{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-011.json",
  "source": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-DATA-011",
    "profile": "data-admission-and-privacy",
    "url": "https://aigovernanceengineer.com/controls/data-admission-and-privacy#aige-ctl-data-011",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-data-011.json",
    "title": "Rights Changes Propagated to Affected Models",
    "version": "0.1",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "derived",
    "objective": "A licence expiry or withdrawal, a new rights reservation, a consent withdrawal, an erasure request or an order marks the affected ledger rows and snapshots, forward lineage lists the affected models, and the remediation (retrain without the source, retire the model, or a documented decision to rely on another basis) is recorded against the same rows with a date and an approver.",
    "failureModes": [
      "An erasure request closes on time at the source system but the training snapshot, retrieval index, logs and models trained on the data are never reached.",
      "A consent withdrawal cannot be traced to the runs and model versions that inherited the consent.",
      "Remedies reach the model itself (an order to delete models developed using unlawfully used data) and, without per-source lineage, the only safe response is to delete everything.",
      "A change in rights does not reopen admission, and the next retrain reads the source again."
    ],
    "scope": "Changes in the right to use a training source or a person's data after admission, and the datasets, indexes and model versions they reach. The per-location response to a data-subject request is the Rights Requests Against Models pattern; this control covers the propagation from the data to the models.",
    "enforcementPoints": [
      "periodic"
    ],
    "verification": [
      {
        "kind": "test",
        "text": "Run a mock erasure request through the corpus, the snapshots, the retrieval index, the logs and the weights, write the fulfilment record, and time it against the one-month deadline."
      }
    ],
    "evidence": [
      {
        "artefact": "Re-admission record for the affected dataset versions",
        "schemaId": "dataset-admission-record",
        "schema": "https://aigovernanceengineer.com/schemas/dataset-admission-record.v1.json",
        "layer": 1
      },
      {
        "artefact": "Remediation recorded against the affected ledger rows, with the models forward lineage listed, a date and an approver",
        "schemaId": null,
        "schema": null,
        "layer": 2
      },
      {
        "artefact": "Fulfilment record: every location, the action in each, the model versions affected and when the gap closes",
        "schemaId": null,
        "schema": null,
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "The change marks the affected rows and reopens admission; the owners of every affected model are told, and each model is retrained without the source, retired or kept on a documented decision to rely on another basis."
    },
    "layer": 2,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "training-data-rights-ledger",
        "title": "Training-Data Rights Ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "slug": "dataset-admission-gate",
        "title": "Dataset Admission Gate",
        "url": "https://aigovernanceengineer.com/patterns/dataset-admission-gate"
      },
      {
        "slug": "rights-requests-against-models",
        "title": "Rights Requests Against Models",
        "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
      }
    ],
    "seeds": [],
    "derivedFrom": [
      {
        "kind": "pattern",
        "ref": "training-data-rights-ledger",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger"
      },
      {
        "kind": "pattern",
        "ref": "rights-requests-against-models",
        "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models"
      },
      {
        "kind": "schema",
        "ref": "dataset-admission-record",
        "url": "https://aigovernanceengineer.com/resources/templates#schema-dataset-admission-record"
      },
      {
        "kind": "chapter",
        "ref": "privacy-and-ai",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai"
      }
    ],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-GDPR-ART15-17-21",
          "name": "GDPR Arts. 15–17 and 21 data subject rights against trained models",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art15-17-21"
        },
        {
          "id": "AIGE-OBL-GDPR-ART7",
          "name": "GDPR Art. 7 conditions for consent and its withdrawal",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-gdpr-art7"
        },
        {
          "id": "AIGE-OBL-DSM-ART4-3",
          "name": "DSM Directive Art. 4(3) text-and-data-mining reservations",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-dsm-art4-3"
        }
      ],
      "iso42001": [],
      "nistAiRmf": [],
      "owasp": [],
      "atlas": [],
      "aiuc1": [],
      "csaAicm": [],
      "other": []
    },
    "references": [
      {
        "n": 11,
        "title": "Training-Data Rights Ledger",
        "text": "Training-Data Rights Ledger (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): one ledger row per training source, joined to lineage so each model knows its sources). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/training-data-rights-ledger",
        "verified": "primary"
      },
      {
        "n": 32,
        "title": "Privacy and data protection law applied to AI",
        "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"Where a request has to reach\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#where-a-request-has-to-reach",
        "verified": "primary"
      },
      {
        "n": 33,
        "title": "Privacy and data protection law applied to AI",
        "text": "Privacy and data protection law applied to AI (AI Governance Engineering Body of Knowledge v0.5.0, chapter 19, section \"The limits of consent\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/privacy-and-ai#the-limits-of-consent",
        "verified": "primary"
      },
      {
        "n": 34,
        "title": "Rights Requests Against Models",
        "text": "Rights Requests Against Models (AI Governance Engineering Body of Knowledge v0.5.0, pattern catalogue (chapter 05): each data-subject request routed to every place the data sits and closed with a fulfilment record). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/patterns/rights-requests-against-models",
        "verified": "primary"
      },
      {
        "n": 28,
        "title": "Governing AI development",
        "text": "Governing AI development (AI Governance Engineering Body of Knowledge v0.5.0, chapter 14, section \"Provenance versus lineage\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-development#provenance-versus-lineage",
        "verified": "primary"
      },
      {
        "n": 18,
        "title": "Regulation (EU) 2016/679 (GDPR)",
        "text": "Regulation (EU) 2016/679 (GDPR) (Art. 5 principles, incl. 5(1)(b) purpose limitation and 5(1)(c) minimisation; Art. 6 lawful basis and 6(4) compatibility; Art. 7 consent; Art. 9 special categories; Arts. 15 to 17 and 21 rights; Art. 25 data protection by design and by default; Art. 30 records of processing; Arts. 35 and 36 DPIA and prior consultation). Publications Office of the EU (EUR-Lex). 2016-04-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
        "verified": "primary"
      },
      {
        "n": 15,
        "title": "In the Matter of Everalbum, Inc., Decision and Order",
        "text": "In the Matter of Everalbum, Inc., Decision and Order (\"Affected Work Product\": models or algorithms developed using users' biometric information, to be deleted within 90 days with a sworn statement). Federal Trade Commission. 2021-05-07.",
        "url": "https://www.ftc.gov/system/files/documents/cases/1923172_-_everalbum_decision_final.pdf",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Keep a consent-purpose log joining each consent to the datasets and model versions that inherited it; without that join a withdrawal cannot be traced to the runs it affects.",
      "For data inside the weights, choose on the ladder chapter 19 sets out (output suppression, retraining without the data, machine unlearning) and record the choice and its reason per request, with the date the next retrain closes the gap."
    ],
    "openQuestions": [
      "How long may a model stay in production on output suppression before retraining without the data is due, and who decides?"
    ],
    "observation": null,
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": []
  }
}
