{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-003.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-003",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-003",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-003.json",
    "title": "Training-Data Rights Ledger Row per Source",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "Every training source has a ledger row, per source and not per merged dataset, that records its acquisition channel, licensor, licence terms for training, commercial use and distribution of derived models, the legal basis where the data is personal, the permitted uses and, for crawled content, the rights-reservation check with its method, result and date.",
    "failureModes": [
      "Nobody can say which sources trained which model version, or on what terms.",
      "A single unlicensed or unlawfully obtained source contaminates every model trained on it, and without per-source lineage the only safe response is to delete everything.",
      "Crawled content is used although the rightholder reserved its rights by machine-readable means, because the reservation check was not run, was not recorded or is stale."
    ],
    "scope": "Every source a provider trains or fine-tunes on: internal data, licensed corpora, open datasets, crawled web content and user data. The ledger records the organisation's position; it does not settle open legal questions.",
    "enforcementPoints": [
      "deploy"
    ],
    "verification": [
      {
        "kind": "test",
        "text": "The corpus build and the dataset admission gate fail on a source with no ledger row, on a source whose terms do not permit the declared use and on a source whose reservation check is missing or stale."
      }
    ],
    "evidence": [
      {
        "artefact": "Ledger row per source and version, with the reservation-check method, result and date for crawled content",
        "schemaId": null,
        "schema": null,
        "layer": 2
      },
      {
        "artefact": "Licence on the dataset card: name, whether training is allowed, whether text-and-data-mining reservations were checked",
        "schemaId": "dataset-card",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-card.v1.json",
        "layer": 2
      },
      {
        "artefact": "Ledger check (rows present) on the admission record",
        "schemaId": "dataset-admission-record",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
        "layer": 1
      }
    ],
    "failureResponse": {
      "effect": "deny",
      "text": "A source with no row, with terms that do not permit the declared use or with a missing or stale reservation check fails the corpus build and admission."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "training-data-rights-ledger",
        "title": "Training-Data Rights Ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "slug": "aibom",
        "title": "AIBOM",
        "url": "https://aigovernanceengineer.com/patterns/aibom"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "training-data-rights-ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "kind": "schema",
        "ref": "dataset-card",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-card"
      },
      {
        "kind": "chapter",
        "ref": "governing-development",
        "url": "https://aigovernanceengineer.com/bok/governing-development"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART10",
          "name": "EU AI Act Art. 10 data and data governance",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art10"
        },
        {
          "id": "AIGE-OBL-EUAIA-ART53-1C",
          "name": "EU AI Act Art. 53(1)(c) copyright policy honouring text-and-data-mining reservations",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art53-1c"
        },
        {
          "id": "AIGE-OBL-DSM-ART4-3",
          "name": "DSM Directive Art. 4(3) text-and-data-mining reservations",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3"
        },
        {
          "id": "AIGE-OBL-GDPR-ART5-1B",
          "name": "GDPR Art. 5(1)(b) and 6(4) purpose limitation",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art5-1b"
        }
      ],
      "iso42001": [
        {
          "id": "A.7.5",
          "title": "Data provenance"
        }
      ],
      "nistAiRmf": [
        {
          "id": "GOVERN 6.1",
          "title": "Policies and procedures are in place that address AI risks associated with third-party entities, including risks of infringement of a third-party’s intellectual property or other rights."
        },
        {
          "id": "MAP 4.1",
          "title": "Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights."
        }
      ],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 11,
        "title": "Training-Data Rights Ledger",
        "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
        "verified": "primary"
      },
      {
        "n": 12,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"The right to use the data\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#the-right-to-use-the-data",
        "verified": "primary"
      },
      {
        "n": 13,
        "title": "Directive (EU) 2019/790 on copyright in the Digital Single Market, Art. 4",
        "text": "Directive (EU) 2019/790 on copyright in the Digital Single Market, Art. 4 (text and data mining exception; 4(3) reservation of rights by machine-readable means for content made publicly available online). Publications Office of the EU (EUR-Lex). 2019-05-17.",
        "url": "https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng",
        "verified": "primary"
      },
      {
        "n": 14,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 53",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 53 (GPAI provider obligations: (c) copyright policy including reservations of rights; (d) public summary of training content on the AI Office template). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_53",
        "verified": "primary"
      },
      {
        "n": 4,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27, Art. 10 (data and data governance: 10(2) practices, including origin, preparation, bias examination and mitigation, and data gaps; 10(3) relevant, sufficiently representative, free of errors and complete; 10(4) specific setting of use). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng#art_10",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "In the Matter of Everalbum, Inc., Decision and Order",
        "text": "In the Matter of Everalbum, Inc., Decision and Order (\"Affected Work Product\": models or algorithms developed using users' biometric information, to be deleted within 90 days with a sworn statement). Federal Trade Commission. 2021-05-07.",
        "url": "https://www.ftc.gov/system/files/documents/cases/1923172_-_everalbum_decision_final.pdf",
        "verified": "primary"
      },
      {
        "n": 7,
        "title": "ISO/IEC 42001:2023, AI management systems, Annex A",
        "text": "ISO/IEC 42001:2023, AI management systems, Annex A (reference control objectives and controls A.2 to A.10, cited by id and short title). ISO/IEC. 2023.",
        "url": "https://www.iso.org/standard/81230.html",
        "verified": "secondary"
      },
      {
        "n": 8,
        "title": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1",
        "text": "Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1 (GOVERN 6.1 third-party risks incl. infringement of intellectual property or other rights; MAP 1.1 intended purposes documented; MAP 2.3 data collection and selection considerations identified and documented; MAP 3.3 targeted application scope; MAP 4.1 legal risks of components incl. third-party data; MEASURE 2.10 privacy risk examined and documented; MANAGE 1.4 negative residual risks to downstream acquirers and end users documented). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "For crawled content, record the crawler identity, the window and the reservation check: the method (for example robots.txt and page metadata read at fetch time), the result and the date. The crawl pipeline should write rows itself, since a row per source is real work for large crawls.",
      "Put the licence in the AIBOM as well, so a licence change surfaces in the next build.",
      "Generate the disclosures (the GPAI training-content summary under Art. 53(1)(d) and similar training-data documentation) as queries over the ledger, not as documents written from memory."
    ],
    "openQuestions": [
      "How fresh must a reservation check be before the gate treats it as stale, and should it be re-run at every corpus build?",
      "At what granularity should rows be kept when rights attach per record (opt-outs, per-record licences) rather than per source?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
