AI Training Data Provenance Checker
Terms family

Fair use claimed

Fair use is a US defence decided case by case, not a licence. The claim belongs with legal.

Triage status: legal review required. A question for legal. The checker reads the words in your terms column, never the licence itself; the terms themselves decide. This reads copyright permission only. Whether training engages those rights, and whether licence conditions reach a model or its outputs, depends on the jurisdiction and the technical facts; privacy, data protection and contract restrictions are separate.

How the checker reads it

A terms column reading fair use places here, and the checker raises "terms that need review for this use": fair use is a defence, not a grant.

Clauses

RegimeClause
ISO/IEC 42001ISO/IEC 42001 A.7.3 Acquisition of data
NIST AI RMFNIST AI RMF MP-4.1 Legal risks of components and third-party data
NIST AI RMF GV-6.1 Third-party and intellectual property risk policy
ISO/IEC 42001 A.7.3Acquisition of data

The organization shall determine and document details about the acquisition and selection of data used in AI systems, including provenance and consent where applicable.

What an auditor asks to see: Data acquisition records; Provenance documentation; Consent records; Source identification; Licensing or consent evidence; Selection criteria and rejection rationale
What an auditor will probe: Is data provenance traceable to lawful sources?
Source: ISO/IEC 42001:2023
NIST AI RMF MP-4.1Legal risks of components and third-party data

Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third-party’s intellectual property or other rights. There is a followed approach for mapping the technology and legal risk carried by each component, including data and software obtained from third parties and the rights position attached to them.

What an auditor asks to see: The documented approach for mapping component technology and legal risk; Component inventory identifying third-party data, models and software; Intellectual property and rights analysis for each third-party component; Evidence the approach was followed for the components actually in use
What an auditor will probe: Approach documented but not applied to components adopted since; Pre-trained models used with no analysis of the provenance of their training data; Rights reviewed for commercial components only, not for freely obtained ones
Source: NIST AI Risk Management Framework
NIST AI RMF GV-6.1Third-party and intellectual property risk policy

Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third party’s intellectual property or other rights. Third-party AI risk is addressed by policy covering data, models, software and services obtained externally, including the rights position on training data and model outputs.

What an auditor asks to see: Third-party AI policy covering data, pre-trained models, software and services; Due diligence records for third-party AI components in use; Contract terms addressing intellectual property, data rights and liability for AI components; The intellectual property position recorded for training data and model outputs
What an auditor will probe: Standard vendor due diligence applied with no AI-specific questions; Open source models adopted with no review of the licence or the training data provenance; Policy addresses suppliers but not freely obtained models and datasets
Source: NIST AI Risk Management Framework

Named, not quoted: the EU copyright directive, Article 4 (text and data mining, and the rightholder's opt-out); US copyright fair use.

Families with the same triage status