RatedWithAI

RatedWithAI

Accessibility scanner

AI Legal & ComplianceAugust 12, 2026

A Data Licence Doesn't Remove Copyright Risk. It Decides Who Absorbs It.

Every company fine-tuning on outside data eventually signs a training data licence and treats the signature as the end of the copyright question. It isn't. The licence relocates the risk into three clauses most buyers never negotiate — chain of title, survival, and the indemnity cap — and a weak version of any one of them leaves you exactly where you started, minus the fee.

Chain of title
The licensor can only grant what it holds — aggregators frequently hold less than they sell
Survival
Rights to models trained during the term must expressly outlive the licence
12× fees
The typical indemnity cap — measured against a claim that costs multiples of it to defend

Start With the Question the Licensor Hopes You Skip

Where did this data come from, and what evidence exists that the licensor can grant rights in it? A first-party licensor — a publisher licensing its own archive, a forum licensing posts under terms of service that assigned the necessary rights — can answer that in a sentence. An aggregator that assembled a corpus from many sources usually cannot, and its licence language will quietly reflect that: rights granted "to the extent held by licensor," warranties limited to "licensor's own contributions," or no warranty of non-infringement at all.

That is not necessarily a deal-breaker. It is a pricing and structuring signal. A corpus with unclear provenance should cost less, carry a tighter use restriction, and never be the sole basis on which you tell a customer your model is "trained on licensed data."

The Clauses That Actually Decide Your Exposure

Grant scope — training is a named use

A licence to 'access, reproduce, and use' content does not obviously include training a model, and licensors have argued exactly that. The grant must name training, fine-tuning, evaluation, and retrieval-augmented use explicitly. Also name internal research versus commercial deployment, because a research-only grant is common and easy to miss.

Derivative model rights

State that model weights, checkpoints, distilled and quantized variants, embeddings, and synthetic data generated from the corpus are yours, free of licensor claims. Embeddings and synthetic data are the two categories licensors most often try to reserve, and the two your engineering team will produce first.

Survival of model rights on termination

Deletion obligations should reach the licensed materials, not the models. Write it explicitly: rights to use, distribute, and commercialize any model trained during the term survive expiry or termination perpetually and irrevocably. Without this, a renewal negotiation becomes a hostage negotiation.

Warranty of non-infringement

Distinguish a warranty that the licensor owns or controls the rights from a warranty that use of the data will not infringe third-party rights. The second is much stronger and much rarer. If you only get the first, understand that upstream contributor infringement lands on you.

Indemnity — cap, defence costs, and control

Three sub-questions: is the cap tied to fees paid or set at a real number; do defence costs sit inside or outside the cap; and who controls the defence and settlement. An indemnity where the licensor controls settlement and the cap includes defence costs can be exhausted before your case is heard.

Audit and takedown obligations

Licensors increasingly reserve the right to require removal of specific records — an opt-out honoured after the fact, a rights dispute resolved upstream. Bound this: require notice, a reasonable removal window, and an express statement that removal does not require retraining models already deployed.

Disclosure carve-out

Confidentiality provisions covering dataset composition can collide with training data transparency requirements. Carve out disclosures required by law or regulation before signing, rather than seeking consent when the deadline arrives.

Personal information handling

If the corpus contains personal information, the licence is also a data agreement. Confirm the licensor's lawful basis, whether consumer deletion requests flow through to you, and who bears the cost of responding. A copyright-clean dataset can still be a privacy liability.

Reading the Licensor Type

How much protection a licence can realistically offer depends far more on who is granting it than on how the clauses are drafted. The same warranty language means different things from different counterparties.

First-party rights holder (publisher, archive, media company)

Protection: Strongest

Clear chain of title, real balance sheet, and a reputational interest in the licence holding up. Expect higher prices and narrower use grants — negotiate scope, not provenance.

Platform licensing user-generated content

Protection: Mixed

Depends entirely on whether their terms of service actually granted sublicensable rights in user content, and whether those terms applied retroactively to older posts. Ask to see the relevant ToS versions and effective dates.

Specialist data vendor with contributor agreements

Protection: Workable

Verifiable if they will show a representative contributor agreement and describe their intake controls. The risk concentrates in whether contributors held what they assigned.

Aggregator or scraper reselling a compiled corpus

Protection: Weakest

Often no meaningful chain of title, thin capitalization, and warranties limited to their own compilation rather than the underlying works. Price accordingly and never rely on it as your sole provenance story.

Diligence That Takes an Afternoon

You do not need a forensic audit to avoid the worst outcomes. Four questions, answered in writing before signature, separate a licence worth having from a receipt.

Name the sources.

A licensor who will not enumerate source categories in the agreement itself — not in a sales deck — is telling you the composition will not survive scrutiny.

Show a sample of the rights documentation.

One representative contributor agreement, or the terms of service version that granted sublicensable rights, with its effective date.

What happens if a source is later challenged?

You want a defined process — notice, removal window, no retraining obligation for deployed models — not silence that becomes a dispute.

Who signs, and what do they have?

An indemnity from a thinly capitalized subsidiary is a document, not a protection. Ask for a parent guarantee where the numbers matter.

Action Checklist: Before You Sign a Training Data Licence

Confirm the grant expressly names training, fine-tuning, evaluation, and retrieval use
Confirm the grant covers commercial deployment, not research use only
Get derivative model rights in writing, listing weights, checkpoints, embeddings, and synthetic data
Add a perpetual survival clause for models trained during the term
Push for a non-infringement warranty, not just a warranty of licensor ownership
Check whether defence costs sit inside the indemnity cap, and who controls settlement
Bound any takedown right with notice, a removal window, and no retraining obligation
Carve out disclosures required by training data transparency laws from confidentiality
Treat any personal information in the corpus as a separate privacy review, not a copyright question
Record dataset name, licensor, term, scope, and survival terms in a dataset registry your engineers can read

Frequently Asked Questions

We licensed a dataset. Can we tell customers our model is trained on licensed data?

Only if it is true of the whole training set. Most models are trained on a base corpus the developer did not license and then fine-tuned on licensed data. Saying 'trained on licensed data' when you mean 'fine-tuned on licensed data over an open-weight base' is the kind of claim that gets characterised as deceptive marketing. Describe the layer accurately — 'fine-tuned on licensed X' is both defensible and specific enough to be persuasive.

The licensor wants a share of revenue from models trained on their data. Is that normal?

It is increasingly common and it is negotiable in structure if not in principle. The thing to resist is not the economics but the entanglement: a revenue share creates an ongoing licensor interest in your model, audit rights over your business, and a counterparty with leverage at every renewal. A higher fixed fee with clean derivative rights is usually worth paying for.

Does a licence protect us if the model reproduces licensed content verbatim in outputs?

Not automatically. Most training licences grant rights for the training process and are silent on outputs, and some expressly disclaim any grant covering generated content that substantially reproduces licensed works. Memorization and regurgitation are an output-side problem you manage technically — filtering, dedup of the training corpus, output similarity checks — not a risk the training licence absorbs on your behalf.

We only fine-tune on a few thousand customer documents. Do we need any of this?

If the documents are your customers' and your terms permit the use, this is a customer-contract question rather than a data licensing one — check that your terms actually authorize training, since many SaaS terms authorize service provision only. The licensing analysis here starts the moment you introduce third-party content you did not create and your customers did not give you.

Is public domain or openly licensed data a safe alternative?

Safer on copyright, not free of obligations. Open licences carry conditions — attribution, share-alike terms that some argue reach model outputs, non-commercial restrictions — and public domain status is jurisdiction-specific and frequently misattributed in aggregated collections. The diligence is different, not absent: verify the licence per source rather than trusting a collection-level label.

The Core Rule to Internalize

The value of a training data licence is the difference between what the licensor warranted and what it can actually pay. A strong warranty from an aggregator with no assets and a fee-capped indemnity is worth roughly the fee. A narrower warranty from a first-party rights holder with a real balance sheet is worth far more.

Negotiate three things before anything else: the grant must name training and commercial deployment, the model rights must survive termination in perpetuity, and the indemnity must exclude defence costs from its cap. Everything else in the agreement is a preference. Those three are the licence.