The clause was two sentences long and it held up a Friday invoice for eleven days.
A game studio I've scored for since 2021 sent over a revised master services agreement with a new rider. I had to warrant that delivered audio infringed no third-party rights, indemnify them if that warranty failed, and disclose in writing whether generative tools were used in producing any delivered asset. Two of the cues were mine end to end — a detuned Juno pad through a broken spring reverb, the kind of thing I can point at a session file to prove. Two were ambient beds I had built out of renders from the Suno AI music generator: 68 BPM, F minor, a low sine drone under filtered noise, bounced to 48kHz WAV, then re-EQ'd and time-stretched in Reaper until the AI-ness sanded off.
The disclosure part was straightforward. I wrote it down. The indemnity part is where I stopped.
Here is the verdict, stated once, because it is the only sentence in this piece you strictly need: after the Munich ruling against Suno, the commercial risk in AI music has very little to do with whether your render sounds cleared, and almost everything to do with whether anyone upstream of you has contractually agreed to stand behind it — and watermarking does not answer that question.
What I actually measured
I spent one evening doing something less interesting than sound design: reading a terms-of-service page against a client contract, clause by clause, looking for one specific thing.
Not ownership. Ownership language is easy to find and it is the thing every generative audio vendor puts in the marketing copy — on a paid tier, the vendor assigns you whatever rights it holds in the output and tells you that you may use it commercially. Fine. That is a real grant and it is worth having.
What I was looking for was the mirror image of the clause my client had put in front of me: a defend-and-indemnify undertaking. The one where the vendor says that if a rights holder comes after you over audio their system produced, they will take the hit — the legal fees, the settlement, the takedown fallout. That is the instrument that makes a supply chain work. It is why a stock-footage house can sell you a clip and why a sample library can sell you a construction kit and why your client is comfortable buying from you at all.
What consumer-tier music generation terms typically offer instead is an assignment of output rights, conditioned on an active paid plan, wrapped in a broad disclaimer of warranties and a liability cap somewhere near the value of your subscription. Those are not the same instrument, and no amount of re-reading converts one into the other. Enterprise agreements are a different conversation, negotiated, and often the only place an indemnity exists at all. Check your own tier's current terms before you sign anything downstream — these documents get revised, sometimes quietly, and the version that binds you is the one in force on the day you deliver.
The measurement, then, was not a number. It was a shape. The warranty chain my client wanted ran: rights holder → model vendor → me → studio → publisher. When I traced it, the chain had a break in it, and the break was directly under my feet.
What the Munich court actually turned on
GEMA, the German collecting society that administers performing and mechanical rights for a very large share of the world's composers, sued Suno before the Landgericht München I. As reported, the court found for GEMA. This is worth reading carefully rather than as a headline, because the reasoning matters more than the result.
Three things stand out in the accounts of the decision and in the legal analyses published alongside it.
The claim was pinned to specific works, not the technology. The case concerned a defined set of well-known compositions — a handful, not a catalogue. Nothing in the ruling declares generative music unlawful as such. A decision about six songs is a decision about six songs; its force comes from the reasoning it hands to the next hundred plaintiffs.
The court engaged with what the model carries, not only with what it emits. The reported reasoning treats a model that can reproduce a recognisable composition as having, in effect, retained that composition — so the reproduction is located inside the system rather than only in a particular download. If that framing survives appeal, it moves the analysis away from the comfortable position that outputs are new works because they are statistically novel. Under that reading, a model's internal state is itself something a rights holder can point at.
Territorial arbitrage got harder. Suno's defence leaned in part on training having taken place in the United States, where fair use is at least a live argument. As reported, the Munich court did not accept that a US training process insulates the service from German law when the service is offered to German users and German works are involved. Whether that holds up is a question for a higher court, and it is being asked in parallel in other jurisdictions with different answers available.
Mind the limits, and mind them out loud: this is a first-instance decision, it is appealable, and as of writing it should not be treated as settled European law. Separately, the major US labels' litigation against Suno and Udio, filed in 2024, has partly moved toward negotiated licensing rather than judgment — meaning the most likely end state for this industry is a set of private deals whose terms nobody outside the parties will ever read. What courts establish and what contracts establish are diverging, and you will be governed by the second one.
Watermarking answers a question nobody sued over
Around the same period, Suno announced audio watermarking on generated output, along with a music-metadata integration. Read the sequencing without cynicism and it still reads oddly: the claim was about material going into the model; the announced remedy operates on material coming out.
A watermark tells a downstream system that a piece of audio was machine-generated. It does not tell anyone whether the training corpus was licensed. It does not create a licence retroactively. If a court concludes that the model itself embodies protected works, a signal embedded in the output has no bearing on that conclusion at all.
And watermarks are fragile in the exact conditions producers work in. I have not tested Suno's implementation — the technical details are not public as of writing, and any claim I made about its survivability would be invention. What I can tell you from a decade of pushing audio through mastering chains is what such a signal has to survive to be useful: MP3 at 128kbps, loudness normalisation to −14 LUFS, a semitone of pitch shift, time-stretching, a 200Hz high-pass, bounce-through-a-phone-speaker-and-re-record, and stem separation that tears the mix into four bands. Robust watermarking under all of that is an unsolved research problem, not a shipped feature. When a vendor announces one, the fair question is not whether it exists but what its false-negative rate looks like after a normal post-production pass — and nobody publishes that number.
None of which makes the move worthless. Detection and attribution plumbing is precisely what a collecting society needs in order to pay anyone. You cannot distribute royalties on a corpus you cannot identify. Building identification into the pipeline is the prerequisite for a licensing regime, which is the outcome both sides of this fight are visibly heading toward. Read the watermark as an opening position in a negotiation rather than as a remedy, and it makes sense on its own terms.
The honest negative: it does nothing for you, today, on a Friday, with a rider in front of you.
The attribution layer
The metadata integration deserves a separate note because it is easy to misread as a licensing feature. Matching generated audio against a reference database of compositions is, functionally, fingerprinting — the same class of technology that content ID systems use. Point it forward and it flags an output that resembles a known work before it ships. Point it backward and it becomes an accounting ledger for a deal that has not been signed.
For a working producer, the forward-facing use is the one with immediate value: an automated similarity check is a real guardrail against the failure mode nobody talks about, which is that generative systems occasionally produce something close enough to an existing song to be actionable, and you will not always be the person who notices. If your vendor offers a pre-publication similarity check, use it. If it does not, run your delivered cues through a consumer song-identification app before they go out. It is a crude test with plenty of false negatives, and it takes ninety seconds per cue.
How I'd decide now
When I evaluate any generative audio vendor for client work, this is the list. It is not about output quality, because output quality is the part you can hear for yourself in an afternoon of trials.
| Criterion | What good looks like | How to test it |
|---|---|---|
| Indemnification | Vendor defends and indemnifies you against third-party IP claims arising from output; cap stated in currency, not in subscription value | Search the terms for "indemnif". If the only hit is you indemnifying them, that is your answer |
| Training-data position | A stated policy on sources, plus disclosure of licensing deals or opt-out mechanisms | Ask support in writing. The reply, or the absence of one, is a document you can keep |
| Licence persistence | Rights in already-delivered work survive cancellation of your plan | Find the termination clause. Some services revoke commercial rights on lapse — this is the trap that burns people two years later, when a client re-uses a cue you can no longer license |
| Territory | Terms that do not assume US law governs your delivery in Berlin or Tokyo | Read the governing-law clause against where your client publishes |
| Export format | 48kHz WAV minimum, stems or multitrack, no permanent loudness normalisation baked in | Bounce one cue and inspect it in an editor. If you only get a 44.1kHz MP3, it is not a professional deliverable |
| Twelve-month cost | Total including the tier that actually carries the commercial grant | Multiply the monthly price by twelve and compare against one bespoke commission |
The first row is the one that changed. Before the Munich decision it was a nice-to-have. Now it is the question, and if a vendor cannot answer it, that is information rather than an obstacle — plenty of professional work gets delivered on tools with no indemnity, by people who priced that risk knowingly.
What actually changes, by scenario
Making tracks for yourself, or for a channel you own. Almost nothing changes. Platform-level takedowns remain the realistic worst case, not a lawsuit. Carry on.
Freelancing into client deliverables. This is the exposed position, and it is mine. You are the last party in the chain with a signature on a warranty and the first with no one behind you. Two practical adjustments: disclose generative tool use proactively rather than when asked, and negotiate your own liability cap in the MSA — capped at fees paid under the agreement is standard and studios accept it more often than freelancers expect, because their own insurers ask for the same thing.
Building a product with generation inside it. You need an enterprise agreement with an indemnity, or you need to own the model, or you need to price litigation as a line item. There is no fourth option, and the diligence question your acquirer or investor will ask is the one at the top of the table above.
Delivering to a label, broadcaster, or ad agency. Assume the metadata question is coming, because rights administration at that level is automated and unsentimental. Keep session files, prompt logs, and render timestamps. The producers who get through this cleanly will be the ones who can show provenance, not the ones who can argue about doctrine.
The alternatives carry their own honest negatives. Udio sits in the same litigation weather with the same open questions. Royalty-free libraries feel safer, but a meaningful number tie your licence to an active subscription and quietly revoke on cancellation — a cleaner-looking risk that lands later and hurts more. Commissioning a human composer resolves the provenance question completely and costs, in my market, somewhere between ten and forty times a monthly generative subscription for equivalent minutes. Those are real trade-offs, not a ranking.
Who this is for, who should skip it
This is for you if your audio ends up inside something with a contract attached: a game build, a client edit, a sponsored video, a product. The paperwork is now part of the craft, in the same way that gain staging is part of the craft.
Skip it if you are making music for the pleasure of making music. The legal machinery grinding away above your head is aimed at platforms and catalogues, not at a person with a laptop and a bass patch. Nothing in the Munich file suggests otherwise, and treating hobbyist output as a liability event is the kind of catastrophising that this story does not need.
Back to the eleven days
I re-cut one of the two beds from scratch. Not out of principle — out of arithmetic. That cue sat under a cinematic in the trailer, which meant broadcast clearance, which meant somebody's insurer would eventually read my warranty. Twelve hours of work against an unquantified risk I could not price, so I paid the twelve hours: modular drone, granular pad, one field recording of an air conditioner in Oakland that I have been reusing since 2019.
The other bed I kept. It plays under a menu screen, non-broadcast, low-visibility, and I disclosed it in writing with a note on the tool and the date. The studio's counsel accepted it in an email that took four minutes to write and closed the file. That is what the eleven days were actually about — not whether AI audio is allowed, but whether anybody could describe where it came from.
My contracts now carry a clause of my own, mirroring the one that stalled the invoice: I warrant my process and my disclosure, not the provenance of every dataset that ever touched a model I used. My liability is capped at the fee. Every client so far has signed it. That is a negotiated allocation of a risk none of us can currently measure, which is the most honest thing available.
What I cannot resolve, and what the courts have not resolved either, is the question underneath the Munich reasoning. If a model can reproduce a melody, has it been storing that melody all along — a copy at rest, infringing the moment the weights were written, regardless of whether anyone ever presses generate? Or is a distributed statistical trace of a song a fundamentally different object from a copy of it, one our doctrine has no vocabulary for yet? The engineers I trust disagree with each other about what memorisation even means in a model of that size, and the lawyers are arguing from analogies to photocopiers and mixtapes that fit badly.
I have four broken synthesizers and a functioning opinion about most things in this field. On that one, I don't have an answer — and I'd be careful with anyone who tells you they do.
Not sure which tool to use?
Compare the top AI music and sound tools side by side — honest reviews, real pricing, no sponsorships.