AI Training Data Provenance Checker
Regime

EU AI Act: what it asks of a training dataset list

When the model is placed on the EU market, put into service in the EU, or its output is used in the EU. Article 10 binds the provider of a high-risk AI system: its data governance lines apply if this system is high-risk under Annex III, so the page says so on each. Annex III names the areas; Article 6(3) can take some Annex III systems out of high-risk where they do not pose a significant risk of harm, so the classification is a question for legal. Articles 10, 11, 15 and 17 bind the provider and Article 26 the deployer. Article 53 applies only to a provider of a general-purpose model and is shown only when that box is ticked.

Annex III lists the high-risk areas the checker offers: biometrics, critical infrastructure, education, employment, essential services (public benefits, creditworthiness of natural persons other than fraud detection, life or health insurance risk assessment and pricing of natural persons, emergency calls), law enforcement, migration and the administration of justice. The classification is a question for legal. Other insurance uses are offered only as a review option, which raises a question and never an Article 10 finding.

Named, not quoted, beside it: the EU copyright directive, Article 4 (text and data mining, and the rightholder's opt-out); US copyright fair use; the EU AI Office template for the public summary of training content.

Findings that cite it

FindingClause
Origin not recordedEU AI Act Art. 10
Terms not recordedEU AI Act Art. 53 general-purpose model providers only
Terms that need review for this useEU AI Act Art. 53 general-purpose model providers only
Article 9, criminal offence or children's data declaredEU AI Act Art. 10
Labelled by a vendor, a crowd or a model with no quality check recordedEU AI Act Art. 17
No version or snapshot dateEU AI Act Art. 11
Declared potential overlap between train and testEU AI Act Art. 10
High-risk use with no bias examination recordedEU AI Act Art. 10
EU AI Act Art. 26
Vendor data with no provider namedEU AI Act Art. 17

Source classes anchored here

42
Source classClause
Claims system extractEU AI Act Art. 10
Policy and underwriting systemEU AI Act Art. 10
CRM exportEU AI Act Art. 10
ERP and finance systemEU AI Act Art. 10
HR records and staff surveysEU AI Act Art. 10
Service desk and ticketingEU AI Act Art. 10
Application logs and telemetryEU AI Act Art. 10
Internal document storeEU AI Act Art. 10
Email archiveEU AI Act Art. 10
Data warehouse or lake extractEU AI Act Art. 10
Internal, system not namedEU AI Act Art. 10
Support and call transcriptsEU AI Act Art. 10
Chat logsEU AI Act Art. 10
Reviews on your own siteEU AI Act Art. 10
Survey and complaint free textEU AI Act Art. 10
Call recordingsEU AI Act Art. 10
Licensed vendor datasetEU AI Act Art. 10
EU AI Act Art. 17
Data broker listEU AI Act Art. 10
EU AI Act Art. 17
Annotation vendor outputEU AI Act Art. 10
EU AI Act Art. 17
Licensed image or media libraryEU AI Act Art. 10
EU AI Act Art. 17
Credit reference extractEU AI Act Art. 10
EU AI Act Art. 17
Government open dataEU AI Act Art. 10
Academic or research datasetEU AI Act Art. 10
Open benchmarkEU AI Act Art. 10
Public register or recordsEU AI Act Art. 10
Open source codeEU AI Act Art. 10
Forum postsEU AI Act Art. 10
EU AI Act Art. 15
EU AI Act Art. 53 general-purpose model providers only
News articlesEU AI Act Art. 10
EU AI Act Art. 15
EU AI Act Art. 53 general-purpose model providers only
Social media postsEU AI Act Art. 10
EU AI Act Art. 15
EU AI Act Art. 53 general-purpose model providers only
General web crawlEU AI Act Art. 10
EU AI Act Art. 15
EU AI Act Art. 53 general-purpose model providers only
Specific website scrapeEU AI Act Art. 10
EU AI Act Art. 15
EU AI Act Art. 53 general-purpose model providers only
Synthetic data, generated in houseEU AI Act Art. 10
Synthetic data from a vendorEU AI Act Art. 10
Simulation outputEU AI Act Art. 10
Labels produced by a modelEU AI Act Art. 10
EU AI Act Art. 15
Text generated by a modelEU AI Act Art. 10
EU AI Act Art. 15
Distillation outputsEU AI Act Art. 10
EU AI Act Art. 15
Pre-trained model or embeddingsEU AI Act Art. 10
EU AI Act Art. 15
Data shared under an agreementEU AI Act Art. 10
Joint venture dataEU AI Act Art. 10
Reinsurer, broker or bank feedEU AI Act Art. 10
Industry consortium dataEU AI Act Art. 10

EU AI Act: every clause cited

6 of the 43 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

EU AI Act Art. 10Data and data governance applies if this system is high-risk under Annex III

High-risk AI systems that make use of techniques involving the training of AI models shall use training, validation and testing data that meet the quality criteria in Art.10(2)-(5): appropriate data governance, examination for possible biases, identification of data gaps/shortcomings, statistically relevant datasets to the intended purpose, and considerations specific to the geographical, contextual, behavioural or functional setting of intended use.

What an auditor asks to see: Data governance procedures; Bias examination records and remediation; Data-quality assessment per dataset
What an auditor will probe: Training data used without bias examination; Datasets not representative of the deployment context
Source: EU AI Act
EU AI Act Art. 11Technical documentation a provider duty

Technical documentation for a high-risk AI system shall be drawn up before the system is placed on the market or put into service and kept up to date. It shall be drawn up in such a way as to demonstrate that the high-risk AI system complies with the Section 2 requirements (incl Annex IV minimum content).

What an auditor asks to see: Annex IV-compliant technical documentation per high-risk system; Document version control and update on material change
What an auditor will probe: Out-of-date technical documentation; Missing Annex IV elements
Source: EU AI Act
EU AI Act Art. 15Accuracy, robustness and cybersecurity a provider duty

High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and shall perform consistently in those respects throughout their lifecycle. Resilience to errors, faults and inconsistencies; protection against attempts by unauthorised third parties to alter use, output or performance (incl data poisoning, model poisoning, adversarial examples and confidentiality attacks).

What an auditor asks to see: Accuracy/robustness measurements relevant to the intended purpose; Adversarial/data-poisoning threat modelling and mitigation; Cybersecurity controls aligned with state-of-the-art
What an auditor will probe: No adversarial-attack threat modelling; Accuracy claims not supported by test evidence
Source: EU AI Act
EU AI Act Art. 17Quality management system a provider duty

Providers must put in place a quality management system that ensures compliance with the Regulation, documented systematically in written policies, procedures and instructions, covering at least: a regulatory compliance strategy including conformity assessment and management of modifications; design, design control and design verification techniques; development, quality control and quality assurance techniques; examination, test and validation procedures before, during and after development and the frequency at which they run; technical specifications and standards to be applied and, where harmonised standards are not applied in full, the means used instead; data management systems and procedures spanning acquisition, collection, analysis, labelling, storage, filtration, mining, aggregation and retention; the Art.9 risk management system; the Art.72 post-market monitoring system; Art.73 serious incident reporting procedures; handling of communication with authorities, notified bodies, other operators and customers; record-keeping; resource management including security of supply; and an accountability framework setting out the responsibilities of management and staff for every one of those aspects. Implementation is proportionate to the size of the provider's organisation, but the degree of rigour required to make the systems compliant is not reducible.

What an auditor asks to see: The written quality management system covering all thirteen Art.17(1) aspects, with a cross-reference showing where each is addressed; The accountability framework naming responsibilities of management and staff for each aspect; Change management records for modifications to the high-risk AI system; Test and validation procedures with their defined frequency, and completed records against them; Where harmonised standards are not applied in full, the documented alternative means of meeting the Section 2 requirements; For financial institutions, the mapping of which internal governance arrangements are relied on under Art.17(4), with evidence that points (g), (h) and (i) are still discharged separately
What an auditor will probe: An existing quality system adopted wholesale without checking it covers the AI-specific aspects (g), (h) and (i); The accountability framework named in policy but never allocated to identified roles; Data management procedures documented for training data only, omitting acquisition, labelling, retention and deletion; Proportionality read as permission to omit aspects rather than to scale the depth at which each is addressed
Source: EU AI Act
EU AI Act Art. 26Obligations of deployers of high-risk AI systems a deployer duty

Deployers shall use high-risk AI systems in accordance with the IFU; assign human oversight to appropriately competent natural persons; ensure input data is relevant and sufficiently representative; monitor operation and inform the provider of risks/incidents; retain automatically generated logs for at least 6 months (longer where required); inform workers/representatives where used in the workplace; carry out a DPIA where required under GDPR; and where a deployer is a public authority, register the system in the EU database.

What an auditor asks to see: Deployer monitoring records; Logs retained at least 6 months; DPIA where applicable; Workforce information for workplace deployment
What an auditor will probe: Deployer not following IFU; No human-oversight assignment; Logs deleted before 6 months
Source: EU AI Act
EU AI Act Art. 53Obligations for providers of general-purpose AI models providers of general-purpose models

Providers of general-purpose AI models must draw up and keep up to date the technical documentation of the model, including its training and testing process and the results of its evaluation, containing at least the Annex XI information, for provision on request to the AI Office and the national competent authorities; draw up, keep up to date and make available to providers who intend to integrate the model information and documentation containing at least the Annex XII elements and sufficient to let them understand the model's capabilities and limitations and meet their own obligations; put in place a policy to comply with Union law on copyright and related rights, including identifying and complying, through state of the art technologies, with a reservation of rights expressed under Art.4(3) of Directive (EU) 2019/790; and draw up and make publicly available a sufficiently detailed summary of the content used for training, following the template provided by the AI Office. The two documentation duties do not apply to models released under a free and open source licence meeting the stated conditions, unless the model has systemic risk. Providers must cooperate with the Commission and the national competent authorities, and where they neither adhere to an approved code of practice nor comply with a European harmonised standard they must demonstrate alternative adequate means of compliance for assessment by the Commission.

What an auditor asks to see: Model technical documentation checked against every Annex XI element, with training, testing and evaluation results included; The downstream integrator pack checked against Annex XII, with evidence it is actually supplied to integrators; The copyright compliance policy, naming the technologies used to identify and honour text and data mining reservations of rights; The published training content summary following the AI Office template, with its publication location and date; Where the open source exemption is claimed, evidence the licence and the published parameters, architecture and usage information meet the Art.53(2) conditions; Where neither an approved code of practice nor a harmonised standard is followed, the documented alternative adequate means of compliance
What an auditor will probe: A training content summary published at a level of generality that is not sufficiently detailed against the template; A copyright policy that states intent but names no technology for identifying reservations of rights; The open source exemption claimed for a model with systemic risk, where it does not apply; Downstream documentation limited to an interface reference, omitting the capability and limitation information integrators need to meet their own duties
Source: EU AI Act