Definition
Ownership of data used to train the Gen AI model and data created by the Gen AI model is unclear, leading to additional legal, commercial and privacy risks.
Controls & guardrails that address this
2Grouped by control function, with the AI lifecycle stage(s) to apply each and the other risks it addresses. Filter by control category below.
Preventive ยท 2
Preliminary legal review of data ownership
Conduct a preliminary legal review of planned training data sources to establish ownership status at design stage.
Lifecycle stage1 โ Use Case Context & Design
Definitive data ownership review and licensing
Conduct a definitive legal review of data ownership for all training datasets before use. Obtain licences where required.
Lifecycle stage2 โ Data Acquisition & Processing
Other risks in Legal & Regulatory
#16 Inability to ensure location compliance for model hosting and data processing#18 Unauthorised data transfer and storage#19 Breach or misalignment with regulatory or organisational standards#20 IP infringement#21 Unavailability of IP protection#22 Inadequate privacy protection#23 Unclear data retention and deletion