Provenance, rights and permitted use
Provenance Red Flags When Buying AI Training Data
Quick answer
The strongest provenance red flags are things a supplier cannot show, not things it says. Stop or escalate when a supplier cannot name the source systems behind the records, refuses to trace sample records to origin, has no consent or notice artifacts for personal data, cannot document how it obtained the right to sublicense, or will not warrant its rights. Volumes that look too large for the claimed source, "licensed" labels with no license text, and "publicly available" used as a rights claim belong on the same list.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Why provenance claims fail more often than buyers expect
Provenance claims fail because labels travel further than the evidence behind them. The Data Provenance Initiative audited widely used fine-tuning collections and found license information frequently omitted or recorded more permissively than the original source terms allowed [1]. A "CC-BY" or "commercial OK" tag on a dataset card often describes the aggregator's wrapper, not the rights in each underlying record.
Time is the second failure mode. The Consent in Crisis audit tracked web domains that feed AI corpora and found that data-use restrictions in robots.txt and terms of service rose sharply within a single year [2]. A supplier's "publicly available" claim may reflect a crawl taken before those restrictions existed, and publicly reachable was never the same as licensed.
The cost of getting this wrong lands on the model, not only the dataset. In the Everalbum matter, the FTC required deletion of models and algorithms built with improperly obtained photos [3]. The FTC has also warned that using customer data for training contrary to privacy or confidentiality commitments can be unfair or deceptive [4]. That is why red flags matter at screening, before any data enters your training pipeline.
Red flags in what the supplier says about the source
Source red flags show up when a supplier describes data in marketing categories instead of systems, parties and dates. A credible supplier can say "Zendesk ticket exports from a B2B SaaS support desk, 2019 to 2024, ticket body, internal notes stripped, agent IDs pseudonymized." A weak one says "millions of real customer conversations."
Watch for these patterns:
- No named source system. If the supplier cannot say whether records came from Salesforce, ServiceNow, Jira, a call-recording platform or a scraper, it probably does not know, or does not want you to know.
- "Proprietary" as an answer to provenance questions. Collection method can be confidential; the existence of a lawful basis cannot.
- Collection dates that do not line up. Records dated before the supplier existed, or a 2026 dataset whose newest record is from 2021, suggest resale of an older corpus.
- Volume inconsistent with the claimed source. A small firm offering tens of millions of support transcripts should be able to explain the arithmetic of seats, years and ticket rates.
- Mixed modalities with one story. Text, audio and images from "one partner" usually means several partners, each with separate terms.
For resold or brokered data, each hop adds a place for rights to break. Our guide to tracing provenance through multiple hands covers how to map each transfer.
Red flags in the rights and documentation package
Documentation red flags appear when the paperwork does not connect the data holder to the right being licensed. A supplier that holds data under a customer contract, a platform's terms or a data processing agreement may have no right to license it for model training at all.
Escalate when you see any of the following:
- No chain-of-title documents. You should be able to follow ownership from the originating business to the licensor. See the chain of title documents that prove a supplier can license data.
- Service-provider data presented as owned data. A BPO, agency or SaaS vendor processing client data typically needs client authorization; a DPA that limits processing to "providing the services" does not cover training. Read customer contracts and DPAs for training use.
- No consent or notice artifacts for personal data. For biometric content such as voiceprints or face geometry, Texas law requires notice and consent before capture for a commercial purpose [7]. A supplier selling call audio or video without consent records is selling your risk.
- "De-identified" with no method. Under the CCPA, deidentified data requires reasonable measures against linkage, a public commitment not to reidentify, and contractual obligations on recipients [6]. Ask which method was used and whether a sample was tested.
- No datasheet-level documentation. Datasheets for Datasets lays out the questions on collection process, preprocessing and intended uses that any serious supplier should answer [5].
- Refusal to warrant. A supplier unwilling to represent that it has the rights it is granting is telling you how confident it is. See data warranties buyers should require.
If your models will be offered in the EU as general-purpose models, your copyright compliance policy must honor text-and-data-mining rights reservations, and your public training-content summary will describe sources [8]. As of October 2026, those Article 53 duties apply, so a supplier that cannot say whether opt-outs were respected creates a disclosure problem for you.
Red flags in how the supplier behaves during diligence
Behavioral red flags are often the earliest and most reliable signal. Suppliers with clean provenance tend to welcome sample-level questions because the answers are cheap for them.
- Refuses sample tracing. You ask for 20 random record IDs to be traced to source system, export date and governing agreement, and the supplier offers a summary deck instead. Our method for testing a supplier's provenance claims on a sample shows what a good answer looks like.
- Pressure to sign before review. Short "exclusive window" deadlines that leave no time for privacy or legal review.
- Delivery by email attachment or public link. This suggests weak handling controls throughout the chain.
- Inconsistent answers across contacts. Sales says "first-party," the data team says "partner feed."
- Indemnity offered in place of documents. An indemnity from a thinly capitalized seller does not replace evidence, and it does not undo a deletion order against your model [3].
Provenance red flag triage table
A triage table turns red flags into a consistent decision: proceed with conditions, escalate to counsel, quarantine, or walk away. Use it during screening calls so different reviewers reach the same outcome.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Red flag observed | What to request | If the supplier provides it | If not |
|---|---|---|---|
| Cannot name source systems | System name, export method, date range per file | Record in your data register; proceed | Walk away |
| Refuses tracing of 20 random records | Record ID to source, export date, governing agreement | Proceed to legal review | Walk away |
| "Licensed" label, no license text | Full upstream license or agreement excerpt | Counsel compares scope to intended use | Exclude affected subset |
| "Publicly available" as rights basis | Crawl dates, robots.txt and terms snapshot, opt-out handling | Counsel review; check EU TDM exposure | Exclude or walk away |
| Personal data, no consent or notice records | Privacy notice versions, consent logs, de-identification method | Privacy review; sample re-identification check | Walk away for biometrics or health |
| Data held as service provider | Client authorization covering AI training | Proceed with authorization in data room | Walk away |
| Will not warrant rights | Rights warranty plus documents | Proceed | Escalate to general counsel; usually walk away |
| Volume inconsistent with business size | Source breakdown by system and year | Proceed if arithmetic reconciles | Treat as resale; apply brokered-data checks |
How to escalate, re-scope or walk away
Escalation should follow severity, and most red flags have a narrower fix than killing the deal. Re-scoping to the subset with clean documentation is often better than accepting a blended corpus.
- Document the flag in your training data register with the question asked, the answer received and the reviewer. A training data use register keeps this auditable.
- Request specific evidence, not reassurance: named files, agreement excerpts, consent records, and sample traces.
- Route to the right reviewer. Copyright and contract questions go to legal; personal data and de-identification go to privacy; delivery and storage go to security. The internal approvals guide maps who signs what.
- Re-scope by excluding sources, date ranges or modalities that fail.
- Walk away when the core rights basis is missing, when personal data involves biometrics, health or children without records, or when the supplier refuses sample tracing.
If a red flag surfaces after data is already in use, the options change: see remediate, re-license, quarantine or retire. For the positive checklist of what to confirm on a clean deal, use the AI training data due diligence checklist; this page covers the signals that should stop that checklist early.
Where an intermediary changes the red flag picture
An intermediary that reviews rights before data reaches you shifts some screening work upstream, but you should still apply the same tests. The difference between a data broker and a data licensing intermediary is largely whether the supplying business approves each release and whether rights are reviewed per dataset.
SourceX sources operational datasets from US companies on request; data is not held in stock, and a request does not guarantee a match. Every dataset is rights-reviewed for ownership and consents, diligence materials covering source, rights, preparation and allowed use are prepared per dataset, and every release is approved by the supplying company. SourceX does not source scraped web content, standalone contact lists or generic CCTV or photos. Buyers can describe the data they need on the SourceX buyers page. For the wider framework, start at the provenance hub or the AI data guides.
Sourcing AI training data with provenance reviewed upfront
SourceX finds US businesses that hold the data you describe, assesses data and licensing permissions, and agrees pricing and allowed uses in a license; nothing is contracted until a supplier agrees. Personal details are removed or replaced before delivery, with the method recorded and a sample checked. Tell us what you need on the SourceX buyers page.
Sources
- Longpre et al., "The Data Provenance Initiative: A Large Scale Audit of Dataset Licensing & Attribution in AI," Nature Machine Intelligence 6 (2024). https://www.nature.com/articles/s42256-024-00878-8
- Longpre et al., "Consent in Crisis: The Rapid Decline of the AI Data Commons," NeurIPS 2024. https://arxiv.org/pdf/2407.14933
- U.S. Federal Trade Commission, "California Company Settles FTC Allegations It Deceived Consumers about use of Facial Recognition in Photo Storage App" (2021). https://www.ftc.gov/news-events/news/press-releases/2021/01/california-company-settles-ftc-allegations-it-deceived-consumers-about-use-facial-recognition-photo
- U.S. Federal Trade Commission (Office of Technology), "AI Companies: Uphold Your Privacy and Confidentiality Commitments" (2024). https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/01/ai-companies-uphold-your-privacy-confidentiality-commitments
- Gebru et al. (arXiv), "Datasheets for Datasets" (2018). https://arxiv.org/pdf/1803.09010
- California Legislature, "California Civil Code section 1798.140 (California Consumer Privacy Act definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- Texas Legislature, "Texas Business and Commerce Code Section 503.001 - Capture or Use of Biometric Identifier". https://statutes.capitol.texas.gov/Docs/BC/htm/BC.503.htm
- European Commission, AI Act Service Desk, "AI Act Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.