Copyright Management Information

Copyright Management Information

Copyright Management Information, or CMI for short, is the information attached to a work that states who created it and under what conditions it may be used. Anyone who intentionally removes or falsifies such information violates separate protective provisions in both the US and the EU – a point that plays a major role in lawsuits against AI companies.

When someone publishes a photo, a text, or a piece of music, small additional details are usually attached to it. This includes, for example, the name of the creator, meaning the person who made the work. Often a copyright notice, a work number, and the conditions under which others may use the work are added as well. These exact details are called Copyright Management Information, abbreviated CMI. Sometimes they appear visibly beneath the image, but often they are invisible, embedded within the file itself. What makes them special is that this information is legally protected in its own right, independent of the work.

Why removing it constitutes a separate legal violation

Normally, copyright law revolves around the question of whether someone was allowed to copy a work. With CMI, it’s about something different. Here, deleting or falsifying the attribution information is prohibited on its own, even if the copy itself was permitted. In the US, this is governed by Section 1202 of the Digital Millennium Copyright Act. In the EU, a similar rule is found in Article 7 of the 2001 Copyright Directive.

The idea behind this is simple. As long as the creator’s name stays attached to a work, rights can be enforced and licensing fees can be demanded. Once the name is gone, the trail goes cold. The work then appears to be orphaned material that anyone can use. So the law doesn’t protect the image itself, but the label attached to the image.

For those affected, this is practical because a violation is easier to prove. There’s no need to determine whether a particular use was exceptionally permitted. It’s enough to show that the information was intentionally removed. In the US, the law provides for statutory damages of $2,500 to $25,000 per violation.

Where this information is stored within a file

For photos, this information is usually located in the metadata. These are additional data stored alongside the image file without being visible in the image itself. Common formats for this are called EXIF and IPTC. Photographers use these to enter names, agency, date taken, and licensing terms. For music and video, there are comparable fields, often supplemented by digital watermarks embedded in the audio or image itself.

However, this information is fragile. Many programs automatically discard it when saving files in order to make them smaller. Social networks frequently strip it out during upload. Even a screenshot deletes all metadata, since it creates an entirely new image in the process. What matters, therefore, is intent: the law applies when someone acts knowingly, not to every technical side effect.

CMI should not be confused with copy protection. Copy protection technically prevents a file from being duplicated. CMI prevents nothing at all — it merely provides information. You can think of it like the sender’s address on a letter. It doesn’t stop anyone from opening the letter, but without it, no one knows where the mail came from anymore.

The dispute over AI training data

Currently, the term mainly comes up in lawsuits against AI companies. Large language and image models are trained on enormous amounts of material collected from the internet. When gathering and processing this data, metadata is often removed because the model only needs the content itself. This is exactly what publishers, photographers, and news agencies are accusing providers of doing.

For plaintiffs, this is an appealing argument. Whether AI training qualifies as permitted use is legally contested and will be litigated for years. The accusation of removed rights information, by contrast, can be framed more concretely. However, several US courts have dismissed such claims because the plaintiffs could not show that the information had been deliberately deleted.

You encounter this topic in everyday life more often than you might think. Anyone who copies an image from a search engine and shares it further without crediting the creator touches on the same issue. At the same time, the industry is working on new labeling systems, such as the C2PA standard, which aims to document the origin of images in a tamper-proof way. At their core, such systems are nothing other than a more modern, harder-to-remove form of CMI.

Related Products

Latest News

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.