Skip to main content
IP Copyright

The AI Act Makes Your Opt-Out Their Obligation. It Still Isn't Your Proof

In short

The EU AI Act tells model providers to go looking for your opt-out and to respect it once they find it. That obligation is real and it is theirs. What it can't do is answer the question a dispute puts to you: what did you make, and when.

You publish work online and you put a reservation on it. Maybe that's a line in robots.txt, maybe a TDM Reservation Protocol file, maybe a sentence in your terms of use. Months later a model ships, and you have no way of knowing whether your material is inside it. The useful question is what the law actually does about that. Since 2 August 2025 the answer is more than many rightsholders expect in one direction, and less than they hope in another.

What Article 53(1)(c) puts on the model provider

Under Article 53(1)(c) of the EU AI Act, a provider of a general-purpose AI model has to put in place a policy to comply with Union copyright law. The provision names one thing specifically: identifying and complying with a reservation of rights expressed under Article 4(3) of the DSM Directive (EU) 2019/790. Obligations for GPAI providers have applied since 2 August 2025.

The verbs are worth reading slowly. Identify, then comply. The GPAI text data mining opt-out obligation sits with the provider, not with you. They're the ones who have to go looking for a reservation before they mine, and they're the ones who have to respect it once they find it. You don't have to notify them, chase them, or file anything with them for that duty to exist.

What a reservation has to look like to count

Article 4 of the DSM Directive is the commercial text and data mining exception. It allows mining of lawfully accessible works unless the rightsholder has reserved the right to prevent it. Article 4(3) is where that reservation lives, and it carries one condition that decides most arguments: for content made publicly available online, the reservation has to be expressed in a machine-readable way.

Machine-readable means a crawler can parse it without a person interpreting it. Robots.txt directives, the TDM Reservation Protocol, and rights metadata attached to the file itself all fit that description. A paragraph in your terms of use, written for a human to read, does not.

That distinction has already been tested. The Higher Regional Court of Hamburg, in its judgment of 10 December 2025 in case 5 U 104/24 (Kneschke v. LAION), held a reservation ineffective because it was expressed only in human-readable general terms of use rather than in a machine-readable format. A further appeal to the Bundesgerichtshof was expressly allowed, so the question is not closed. That judgment is covered on its own elsewhere on this blog. The short version here is that the format of a reservation carries as much weight as the fact you made one.

The duty runs against them, not for you

This is where the asymmetry starts to matter. Article 53(1)(c) is a compliance obligation placed on model providers, enforceable against them by the authorities set up to supervise them. Its existence is good news for rightsholders.

What it isn't is evidence of anything you own. A duty on someone else to look for your reservation tells nobody:

  • What you actually created, as opposed to what sits on the page today
  • The form the work was in at a given moment, before edits, later versions and re-uploads
  • The date it existed in that form
  • Whether any of that can be shown without relying on the platform that happens to host it

What a concrete dispute asks you

The moment a disagreement stops being abstract, the questions turn around. You stop asking whether a provider met a duty and start being asked to establish your own position. The questions put to you are the ordinary ones: what is the work, what form was it in, from what date, and how do you show that independently of your own systems.

Most publishers and dataset teams answer the last one with a CMS entry, a Git history, or a cloud storage timestamp. Those records are useful internally, but they sit inside infrastructure you control, so the date rests on the trustworthiness of that infrastructure rather than on something a third party can check on its own. A counterparty who wants to contest the date has an obvious line to take.

Two records, two different jobs

Question in disputeMachine-readable reservationDated record of the work
May a GPAI provider mine this content for commercial trainingThis is exactly what it addressesNot what it does
Does the provider have to go looking before miningYes, under Article 53(1)(c), applying since 2 August 2025Not applicable
What is the work and what form was it inNothing, a reservation is not the workThis is what the record fixes
On what date did it exist in that formOnly the date the reservation itself was publishedFixed by a qualified timestamp at sealing
Can a third party check it without your systemsDepends on what your site served that dayVerifiable independently of where the file is stored

What's worth putting in place now

  1. Express the reservation in a machine-readable form, not only in your terms of use. Robots.txt, the TDM Reservation Protocol, and embedded rights metadata are the formats currently in use.
  2. Separately, create a dated, tamper-evident record of each work at the point it is finished, before it goes anywhere public.
  3. If you want the regulatory background in one place first, our EU AI Act overview sets out how the obligations are sequenced.

Swiss Trust Layer covers the second item on that list: a qualified electronic seal and timestamp applied to a file, so the content and the date can be verified by anyone, without access to your CMS or your storage. It says nothing about whether a model provider met its own obligation, and that's the point.

The AI Act put a real obligation on model providers, and it is theirs to meet. What it did not do, and could not have done, is answer the question that gets asked of you: what did you make, and when.

Protect your work with Swiss Trust Layer AG

Seal your intellectual property with a court-proof e-Seal backed by Swisscom Trust Services.

Book a Free Demo

Related Articles

A German Appeal Court Threw Out a Copyright Opt-Out Because a Machine Couldn't Read It
IP & Copyright

A notice in your terms of use tells a human reader you object to AI training. A German appeal court has held that a reservation in that form doesn't satisfy Article 4(3) DSM, because the crawler it addressed was never able to read it.

September 14, 2026Read Article
An NDA Doesn't Date Your Idea. Here's the Gap That Costs Agencies Pitches
IP & Copyright

An NDA tells a prospect they cannot repeat what you shared. It says nothing about when you actually came up with it, or what happens once the pitch leaves the room. That is the gap that costs agencies their best ideas.

September 9, 2026Read Article
A Landmark US Copyright Fight Over AI Art Is Heading to Trial. What to Have Ready Regardless of the Verdict
IP & Copyright

Andersen v. Stability AI is a major US copyright case over how AI image generators were trained. The jury trial is now set for April 2027. No verdict answers the question every photographer and illustrator already has to answer for themselves: can you prove what you made, and when.

September 8, 2026Read Article
September, in one checklist: what's live, what's changing, what to fix first
IP & Copyright

This week closed with a record AI copyright settlement, a new EU disclosure law in force, and a jury trial underway that could reshape how image generators are treated. Here is a practical checklist covering what to check and fix in September, from AI content disclosure to dated proof of your own work.

September 6, 2026Read Article
The AI Copyright Lawsuit Count Nearly Tripled in a Year. Here's What Actually Changed
IP & Copyright

AI-related copyright lawsuits in the US grew from roughly 30 to over 70 in 2025, according to the Copyright Alliance. Courts are now ruling instead of settling quietly, and the EU has introduced its own transparency rules for AI-generated content. Here is what is driving the surge and what it means for anyone publishing AI-generated material.

September 5, 2026Read Article