Low‑Code, No‑Code, AI prompts and EU Copyright
Today, most businesses seek to cut costs and speed up development by turning to No‑Code and Low‑Code („NC/LC”) platforms. Schoenherr Attorneys at Law recently published a detailed analysis of this trend, „EU: No‑Code/Low‑Code platforms: future tech, present copyright challenges”, examining how these tools challenge traditional notions of software copyright in the EU.
What the original article argues
The Schoenherr post walks through the EU copyright framework for software: under Directive 2009/24/EC [12], computer programs are protected as literary works, covering source code, object code and preparatory design materials — but not the underlying ideas or algorithms. Protection requires a level of creative input reflecting the author’s free and personal choices, as also emphasised by the CJEU’s SAS v. WPL (C‑406/10) [6].
The article’s central claim, under the heading „No coding, no copyright,” is that because NC/LC users select from a finite set of predetermined components via drag‑and‑drop interfaces, their contribution may not clear the originality threshold — since the arrangement doesn’t reflect genuinely free creative choice.
Where a sharper distinction is needed
This is a genuinely important topic, but the analysis benefits from separating two different paradigms that the article treats as one:
– No‑Code environments do confine users to a closed set of predefined components, and it is legitimate to ask whether the user’s contribution reaches the level of originality in the sense of being the author’s own intellectual creation.
– Low‑Code environments, by contrast, are explicitly designed to allow — and often require — custom code injection: business logic and custom functions written in general‑purpose languages (JavaScript, Python, C#, SQL, etc.). From a copyright perspective, this custom code can be easily indistinguishable from „traditional” software development [9]: the developer is free to design complex logic and data flows, and those choices can clearly embody individual, original character under EU copyright standards.
Why „no coding, no copyright” is not an accurate test
I’d also be cautious with any shorthand like „no coding, no copyright.” EU copyright protects expression, not just the source code itself. A finite set of building blocks, by itself, is not unusual in copyright: literature is built from 26 letters, Western music from 12 semitones — yet the number of possible solutions leaves ample room for original works when authors can choose between different ways of solving the same problem.
Visually built workflows, decision trees or user interfaces can still reflect individual, non‑trivial choices in structure and arrangement, and in some cases be protected as works under general copyright rules, even if they are not protected as computer programs. Moreover, even preparatory design material that is capable of leading to a computer program can be protected as a program, although it never takes the form of source code. Finally, as the CJEU made clear in BSA (C‑393/09) [7], while a graphic user interface is not an expression of a computer program under the Software Directive, it can still qualify as a copyright work under general rules if it is the author’s own intellectual creation.
The AI‑prompt dimension
The originality question becomes even more layered once AI prompting and vibe coding enter the picture [2]. Many modern Low‑Code and No‑Code platforms now let users generate components, logic or even entire workflows via natural‑language prompts to an integrated AI assistant.
EU case law offers a clear starting point here, even though it long predates generative AI: the CJEU’s Infopaq (C‑5/08) [4] ruling established the uniform „author’s own intellectual creation” test across all subject matter, including software, and in Painer (C‑145/10) [5] Advocate General Trstenjak’s position — that „only human creations are protected” — was endorsed by the Court. Applied to AI, this means that output generated entirely autonomously, without meaningful human creative input, falls outside copyright protection, as confirmed by the European Parliament’s 2025 briefing [3] on AI-generated works [10].
The harder — and more relevant — question for NC/LC is what happens with AI‑assisted output, where a human is in the loop. Here, the leading doctrinal framework is Hugenholtz and Quintais’ four‑step test [8], which asks whether the human’s free and creative choices — in framing the task, in iterating on the prompt, or in editing and integrating the AI‑generated result — are actually reflected in the final work. Crucially, while a single natural-language prompt may merely constitute an unprotected idea or functional instruction, an iterative vibe coding or agentic engineering process can bridge the gap into protected expression. As Widła also points out [11], under this test, originality does not have to reside in hand‑typed code: it can just as well reside in the human’s selection, sequencing and curation of AI‑generated components, provided those choices go beyond trivial or purely functional decisions. Importantly, this shift implies a compilation-style copyright: the workflow’s overall structure and arrangement enjoy protection, even if the raw, AI-generated components embedded within it remain unprotected by copyright law.
If copyright is this uncertain, what else can protect NC/LC outputs?
It is worth asking what other legal tools remain available when copyright protection is doubtful or simply too slow/expensive to establish in a dispute. Two regimes deserve particular attention.
Database rights. Many NC/LC applications are built around a data model: tables, relationships, lookup logic, validation rules. Under the Database Directive (96/9/EC), a database can be protected in two independent ways: as a copyright work, if the selection or arrangement of its contents is the author’s own intellectual creation, and separately as a sui generis database right, if there has been substantial investment in obtaining, verifying or presenting the contents — regardless of whether any creative choice was involved. This second route is particularly relevant for NC/LC projects: even where the originality of a visually assembled data model is contestable, the investment made in populating, structuring and maintaining that data may independently qualify for sui generis protection. It is, however, important to flag the CJEU’s spin‑off doctrine. The mere recording of data generated automatically during a company’s core operations (like sensor readings or transaction logs) does not justify sui generis protection. To qualify, the substantial investment must be specifically directed at obtaining data from external sources, or at verifying and presenting it. It is, however, important to note that this does not automatically apply in every case. For example, in an enterprise resource planning (ERP) system or a financial system, the mere presence of data does not in itself confer sui generis protection.
Trade secrets and know‑how. Business logic built inside an NC/LC platform — pricing rules, eligibility criteria, scoring algorithms, workflow sequencing — often has more commercial value as a secret than as a copyrightable expression. The EU Trade Secrets Directive (2016/943/EU) is often a more practical fit for NC/LC and AI‑prompted development: it does not matter whether the configuration is „original” in the copyright sense, whether it was built via drag‑and‑drop, custom code or a prompt — what matters is confidentiality and reasonable protective measures (access controls, NDAs, internal policies). As vibe coding and prompt‑driven development make the originality of the resulting artefact harder to pin down, trade secret protection is likely to become the more reliable, and increasingly favoured, layer of protection for the underlying business logic itself.
Taken together, these two regimes suggest that software protection is not disappearing — it is diversifying. Copyright remains central for genuinely creative code and interface design, but database rights and trade secrets fill in precisely where the originality test is weakest: structured data investment on one side, confidential business logic on the other.
A more nuanced view on No‑Code/Low‑Code and copyright
From the perspective of both developers and IP practitioners, a more nuanced approach would:
– Distinguish clearly between No‑Code and Low‑Code in terms of user freedom and originality,
– Recognise that custom code injected into Low‑Code platforms is fully capable of meeting the originality threshold,
– Address AI‑prompted or vibe coded components as a distinct category, where originality may reside in selection and arrangement rather than in code authorship,
– Consider database rights and trade secrets as independent, originality‑free protection layers for data models and business logic, and
– Avoid reducing copyright subsistence to a „no coding, no copyright” formula, which does not align with the broader principles of EU copyright law.
As No‑Code/Low‑Code platforms — increasingly layered with AI‑assisted generation — continue to spread across the EU, I hope to see more dialogue between IP lawyers and developers on the boundaries of copyright law in this context [11].
The author wishes to thank Dr. Gergely Békés [13] for his valuable comments.
~~~
dr. Péter Somkutas, MSc, lawyer and computer scientist, specializes in copyright law, with a particular focus on software law. He earned his law degree at Eötvös Loránd University and his degree in computer science at the University of Szeged, followed by a supplementary master’s program specializing in software architecture in Germany. For two decades, he has served as a lead developer on multinational software development projects. Additionally, as a consultant and a member of the Council of Copyright Experts, he regularly addresses IT-related copyright issues.
