RatedWithAI

RatedWithAI

Accessibility scanner

AI Copyright & LiabilityAugust 24, 2026

The Dataset Licence Is Not the Point. The Four Clauses After It Are.

Buying training data feels like buying software: sign, download, build. It is closer to buying a building with an unresolved title. What you are really acquiring is a set of promises about where every item came from — and the value of the deal is decided by what happens when one of those promises turns out to be wrong.

Chain of title
A licence binds your vendor, not the rights holder who never consented
Weights ≠ data
Most grants permit copying and processing but never name the derived model
Deletion cost
Removing records is cheap; removing their influence from weights is not

Why the Purchase Order Model Fails Here

A normal software licence covers an artefact the licensor made. A training-data licence usually covers an artefact the licensor assembled from work other people made. The licensor's ability to grant anything at all depends on a chain of permissions running backwards from the file you downloaded to every photographer, author, forum poster, repository owner and voice in the corpus.

That chain is where deals break. A dataset aggregated from public web sources carries no consent from the underlying creators. A dataset licensed onward from another aggregator inherits whatever defects existed upstream. A dataset built from user-generated content on a platform depends on whether that platform's terms of service actually conferred a sublicensable right to license the content for model training — many platform terms predate the practice and were drafted for hosting and display.

None of this makes licensing pointless. It makes the diligence and the remedy structure the substance of the transaction, and the price a secondary term. A cheap dataset with a fee-capped liability clause and no clearance description is an unpriced liability with a receipt attached.

Four Clauses That Decide the Deal

1. Representations about provenance, with method attached

A bare warranty that the licensor 'has all necessary rights' is boilerplate that tells you nothing about how those rights were obtained. Ask for the mechanism: originally created, acquired by assignment, licensed from identified upstream holders, collected under an open licence with the licence identifier recorded per item, or opt-in contributed with consent records retained.

Why it decides the deal: The mechanism is what you will need if a claim arrives, and it is also the fastest diligence signal. A licensor that can describe clearance per source category has done the work. A licensor that offers only the conclusory warranty is asking you to fund its risk.

2. A grant that reaches model weights and survives the term

Training creates derived artefacts — weights, embeddings, adapters, checkpoints, distilled student models — that persist after the licensed corpus is deleted. The grant must name them, permit their commercial exploitation and distribution, and state expressly that those rights survive expiry or termination of the data licence for models trained during the term.

Why it decides the deal: Without survival language, a data licence that lapses can be argued to strand every model built on it. Renewal then stops being a purchasing decision and becomes a hostage negotiation, which is precisely why some licensors leave the clause out.

3. Output ownership and field-of-use freedom

State that outputs generated by models trained on the data are owned by the licensee, without royalty, attribution or reporting obligations, and that the licensor asserts no interest in them. Then check the definitions and restrictions sections for a non-compete that limits use against the licensor's own products or customer base.

Why it decides the deal: Output claims and competitive-use restrictions are frequently placed outside the ownership clause where a reviewer focused on IP will not look. A restriction on competing with the licensor can foreclose your actual roadmap while the ownership clause reads perfectly.

4. A deletion obligation you can actually perform

Define what deletion means at each layer: removal from stored corpora, exclusion from future training runs, and — separately and only where required — retraining to remove influence from existing weights. Attach timing to your training cycle rather than to a fixed number of days, and allocate retraining cost to whoever caused the removal.

Why it decides the deal: A promise to 'delete the affected data within thirty days' looks harmless until a removal demand implies a full retrain of a production model. Teams sign that clause routinely because the cost is invisible at signature and arrives in the middle of an incident.

Indemnity Structure Matters More Than Indemnity Presence

Almost every training-data contract contains the word indemnity. Very few contain an indemnity that would fund a defence. The differences that matter are mechanical:

  • Cap. An indemnity capped at fees paid means a dataset that cost forty thousand dollars covers forty thousand dollars of a claim that will cost more than that in the first month of motion practice. Push for the IP indemnity to sit outside the general cap, which is standard in software and routinely resisted in data.
  • Defence versus reimbursement. A duty to defend puts the licensor's counsel in the case from the start. A reimbursement obligation pays you back after final judgment, which is years away and contingent on the licensor still existing.
  • Scope of covered claims. Confirm the indemnity reaches claims arising from the data itself, from models trained on it, and from outputs of those models. Data-only indemnities are common and exclude the two categories most likely to be asserted.
  • Control and settlement. A licensor with sole settlement authority can agree to an injunction that ends your product in order to cap its own exposure. Reserve consent rights over any settlement imposing non-monetary obligations on you.
  • Counterparty substance. An uncapped indemnity from a two-person data broker is a document, not a remedy. Where the counterparty is thin, price the risk instead: escrow, holdback, insurance requirement, or a narrower use case.

The Provenance Register

Whatever the contract says, you will be asked one day to explain where a model's training data came from — by a customer's security review, by a regulator, by a litigant, or by an acquirer's diligence team. The teams that answer that question in a week rather than a quarter maintain a register from the beginning.

It does not need to be sophisticated. One row per source, recording: what the source is, how it was obtained, the legal basis relied on, the contract reference and its term, whether personal data is present, which model versions consumed it, and what would have to happen operationally to remove it. The last column is the one nobody writes and everybody needs.

The Training Data Licensing Checklist

Run this before signature on any corpus you intend to train, fine-tune or embed on — including the ones a team acquired on a corporate card as "research data."

1. Provenance and Diligence
  • Obtain a written description of how rights were cleared, by source category, not a conclusory warranty
  • Confirm whether the corpus is originally created, assigned, sublicensed onward, openly licensed, or scraped
  • For openly licensed material, verify the specific licence identifiers and any attribution or share-alike terms
  • Ask whether any portion originates from a platform's user-generated content and on what sublicensing right
  • Require disclosure of personal data, special-category data, and any minors' data present in the corpus
  • Ask whether any upstream supplier can terminate the licensor's own rights, and on what notice
2. Scope of Grant
  • Grant expressly permits training, fine-tuning, evaluation and the creation of derived artefacts
  • Model weights, embeddings, checkpoints and adapters are named as permitted derivatives
  • Rights in models trained during the term survive expiry and termination of the data licence
  • Commercial use, sublicensing to customers, and distribution of the model are permitted as your product requires
  • No field-of-use or anti-competitive-use restriction that conflicts with the roadmap
  • Outputs are owned by the licensee with no royalty, attribution or reporting obligation
3. Removal and Change
  • Deletion is defined by layer: stored corpus, future training runs, and existing weights
  • Retraining obligations are tied to the next scheduled training cycle, not a fixed short deadline
  • Cost of removal-driven retraining is allocated to the party whose defect caused it
  • Licensor must notify promptly of any upstream takedown, consent withdrawal or licence loss
  • A documented process exists to trace an individual item to the model versions that consumed it
  • Your own data-subject deletion workflow is reconciled with the training pipeline, not bolted on later
4. Remedy and Governance
  • IP indemnity sits outside the general liability cap and covers data, models and outputs
  • Licensor owes a duty to defend with counsel engaged from the outset, not reimbursement after judgment
  • You hold consent rights over settlements imposing non-monetary obligations on you
  • Audit or verification rights over the licensor's clearance records, exercisable on reasonable notice
  • Counterparty financial substance assessed; escrow, holdback or insurance where the indemnity is nominal
  • Provenance register maintained per source with a removal-path column, from the first dataset onward

Frequently Asked Questions

Our dataset is licensed under an open licence. Isn't that the end of the analysis?

It is the beginning of it. An open licence is a licence granted by whoever applied it, which presumes that party held the rights — a presumption that fails routinely for aggregated corpora where an uploader applied a permissive licence to material they did not create. Then there are the licence terms themselves: attribution requirements that are difficult to satisfy at model scale, share-alike terms whose application to model weights is contested, and non-commercial restrictions that quietly exclude the use you are planning. Record the specific licence identifier per source rather than a general note that the corpus is 'open', because the obligations differ sharply between them and a compliance question later will be asked at that granularity.

The licensor will not remove the fee cap on the IP indemnity. What is the fallback?

Reprice the risk rather than accepting the paper. Options in rough order of preference: carve the IP indemnity out of the cap for third-party claims only while leaving the general cap intact; raise the cap to a multiple of fees with a floor that reflects defence cost; require the licensor to carry specific insurance naming you as an additional insured; hold back a portion of the fee against the survival period; or narrow your own use so the exposure is smaller — internal evaluation rather than a customer-facing model, for example. If none of those are available, the honest conclusion is that the dataset costs more than its price and the decision belongs with whoever owns the risk budget, not with the team that wants the data.

Do we need to disclose our training sources to customers?

Increasingly yes, and the pressure is arriving from procurement before it arrives from regulators. Enterprise security reviews now routinely ask whether models were trained on customer data, whether any training corpus contains personal data, and whether the vendor can attest to clearance. Separately, transparency obligations in several jurisdictions require summary disclosure of training data for certain model categories, and disclosure regimes for AI-generated content interact with it. The practical takeaway is that the provenance register is not just a defensive artefact — it is what lets sales answer a security questionnaire without escalating to counsel every time, which is a revenue argument for building it early.

What if we only fine-tune on a small dataset over someone else's base model?

You inherit two chains rather than avoiding one. Your fine-tuning corpus carries its own clearance question, and the base model carries whatever provenance issues its developer has. Read the base model licence for three things specifically: whether commercial use of fine-tuned derivatives is permitted, whether the developer indemnifies you for claims arising from the base model's training data, and whether there are use restrictions that flow down to your customers. Several widely used model licences include acceptable-use terms that you are contractually obliged to pass through, which means your own terms of service need matching language. Fine-tuning reduces your data volume; it does not reduce the number of contracts that govern your product.

How do we handle a takedown demand for content that is already in a deployed model?

Sequence it: acknowledge and preserve, then scope, then respond on the record. Acknowledge receipt and place a litigation hold before anything is deleted, because destroying the evidence of what was in the corpus is worse than the underlying claim. Scope by querying the provenance register for which model versions consumed the source and whether the specific items are identifiable. Then respond with what you can actually perform — removal from stored corpora and exclusion from future training is usually deliverable in days, while retraining is a scheduled activity — and say so plainly rather than promising a timeline you will miss. Simultaneously notify your licensor if the content came from a licensed corpus, because most contracts require prompt notice as a condition of the indemnity, and late notice is the most common way companies forfeit protection they actually paid for.

Start With the Removal Path

The fastest diagnostic on an existing stack is to pick one training source and try to answer three questions from records that already exist: what legal basis permits its use, which deployed model versions consumed it, and what would have to happen to take it out. Most teams can answer the first and stall on the second.

That gap is the whole exposure. A contract negotiated without it produces obligations you cannot perform, and an obligation you cannot perform is the one that turns a routine takedown into a product incident.