TL;DR
- A federal court gave final approval on July 20, 2026 to Anthropic's $1.5 billion settlement in Bartz v. Anthropic, the largest copyright recovery in United States history, but a settlement is a private bargain, not a precedent, and it decided nothing that binds any other court.
- The June 2025 ruling underneath the settlement did decide one thing every lawyer buying AI should understand: training a model on lawfully acquired books can be fair use, while building a library out of pirated copies is infringement. Provenance, meaning where the training data came from, is the risk.
- For a solo or small firm practice, the operational consequence is concrete. Ask your vendors where their training data came from, read the indemnity clause instead of trusting the marketing, and keep client confidences out of tools you have not vetted.
Key Findings
- The court approved money and the destruction of pirated files. It did not rule that AI training is lawful for everyone.
- Judge Alsup's fair use holding on training survives only because Anthropic paid to avoid appeal. As a matter of who is bound, it reaches three named plaintiffs, and it is one trial court's view.
- Courts are split on whether to analyze acquisition separately from training. That split is unresolved and it drives your exposure.
- Vendor indemnities exist, but they are narrow, conditional, and, in the legal AI market, inconsistent about whether they even reach the model's output.
- Your professional duties do not soften because a vendor made a promise.
Details
The headline and the fine print
On July 20, 2026, Judge Araceli Martinez-Olguin of the Northern District of California granted final approval to the settlement in Bartz v. Anthropic PBC. Anthropic will pay $1.5 billion. Class counsel reported that more than 500,000 potential class members will each receive an estimated $3,100 per work, drawn from roughly 482,000 works that Anthropic downloaded from two pirate repositories, Library Genesis and Pirate Library Mirror. The court called the deal fair, reasonable, and adequate, overruled the objections filed against it, and awarded class counsel $101,561,111 in fees, which the Authors Guild calculated at about 6.8 percent of the fund. That was well below the $187.5 million counsel had requested. The court reached the fee number by applying a 3.75 multiplier to an estimated lodestar of $27,082,963, rather than the far larger multiplier counsel sought. Class counsel reported 350 valid opt outs covering 1,802 works. Anthropic funds the payment in installments running through 2027 and must destroy the original pirated files, and copies derived from them, within 30 days of the final judgment.
Two facts matter more than the dollar figure. First, Anthropic admitted no wrongdoing. A settlement is purchased peace, not a judgment. Second, and most coverage buried this, the release is narrow. As the Kluwer Copyright Blog put it, the settlement "only releases Anthropic from liability for past conduct, specifically, its acquisition, retention, and use of the identified pirated works before August 25, 2025." It did not release claims based on the outputs of Anthropic's models. If Claude reproduces a protected work tomorrow, that is a separate fight.
What the court actually held, before anyone settled
The legal substance came a year earlier. In June 2025, Judge William Alsup granted summary judgment in part and denied it in part, and he held three separate things. Training a model on books to produce new text was, on these facts, spectacularly transformative and a fair use. Digitizing print books that Anthropic had lawfully purchased, then discarding the print, was also fair use because it merely changed the format. But downloading millions of pirated copies to build a permanent central library was not fair use, and that piece was headed to a December 2025 trial where statutory damages could have climbed into the hundreds of billions of dollars.
Read that again, because the acquisition versus use distinction is the whole ballgame. The court did not bless everything Anthropic did with books. It approved what Anthropic did with books it obtained legally and it condemned how the company got the rest. When Alsup later certified a class, he certified only the piracy claim, not the training question. So the fair use holding on training binds, as a matter of who is a party, only the three named plaintiffs. The class that recovered $1.5 billion recovered on piracy.
Why this is not precedent, and why that is not a technicality
Because Anthropic settled rather than appeal, Alsup's reasoning will never be tested by the Ninth Circuit. It is one trial judge's opinion. Other judges are free to disagree, and they already have. Two days after Alsup ruled, Judge Vince Chhabria reached a fair use result for Meta in Kadrey v. Meta Platforms, Inc., but he refused to separate the pirated downloads from the training purpose, analyzing them together as a single act, and he warned that in most cases plaintiffs with a better market harm record should win. So the two most cited AI training decisions in the country agree on the result and disagree on the method. That is not settled law. That is a fault line.
Elsewhere the picture is more varied. In February 2025, in Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc., Judge Bibas rejected a fair use defense outright where an AI tool was built to compete with the copyright owner, a case with obvious resonance for anyone selling legal research AI. In November 2025, the High Court in Getty Images (US) Inc. v. Stability AI Ltd. largely rejected Getty's copyright claims on narrow and fact specific grounds. The New York Times case against OpenAI and Microsoft remains in discovery, with summary judgment briefing not yet resolved. Any vendor who tells you AI training is now legal has read a press release, not the cases.
The landscape you are buying into
Anthropic is an outlier. Rather than license, it litigated and then wrote a very large check. Others chose the market. Wiley reported $40 million in AI licensing revenue in fiscal year 2025, up from $23 million the year before. HarperCollins struck a three year deal with Microsoft that pays $5,000 per title, split evenly between publisher and author, on an opt in basis, with output capped at no more than 200 consecutive words or 5 percent of a book's text. Publishers Weekly describes HarperCollins as the first and only large publisher to offer such a deal. On the news side, News Corp signed with OpenAI in a deal the Wall Street Journal reported could be worth more than $250 million over five years.
A licensed data market is forming in real time. That fact carries an argument, and I want to label it as an argument rather than a holding. As that market matures, it becomes harder for a defendant to claim there is no market to harm, which is the very ground on which Meta and Anthropic won the training question. Whether courts accept that argument is unresolved.
Congress has noticed. The bipartisan TRAIN Act would let a copyright owner obtain a subpoena to learn whether a specific work was used to train a model. The Hawley and Blumenthal AI Accountability and Personal Data Protection Act would create a federal cause of action for training on copyrighted work without consent. California already requires training data disclosures under AB 2013. None of these governs your vendor contract today. All of them signal where diligence expectations are heading.
The provider versus deployer distinction, in plain terms
There are layers. The model provider builds the model. The application vendor wraps it in a product a lawyer actually uses. The law firm deploys it. Exposure for how training data was acquired sits mostly with the provider. That is comforting until you notice two things. Your firm can be named in a suit and pay to extract itself even when it ultimately wins. And if your firm builds an internal tool on its own document sets, it has stepped toward the provider role, and Alsup's warning about how you acquire your corpus becomes your problem, not someone else's.
What the indemnities really say
Vendors advertise copyright indemnities. Read them. Microsoft's Copilot Copyright Commitment, OpenAI's Copyright Shield, and comparable promises from Google and Anthropic all defend paying customers against copyright claims arising from output, but only if you kept the safety systems on, held the rights to your inputs, and did not use output you knew or should have known was infringing. That last condition is a trap for the non specialist, because infringement that is obvious to a copyright lawyer is invisible to everyone else. Anthropic's commercial terms state that it will defend customers against copyright claims for authorized use of the service and its outputs and pay approved settlements or judgments.
The legal AI vendors are less uniform than the general providers, and this is where diligence earns its fee. Harvey's platform agreement expressly indemnifies customers against claims that its output infringes, subject to the familiar carve out for output the customer knew or should have known would infringe, and it places that indemnity outside its general liability cap. Thomson Reuters offers an intellectual property indemnity in its general terms, but that indemnity excludes portions of the service provided by its third party model suppliers, and CoCounsel runs on third party models, which raises a genuine question whether generated output is covered at all. LexisNexis provides an intellectual property indemnity in its general terms, yet it separately tells customers that output may include content subject to third party rights and offers no warranty to the contrary. Three legal vendors, three different answers on the one question that matters. Do not assume. Ask, and get it in writing.
And understand what an indemnity is not. It is a contractual promise to defend and pay, dependent on the vendor's solvency and on your compliance with its conditions. It does not stop a plaintiff from naming your firm, and it does not make your malpractice carrier, rather than the vendor, your real backstop.
Ohio, specifically
Ohio has not created new AI rules. It has told you the old ones apply. The Ohio Board of Professional Conduct issued an ethics guide on artificial intelligence for lawyers and judicial officers in 2026, and the Ohio State Bar Association issued Informal Advisory Opinion 2024-01 in June 2024. Both route back to duties you already carry: competence under Prof.Cond.R. 1.1, confidentiality under Prof.Cond.R. 1.6, candor under Prof.Cond.R. 3.3, and supervision under Prof.Cond.R. 5.1 and 5.3. The American Bar Association said the same nationally in Formal Opinion 512. For a domestic relations practitioner, Rule 1.6 is the sharp edge. A public chatbot that trains on your inputs can turn a client's financial affidavit or a custody allegation into training data. That is not a copyright problem. That is a confidentiality breach, and no vendor indemnity covers it.
Recommendations
Start here, in order, and stop trusting slide decks.
- Protect confidences first. For any matter that involves client information, use only tools that carry a contractual commitment not to train on your inputs and that provide adequate security, and confirm both in writing. Public consumer chatbots do not qualify. This is a Prof.Cond.R. 1.6 obligation, not a preference, and it is the single risk most likely to reach a solo domestic relations practice.
- Before you renew or sign, get three answers in writing. Where did the training data come from, and will the vendor represent that it was lawfully acquired or licensed. Does the indemnity reach claims arising from the model's output, not merely the software. What conditions void that indemnity. Hand these three questions to whoever runs procurement. If the vendor will not answer the first, or the indemnity excludes output, treat that as a red flag, not a formality.
- Read the indemnity against your actual use. Confirm that it survives outside the liability cap, confirm it is not limited to the fees you paid, and identify every carve out, especially any knew or should have known clause. Ask whether your enterprise order form alters the standard terms, because it frequently does.
- If your firm builds its own tool on its own files, treat acquisition as the risk. Document that you hold the rights to every document set you ingest. That is the direct, practical lesson of the acquisition versus use line.
- Verify every output. Prof.Cond.R. 3.3 and the Ohio guidance make you, not the tool, responsible for what you file.
The threshold that would change this advice is a federal appellate ruling squarely on AI training, or a statute such as the TRAIN Act becoming law. Until then, the law is unsettled and prudence is the only defensible posture.
Caveats
I am describing a settlement and a set of trial court rulings, not settled law. The fair use holdings could be narrowed or rejected on appeal or in other circuits. Vendor terms change often and enterprise contracts are negotiated, so verify the current version before relying on anything here. Nothing in this article is legal advice for a specific matter, and where I have flagged the law as unsettled, it genuinely is.
Appendix: Sources
Cases
- Bartz v. Anthropic PBC, No. 3:24-cv-05417 (N.D. Cal.) (SJ June 23, 2025; final approval July 20, 2026).
- Kadrey v. Meta Platforms, Inc., No. 23-cv-03417-VC (N.D. Cal. June 25, 2025).
- Thomson Reuters Enter. Ctr. GmbH v. Ross Intelligence Inc., 765 F. Supp. 3d 382 (D. Del. 2025).
- Concord Music Grp., Inc. v. Anthropic PBC, 772 F. Supp. 3d 1131 (N.D. Cal. 2025).
- Getty Images (US) Inc. v. Stability AI Ltd., [2025] EWHC 2863 (Ch).
- N.Y. Times Co. v. Microsoft Corp., No. 1:23-cv-11195 (S.D.N.Y.).
Ethics and regulatory authority
- ABA Comm. on Ethics & Prof'l Responsibility, Formal Op. 512 (2024).
- Ohio Bd. of Prof'l Conduct, Ethics Guide on Artificial Intelligence for Lawyers and Judicial Officers (2026).
- Ohio State Bar Ass'n, Informal Advisory Op. 2024-01 (June 2024).
- Ohio Prof.Cond.R. 1.1, 1.6, 3.3, 5.1, 5.3.
- Transparency and Responsibility for Artificial Intelligence Networks (TRAIN) Act (proposed).
- AI Accountability and Personal Data Protection Act (proposed).
- Cal. AB 2013 (Generative AI Training Data Transparency).
Selected reporting and analysis
- AP — Anthropic settlement
- Reuters via Claims Journal — final approval
- Authors Guild — final approval
- Authors Guild — what authors need to know
- Authors Alliance — final approval recap
- Courthouse News — destruction and class definition
- Susman Godfrey — terms and release scope
- Kluwer Copyright Blog — release scope
- Goodwin — Alsup SJ analysis
- Goodwin — Kadrey v. Meta
- Jenner & Block — Thomson Reuters v. Ross
- Ropes & Gray — Getty v. Stability AI
- LegalClarity — NYT v. OpenAI status
- Proskauer — provider indemnities
- Kemp IT Law — Microsoft indemnity conditions
- Anthropic — commercial terms indemnity
- Berkeley Tech. L.J. — TRAIN Act
- Crowell & Moring — California AB 2013
- ABA — Formal Op. 512 announcement
- Benesch — Ohio Board AI ethics guide
- OBLIC — Ohio AI developments
Matthew A. Mishak, Esq. is the Managing Attorney of Mishak Law LLC and the Founder and CEO of LegalTek.ai (SilverTung), an AI powered legal practice management and governance platform. He serves as Law Director for the Village of South Amherst, Ohio. A summa cum laude graduate of Cleveland-Marshall College of Law with executive AI credentials from MIT Sloan and Harvard Business School Online, he brings twenty years of Ohio legal practice across domestic relations, criminal defense, and municipal law. He is the architect of the COUNSEL framework operationalizing ABA Formal Opinion 512.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Attorney review required before reliance. LegalTek.ai is a technology company, not a law firm.









