Skip to content

Regulation and governance for data buyers

AI Training Data Compliance: The Regulations, Standards and Records Data Buyers Need

Quick answer

AI training data compliance means being able to show, for every dataset you acquire, that you may use it for the intended training, that any personal data in it meets the right legal standard, and that you can describe it the way regulators now require. As of October 2026, those duties come from four tracks: AI-specific laws, copyright and text-and-data-mining (TDM) rules, privacy law, and your license terms. Each track asks for specific records, and they are cheapest to collect when the data arrives.

By SourceX Editorial · Updated

Four tracks of obligation and the record each one demands

Every compliance question about acquired data falls into one of four tracks, with voluntary governance frameworks layered on top; each is answered by a filed document, not a supplier's assurance.

TrackMain instruments (as of October 2026)Record to collect at acquisitionGo deeper
AI law: EU high-risk systemsAI Act Article 10 [1]Origin and collection description, preparation log, bias examination, known gapsArticle 10 data governance
AI law: EU general-purpose modelsAI Act Article 53, training-content template, GPAI Code of Practice [2][3][4]Acquisition route and legal basis per source, opt-out check resultsArticle 53 obligations
AI law: US state disclosureCalifornia AB 2013, Colorado SB26-189 [5][6]One disclosure sheet per dataset: owner, IP status, personal information, collection period, synthetic share, categoriesDisclosure requirements compared
Copyright and TDMFair use and national TDM exceptionsLicense reference, lawful-access evidence, training location, purposeTDM exceptions by country
PrivacyGDPR, HIPAA, CCPA, FTC ActDe-identification standard and method, notice versions, re-identification termsDe-identified data hub
ContractYour license and the supplier's customer contractsSigned license, permitted-use register entry, deletion datesLicensing guide
Governance frameworksNIST AI RMF, ISO/IEC 42001, ISO/IEC 5259 [7][8]Pre-acquisition risk assessment, supplier assessment, dataset registerNIST AI RMF for acquired data

The provenance hub covers verifying that evidence; the Data Provenance Standards explainer covers metadata for carrying it.

Your role with the model decides which duties attach

One dataset can trigger no AI-specific duty for one buyer and several for another, because these laws attach to what you do with the model. Classify each intended use before acquisition.

If your team...Role and data duty
Places a general-purpose model on the EU marketGPAI model provider (Article 53, since 2 August 2025): copyright policy and training-content summary [9]
Provides a high-risk AI system in the EUHigh-risk provider: Article 10 governance of training, validation and test sets [1]
Releases or substantially modifies a generative AI system available to CaliforniansAB 2013 developer: website documentation of training datasets [5]
Builds automated decision-making technology (ADMT) that materially influences employment, lending, insurance or similar decisions in ColoradoSB26-189 developer: documentation to deployers, including training data categories [6]
Only researches, tests or develops before releaseOutside the AI Act under Article 2(8), except testing in real-world conditions [10]; duties start once the model or system is placed on the market or put into service

One summary of the statute notes that its disclosure duty applies after a "substantial modification," but the law does not define the term [11], so fine-tuning a public model on licensed data may create your own disclosure duty (fine-tuning and provider duties). The research exclusion also ends at market placement, so capture disclosure facts while the supplier can still answer.

What Articles 10 and 53, AB 2013 and SB26-189 ask about the data

Article 10 governs high-risk training data, Article 53 sets copyright and transparency duties for general-purpose models, and two US state laws require written disclosures.

Article 10. Training, validation and testing sets for high-risk systems need data governance and management practices covering design choices, collection processes and data origin, preparation such as annotation and cleaning, assumptions, suitability, possible biases and data gaps, and must be relevant, sufficiently representative and, to the best extent possible, free of errors and complete [1]. Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 [12], reportedly moved the high-risk start dates shown below [13]; the Commission's AI Act Service Desk text, based on the consolidated version of 27 July 2026, marks Article 10(1) as amended [1].

Article 53. General-purpose AI (GPAI) model providers must keep a copyright policy that honors rights reservations under Article 4(3) of the Digital Single Market (DSM) Directive, and publish a training-content summary on the AI Office template [2]. The template, published 24 July 2025, applies to open-source models too [3]; a law-firm summary describes sections on general information, data sources by type and origin, and collection and processing [14]. See what buyers need from suppliers for EU summaries.

AB 2013. Documentation, due by 1 January 2026 and before each later release or substantial modification of systems released since 1 January 2022, covers dataset sources or owners, copyrighted or licensed material, personal information, collection periods and synthetic data [5] (AB 2013 supplier records).

SB26-189. Signed on 14 May 2026 to replace the consumer protections of SB 24-205, it requires developers of covered ADMT to give deployers documentation of intended uses, training data categories, known limitations and human-review guidance from 1 January 2027, enforced by the Attorney General [6], who released interim draft rules on 6 October 2026 [15] (SB 26-189 documentation).

Dates to plan around

DateEvent (as of October 2026)
2 Aug 2025Article 53 GPAI duties apply [9]
1 Jan 2026AB 2013 documentation due [5]
2 Aug 2026AI Office enforcement powers over GPAI providers, including fines, apply (Articles 101 and 113) [9]
26 Oct 2026Comments due on Colorado's interim draft ADMT rules [15]
1 Jan 2027SB26-189 duties begin [6]
2 Aug 2027GPAI models placed on the market before 2 August 2025 must comply (Article 111(3)) [9]
2 Dec 2027High-risk duties, including Article 10, reportedly apply to Annex III systems [13]
2 Aug 2028Same duties reportedly apply to Annex I systems [13]

See EU AI Act deadlines after the Digital Omnibus.

As of October 2026, no major jurisdiction gives commercial developers an unconditional right to train on accessible works; each exception carries a condition that decides the record you need. Exceptions are national, so record where each copy is made and why.

JurisdictionRule and its conditionRecord that answers it
United StatesFair use, case by case. The Copyright Office's Part 3 report (May 2025, still pre-publication) says copying works into training datasets may be prima facie infringing absent a defense, and weighs competing use and illegal access against fair use [16]; on 29 September 2026 the Third Circuit held that training a non-generative legal-research tool on Westlaw headnotes was not fair use [17]License, purchase or access record per source
European UnionDSM Directive Article 4 exception, unavailable where rightsholders have reserved their rights (for online content, by machine-readable means); GPAI providers must honor those reservations [2]Dated opt-out checks; license for reserved content
United KingdomCDPA section 29A covers computational analysis for non-commercial research only, with lawful access; copies cannot be passed on [18]License for any commercial use
JapanArticle 30-4 permits uses not aimed at enjoying the work, unless they unreasonably prejudice the rightsholder; commentary on 2024 government guidance notes that the exception does not apply if it would 'unreasonably prejudice the interests of the copyright owner,' with copying a database sold for analysis being one example of such prejudice [19]Whether the source is licensed for analysis
SingaporeSection 244 computational data analysis exception; conditions include lawful access, per practitioner commentary [20]Access terms and subscriptions
ChinaA 2023 draft technical document, TC260-003, asked providers to keep a corpus source blacklist and assess each source corpus [21]; confirm whether a later national standard now governsPer-source assessment

See the Copyright Office report and licensing, lawful access and pirated sources, EU opt-out checks under DSM Article 4 and whether to license or rely on fair use.

Privacy law: the de-identification standard decides which rules follow the data

Privacy compliance turns on whether the records are still personal data where you receive them, and under which standard they were de-identified; answers differ by jurisdiction.

  • EU. Pseudonymised data that can be re-attributed remains personal data under the GDPR, and special categories such as health data need an Article 9(2) condition [22]; the AI Act leaves the GDPR unaffected [10]. EDPB Opinion 28/2024 says a model trained on personal data cannot be presumed anonymous and that legitimate interest must pass a three-step test [23]. As of September 2026, Digital Omnibus proposals to narrow the personal-data definition were not law [24].
  • US health data. HIPAA de-identification uses Expert Determination or Safe Harbor removal of listed identifiers [25] (which method to require).
  • California. CCPA "deidentified" status requires the holder to bind recipients by contract to its conditions, including no re-identification [26] (obligations a buyer inherits).
  • Promises to customers and users. FTC staff warned in January 2024 that breaking promises not to train on customer data may violate FTC-enforced law, citing past orders to delete models built with unlawfully obtained data [27] (algorithmic disgorgement).

Where SourceX sources a dataset, names, emails and account numbers are removed or replaced before delivery, the method is recorded and a processed sample is checked; health records must meet HIPAA Safe Harbor or Expert Determination before a license is considered. No method is perfect, so classify the result yourself with the legal definitions compared and SourceX's guides to privacy and data laws.

Governance frameworks that turn duties into acquisition controls

Voluntary frameworks create no legal duties, but auditors and customers test against them.

  • NIST AI RMF 1.0 (AI 100-1, January 2023) structures risk work under Govern, Map, Measure and Manage [7]; NIST says it is being revised as part of the White House AI Action Plan, with no revision published as of early October 2026 [28].
  • NIST AI 600-1, the Generative AI Profile (July 2024), lists 12 risks, including data privacy, intellectual property, and value chain and component integration, with coded actions such as GV-1.1-001 [29]; acquisition controls fit the last two (NIST controls for acquired data).
  • ISO/IEC 42001:2023 sets requirements for an AI management system, with controls in Annex A; certification is optional [8] (Annex A data and supplier controls).
  • ISO/IEC 5259 covers data quality for machine learning: Parts 1 to 4 appeared in 2024 [30] and Part 5, on governance, in 2025 [31]; measures belong to the training data quality hub.

Start internal rules from the governance policy template, pre-acquisition risk scoring and the data governance definition.

AI training data compliance checklist per dataset

Run these nine checks before a dataset enters any pipeline; together they produce every record the tracks above ask for.

  1. Classify use and role. Intended uses, and which roles above each one creates.
  2. Name the source. System of record, legal owner, prior holders, collection period.
  3. Prove the acquisition route. License, purchase or access terms; dated opt-out checks for web-derived content.
  4. Fix permitted uses. Allowed uses, term, deletion duties and regulator access.
  5. Classify personal data. Status per jurisdiction, de-identification standard and method, special categories.
  6. Capture disclosure facts. IP status, synthetic share, data categories and volume, in publishable wording.
  7. Log preparation. Annotation, cleaning and filtering, bias examination and known gaps.
  8. Record location and retention. Where copies are made, and retention periods for data and records.
  9. Record sign-off. Legal, privacy and security internal approvals against the dataset ID.

Illustrative example: invented to show structure; it does not describe an available dataset.

dataset_id: ds-0142
description: "Field service work orders, commercial HVAC, 2019-2024"
supplier: "Supplier B (US facilities services company)"
role_assessment:
  eu_gpai_provider: true
  eu_high_risk_use: false
  ab2013_developer: true            # model offered to the public in California
  co_sb26_189_developer: false
acquisition:
  route: direct_license
  license_ref: LIC-2026-031
  permitted_uses: [pre-training, fine-tuning, evaluation]
  prohibited_uses: [resale, retrieval_display]
  regulator_disclosure_allowed: true
  training_location: US
disclosure_facts:                   # feeds AB 2013, the EU summary and SB26-189 documentation
  source_owner: "Supplier B"
  ip_status: "owned by supplier; customer attachments removed"
  personal_information: "names and phone numbers replaced with surrogates"
  collection_period: "2019-01 to 2024-12"
  synthetic_share: 0.0
  data_categories: ["work orders", "technician notes", "parts usage"]
privacy:
  jurisdictions: [US-CA]
  standard: "Cal. Civ. Code 1798.140(m) deidentified"
  method: "NER plus rules, surrogate replacement; post-processing sample checked"
  contract_terms: ["no re-identification", "keep in deidentified form"]
art10_governance: not_applicable    # complete if the data feeds a high-risk system
retention:
  license_end: 2029-06-30
  deletion_duty: "delete data copies within 30 days of license end"
approvals: {legal: 2026-09-14, privacy: 2026-09-16, security: 2026-09-16}

Keep entries in a training data use register, package them for audit readiness, and ask suppliers through a due diligence questionnaire or due diligence checklist.

If you source operational data through SourceX, every dataset goes through rights review, which checks that the business owns or may share the records and that required consents are in place, and diligence materials on source, rights, preparation and allowed use are prepared per dataset for your review (legal framework, data governance). You can list the compliance records your review requires when you describe the data.

Start here: compliance guides by question

Each guide below takes one question from this map further; for sourcing and licensing beyond compliance, start from the AI data buyer's guide.

Mistakes that create compliance debt

  • Treating a security review as a compliance review. Encryption protects files; it does not show rights, legal basis or disclosure facts.
  • Assuming an exception travels. The UK exception is non-commercial only [18]; Japan's yields where analysis licenses are sold [19].
  • Signing a license that blocks disclosure. If it bars public description or regulator access, you may be unable to meet these duties.

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Bring your compliance requirements to a data request

Describe the operational data you need and the records your compliance review requires. SourceX looks for US businesses that hold that data, checks the data and the supplier's licensing permissions, and manages a license that defines which records are included, what they can be used for and how delivery happens. Nothing is contracted until a supplier agrees, and a request does not guarantee a matching dataset. Submit your data and compliance requirements.

Guides in this section

Sources

  1. European Commission, AI Act Service Desk, "AI Act Article 10: Data and data governance". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-10
  2. European Commission, AI Act Service Desk, "AI Act Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
  3. European Commission (AI Office), "Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models" (2025). https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
  4. European Commission, "The General-Purpose AI Code of Practice" (2025). https://digital-strategy.ec.europa.eu/en/policies/gpai-code-practice
  5. California Legislature, "AB-2013 Generative artificial intelligence: training data transparency (Chapter 817, Statutes of 2024)" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
  6. Colorado General Assembly, "SB26-189 Automated Decision-Making Technology" (2026). https://leg.colorado.gov/bills/sb26-189
  7. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1" (2023). https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
  8. ISO/IEC, "ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system" (2023). https://www.iso.org/standard/42001
  9. European Parliament and Council of the European Union, "Regulation (EU) 2024/1689 (Artificial Intelligence Act)" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  10. European Parliament and Council of the European Union, "Regulation (EU) 2024/1689 (AI Act), Article 2: Scope" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/art_2/oj
  11. Conventus Law, "US: California's AB 2013 Requires Generative AI Data Disclosure By January 1, 2026". https://conventuslaw.com/report/us-californias-ab-2013-requires-generative-ai-data-disclosure-by-january-1-2026/
  12. European Parliament and Council of the European Union, "Regulation (EU) 2026/1744 (Digital Omnibus on AI)" (2026). https://eur-lex.europa.eu/eli/reg/2026/1744/oj?locale=en
  13. K&L Gates, "EU Digital Omnibus on AI Enters Into Force" (2026). https://www.klgates.com/EU-Digital-Omnibus-on-AI-Enters-Into-Force-7-31-2026
  14. WilmerHale, "European Commission Releases Mandatory Template for Public Disclosure of AI Training Data" (2025). https://wilmerhale.com/en/insights/blogs/wilmerhale-privacy-and-cybersecurity-law/european-commission-releases-mandatory-template-for-public-disclosure-of-ai-training-data
  15. Colorado Attorney General, "Colorado Automated Decision-Making Technology & Chatbot Safety Rulemaking" (2026). https://coag.gov/ai/
  16. U.S. Copyright Office, "Copyright and Artificial Intelligence, Part 3: Generative AI Training (Pre-Publication Version)" (2025). https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf
  17. U.S. Court of Appeals for the Third Circuit, "Thomson Reuters Enterprise Centre GmbH v. ROSS Intelligence Inc., No. 25-2153 (precedential opinion)" (2026). https://www2.ca3.uscourts.gov/opinarch/252153p.pdf
  18. UK Intellectual Property Office, "Copyright, Designs and Patents Act 1988 - Consolidated (section 29A)". https://assets.publishing.service.gov.uk/media/60180c2b8fa8f53fc62c5897/Copyright-designs-and-patents-act-1988.pdf
  19. Hugh Stephens Blog, "Japan's Text and Data Mining (TDM) Copyright Exception for AI Training: A Needed and Welcome Clarification from the Responsible Agency" (2024). https://hughstephensblog.net/2024/03/10/japans-text-and-data-mining-tdm-copyright-exception-for-ai-training-a-needed-and-welcome-clarification-from-the-responsible-agency/
  20. Rouse, "Artificial intelligence in Singapore: copyright infringement defence for artificial intelligence and machine learning" (2024). https://rouse.com/insights/news/2024/artificial-intelligence-in-singapore-copyright-infringement-defence-for-artificial-intelligence-machine-learning
  21. Center for Security and Emerging Technology, "Basic Security Requirements for Generative Artificial Intelligence Services (TC260-003), English translation" (2024). https://cset.georgetown.edu/wp-content/uploads/t0574_generative_AI_safety_EN.pdf
  22. European Parliament and Council of the European Union (Official Journal of the EU, via EUR-Lex), "Regulation (EU) 2016/679 (General Data Protection Regulation)". https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
  23. CMS, "EDPB Opinion 28/2024: key takeaways on processing personal data in the context of AI models". https://cms.law/en/int/legal-updates/edpb-opinion-28-2024-key-takeaways-on-processing-personal-data-in-the-context-of-ai-models
  24. Acompli, "Digital Omnibus GDPR and Cookie Reforms Stall Without a Council Mandate" (2026). https://acompli.ie/news/digital-omnibus-gdpr-cookies-status-september-2026/
  25. eCFR, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
  26. California Legislature, "California Civil Code section 1798.140 (CCPA definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.140
  27. Federal Trade Commission, "AI Companies: Uphold Your Privacy and Confidentiality Commitments" (2024). https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/01/ai-companies-uphold-your-privacy-confidentiality-commitments
  28. National Institute of Standards and Technology, "AI Risk Management Framework (NIST ITL program page)". https://www.nist.gov/itl/ai-risk-management-framework
  29. National Institute of Standards and Technology, "Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)" (2024). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf
  30. ISO/IEC, "ISO/IEC 5259-1:2024 Artificial intelligence - Data quality for analytics and machine learning (ML) - Part 1: Overview, terminology, and examples" (2024). https://www.iso.org/standard/81088.html
  31. ISO/IEC, "ISO/IEC 5259-5:2025 Artificial intelligence - Data quality for analytics and machine learning (ML) - Part 5: Data quality governance framework" (2025). https://www.iso.org/standard/5259-5

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data