Resolving an Interlocutory Appeal, Ninth Circuit Affirms Dismissal of Section 1202 DMCA Claims in ongoing Doe v. GitHub litigation

Doe and Two Fawns (1882) Arthur Fitzwilliam Tait, from the Met’s Open Access Collection

On September 16, 2026, the Ninth Circuit issued its published opinion in Doe v. GitHub, Inc., affirming the district court’s dismissal of programmers’ claims under Section 1202(b) of the DMCA against GitHub, Microsoft, and OpenAI. Authors Alliance filed an amicus brief in support of affirmance, and we are pleased with the result.

The Ninth Circuit has rejected an attempt to stretch the DMCA’s copyright management information (CMI) provision to cover anyone who creates a new work that resembles an existing one without carrying over its attribution. This matters for authors because Section 1202(b) has an unusually punishing remedy: statutory damages of $2,500 to $25,000 per violation, plus attorney’s fees, available even without registering the work and potentially without any showing that the work was infringed at all. 

Those numbers multiply quickly. The anonymous Doe plaintiffs estimated their damages at more than $9 billion. Had the court accepted their theory, nearly any claim of substantial similarity without attribution could have been recast as a DMCA claim, which would have put many other non-AI uses, such as quotation, adaptation, remix, and fan fiction at risk. Instead, the court held that making something new is not “removing” or “altering” CMI. Plaintiffs must allege that CMI was actually stripped from a copy of an existing work.

Background

The plaintiffs are programmers who published copyrighted code under open-source licenses that condition reuse on attribution, in public GitHub repositories. Their suit is aimed at GitHub Copilot and OpenAI’s Codex, alleging that those tools sometimes generate verbatim or near-verbatim copies of their code stripped of the attribution, copyright notices, and license terms that accompanied it. After two rounds of motions to dismiss, the case had narrowed to one DMCA claim and two breach-of-contract claims. On June 24, 2024, Judge Jon S. Tigar dismissed the Section 1202(b) claim with prejudice, reasoning that such claims require that copies be identical.  

Note: We wrote about this issue and what was then called the “identicality” requirement in this issue brief.  

Interlocutory appeals

It’s worth a short diversion to say that federal appellate courts ordinarily hear appeals only from final judgments. 28 U.S. Code § 1292 offers a narrow exception. A district court may certify an otherwise non-final order when it “involves a controlling question of law as to which there is substantial ground for difference of opinion” and where an immediate appeal may materially advance the litigation; the court of appeals then has discretion to take the case. Judge Tigar certified the question whether Sections 1202(b)(1) and (b)(3) “impose an identicality requirement,” and the Ninth Circuit accepted. 

This was an important question to resolve, and not just for this case. Section 1202 claims have become a staple of AI litigation. They appear in many of the most closely watched suits, including New York Times v. Microsoft, The Intercept v. OpenAI, Concord v. Anthropic, Kadrey v. Meta, and Andersen v. Stability AI, and newer complaints keep adding them. We think plaintiffs like these claims because they require no registration, carry statutory damages for every violation, and offer a theory of liability that plaintiffs hope will survive even if AI training turns out to be fair use. 

The Ninth Circuit’s answer now binds the Northern District of California, where nearly half of U.S. AI copyright suits have been filed, and it will be persuasive authority elsewhere such as in the Southern District of New York, home of the consolidated OpenAI litigation. The opinion doesn’t dispose of every Section 1202 theory (see the discussion of input-stage claims below). But it rejects the version with the most potential to reach authors: the theory that a new work lacking CMI transposed from source material is itself a violation.

Our amicus brief

Authors Alliance filed its brief on July 18, 2025, working with the Cyberlaw Clinic at Harvard Law School. We argued that CMI attaches to particular “copies” of a work rather than to the work itself; that “remove” and “alter” describe an active act of stripping or changing CMI already affixed to a copy, not a failure to add CMI to something new; and that an expansive reading would expose authors, remixers, researchers, and fan fiction writers to opportunistic litigation under a statute with no registration requirement and statutory damages of up to $25,000 per violation.

Where the opinion aligns with our position

The panel’s reasoning tracks ours closely on the statutory text, specifically how to understand “removed” and “altered.” Both verbs, the court explained, “imply taking an affirmative act with respect to CMI connected to a work that already exists,” so that “[o]ne who creates a new work and fails to include CMI cannot be said to have ‘removed’ or ‘altered’ anything” (Doe v. GitHub COA Opinion, p. 14). The court grounded that reading in the definition of CMI as information conveyed in connection with copies of a work, “not in connection with excerpts or derivative works.”

The panel also took seriously the types of consequences we described. Observing that many copyright cases involve a substantially similar work created without attribution, it warned that if that alone violated Section 1202(b), “the DMCA would supplant traditional copyright protections and subject defendants to potentially ruinous liability under the DMCA’s enhanced statutory damages” (Doe v. GitHub COA Opinion, p. 18).

From “identicality” to a better standard

The most significant doctrinal development is the panel’s declining to adopt “identicality” as a freestanding test. The court called the label “something of a misnomer because the DMCA does not require literal identicality between the plaintiff’s work and the allegedly infringing work,” and explained that the concept “is best understood as a gloss on the statutory terms ‘remove,’ ‘alter,’ and ‘copies’ rather than an independent (and atextual) element of a section 1202(b) claim” (Doe v. GitHub COA Opinion, p. 15).

We think this is an improved framing, and it echoes a point our brief made: the phrase “identical copies” appears nowhere in the statute and cannot capture the nuance the text actually requires. An identicality rule invites the plaintiffs’ objection that a defendant could escape liability by changing a single word while deleting the notice. The court closed that door, noting that “[m]inor cosmetic changes will not necessarily protect a defendant who substantially or entirely reproduces the protected work and removes CMI” (Doe v. GitHub COA Opinion, p. 16). 

What replaces identicality is an affirmative pleading requirement that originates in the statutory text: plaintiffs “must therefore allege that defendants removed or altered CMI from copies of existing protected works,” and alleging only that a similar or derivative work lacks CMI, without facts showing removal or alteration, is not sufficient (Doe v. GitHub COA Opinion, p. 15). Close similarity remains relevant, but as circumstantial evidence of removal rather than as a checkbox.

The panel applied that standard to Copilot as the plaintiffs themselves described it, concluding that the tool “is best understood as learning from existing works and then creating new works based on that learning process, not as making copies of existing works” (Doe v. GitHub COA Opinion, p. 17).

Some issues remain open

While this opinion provides welcome clarity regarding CMI and outputs, a number of issues remain. Here are a few:  

  • The “input” theory. The plaintiffs also argued that defendants violated Section 1202(b)(1) at the training stage by stripping CMI from code before feeding it into the model. The panel declined to reach it, finding that the plaintiffs had failed to preserve the theory below and “therefore conclude[d] that plaintiffs forfeited the theory” (Doe v. GitHub COA Opinion, p. 11). Because the panel resolved it on forfeiture, the opinion leaves the input theory open, in the Ninth Circuit and elsewhere. 
  • Infringement claims related to AI outputs. Outputs will sometimes be identical or substantially similar to in copyright works. The court was explicit that it “express[es] no view on whether that similarity would allow plaintiffs to assert a claim for copyright infringement” (Doe v. GitHub COA Opinion, p. 18). This is a DMCA holding, not a fair use holding, so infringement claims related to AI outputs continue to be a live issue and one we expect to see more often in the coming years.  
  • Lawful uses. Having resolved the case through close analysis of the statute, the panel did not reach the broader arguments raised about whether a Section 1202(b) claim can stand untethered from a viable infringement claim. Our view continues to be that a Section 1202(b) claim cannot and should not proceed independent of a valid copyright infringement claim.

Conclusion

We are heartened that the Ninth Circuit declined to endorse what would have been a monumental expansion of DMCA liability, one that could have turned every allegation of substantial similarity without attribution into a claim for enhanced statutory damages. We think the panel put it very well: “We decline plaintiffs’ invitation to transform run-of-the-mill copyright-infringement claims into DMCA claims” (Doe v. GitHub COA Opinion, p. 18). That result protects the space authors need to quote, adapt, analyze, and build on the works that came before them without a constant new dread that these essential activities will invite opportunistic CMI removal claims.


Discover more from Authors Alliance

Subscribe to get the latest posts sent to your email.

Leave a Comment

Scroll to Top