HomeEU AI Act

Reference · CDSM Article 4 · updated 31 July 2026

How do you express a TDM opt-out under Article 4(3) CDSM so that it binds?

Article 4(3) requires the reservation to be expressed in an appropriate manner, such as machine-readable means for content made publicly available online. In practice that means a signal a crawler parses automatically — robots.txt directives, Content Signals, a TDMRep header or in-page metadata — not prose in a terms-of-service page. A Dutch court has already held that a reservation which is not properly machine-readable does not bind.

Last reviewed . This page is maintained against primary sources and updated on every relevant Commission action — see the changelog at the foot.

The structure of Article 4

Article 4 of Directive (EU) 2019/790 does three things in sequence, and reading them in order is the fastest way to see where the leverage sits.

ProvisionEffect
Article 4(1)Creates an exception permitting reproductions and extractions of lawfully accessible works for the purposes of text and data mining.
Article 4(2)Permits copies made under the exception to be retained for as long as necessary for the mining.
Article 4(3)Makes the exception conditional: it applies only where the use has not been expressly reserved by the rightsholder in an appropriate manner, such as machine-readable means in the case of content made publicly available online.

Two words carry the weight. Lawfully accessible, in 4(1) — content behind a paywall or authentication that was bypassed was never in the exception's scope in the first place. And appropriate manner, in 4(3) — the standard your reservation has to meet.

Why “lawfully accessible” comes first

It is worth pausing here because it is routinely skipped. The Article 4 exception applies only to works to which the miner has lawful access. A reservation is the second line of defence; access control is the first. If content sits behind authentication, a paywall, or an enforced rate limit, the question of whether the reservation was machine-readable may never arise, because the exception was never available.

This is also why access control and signalling are complements rather than alternatives. Blocking everything protects the content and destroys the distribution. Signalling preserves the distribution and depends on the crawler's compliance. Most publishers need both, applied to different parts of the estate.

What the Amsterdam ruling actually decided

Rechtbank Amsterdam, 30 October 2024, ECLI:NL:RBAMS:2024:6563 — a text and data mining and media-monitoring dispute — held that a rights reservation which was not properly machine-readable did not bind the miner. The decision is under appeal, so it is not settled law, and it is a first-instance national decision rather than a European one.

What makes it worth knowing anyway is that it is the first concrete judicial engagement with the machine-readability condition, and it went the way the text suggests it should: the burden sits with the rightsholder to express the reservation in a form a machine can act on. Legal commentary — including a well-known line of criticism arguing that existing opt-outs are “machine-readable but still not actionable” — has been pushing at the same seam.

The open question nobody has answered. There is no European authority articulating general criteria for machine readability, and no court has yet had to assess a specific signalling mechanism against the standard. Anyone telling you their protocol is “Article 4(3) compliant” is stating a view, not a finding. The Commission's Measure 1.3 list, targeted for late 2026, is currently the closest thing to an authoritative answer in prospect.

Reservations that are likely to fail

  • Prose in terms and conditions. A sentence in your T&Cs saying you reserve rights against text and data mining is human-readable. Recital 18 mentions terms and conditions, but a crawler cannot parse a paragraph, and Amsterdam suggests a court may not accept that it should have to.
  • A copyright notice in the page footer. Asserts ownership, reserves nothing specific against mining.
  • A signal only a crawler you have named would see. Per-user-agent Disallow rules require you to have listed the crawler. New crawlers appear constantly; a list-based reservation silently degrades.
  • A reservation with no evidence of when it was set. If the dispute is about ingestion in 2026, what your site says in 2029 proves very little.

A configuration that is defensible

  1. Express it in at least two machine-readable channels. A robots.txt policy and an HTTP response header, or header plus in-page metadata. Redundancy costs nothing and closes the “our crawler doesn't read that file” argument.
  2. Separate purposes. Reserve training without reserving search. A single blanket refusal is legally simpler and commercially expensive.
  3. Use a wildcard default plus named exceptions, not a named-crawler blocklist. The default should be the reservation; the exceptions should be the crawlers you have decided to permit.
  4. Timestamp and archive it. Keep a dated record of the reservation configuration — versioned in a repository, or captured by a third-party archive. The reservation is only useful if you can prove it was in force at the moment of the use you are complaining about.
  5. Give the reservation a destination. A refusal with no licensing path is a dead end for both sides. Point at terms, and — when you grant — at a signed record of what you granted. The reservation says no by default; the credential says yes to a named party, and can be revoked when that changes.

The half of this that Article 4 does not address

Article 4(3) is entirely about the “no.” It gives a rightsholder a mechanism to withhold, and it conditions the exception on using that mechanism properly. It says nothing at all about how a permission is recorded, because in 2019 nobody was licensing content to machine pipelines at the scale that now makes that the harder problem.

So a publisher who does everything right under Article 4(3) — a clean, redundant, purpose-separated, dated reservation — has established what they refuse and nothing about what they allow. And an AI lab that honours every reservation it encounters has established that it did not take what was withheld, and nothing about whether it was entitled to what it took. Both sides end up in the same place: a defensible “no” and an unprovable “yes.”

Check where you actually stand — free, no login

Point the rights checker at any URL and it reads what that content declares to AI right now: reserved, granted, verified — or silent. ASSESS scores a rights declaration against the public compliance framework and returns the specific gaps.

Check what your content allows Run a free ASSESS score

Changelog

  • 2026-07-31 — Hub pillar expanded: added the Digital Omnibus (Regulation (EU) 2026/1744) compliance timeline, the Article 88 exclusive-competence distinction, the three-tier penalty detail, a 'what counts as evidence' section, and a 'where to start' checklist. Dates re-confirmed against primary sources.
  • 2026-07-30 — Page published. Enforcement table, Article 53 / Article 4(3) plain-language summary, and Measure 1.3 consultation status current as of this date.

LicenseFoundry is not a law firm and this page is not legal advice. It is a plain-language technical reference maintained against primary sources — the AI Act text, the CDSM Directive, and published European Commission process documents. Where a question is genuinely unsettled, this page says so rather than resolving it. Verify against the primary sources before relying on any of it in a filing.