Regulation and governance for data buyers
AI Training Data Compliance: The Regulations, Standards and Records Data Buyers Need
Quick answer
AI training data compliance means being able to show, for every dataset you acquire, that you may use it for the intended training, that any personal data in it meets the right legal standard, and that you can describe it the way regulators now require. As of October 2026, those duties come from four tracks: AI-specific laws, copyright and text-and-data-mining (TDM) rules, privacy law, and your license terms. Each track asks for specific records, and they are cheapest to collect when the data arrives.
By SourceX Editorial · Updated
Four tracks of obligation and the record each one demands
Every compliance question about acquired data falls into one of four tracks, with voluntary governance frameworks layered on top; each is answered by a filed document, not a supplier's assurance.
| Track | Main instruments (as of October 2026) | Record to collect at acquisition | Go deeper |
|---|---|---|---|
| AI law: EU high-risk systems | AI Act Article 10 [1] | Origin and collection description, preparation log, bias examination, known gaps | Article 10 data governance |
| AI law: EU general-purpose models | AI Act Article 53, training-content template, GPAI Code of Practice [2][3][4] | Acquisition route and legal basis per source, opt-out check results | Article 53 obligations |
| AI law: US state disclosure | California AB 2013, Colorado SB26-189 [5][6] | One disclosure sheet per dataset: owner, IP status, personal information, collection period, synthetic share, categories | Disclosure requirements compared |
| Copyright and TDM | Fair use and national TDM exceptions | License reference, lawful-access evidence, training location, purpose | TDM exceptions by country |
| Privacy | GDPR, HIPAA, CCPA, FTC Act | De-identification standard and method, notice versions, re-identification terms | De-identified data hub |
| Contract | Your license and the supplier's customer contracts | Signed license, permitted-use register entry, deletion dates | Licensing guide |
| Governance frameworks | NIST AI RMF, ISO/IEC 42001, ISO/IEC 5259 [7][8] | Pre-acquisition risk assessment, supplier assessment, dataset register | NIST AI RMF for acquired data |
The provenance hub covers verifying that evidence; the Data Provenance Standards explainer covers metadata for carrying it.
Your role with the model decides which duties attach
One dataset can trigger no AI-specific duty for one buyer and several for another, because these laws attach to what you do with the model. Classify each intended use before acquisition.
| If your team... | Role and data duty |
|---|---|
| Places a general-purpose model on the EU market | GPAI model provider (Article 53, since 2 August 2025): copyright policy and training-content summary [9] |
| Provides a high-risk AI system in the EU | High-risk provider: Article 10 governance of training, validation and test sets [1] |
| Releases or substantially modifies a generative AI system available to Californians | AB 2013 developer: website documentation of training datasets [5] |
| Builds automated decision-making technology (ADMT) that materially influences employment, lending, insurance or similar decisions in Colorado | SB26-189 developer: documentation to deployers, including training data categories [6] |
| Only researches, tests or develops before release | Outside the AI Act under Article 2(8), except testing in real-world conditions [10]; duties start once the model or system is placed on the market or put into service |
One summary of the statute notes that its disclosure duty applies after a "substantial modification," but the law does not define the term [11], so fine-tuning a public model on licensed data may create your own disclosure duty (fine-tuning and provider duties). The research exclusion also ends at market placement, so capture disclosure facts while the supplier can still answer.
What Articles 10 and 53, AB 2013 and SB26-189 ask about the data
Article 10 governs high-risk training data, Article 53 sets copyright and transparency duties for general-purpose models, and two US state laws require written disclosures.
Article 10. Training, validation and testing sets for high-risk systems need data governance and management practices covering design choices, collection processes and data origin, preparation such as annotation and cleaning, assumptions, suitability, possible biases and data gaps, and must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete [1]. Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 [12], reportedly moved the high-risk start dates shown below [13]; the Commission's AI Act Service Desk text, based on the consolidated version of 27 July 2026, marks Article 10(1) as amended [1].
Article 53. General-purpose AI (GPAI) model providers must keep a copyright policy that honors rights reservations under Article 4(3) of the Digital Single Market (DSM) Directive, and publish a training-content summary on the AI Office template [2]. The template, published 24 July 2025, applies to open-source models too [3]; a law-firm summary describes sections on general information, data sources by type and origin, and collection and processing [14]. See what buyers need from suppliers for EU summaries.
AB 2013. Documentation, due by 1 January 2026 and before each later release or substantial modification of systems released since 1 January 2022, covers dataset sources or owners, copyrighted or licensed material, personal information, collection periods and synthetic data [5] (AB 2013 supplier records).
SB26-189. Signed on 14 May 2026 to replace the consumer protections of SB 24-205, it requires developers of covered ADMT to give deployers documentation of intended uses, training data categories, known limitations and human-review guidance from 1 January 2027, enforced by the Attorney General [6], who released interim draft rules on 6 October 2026 [15] (SB 26-189 documentation).
Dates to plan around
| Date | Event (as of October 2026) |
|---|---|
| 2 Aug 2025 | Article 53 GPAI duties apply [9] |
| 1 Jan 2026 | AB 2013 documentation due [5] |
| 2 Aug 2026 | AI Office enforcement powers over GPAI providers, including fines, apply (Articles 101 and 113) [9] |
| 26 Oct 2026 | Comments due on Colorado's interim draft ADMT rules [15] |
| 1 Jan 2027 | SB26-189 duties begin [6] |
| 2 Aug 2027 | GPAI models placed on the market before 2 August 2025 must comply (Article 111(3)) [9] |
| 2 Dec 2027 | High-risk duties, including Article 10, reportedly apply to Annex III systems [13] |
| 2 Aug 2028 | Same duties reportedly apply to Annex I systems [13] |
See EU AI Act deadlines after the Digital Omnibus.
Copyright and TDM: where commercial training still needs permission
As of October 2026, no major jurisdiction gives commercial developers an unconditional right to train on accessible works; each exception carries a condition that decides the record you need. Exceptions are national, so record where each copy is made and why.
| Jurisdiction | Rule and its condition | Record that answers it |
|---|---|---|
| United States | Fair use, case by case. The Copyright Office's Part 3 report (May 2025, still pre-publication) says copying works into training datasets may be prima facie infringing absent a defense, and weighs competing use and illegal access against fair use [16]; on 29 September 2026 the Third Circuit held that training a non-generative legal-research tool on Westlaw headnotes was not fair use [17] | License, purchase or access record per source |
| European Union | DSM Directive Article 4 exception, unavailable where rightsholders have reserved their rights (for online content, by machine-readable means); GPAI providers must honor those reservations [2] | Dated opt-out checks; license for reserved content |
| United Kingdom | CDPA section 29A covers computational analysis for non-commercial research only, with lawful access; copies cannot be passed on [18] | License for any commercial use |
| Japan | Article 30-4 permits uses not aimed at enjoying the work, unless they unreasonably prejudice the rightsholder; commentary on 2024 government guidance notes that the exception does not apply if it would 'unreasonably prejudice the interests of the copyright owner,' with copying a database sold for analysis being one example of such prejudice [19] | Whether the source is licensed for analysis |
| Singapore | Section 244 computational data analysis exception; conditions include lawful access, per practitioner commentary [20] | Access terms and subscriptions |
| China | A 2023 draft technical document, TC260-003, asked providers to keep a corpus source blacklist and assess each source corpus [21]; confirm whether a later national standard now governs | Per-source assessment |
See the Copyright Office report and licensing, lawful access and pirated sources, EU opt-out checks under DSM Article 4 and whether to license or rely on fair use.
Privacy law: the de-identification standard decides which rules follow the data
Privacy compliance turns on whether the records are still personal data where you receive them, and under which standard they were de-identified; answers differ by jurisdiction.
- EU. Pseudonymised data that can be re-attributed remains personal data under the GDPR, and special categories such as health data need an Article 9(2) condition [22]; the AI Act leaves the GDPR unaffected [10]. EDPB Opinion 28/2024 says a model trained on personal data cannot be presumed anonymous and that legitimate interest must pass a three-step test [23]. As of September 2026, Digital Omnibus proposals to narrow the personal-data definition were not law [24].
- US health data. HIPAA de-identification uses Expert Determination or Safe Harbor removal of listed identifiers [25] (which method to require).
- California. CCPA "deidentified" status requires the holder to bind recipients by contract to its conditions, including no re-identification [26] (obligations a buyer inherits).
- Promises to customers and users. FTC staff warned in January 2024 that breaking promises not to train on customer data may violate FTC-enforced law, citing past orders to delete models built with unlawfully obtained data [27] (algorithmic disgorgement).
Where SourceX sources a dataset, names, emails and account numbers are removed or replaced before delivery, the method is recorded and a processed sample is checked; health records must meet HIPAA Safe Harbor or Expert Determination before a license is considered. No method is perfect, so classify the result yourself with the legal definitions compared and SourceX's guides to privacy and data laws.
Governance frameworks that turn duties into acquisition controls
Voluntary frameworks create no legal duties, but auditors and customers test against them.
- NIST AI RMF 1.0 (AI 100-1, January 2023) structures risk work under Govern, Map, Measure and Manage [7]; NIST says it is being revised as part of the White House AI Action Plan, with no revision published as of early October 2026 [28].
- NIST AI 600-1, the Generative AI Profile (July 2024), lists 12 risks, including data privacy, intellectual property, and value chain and component integration, with coded actions such as GV-1.1-001 [29]; acquisition controls fit the last two (NIST controls for acquired data).
- ISO/IEC 42001:2023 sets requirements for an AI management system, with controls in Annex A; certification is optional [8] (Annex A data and supplier controls).
- ISO/IEC 5259 covers data quality for machine learning: Parts 1 to 4 appeared in 2024 [30] and Part 5, on governance, in 2025 [31]; measures belong to the training data quality hub.
Start internal rules from the governance policy template, pre-acquisition risk scoring and the data governance definition.
AI training data compliance checklist per dataset
Run these nine checks before a dataset enters any pipeline; together they produce every record the tracks above ask for.
- Classify use and role. Intended uses, and which roles above each one creates.
- Name the source. System of record, legal owner, prior holders, collection period.
- Prove the acquisition route. License, purchase or access terms; dated opt-out checks for web-derived content.
- Fix permitted uses. Allowed uses, term, deletion duties and regulator access.
- Classify personal data. Status per jurisdiction, de-identification standard and method, special categories.
- Capture disclosure facts. IP status, synthetic share, data categories and volume, in publishable wording.
- Log preparation. Annotation, cleaning and filtering, bias examination and known gaps.
- Record location and retention. Where copies are made, and retention periods for data and records.
- Record sign-off. Legal, privacy and security internal approvals against the dataset ID.
Illustrative example: invented to show structure; it does not describe an available dataset.
dataset_id: ds-0142
description: "Field service work orders, commercial HVAC, 2019-2024"
supplier: "Supplier B (US facilities services company)"
role_assessment:
eu_gpai_provider: true
eu_high_risk_use: false
ab2013_developer: true # model offered to the public in California
co_sb26_189_developer: false
acquisition:
route: direct_license
license_ref: LIC-2026-031
permitted_uses: [pre-training, fine-tuning, evaluation]
prohibited_uses: [resale, retrieval_display]
regulator_disclosure_allowed: true
training_location: US
disclosure_facts: # feeds AB 2013, the EU summary and SB26-189 documentation
source_owner: "Supplier B"
ip_status: "owned by supplier; customer attachments removed"
personal_information: "names and phone numbers replaced with surrogates"
collection_period: "2019-01 to 2024-12"
synthetic_share: 0.0
data_categories: ["work orders", "technician notes", "parts usage"]
privacy:
jurisdictions: [US-CA]
standard: "Cal. Civ. Code 1798.140(m) deidentified"
method: "NER plus rules, surrogate replacement; post-processing sample checked"
contract_terms: ["no re-identification", "keep in deidentified form"]
art10_governance: not_applicable # complete if the data feeds a high-risk system
retention:
license_end: 2029-06-30
deletion_duty: "delete data copies within 30 days of license end"
approvals: {legal: 2026-09-14, privacy: 2026-09-16, security: 2026-09-16}
Keep entries in a training data use register, package them for audit readiness, and ask suppliers through a due diligence questionnaire or due diligence checklist.
If you source operational data through SourceX, every dataset goes through rights review, which checks that the business owns or may share the records and that required consents are in place, and diligence materials on source, rights, preparation and allowed use are prepared per dataset for your review (legal framework, data governance). You can list the compliance records your review requires when you describe the data.
Start here: compliance guides by question
Each guide below takes one question from this map further; for sourcing and licensing beyond compliance, start from the AI data buyer's guide.
- How do we document data for the EU? The training-content summary for licensed datasets, the GPAI Code copyright chapter, Annex IV technical documentation and models trained outside the EU.
- What do US states require? US state AI laws that reach training data, model cards that reference licensed data and CCPA risk assessments for AI training.
- Does an exception cover our training? Japan Article 30-4, UK commercial training, Singapore's exception and China's training data rules.
- Sector rules: bank model risk, insurers' external data, FDA devices, export controls.
- Who signs off? In-house counsel review of AI data licenses.
Mistakes that create compliance debt
- Treating a security review as a compliance review. Encryption protects files; it does not show rights, legal basis or disclosure facts.
- Assuming an exception travels. The UK exception is non-commercial only [18]; Japan's yields where analysis licenses are sold [19].
- Signing a license that blocks disclosure. If it bars public description or regulator access, you may be unable to meet these duties.
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Bring your compliance requirements to a data request
Describe the operational data you need and the records your compliance review requires. SourceX looks for US businesses that hold that data, checks the data and the supplier's licensing permissions, and manages a license that defines which records are included, what they can be used for and how delivery happens. Nothing is contracted until a supplier agrees, and a request does not guarantee a matching dataset. Submit your data and compliance requirements.
Guides in this section
- AI Training Data Compliance Audit: The Evidence PackPrepare for an AI training data compliance audit: what goes in the evidence pack, who asks for what, a per-dataset checklist and a mock audit to run.
- AI Training Data Disclosure Rules: AB 2013, EU, ColoradoCompare AI training data disclosure rules in California AB 2013, the EU training content summary and Colorado SB 26-189, with one supplier record for all.
- AI Training Data Retention: Regulatory Periods vs DeletionHow long to keep AI training data, manifests and documentation under the EU AI Act, Colorado and HIPAA without breaching license deletion clauses.
- California AB 2013 Training Data Disclosure Supplier RecordsWhat California AB 2013 requires in a training data summary, which items licensed datasets trigger, and the records to collect from each data supplier.
- Copyright Office AI Training Report: Licensing ImpactWhat the US Copyright Office Part 3 report says on fair use, RAG, model weights and licensing markets, and how it shapes build-versus-license decisions.
- EU AI Act Article 10: Data Governance for Licensed DatasetsTurn EU AI Act Article 10(2)-(6) into concrete checks and supplier documents for licensed training, validation and test data in high-risk AI systems.
- EU AI Act Article 53: GPAI Training Data ObligationsThe four EU AI Act Article 53 duties that touch GPAI training data: Annex XI, the copyright policy, the public summary, and what licenses must allow.
- GPAI Code Copyright Chapter: Policy for Licensed DataThe GPAI Code of Practice copyright chapter's five measures, where licensed non-crawled data fits, and a copyright policy outline for licensed datasets.
- Japan Article 30-4 and AI Training: Where a License AppliesHow Japan's Article 30-4 covers AI training, where the enjoyment and unreasonable-prejudice limits apply, and why databases, RAG and LoRA need licenses.
- Lawful Access and Pirated Sources in AI Training DataHow the way you acquire training data, by license, purchase, public access or piracy, changes copyright risk in the EU, UK, Singapore, Japan and US.
- TDM Exceptions by Country: EU, UK, Japan, Singapore, USCompare text and data mining exceptions for AI training in the EU, UK, Japan, Singapore, the US and China, and see where a data license is still required.
- UK TDM Exception and Commercial AI Training in 2026After the UK's March 2026 copyright and AI report, s29A still covers non-commercial research only. What commercial trainers need to license and record.
- AI Act Digital Omnibus: Training Data Deadlines 2027-2028Regulation (EU) 2026/1744 moved AI Act high-risk dates to 2 Dec 2027 and 2 Aug 2028. Plan Article 10 dataset acquisition and supplier evidence.
- AI Training Data Governance Policy: Template and ClausesA section-by-section template for an internal AI training data governance policy covering licensed data across pre-training, fine-tuning, eval and RAG.
- Algorithmic Disgorgement: FTC Model Deletion OrdersHow FTC orders have required deleting models trained on improperly obtained data, what triggers the remedy, and the data controls that limit exposure.
- Annex IV Technical Documentation for Licensed DatasetsHow to write the EU AI Act Annex IV point 2(d) data section for licensed training, validation and test sets: provenance, selection, labelling and cleaning.
- Colorado SB 26-189: Training Data Documentation for ADMTWhat Colorado SB 26-189 asks ADMT developers to tell deployers about training data from 1 January 2027, and the supplier records to collect now.
- EU Copyright Duties for Models Trained Outside the EUHow AI Act Article 53(1)(c), Recital 106 and Article 54 apply to a US-trained model placed on the EU market, and what to record about training data.
- EU Training Content Summary: Licensed and Private DataHow to complete the EU public summary of training content template for commercially licensed and private datasets without over- or under-disclosing.
- Fine-Tuning Duties: EU GPAI Provider and AB 2013 DeveloperWhen fine-tuning a third-party model with acquired data makes you an EU AI Act GPAI provider or a California AB 2013 developer, and what to document.
- GPAI Model Documentation Form: Training Data FieldsWhich training-data fields the GPAI Code's Model Documentation Form asks for, who sees each answer, and which supplier records fill them for licensed data.
- ISO 42001 Annex A Data and Supplier Controls for AI DataHow ISO/IEC 42001 Annex A.7 data controls and A.10 supplier controls apply to acquired training data, and the audit evidence to keep for each one.
- ITAR and EAR Checks for Engineering Training DataHow to screen acquired drawings, CAD files, MRO records and process specs for ITAR technical data and EAR technology before training or sharing them.
- Model Card Training Data Sections for Licensed DataWrite the training data section of a model or system card for licensed data: what to disclose, what to withhold, and how to match AB 2013 and EU summaries.
- NIST AI RMF Controls for Third-Party Training DataMap NIST AI RMF GOVERN 6, MAP 4 and MANAGE 3 to concrete controls and evidence for licensed, acquired and third-party AI training data.
- Regulator Access to Licensed Training Data Under the AI ActHow AI Act Article 74, Article 78 and Annex VII let authorities and notified bodies access training data, and the license terms buyers need to allow it.
- Singapore's CDA Exception (s244) and AI Training DataHow Singapore's Copyright Act 2021 s243-244 computational data analysis exception applies to AI training, its lawful access conditions and when to license.
- Training Data Risk Assessment: Scoring a Dataset to AcquireScore a candidate training dataset on eight risk dimensions, tier it for counsel, privacy and security sign-off, and record the result in your register.
- US State AI Laws That Reach Training Data (Oct 2026)Which US state AI laws impose training-data duties as of October 2026: California AB 2013, Colorado SB26-189, what each needs, and how to track changes.
Sources
- European Commission, AI Act Service Desk, "AI Act Article 10: Data and data governance". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-10
- European Commission, AI Act Service Desk, "AI Act Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
- European Commission (AI Office), "Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models" (2025). https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
- European Commission, "The General-Purpose AI Code of Practice" (2025). https://digital-strategy.ec.europa.eu/en/policies/gpai-code-practice
- California Legislature, "AB-2013 Generative artificial intelligence: training data transparency (Chapter 817, Statutes of 2024)" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- Colorado General Assembly, "SB26-189 Automated Decision-Making Technology" (2026). https://leg.colorado.gov/bills/sb26-189
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1" (2023). https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
- ISO/IEC, "ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system" (2023). https://www.iso.org/standard/42001
- European Parliament and Council of the European Union, "Regulation (EU) 2024/1689 (Artificial Intelligence Act)" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- European Parliament and Council of the European Union, "Regulation (EU) 2024/1689 (AI Act), Article 2: Scope" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/art_2/oj
- Conventus Law, "US: California's AB 2013 Requires Generative AI Data Disclosure By January 1, 2026". https://conventuslaw.com/report/us-californias-ab-2013-requires-generative-ai-data-disclosure-by-january-1-2026/
- European Parliament and Council of the European Union, "Regulation (EU) 2026/1744 (Digital Omnibus on AI)" (2026). https://eur-lex.europa.eu/eli/reg/2026/1744/oj?locale=en
- K&L Gates, "EU Digital Omnibus on AI Enters Into Force" (2026). https://www.klgates.com/EU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026
- WilmerHale, "European Commission Releases Mandatory Template for Public Disclosure of AI Training Data" (2025). https://wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/european-commission-releases-mandatory-template-for-public-disclosure-of-ai-training-data
- Colorado Attorney General, "Colorado Automated Decision-Making Technology & Chatbot Safety Rulemaking" (2026). https://coag.gov/ai/
- U.S. Copyright Office, "Copyright and Artificial Intelligence, Part 3: Generative AI Training (Pre-Publication Version)" (2025). https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf
- U.S. Court of Appeals for the Third Circuit, "Thomson Reuters Enterprise Centre GmbH v. ROSS Intelligence Inc., No. 25-2153 (precedential opinion)" (2026). https://www2.ca3.uscourts.gov/opinarch/252153p.pdf
- UK Intellectual Property Office, "Copyright, Designs and Patents Act 1988 - Consolidated (section 29A)". https://assets.publishing.service.gov.uk/media/60180c2b8fa8f53fc62c5897/Copyright-designs-and-patents-act-1988.pdf
- Hugh Stephens Blog, "Japan's Text and Data Mining (TDM) Copyright Exception for AI Training: A Needed and Welcome Clarification from the Responsible Agency" (2024). https://hughstephensblog.net/2024/03/10/japans-text-and-data-mining-tdm-copyright-exception-for-ai-training-a-needed-and-welcome-clarification-from-the-responsible-agency/
- Rouse, "Artificial intelligence in Singapore: copyright infringement defence for artificial intelligence and machine learning" (2024). https://rouse.com/insights/news/2024/artificial-intelligence-in-singapore-copyright-infringement-defence-for-artificial-intelligence-machine-learning
- Center for Security and Emerging Technology, "Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003), English translation" (2024). https://cset.georgetown.edu/wp-content/uploads/t0574_generative_AI_safety_EN.pdf
- European Parliament and Council of the European Union (Official Journal of the EU, via EUR-Lex), "Regulation (EU) 2016/679 (General Data Protection Regulation)". https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- CMS, "EDPB Opinion 28/2024: key takeaways on processing personal data in the context of AI models". https://cms.law/en/int/legal-updates/edpb-opinion-28-2024-key-takeaways-on-processing-personal-data-in-the-context-of-ai-models
- Acompli, "Digital Omnibus GDPR and Cookie Reforms Stall Without a Council Mandate" (2026). https://acompli.ie/news/digital-omnibus-gdpr-cookies-status-september-2026/
- eCFR, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- California Legislature, "California Civil Code section 1798.140 (CCPA definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- Federal Trade Commission, "AI Companies: Uphold Your Privacy and Confidentiality Commitments" (2024). https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/01/ai-companies-uphold-your-privacy-confidentiality-commitments
- National Institute of Standards and Technology, "AI Risk Management Framework (NIST ITL program page)". https://www.nist.gov/itl/ai-risk-management-framework
- National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)" (2024). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
- ISO/IEC, "ISO/IEC 5259-1:2024 Artificial intelligence - Data quality for analytics and machine learning (ML) - Part 1: Overview, terminology, and examples" (2024). https://www.iso.org/standard/81088.html
- ISO/IEC, "ISO/IEC 5259-5:2025 Artificial intelligence - Data quality for analytics and machine learning (ML) - Part 5: Data quality governance framework" (2025). https://www.iso.org/standard/5259-5
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.