The argument over AI training has mostly been fought on fair use: whether learning from a recording is transformative enough to be excused. On 15 April 2026, Judge Alvin K. Hellerstein of the Southern District of New York let a different claim proceed against the company behind Udio — not that training infringed, but that the training data was obtained by circumventing a technical measure. That claim does not need the fair-use question answered at all.
01
The allegation
Universal's entities allege that Udio used a stream-ripping tool to bypass YouTube's encryption and pull down recordings in bulk to train its music model.
YouTube employs technical measures — including what the filings call a rolling cipher — to control access to uploaded content and to stop external services from downloading the underlying media files directly. The claim is that defeating that mechanism, whatever happened afterwards, is itself a violation of section 1201(a) of the DMCA.
02
Access control or copy control
The legal fight turned on a distinction that sounds academic and decides the case. Section 1201 draws a line between measures that control access to a work and measures aimed at preventing copying once access has lawfully been obtained. Circumventing the first is actionable in a way that the second is not.
Udio argued that YouTube's encryption belongs in the second category: anyone can watch a YouTube video, so the technology is not restricting access, it is restricting copying. Universal argued the opposite — that the cipher governs whether you can obtain the file at all.
The court sided with the plaintiffs at this stage, drawing on the established line of cases about DVD encryption, where scrambling that must be defeated to reach the content has been treated as an access control.
03
Why the ruling is narrower than it looks
This was a motion to dismiss, so the court accepted well-pleaded allegations as true and asked only whether they stated a claim. It did not find that Udio scraped anything, that any particular file belonged to Universal, or that damages will follow.
The court was explicit about its own limits, noting that whether YouTube's measures ultimately constitute access controls within the meaning of section 1201 requires a greater factual record, and expressly permitting Udio to renew the argument later.
So the holding is that the claim is legally plausible — not that it is right. The technical question has been deferred, not decided.
04
Why this front matters more than fair use
A fair-use defence, if it succeeds, is close to total: it excuses the copying at the heart of training. The circumvention claim is designed to sidestep that battlefield entirely.
If a model was trained on data acquired by defeating a technical protection, the manner of acquisition is independently unlawful whether or not the training itself would have been fair. It converts a contested question about the nature of machine learning into a much more familiar question about how somebody got the files.
That is why the same theory now appears in the majors' other AI complaints, including Sony's second action against Udio — and why it may end up mattering more to the outcome of this litigation than the doctrinal argument everyone has been having in public.
05
What the evidence will have to show
On a developed record the case turns on software architecture: what YouTube's cipher actually restricts, how any ripping tool interacted with it, who operated that tool, and whether the resulting files entered Udio's training systems.
Each of those is a discovery question with a documentary answer, which is a different prospect for a defendant than an argument about the philosophy of transformation. It is also the reason the court left itself room to reclassify the technology once it can see how it works.

Comments
Sign in to join the discussion.