe to ship, and it was never designed to.
The governance question this actually raises
For a team shipping AI-generated code, legal risk and governance risk are not the same question, and this ruling is a clean illustration of why. Legal risk is what a court will eventually decide, case by case, under statutes and licenses that are still being tested against generative AI for the first time, on a timeline measured in years and an outcome that depends on which circuit, which facts, and which theory a future plaintiff happens to plead. Governance risk is what your own process catches today, on the far more mundane question of whether a specific diff, right now, looks like it reproduces a recognizable licensed pattern closely enough that a human should look at it before it merges. Waiting for the DMCA, copyright, and contract theories to fully settle in the courts is not a governance strategy, because your team ships code every day while that litigation is still pending.
A diff review process that flags "this looks like it might be lifted from a specific, identifiable, licensed source" as a risk signal does not need to know, or care, how any particular statute's elements eventually get interpreted. It just needs to surface the pattern to a person who can make the call, the same way a security review flags a suspicious pattern without waiting for a court to decide whether that exact exploit has ever been litigated. The standard for a governance flag is lower than the standard for a legal claim on purpose: a false positive costs a reviewer a few minutes, while a missed pattern that later turns into a dispute costs considerably more. That asymmetry is the whole argument for building the check into the process now rather than deferring it to whatever the courts eventually decide.
- Separate the two problems explicitly. Track what courts decide about AI and copyright as a legal-risk question for counsel, and keep your diff-review process answering a narrower, faster question: does this specific output look like it closely tracks an identifiable licensed source, right now.
- Keep a record of what generated a change and what it was reviewed against. If a license or provenance question comes up later, a diff with no record of its origin or review is harder to defend than one with a clear trail, regardless of how any pending litigation eventually resolves.
- Do not treat a dismissal in one case as clearance for your own pipeline. Doe v. GitHub turned on how that specific complaint described Copilot's process. A different output, a different training set, or a different plaintiff's theory is not covered by the same holding.
- Flag large, verbatim-looking blocks for a human to look at before merge, independent of whatever any DMCA, copyright, or contract theory eventually resolves to. The review standard for a governance flag is intentionally lower than the standard for a legal claim.
| Question | Status after Sept 16, 2026 | What it means for engineering teams |
|---|---|---|
| DMCA Section 1202(b) CMI claim (generation theory) | Dismissed, affirmed by the Ninth Circuit | This specific theory against AI code generators is closed on these facts |
| DMCA CMI claim (substantial-reproduction theory) | Left open by the court's own reasoning | A claim tied to a specific reproduced original is a different case than the one decided here |
| Contract claims over license attribution terms | Still pending in the district court | The same lawsuit continues on separate grounds the ruling does not touch |
| Whether merged code inherits license obligations from training data it resembles | Not addressed by any part of this case | A governance and provenance question your own process has to own |
Where TLM Forge fits, and where it does not
A disclosure before the pitch: we build TLM Forge, so weigh the scope claim below against that. TLM Forge audits a spec before code gets generated, runs independent diff review against that spec, runs an adversarial red-team pass for security issues, and holds a convergence gate that blocks a merge until flagged issues hit zero. That is a correctness, security, and spec-adherence process. It is not a license-compliance scanner and does not currently fingerprint output against known licensed codebases to detect reproduced patterns. If your team's real exposure is "did this output come too close to a specific GPL or AGPL-licensed project," that is a distinct tooling category, closer to code-similarity and license-scanning tools, and it belongs alongside a governance review like this one rather than inside it. Overstating what any review process catches is its own risk; see guardrails for AI-generated code for where a license check sits among the other deterministic checks a CI pipeline should actually enforce, and where it does not.
If license exposure is a real concern, make it an explicit, separate check in your pipeline, not an assumption that it is covered because a court dismissed an unrelated legal theory in someone else's lawsuit.
Frequently asked questions
01What did the Ninth Circuit rule in Doe v. GitHub?
On September 16, 2026, it affirmed dismissal of DMCA Section 1202(b) claims against GitHub Copilot, holding that AI-generated code produced through a probabilistic process is a new work, not a copy stripped of copyright-management information.
02Does the Copilot DMCA ruling mean AI-generated code cannot infringe copyright?
No. The ruling only addressed one DMCA provision about removing copyright-management information. Direct copyright infringement, substantial-similarity claims, and license-obligation questions are separate legal theories this case did not resolve.
03What claims are still pending in Doe v. GitHub after this ruling?
Two contract claims remain active in the district court, alleging GitHub and OpenAI breached open-source license and attribution terms. The Ninth Circuit's DMCA ruling does not affect those claims either way.
04Is this the first appellate ruling on AI and copyright-management information?
Multiple outlets covering the case, including the law firm that won it for Microsoft and GitHub, describe it as the first federal appellate decision to squarely address how DMCA Section 1202(b) applies to generative AI output.
05Does a DMCA dismissal mean AI-generated code is safe to merge without a license review?
No. It closes off one specific liability theory. It says nothing about whether code resembling copyleft-licensed training data carries license obligations, which is a separate legal and governance question this case did not reach.