Doe v. GitHub, Inc.: Ninth Circuit Holds That Generating New AI Code Without Copyright Management Information (CMI) Does Not State a DMCA Claim (2026)

In Doe v. GitHub, Inc., No. 24-7700 (9th Cir. Sept. 16, 2026), a unanimous Ninth Circuit panel affirmed dismissal of claims under Section 1202(b) of the Digital Millennium Copyright Act (DMCA), holding that where generative-AI tools create new code rather than reproduce existing code from which CMI has been removed or altered, the omission of CMI does not state a Section 1202(b) claim.

The plaintiffs were programmers who published open-source code on GitHub. They alleged, under 17 U.S.C §§ 1202(b)(1) and (b)(3), that GitHub Copilot and OpenAI’s Codex were trained on public repositories and sometimes generated their code without accompanying attribution, copyright notices, or license terms.

The district court dismissed the DMCA claims on the ground that Section 1202(b) requires “identical” copies and certified that issue for interlocutory appeal. The Ninth Circuit affirmed on a narrower basis.

The Ninth Circuit explained that “identicality” is not an independent statutory requirement. Rather, it is a shorthand for the statutory concepts of “remove,” “alter,” and “copies.” Section 1202(b) requires removal or alteration of CMI from an existing protected work. Thus, literal identicality is unnecessary — substantial reproduction with CMI omitted may provide circumstantial evidence that CMI was removed. But merely creating a similar or derivative work without CMI is insufficient unless the facts show that CMI was actually removed or altered from an existing copy.

That distinction was dispositive here. Based on the plaintiffs’ own allegations, Copilot and Codex learn from existing works and generate new works through a probabilistic process; they do not simply retrieve and reproduce stored copies. The court therefore concluded that the alleged outputs could not reasonably be characterized as copies from which CMI had been removed or altered.

The court also held that the plaintiffs had Article III standing because they plausibly alleged a substantial risk that their code would be reproduced without CMI. But it declined to consider the plaintiffs’ separate “input” theory—that CMI was removed from code at the training stage—because that theory had been forfeited.

The decision does not determine whether substantially similar AI-generated code may infringe copyright; nor does it resolve whether training on copyrighted code violates copyright law. The plaintiffs’ breach-of-contract claims remain pending.

For rights holders, the decision underscores an important distinction: Section 1202(b) addresses the removal or alteration of CMI from existing copies. An AI-generated work that merely lacks the CMI presents a different question—one that may implicate copyright infringement, contract or license restrictions, or other theories, but does not, without more, establish DMCA liability.

← Back to Insights