Case Update: Andersen v. Stability AI

unlicensed use of copyright-protected artistic works in generative-AI systems.

Andersen v. Stability AI is one of the top 12 generative-AI lawsuits. To recap, artists Sarah Andersen, Kelly McKernan, and Karla Ortiz filed a class action lawsuit against Stability AI, DeviantArt, and MidJourney in federal district court alleging causes of action for copyright infringement, removal or alteration of copyright management information, and violation of publicity rights. (Andersen, et al. v. Stability AI Ltd. et al., No. 23-cv-00201-WHO (N.D. Calif. 2023).) The claims relate to the defendants’ alleged unlicensed use of their copyright-protected artistic works in generative-AI systems.

On October 30, 2023, Judge Orrick dismissed all claims except for Andersen’s direct infringement claim against Stability. Most of the dismissals, however, were granted with leave to amend.

The Claims

McKernan’s and Ortiz’s copyright infringement claims

The judge dismissed McKernan’s and Ortiz’s copyright infringement claims because they did not register the copyrights in their works with the U.S. Copyright Office.

I criticized the U.S. requirement of registration as a prerequisite to the enforcement of a domestic copyright in a U.S. court in a 2019 Illinois Law Review article (Copyright Enforcement: Time to Abolish the Pre-Litigation Registration Requirement.) This is a uniquely American requirement. Moreover, the requirement does not apply to foreign works. This has resulted in the anomaly that foreign authors have an easier time enforcing the copyrights in their works in the United States than U.S. authors do. Nevertheless, until Congress acts to change this, it is still necessary for U.S. authors to register their copyrights with the U.S. Copyright Office before they can enforce their copyrights in U.S. courts.  

Since there was no claim that McKernan or Ortiz had registered their copyrights, the judge had no real choice under current U.S. copyright law but to dismiss their claims.

Andersen’s copyright infringement claim against Stability

The Andersen complaint alleges that she “owns a copyright interest in over two hundred Works included in the Training Data” and that Stability used some of them as training data. Defendants moved to dismiss this claim because it failed to specifically identify which of those works had been registered. The judge, however, determined that her attestation that some of her registered works had been used as training images sufficed, for pleading purposes.  A motion to dismiss tests the sufficiency of a complaint to state a claim; it does not test the truth or falsity of the assertions made in a pleading. Stability can attempt to disprove the assertion later in the proceeding. Accordingly, Judge Orrick denied Stability’s motion to dismiss Andersen’s direct copyright infringement claim.

Andersen’s copyright infringement claims against DeviantArt and MidJourney

The complaint alleges that Stability created and released a software program called Stable Diffusion and that it downloaded copies of billions of copyrighted images (known as “training images”), without permission, to create it. Stability allegedly used the services of LAION (LargeScale Artificial Intelligence Open Network) to scrape the images from the Internet. Further, the complaint alleges, Stable Diffusion is a “software library” providing image-generating service to the other defendants named in the complaint. DeviantArt offers an online platform where artists can upload their works. In 2022, it released a product called “DreamUp” that relies on Stable Diffusion to produce images. The complaint alleges that artwork the plaintiffs uploaded to the DeviantArt site was scraped into the LAION database and then used to train Stable Diffusion. MidJourney is also alleged to have used the Stable Diffusion library.

Judge Orrick granted the motion to dismiss the claims of direct infringement against DeviantArt and MidJourney, with leave to amend the complaint to clarify the theory of liability.

DMCA claims

The complaint makes allegations about unlawful removal of copyright management information in violation of the Digital Millennium Copyright Act (DMCA). Judge Orrick found the complaint deficient in this respect, but granted leave to amend to clarify which defendant(s) are alleged to have done this, when it allegedly occurred, and what specific copyright management information was allegedly removed.

Publicity rights claims

 Plaintiffs allege that the defendants used their names in their products by allowing users to request the generation of artwork “in the style of” their names. Judge Orrick determined the complaint did not plead sufficient factual allegations to state a claim. Accordingly, he dismissed the claim, with leave to amend. In a footnote, the court deferred to a later time the question whether the Copyright Act preempts the publicity claims.

In addition, DeviantArt filed a motion to strike under California’s Anti-SLAPP statute. The court deferred decision on that motion until after the Plaintiffs have had time to file an amended complaint.

Unfair competition claims

The court also dismissed plaintiffs’ claims of unfair competition, with leave to amend.

Breach of contract claim against DeviantArt

Plaintiffs allege that DeviantArt violated its own Terms of Service in connection with their DreamUp product and alleged scraping of works users upload to the site. This claim, too, was dismissed with leave to amend.

Conclusion

Media reports have tended to overstate the significance of Judge Orrick’s October 30, 2023 Order. Reports of the death of the lawsuit are greatly exaggerated. It would have been nice if greater attention had been paid to the registration requirement during the drafting of the complaint, but the lawsuit nevertheless is still very much alive. We won’t really know whether it will remain that way unless and until the plaintiffs amend the complaint – which they are almost certainly going to do.

Visit my extensive Copyright FAQs page.

Need help with copyright registration? Contact attorney Tom James.

AI Legislative Update

Congressional legislation to regulate artificial intelligence (“AI”) and AI companies is in the early formative stages. Just about the only thing that is certain at this point is that federal regulation in the United States is coming.

Congressional legislation to regulate artificial intelligence (“AI”) and AI companies is in the early formative stages. Just about the only thing that is certain at this point is that federal regulation in the United States is coming.

In August, 2023, Senators Richard Blumenthal (D-CT) and Josh Hawley (R-MO) introduced a Bipartisan Framework for U.S. AI Act. The Framework sets out five bullet points identifying Congressional legislative objectives:

  • Establish a federal regulatory regime implemented through licensing AI companies, to include requirements that AI companies provide information about their AI models and maintain “risk management, pre-deployment testing, data governance, and adverse incident reporting programs.”
  • Ensure accountability for harms through both administrative enforcement and private rights of action, where “harms” include private or civil right violations. The Framework proposes making Section 230 of the Communications Decency Act inapplicable to these kinds of actions. (Second 230 is the provision that generally grants immunity to Facebook, Google and other online service providers for user-provided content.) The Framework identifies the harms about which it is most concerned as “explicit deepfake imagery of real people, production of child sexual abuse material from generative A.I. and election interference.” These are not, by any means, the only AI legal issues there are. Noticeably absent, for example,  is any mention of harms caused by copyright infringement.
  • Restrict the sharing of AI technology with Russia, China or other “adversary nations.”
  • Promote transparency: The Framework would require AI companies to disclose information about the limitations, accuracy and safety of their AI models to users; would give consumers a right to notice when they are interacting with an AI system; would require providers to watermark or otherwise disclose AI-generated deepfakes; and would establish a public database of AI-related “adverse incidents” and harm-causing failures.
  • Protect consumers and kids. “Consumer should have control over how their personal data is used in A.I. systems and strict limits should be imposed on generative A.I. involving kids.”

The Framework does not address copyright infringement, whether of the input infringement or the output infringement  variety.

The Senate Judiciary Committee Subcommittee on Privacy, Technology, and the Law held a hearing on September 12, 2023. Witnesses called to testify generally approved of the Framework as a starting point.

The Senate Commerce, Science, and Transportation Subcommittee on Consumer Protection, Product Safety and Data Security also held a hearing on September 12, called The Need for Transparency in Artificial Intelligence. One of the witnesses, Dr. Ramayya Krishnan, Carnegie Mellon University, did raise a concern about the use of copyrighted material by AI systems and the economic harm it causes for creators.

On September 13, 2023, Sen. Chuck Schumer (D-NY) held an “AI Roundtable.” Invited attendees present at the closed-door session included Bill Gates (Microsoft), Elon Musk (xAI, Neuralink, etc.) Sundar Pichai (Google), Charlie Rivkin (MPA), and Mark Zuckerberg (Meta). Gates, whose Microsoft company, like those headed by some of the other invitees, has been investing heavily in generative-AI development, touted the claim that AI could target world hunger.

Meanwhile, Dana Rao, Adobe’s Chief Trust Officer, penned a FAIR Act proposal that Congress establish a federal anti-impersonation right to address the economic harms generative-AI causes when it impersonates the style or likeness of an author or artist. The proposed law would be called the Federal Anti-Impersonation Right Act, or “FAIR Act,” for short. The proposal would provide for the recovery of statutory damages by artists who are unable to prove actual economic damages.

AI Legal Issues

AI has been trained not just to perform customer service tasks, but also to perform analytics and diagnostic tests; to repair products; to update software; to drive cars; and even to write articles and create images and videos. These developments may be helping to streamline tasks and improve productivity, but they have also generated a range of new legal issues.

AI is not new. Its implementation also is not new. In fact, consumers regularly interact with AI-powered systems every day. Online help systems often use AI to provide quick answers to questions that customers routinely ask. Sometimes these are designed to give a user the impression that s/he is communicating with a person.

AI systems also perform discrete functions such as analyzing a credit report and rendering a decision on a loan or credit card application, or screening employment applications.

Many other uses have been found for AI and new ones are being developed all the time. AI has been trained not just to perform customer service tasks, but also to perform analytics and diagnostic tests; to repair products; to update software; to drive cars; and even to write articles and create images and videos. These developments may be helping to streamline tasks and improve productivity, but they have also generated a range of new legal issues.

"The March of Intgelligence,"19th century illustration of a fantastical giant robot trampling judges and wreaking havoc
(Public domain)

Tort liability

While there are many different kinds of tort claims, the elements of tort claims are basically the same: (1) The person sought to be held liable for damages or ordered to comply with a court order must have owed a duty to the person who is seeking the legal remedy; (2) the person breached that duty; (3) the person seeking the legal remedy experienced harm, i.e., real or threatened injury; and (4) the breach was the actual and proximate cause of the harm.

The kind of harm that must be demonstrated varies depending on the kind of tort claim. For example, a claim of negligent driving might involve bodily injury, while a claim of defamation might involve injury to reputation. For some kinds of tort claims, the harm might involve financial or economic injury. 

The duty may be specified in a statute or contract, or it might be judge-made (“common law.”) It may take the form of an affirmative obligation (such as a doctor’s obligation to provide a requisite level of care to a patient), or it may take a negative form, such as the common law duty to refrain from assaulting another person.

The advent of AI does not really require any change in these basic principles, but they can be more difficult to apply to scenarios that involve the use of an AI system.

Example. Acme Co. manufactures and markets Auto-Doc, a machine that diagnoses and repairs car problems. Mike’s Repair Shop lays off its automotive technician employees and replaces them with one of these machines. Suzie Consumer brings her VW Jetta to Mikes Repair Shop for service because she has been hearing a sound that she describes as being a grinding noise that she thinks is coming from either the engine or the glove compartment. The Auto-Doc machine adds engine oil, replaces belts, and removes the contents of the glove compartment. Later that day, Suzie’s brakes fail and her vehicle hits and kills a pedestrian in a crosswalk. A forensic investigation reveals that her brakes failed because they were badly worn. Who should be held liable for the pedestrian’s death – Suzie, Mike’s, Acme Co., some combination of two of them, all of them, or none of them?

The allocation of responsibility will depend, in part, on the degree of autonomy the AI machine possesses. Of course, if it can be shown that Suzie knew or should have known that her brakes were bad, then she most likely could be held responsible for causing the pedestrian’s death. But what about the others? Their liability, or share of liability, is affected by the degree of autonomy the AI machine possesses. If it is completely autonomous, then Acme might be held responsible for failing to program the machine in such a way that it would test for and detect worn brake pads even if a customer expresses an erroneous belief that the sound is coming from the engine or the glove compartment. On the other hand, if the machine is designed only to offer suggestions of possible problems and solutions,  leaving it up to a mechanic to accept or reject them, then Mike’s might be held responsible for negligently accepting the machine’s recommendations. 

Product liability

 Example.  Acme Co. manufactures and sells Auto-Article, a software program that is designed to create content of a type and kind the user specifies. The purpose of the product is to enable a website owner to generate and publish a large volume of content frequently, thereby improving the website’s search engine ranking. It operates   by scouring the Internet and analyzing instances of the content the user specifies to produce new content that “looks like” them. XYZ Co. uses the software to generate articles on medical topics. One of these articles explains that chest pain can be caused by esophageal spasms but that these typically do not require treatment unless they occur frequently enough to interfere with a person’s ability to eat or drink. Joe is experiencing chest pain. He does not seek medical help, however, because he read the article and therefore believes he is experiencing esophageal spasms. He later collapses and dies from a heart attack. A medical doctor is prepared to testify that his death could have been prevented if he had sought medical attention when he began experiencing the pain.

It is conceivable that an AI system might engage in activity that is prohibited by an applicable jurisdiction’s criminal laws. E-mail address harvesting is an example. In the United States, for example, the CAN-SPAM Act makes it a crime to send a commercial email message to an email address that was  obtained  by automated scraping of Internet websites for email addresses. Of course, if a person intentionally uses an AI system for scraping, then liability should be clear. But what if an AI system “learns” to engage in scraping?

AI-generated criminal output may also be a problem. Some countries have made it a crime to display a Nazi symbol, such as a swastika, on a website. Will criminal liability attach if a website or blog owner uses AI to generate illustrated articles about World War II and the system generates and displays articles that are illustrated with World War II era German flags and military uniforms? In the United States, creating or possessing child pornography is illegal. Will criminal liability attach if an AI system generates it?

Some of these kinds of issues can be resolved through traditional legal analysis of the intent and scienter elements of the definitions of crimes. A jurisdiction might wish to consider, however, whether AI systems should be regulated to require system creators to implement measures that would prevent illegal uses of the technology. This raises policy and feasibility questions, such as whether and what kinds of restraints on machine learning should be required, and how to enforce them. Further, would prior restraints on the design and/or use of AI-powered expressive-content-generating systems infringe on First Amendment rights?  

Forensic and evidentiary issues

In situations involving the use of semi-autonomous AI, allocating responsibility for harm resulting from the operation of the AI  system  may be difficult. The most basic question in this respect is whether an AI system was in use or not. For example, if a motor vehicle that can be operated in either manual or autonomous mode is involved in an accident, and fault or the extent of liability depends on that (See the discussion of tort liability, above), then a way of determining the mode in which the car was being driven at the time will be needed.

If, in the case of a semi-autonomous AI system, tort liability must be allocated between the creator of the system and a user of it, the question of fault may depend on who actually caused a particular tortious operation to be executed – the system creator or the user. In that event, some method of retracing the steps the AI system used may be essential. This may also be necessary in situations where some factor other than AI contributed, or might have contributed, to the injury. Regulation may be needed to ensure that the steps in an AI system’s operations are, in fact, capable of being ascertained.

Transparency problems also fall into this category. As explained in the Journal of Responsible Technology, people might be put on no-fly lists, denied jobs or benefits, or refused credit without knowing anything more than that the decision was made through some sort of automated process. Even if transparency is achieved and/or mandated, contestability will also be an issue.

Data Privacy

To the extent an AI system collects and stores personal or private information, there is a risk that someone may gain unauthorized access to it.. Depending on how the system is designed to function, there is also a risk that it might autonomously disclose legally protected personal or private information. Security breaches can cause catastrophic problems for data subjects.

Publicity rights

Many jurisdictions recognize a cause of action for violation of a person’s publicity rights (sometimes called “misappropriation of personality.”) In these jurisdictions, a person has an exclusive legal right to commercially exploit his or her own name, likeness or voice. To what extent, and under what circumstances, should liability attach if a commercialized AI system analyzes the name, likeness or voice of a person that it discovers on the Internet? Will the answer depend on how much information about a particular individual’s voice, name or likeness the system uses, on one hand, or how closely the generated output resembles that individual’s voice, name or likeness, on the other?

Contracts

The primary AI-related contract concern is about drafting agreements that adequately and effectively allocate liability for losses resulting from the use of AI technology. Insurance can be expected to play a larger role as the use of AI spreads into more areas.

Bias, Discrimination, Diversity & Inclusion

Some legislators have expressed concern that AI systems will reflect and perpetuate biases and perhaps discriminatory patterns of culture. To what extent should AI system developers be required to ensure that the data their systems use are collected from a diverse mixture of races, ethnicities, genders, gender identities, sexual orientations, abilities and disabilities, socioeconomic classes, and so on? Should developers be required to apply some sort of principle of “equity” with respect to these classifications, and if so, whose vision of equity should they be required to enforce? To what extent should government be involved in making these decisions for system developers and users?

Intellectual Property

AI-generated works like articles, drawings, animations, music and so on, raise three kinds of copyright issues:

  1. Input infringement issues, i.e., questions like whether AI systems that are designed to create new works based on existing copyright-protected works infringe the copyrights in those works. The highest-stake legal battleground today centers on this. I provide a layperson-friendly explanation of this issue and the initial lawsuits raising it in Does AI Infringe Copyright?  
  2. Output infringement issues, i.e., whether output generated by AI tools infringes copyrights in the works on which the AI was trained.
  3. Copyright in output. To what extent, if at all, may copyright be claimed in AI-generated output?
Large computer with a woman reading a notebook and flipping a switch, B&W, from 1950's

Patents, Trademarks, and other IP

Computer programs can be patented. AI systems can be devised to write computer programs. Can an AI-generated computer program that meets the usual criteria for patentability (novelty, utility, etc.) be patented?

Contact Minnesota attorney Thomas James for help with copyright and trademark registration and other copyright and trademark-related matters.