For years, Meta employees have internally discussed using copyrighted works obtained through legally questionable means to train the companyโs AI models, according to court documents unsealed on Thursday.
The documents were submitted by plaintiffs in the case Kadrey v. Meta, one of many AI copyright disputes slowly winding through the U.S. court system. The defendant, Meta, claims that training models on IP-protected works, particularly books, is โfair use.โ The plaintiffs, who include authors Sarah Silverman and Ta-Nehisi Coates, disagree.
Previous materials submitted in the suit alleged that Meta CEO Mark Zuckerbergย gave Metaโs AI team the OK to train on copyrightedย content and that Meta halted AI training data licensing talks with book publishers. But the new filings, most of which show portions of internal work chats between Meta staffers, paint the clearest picture yet of how Meta may have come to use copyrighted data to train its models, including models in the companyโs Llama family.
In one chat, Meta employees, including Melanie Kambadur, a senior manager for Metaโs Llama model research team, discussed training models on works they knew may be legally fraught.
โ[M]y opinion would be (in the line of โask forgiveness, not for permissionโ): we try to acquire the books and escalate it to execs so they make the call,โ wrote Xavier Martinet, a Meta research engineer, in a chat dated February 2023, according to the filings. โ[T]his is why they set up this gen ai org for [sic]: so we can be less risk averse.โ
Martinet floated the idea of buying e-books at retail prices to build a training set rather than cutting licensing deals with individual book publishers. After another staffer pointed out that using unauthorized, copyrighted materials might be grounds for a legal challenge, Martinet doubled down, arguing that โa gazillionโ startups were probably already using pirated books for training.
โI mean, worst case: we found out it is finally ok, while a gazillion start up [sic] just pirated tons of books on bittorrent,โ Martinet wrote, according to the filings. โ[M]y 2 cents again: trying to have deals with publishers directly takes a long timeย โฆโ
In the same chat, Kambadur, who noted Meta was in talks with document hosting platform Scribd โand othersโ for licenses, cautioned that while using โpublicly available dataโ for model training would require approvals, Metaโs lawyers were being โless conservativeโ than they had been in the past with such approvals.
โYeah we definitely need to get licenses or approvals on publicly available data still,โ Kambadur said, according to the filings. โ[D]ifference now is we have more money, more lawyers, more bizdev help, ability to fast track/escalate for speed, and lawyers are being a bit less conservative on approvals.โ
Talks of Libgen
In another work chat relayed in the filings, Kambadur discusses possibly using Libgen, a โlinks aggregatorโ that provides access to copyrighted works from publishers, as an alternative to data sources that Meta might license.
Libgen has been sued a number of times, ordered to shut down, and fined tens of millions of dollars for copyright infringement. One of Kambadurโs colleagues responded with a screenshot of a Google Search result for Libgen containing the snippet โNo, Libgen is not legal.โ
Some decision-makers within Meta appear to have been under the impression that failing to use Libgen for model training could seriously hurt Metaโs competitiveness in the AI race, according to the filings.
In an email addressed to Meta AI VP Joelle Pineau, Sony Theakanath, director of product management at Meta, called Libgen โessential to meet SOTA numbers across all categories,โ referring to topping the best, state-of-the-art (SOTA) AI models and benchmark categories.
Theakanath also outlined โmitigationsโ in the email intended to help reduce Metaโs legal exposure, including removing data from Libgen โclearly marked as pirated/stolenโ and also simply not publicly citing usage. โWe would not disclose use of Libgen datasets used to train,โ as Theakanath put it.
In practice, these mitigations entailed combing through Libgen files for words like โstolenโ or โpirated,โ according to the filings.
In a work chat, Kambadur mentioned that Metaโs AI team also tuned models to โavoid IP risky promptsโ โ that is, configured the models to refuse to answer questions like โreproduce the first three pages of โHarry Potter and the Sorcererโs Stoneโโ or โtell me which e-books you were trained on.โ
The filings contain other revelations, implying that Meta may have scraped Reddit data for some type of model training, possibly by mimicking the behavior of a third-party app called Pushshift. Notably, Reddit said in April 2023 that it planned to begin charging AI companies to access data for model training.
In one chat dated March 2024, Chaya Nayak, director of product management at Metaโs generative AI org, said that Meta leadership was considering โoverridingโ past decisions on training sets, including a decision not to use Quora content or licensed books and scientific articles, to ensure the companyโs models had sufficient training data.
Nayak implied that Metaโs first-party training datasets โ Facebook and Instagram posts, text transcribed from videos on Meta platforms, and certain Meta for Business messages โ simply werenโt enough. โ[W]e need more data,โ she wrote.
The plaintiffs in Kadrey v. Meta have amended their complaint several times since the case was filed in the U.S. District Court for the Northern District of California, San Francisco Division, in 2023. The latest alleges that Meta, among other claims, cross-referenced certain pirated books with copyrighted books available for license to determine whether it made sense to pursue a licensing agreement with a publisher.
In a sign of how high Meta considers the legal stakes to be, the company has added two Supreme Court litigators from the law firm Paul Weiss to its defense team on the case.
Meta didnโt immediately respond to a request for comment.


