Regulation and governance for data buyers
Can Regulators Inspect Your Licensed Training Data? Authority, Notified Body and AI Office Access and What Your License Must Allow
Quick answer
Yes. Under the EU AI Act, market surveillance authorities can be given full access to a high-risk system's training, validation and testing data sets, including remotely through an API [1]. Notified bodies doing an Annex VII conformity assessment get the same access [7]. For general-purpose models, the AI Office can demand documentation [5]. A data license that forbids disclosure to third parties, or forces deletion at term end, can therefore put the provider in breach of either the license or the regulation. Fix this when you negotiate the license, not when an authority writes to you, and say so when you describe the data you need to SourceX.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Who can demand access, and to what
Three kinds of body can reach your data or its records, and each one has a different legal basis and scope. The table below maps them. Article and annex references are to Regulation (EU) 2024/1689 as amended [7][8]. As of October 2026, secondary commentary reports that Regulation (EU) 2026/1744 moved the high-risk start dates to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products [8].
| Body | Legal hook | What it can reach | Conditions |
|---|---|---|---|
| National market surveillance authority | Art. 74(12)-(13) [1] | Documentation and full training, validation and testing data sets; source code as a last resort | Where relevant and necessary for its tasks; API or remote access subject to security safeguards; source code only on reasoned request once testing or auditing has failed |
| Notified body | Annex VII [7] | Full training, validation and testing data sets; trained models as a last resort | Granted within its examination of the technical documentation; remote API access with safeguards; model access only on reasoned request, subject to IP and trade secret law |
| AI Office / Commission | Arts. 53 and 91 [4][5] | GPAI technical documentation, information on training data, copyright policy | Applies to general-purpose AI model providers, not to the data sets of high-risk systems as such |
The key word is "full." Article 74(12) does not limit access to a sample or a datasheet [1]. If your license lets you show a regulator only a summary, you have not secured the access the Act expects.
Market surveillance access under Article 74
Article 74 lets a national authority inspect the actual data sets behind a high-risk system, not just your description of them [1]. The authority reviews what you used to meet Article 10's quality, representativeness and bias-examination criteria [3]. Its evidence is the records themselves: the ticket exports, labeled documents or sensor recordings you licensed.
Two practical points follow. First, the Act names APIs and remote technical means [1], so assume an authority may ask for programmatic, read-only access rather than a disk handover. Second, source code access sits behind a higher bar, a reasoned request after testing or auditing proves insufficient [1]. Data set access has no such bar. Draft for the more likely request.
For how to describe each licensed set in the dossier the authority reads first, see Annex IV technical documentation for licensed data sets. For the underlying quality duties, see Article 10 data governance for licensed training data.
Notified body access during conformity assessment
When a notified body assesses your technical documentation under Annex VII, it can be granted full access to the training, validation and testing data sets used, including through an API with security safeguards [7]. It may also ask for more evidence, require further tests, or run tests of its own [7]. Its access to trained models comes later, only on a reasoned request after other means have failed, and subject to EU IP and trade secret law [7].
This matters for licensing because a notified body is a private conformity assessment body, not a public authority. Many standard data licenses allow disclosure "as required by law or to a governmental authority." A notified body may fall outside that wording, so name it expressly.
Confidentiality: what Article 78 protects, and what it does not
Article 78 binds the Commission, market surveillance authorities, notified bodies and anyone else applying the Act to protect intellectual property, confidential business information and trade secrets [7]. They may request only data strictly necessary for their tasks, must keep cybersecurity measures, and must delete data once it is no longer needed [7]. Article 74 routes anything an authority obtains into that regime [1].
Suppliers often accept regulator disclosure once they see Article 78. It does not, however, make the provider's own handling irrelevant. You still control how the data leaves your environment, who on your side assembles the extract, and whether personal data in it is minimized first. The supplier will also want to know which body saw which records. That is why the access log below exists.
Retention versus deletion: the clause most likely to fail
Article 18 requires providers to keep technical documentation and related records available to authorities for 10 years after the system is placed on the market or put into service [2]. Article 18's list centers on documentation, not on the raw data sets. However, Article 74(12) and Annex VII access only works if the data sets, or a faithful snapshot, still exist [1][7]. A license with a 3-year term and a "delete all copies on expiry" clause collides with that.
Common ways to reconcile the two:
- Regulatory retention carve-out. The licensee may keep a frozen, access-controlled copy solely to answer authority and notified body requests, with no further training use.
- Escrowed snapshot. A hashed snapshot (for example, a manifest of SHA-256 checksums per file plus a Parquet or JSONL export) sits with the supplier or a neutral escrow agent, retrievable on a documented regulator request.
- Reproducible pointer. If the supplier keeps the data, the license obliges it to preserve the exact version (dataset ID, version tag, record IDs, extraction date) for the regulatory window.
The trade-offs, including GDPR storage limitation, are covered in training data retention vs license deletion duties. For general background on term and deletion language, see AI data license terms explained.
License clauses to negotiate before signing
Your license should name each body that may receive the data, the form of access, and who bears the cost and notice duties. The checklist below is a starting point for counsel. It is not a SourceX license term.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Clause | Draft position for the licensee | Supplier concern to expect |
|---|---|---|
| Permitted disclosure | Licensee may disclose licensed data, documentation and derived evaluation results to EU and member state market surveillance authorities, notified bodies, the AI Office and Commission, and equivalent bodies, as required under Regulation (EU) 2024/1689 | Scope creep to "any regulator worldwide"; narrow by naming statutes |
| Form of access | Disclosure may be by on-site inspection, secure data room, or read-only API with authentication and logging | API exposure; agree rate limits and no bulk export |
| Notice | Licensee notifies supplier within an agreed number of business days of a request, unless the authority prohibits notice | Wants advance notice and the right to seek protective treatment |
| Confidentiality marking | Licensee marks disclosures as confidential business information and trade secrets and invokes Article 78 [7] | Wants proof of marking |
| Retention carve-out | Licensee may retain a frozen copy and checksums for the period required by Article 18 [2], for regulatory use only | Conflicts with deletion and data-protection duties; may require escrow instead |
| Supplier cooperation | Supplier provides provenance, consent and preparation records needed to answer an authority within a reasonable time | Cost recovery; cap on hours |
| Personal data | Disclosed extracts are minimized and de-identified where the request allows | Re-identification risk on small samples |
| Survival | Disclosure, retention and cooperation clauses survive termination | Open-ended obligations; agree an end date tied to the system's market life |
The regulator access log
An access log turns a one-off disclosure into an auditable event that you can show the supplier, your quality management system and a later inspector. Keep one row per disclosure, linked to the dataset version in your technical documentation. The schema below is a minimal starting point.
Illustrative example: invented to show structure; it does not describe an available dataset.
{
"request_id": "MSA-2028-0142",
"requesting_body": "National market surveillance authority (named)",
"legal_basis": "AI Act Art. 74(12)",
"ai_system_id": "HR-credit-scoring-v3.2",
"dataset_id": "lic-support-tickets-2026Q1",
"dataset_version": "v1.4",
"manifest_sha256": "9f2c...e71a",
"records_disclosed": "test split only, record IDs 10001-12500",
"access_mode": "read-only API, 14-day token",
"confidentiality_marking": "CBI / trade secret, Art. 78",
"supplier_notified_at": "2028-03-04",
"access_opened_at": "2028-03-06",
"access_closed_at": "2028-03-20",
"approved_by": "Regulatory counsel; data owner"
}
Record the data set split. An authority checking bias or representativeness may ask for training data, while a notified body rerunning tests may only need the held-out test set [7]. Logging the split keeps disclosures minimal, which Article 78 also expects from the requester [7]. The full evidence pack is covered in AI training data audit readiness.
The GPAI side: AI Office requests from August 2026
General-purpose model providers face documentation requests rather than data set inspection. Article 53 sets these documentation duties for general-purpose AI model providers [4]. Under Article 91, the Commission can request the documentation drawn up under Articles 53 and 55 and further information needed to assess compliance [5].
For licensed data, that means a request may cover the provenance and terms behind the public training-content summary built on the AI Office template of 24 July 2025 [6]. The license should allow you to describe the dataset's source category, collection period and rights basis to the AI Office without breaching confidentiality. See Article 53 training data obligations for GPAI providers for the full duty set.
Failure modes seen in data license reviews
The same few drafting gaps recur when a provider's licenses meet the AI Act's access rules:
- "Government authority" only. Notified bodies are not covered, so an Annex VII assessment needs supplier consent mid-audit.
- No remote access right. The license permits "on-premises use only," which blocks an API-based inspection [1][7].
- Deletion without carve-out. Data is destroyed at term end, years before the Article 18 window closes [2].
- No version pinning. The supplier refreshes the feed, so the exact records used for training cannot be reconstructed.
- Sublicense ambiguity. Disclosure to an authority is treated as an unlicensed transfer.
For how these fit an Article 17 quality management system, see writing the data management procedure. The full cluster is at the training data compliance hub.
License training data you can show a regulator
SourceX sources operational datasets from US companies on request, and every dataset is rights-reviewed for ownership and consents and delivered under a license that defines records, uses, term and delivery. Diligence materials covering source, rights, preparation and allowed use are prepared per dataset, and nothing is contracted until the supplier agrees. Describe the data and your regulator-access requirements at SourceX for AI data buyers.
Related reading: enterprise data licensing explained, the SourceX legal framework, and approving third-party training data as an AI governance lead.
Frequently asked questions
Does a regulator get the whole dataset or a sample?
Article 74(12) and Annex VII both speak of "full access" to training, validation and testing data sets [1][7]. Article 74(12) limits authority access to what is relevant and necessary for its tasks, and Article 78 lets any requester ask only for data strictly necessary [1][7]. In practice, a well-scoped request and a split-level log can keep disclosure narrower than the whole corpus.
Can a supplier refuse to let its data be shown to a notified body?
Under the license, it can if the license does not permit the disclosure. That leaves the provider unable to complete conformity assessment with that data, so the right needs to be agreed before signing.
Do these access rules apply to non-EU buyers?
They apply to providers placing high-risk systems or GPAI models on the EU market, wherever the provider or its suppliers sit [7]. A US supplier's license therefore needs the same disclosure language.
Sources
- European Commission, AI Act Service Desk, "Article 74: Market surveillance and control of AI systems in the Union market". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-74
- European Commission, AI Act Service Desk, "Article 18: Documentation keeping". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-18
- European Commission, AI Act Service Desk, "Article 10: Data and data governance". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-10
- European Commission, AI Act Service Desk, "Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
- European Commission, AI Act Service Desk, "Article 91: Power to request documentation and information". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-91
- European Commission (AI Office), "Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models" (2025). https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
- Official Journal of the EU, via EUR-Lex, "Regulation (EU) 2024/1689 (Artificial Intelligence Act)" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- Official Journal of the EU, via EUR-Lex, "Regulation (EU) 2026/1744 (Digital Omnibus on AI)" (2026). https://eur-lex.europa.eu/eli/reg/2026/1744/oj?locale=en
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.