Foundation Models and Fair Use
Peter HendersonXuechen LiDan JurafskyTatsunori HashimotoMark A. LemleyPercy Liang
Examines the legal risks of training foundation models on copyrighted data under United States fair use law and proposes technical mitigation strategies alongside policy safe harbors to prevent copyright infringement in generative outputs.
Rapid advancements in foundation models—large machine learning models trained on vast web-scraped datasets—have sparked urgent legal and ethical concerns regarding copyright infringement. Developers commonly rely on the United States fair use doctrine to justify ingesting copyrighted material without direct licenses. However, fair use protection is not guaranteed when generative models produce outputs that closely resemble protected works or compete in the same commercial markets as the original data creators.
The article evaluates how U.S. copyright and fair use case law applies to modern foundation models generating text, source code, and visual art. It demonstrates the technical vulnerabilities of current models to verbatim and non-verbatim copying, while assessing methods to mitigate intellectual property risks.
The authors conducted a legal analysis of relevant U.S. fair use precedents, intermediate copying decisions, and the Digital Millennium Copyright Act. To ground this analysis empirically, they ran experiments using the Holistic Evaluation of Language Models benchmark and commercial application programming interfaces across various large models, including versions of Generative Pre-trained Transformer models and OpenAI Codex. They evaluated data regurgitation using string matching, plagiarism-detection software across Linux kernel source code licensed under the General Public License, and named entity recognition across 10 million user image prompts.
The analysis reveals several critical findings. First, existing foundation models can regurgitate verbatim training material, such as entire children's books or hundreds of lines of source code; in code generation tests, between 0.3% and 0.91% of samples exhibited more than a 20% match to reference source files, averaging 45% to 60% overlap among flagged outputs. Second, copyright infringement under U.S. law does not require exact verbatim reproduction; non-literal copying, such as abridgments, translations, or unauthorized adaptations that extract the qualitative core of a work, also fails fair use scrutiny. Third, larger models with longer context windows show an increased tendency to extract and reconstruct substantial spans of training data. Fourth, common technical guardrails, such as basic keyword or n-gram matching, are easily bypassed using simple instruction reframing or character substitutions. Finally, statutory protections such as Digital Millennium Copyright Act safe harbors are not guaranteed for automatically generated outputs, creating direct and secondary liability risks for deployers and creators.
These findings indicate that deploying generative artificial intelligence without robust safeguards poses substantial legal, financial, and compliance risks. Overly permissive interpretations could severely harm data creators and creative labor, whereas overly restrictive rulings might ban web-scale training entirely and concentrate market power among a few incumbent tech platforms. Simple contractual disclaimers or standard terms of service do not shield deployers from strict-liability copyright infringement.
To manage these risks, practitioners should implement multi-layered mitigation architectures. At training time, organizations should deduplicate data and incorporate feedback-based learning techniques that reward transformativeness while penalizing exact extraction. At inference time, deployers must move beyond simple string matching toward semantic output filters that detect non-literal transformations, protected characters, and uncredited source code. Policymakers and courts should co-evolve legal standards with technical realities by considering meaningful safe harbors for deployers who implement verified mitigation tools, while exploring broader policy remedies to protect creative labor.
The authors acknowledge key limitations in technical mitigations: formal methods like differential privacy introduce sharp trade-offs with utility, and instance attribution remains computationally expensive at scale. Furthermore, algorithmic filters cannot fully replicate nuanced, subjective judicial determinations of fair use. While technical mitigations significantly reduce operational exposure, they cannot entirely eliminate liability or resolve the broader socioeconomic disruptions facing creative industries.
- Paper: On the Opportunities and Risks of Foundation Models, Rishi Bommasani et al. (2021). This foundational survey frames the capabilities and societal risks of foundation models, providing the conceptual basis for the source’s analysis of copyright risks in their development and deployment.
- Paper: LLM Dataset Inference: Did you train on my dataset?, Pratyush Maini et al. (2024). Building on the source’s discussion of copyright accountability, this work develops dataset-level inference methods to test whether a model was trained on a creator’s collection of works.
- Paper: Machine Unlearning of Pre-trained Large Language Models, Jin Yao et al. (2024). Extending the source’s call for technical mitigations, this study benchmarks methods for removing copyrighted and other targeted material directly from pretrained language models.
- Paper: Unlearning Concepts in Diffusion Model via Concept Domain Correction and Concept Preserving Gradient, Yongliang Wu et al. (2025). This study carries the source’s mitigation agenda into image generation, developing unlearning methods to remove copyrighted styles and other targeted concepts from diffusion models.
