The Trump administration has intervened in a major AI copyright case, filing a 20-page brief backing OpenAI's position that training large language models on copyrighted material without a licence does not violate copyright law.

The brief, filed by the Department of Justice on 1 September in the US District Court for the Southern District of New York, was submitted as a "Statement of Interest of the United States" in the consolidated litigation against OpenAI, which includes a lawsuit brought by the New York Times. It argues the government has "a strong interest in continuing to develop a robust and competitive artificial intelligence industry that sets the standard for the practice and procedure of AI use globally," citing an executive order President Trump signed in January 2025 on "Removing Barriers to American Leadership in Artificial Intelligence," as well as a further order from June 2026 on "Promoting Advanced Artificial Intelligence Innovation and Security."

Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.

The filing centres on the doctrine of fair use, the copyright law exception that permits certain unlicensed uses of protected works. The government argues that training an LLM is "exceedingly transformative," comparing the process to a person learning patterns of language rather than reproducing a work's expressive content, and warns that "constraining LLM development under a misunderstanding of fair use doctrine would thwart such creative and scientific progress while hindering American prosperity and economic mobility." It further argues that requiring licensing fees for training data would disadvantage smaller AI developers and independent publishers relative to large technology companies and legacy media outlets with substantial back catalogues to licence.

The brief also directly criticises a separate ruling, Kadrey v. Meta Platforms, arguing that court wrongly conflated the training of an LLM with its outputs when assessing potential market harm to copyright holders, calling that reasoning "deeply flawed." It illustrates the point with an analogy to the writer Joan Didion, who as a teenager retyped Ernest Hemingway's stories to study his prose; the government argues that treating LLM training as equivalent to competing in an author's market would, by the same logic, have made Didion liable to Hemingway every time she later published her own work.

As the brief is not a ruling, and the Department of Justice has no jurisdiction over the case's outcome, the intervention carries no binding legal weight, though it may still influence the presiding judge's reasoning.


Execution Level Governance- What audit-ready agent governance actually looks like
David Girvin, founder and CEO of Assury argues that model-in-the-loop review, AI governing AI, is fundamentally unreliable for regulated environments: even the best-performing models miss a meaningful share of violations, the reviewing model is typically provided by the same vendor being reviewed, and prompt injection or context poisoning can compromise both the acting agent and its supposed overseer simultaneously. He makes the case for deterministic, architecturally enforced controls instead, walking through Assury’s approach of autonomy zones, session risk accumulation, and credential starvation, which lets a compromised agent be cut off from its tools instantly rather than relying on time-boxed access. The conversation touches on why David is sceptical of just-in-time credentialing as a solution for agent security more broadly, since agent sessions don’t run on predictable human timescales, along with the current gap between how identity and security vendors are pitching agent protection and what he sees happening at the execution layer in practice. He also discusses the compliance and audit implications of probabilistic decision-making, arguing that regulated industries will increasingly need tamper-evident, hash-chained audit trails that can withstand scrutiny from auditors and regulators who are only beginning to understand agentic risk, and reflects on a named frontier lab’s own published framework as an example of the gap between research and practitioner reality. Elsewhere, David reflects candidly on building a bootstrapped security company in an increasingly crowded market, why he turned down aggressive VC funding to stay in control of the product, and what a credible third-party assessment of his own gateway would need to look like given that Assury sits directly in the execution path for every customer’s agents.
Share this post
The link has been copied!