Buying guides
Data licenses for AI. Name the level before you pick the model.
- Every dataset that feeds an AI system should carry a named level, the way open-source code carries a named license.
- We propose six AI Data Levels, ADL-0 to ADL-5. Each says which model deployments may use a dataset under privacy, residency and sovereignty rules.
- A pipeline takes the level of its most sensitive input, and everything derived from it keeps that level until a documented step lowers it.
- Name the level before you pick the model. It shrinks the shortlist and tells counsel which agreements to start.
We think every dataset that feeds an AI system should carry a named level, the way open-source code carries a named license. The level decides the model shortlist, the contracts to sign and the evidence an auditor will ask for, so naming it first makes delivery and audits faster.
We propose six AI Data Levels, ADL-0 to ADL-5. Each says which model deployments may use a dataset under privacy, residency and sovereignty rules. A model deployment is a way of running a model, such as a vendor's API or your own servers.
Our companion post, What AI providers' data terms allow, checks provider terms against each level. This is a proposal for discussion.
Classification schemes answer the wrong question
Company schemes such as public, internal and confidential say who may read a file. None of the common ones says which AI deployment may process it, so every project argues the point again.
Dataset licenses are unreliable too. When the Data Provenance Initiative audited more than 1,800 text datasets used in AI in 2023, licenses on widely used hosting sites were missing over 70% of the time and wrong over 50% of the time.
Existing labels, and the question none of them answers
| SPDX | RAIL | TLP | AI Data Levels | |
|---|---|---|---|---|
| What it is | An open standard whose License List gives each license an identifier, such as Apache-2.0 | Responsible AI Licenses for AI code, data and models | FIRST's Traffic Light Protocol, with four sharing labels | Six levels, ADL-0 to ADL-5 |
| What it sets | Which licenses apply. License expressions join identifiers with AND, OR and WITH, and AND means a user must comply with every license named | Use restrictions that derivatives must carry | Sharing limits, which SPDX 3.0 reuses as a dataset's confidentiality level | Which model deployments may use the data |
| Says which deployment may process data under privacy law | no | no | no | yes |
SPDX
- What it is
- An open standard whose License List gives each license an identifier, such as Apache-2.0
- What it sets
- Which licenses apply. License expressions join identifiers with AND, OR and WITH, and AND means a user must comply with every license named
- Says which deployment may process data under privacy law
- no
RAIL
- What it is
- Responsible AI Licenses for AI code, data and models
- What it sets
- Use restrictions that derivatives must carry
- Says which deployment may process data under privacy law
- no
TLP
- What it is
- FIRST's Traffic Light Protocol, with four sharing labels
- What it sets
- Sharing limits, which SPDX 3.0 reuses as a dataset's confidentiality level
- Says which deployment may process data under privacy law
- no
AI Data Levels
- What it is
- Six levels, ADL-0 to ADL-5
- What it sets
- Which model deployments may use the data
- Says which deployment may process data under privacy law
- yes
TLP itself says it "was not designed to handle licensing terms, nor information handling or encryption rules." AI Data Levels borrow SPDX's identifiers and RAIL's derivative rule and apply them to handling rules.
Six levels, and the rules at each
We keep three decisions apart. The level sets the deployment boundary, the data's laws set the paperwork, and the use sets the human review. A DPA is the data processing agreement GDPR requires with each vendor that handles personal data for you, and a DPIA is a data protection impact assessment. A BAA is the business associate agreement HIPAA requires, and PHI is protected health information.
A higher number means tighter rules
ADL-0Public
Public, licensed for the use, no personal data.
Any, including consumer apps.
ADL-1Internal
Business-confidential data with no personal data.
Business terms with no training on your content.
ADL-2Personal
Ordinary personal data.
Business terms under a DPA.
ADL-3Sensitive
Special categories, criminal records, children's data, account and ID numbers.
Zero-retention endpoints with in-region processing, your own cloud account, or self-hosted.
ADL-4Regulated
Data a sector law ties to a signed agreement, such as PHI.
Features covered by a signed BAA, or self-hosted.
ADL-5Sovereign
Data that must stay under one jurisdiction's control.
Self-hosted or a sovereign cloud inside the jurisdiction.
The other rules at each level
| ADL-0 Public | ADL-1 Internal | ADL-2 Personal | ADL-3 Sensitive | ADL-4 Regulated | ADL-5 Sovereign | |
|---|---|---|---|---|---|---|
| Logging and retention | As the source license allows | Provider's standard abuse-monitoring retention | Your retention schedule, with deletion on request | No provider retention beyond listed safety exceptions; your logs redacted and short-lived | As ADL-3, plus audit logs of access to PHI; HIPAA records kept six years | Logs and keys stay in the jurisdiction |
| Training use | Allowed if the source license allows | No provider training; your fine-tunes stay ADL-1 | No provider training; your own only for a compatible purpose | Only on de-identified copies, labelled again | Only as the BAA permits, or on de-identified copies | Only inside the boundary |
| Human review | Not required | Not required | A route to a person for decisions with legal or similar effects | A person checks every output used about a person | A qualified person signs off outputs that reach a record or a patient | Reviewers based in the jurisdiction |
| Paperwork | Source and license record | No-training terms; the vendor's SOC 2 report or ISO 27001 certificate | DPA, record of processing, transfer mechanism, DPIA if high risk | DPIA, written zero-retention terms, documented legal condition for special data | BAA with every vendor in the path, risk analysis, minimum-necessary policy | Sovereignty assessment, plus the paperwork the data's laws require |
| Residency and sovereignty | None | None unless a contract sets one | May leave under a lawful transfer mechanism | Stored and processed in the labelled region; no global endpoints | As ADL-3 | Data, processing, keys, logs and admin access in the jurisdiction |
ADL-0 Public
- Logging and retention
- As the source license allows
- Training use
- Allowed if the source license allows
- Human review
- Not required
- Paperwork
- Source and license record
- Residency and sovereignty
- None
ADL-1 Internal
- Logging and retention
- Provider's standard abuse-monitoring retention
- Training use
- No provider training; your fine-tunes stay ADL-1
- Human review
- Not required
- Paperwork
- No-training terms; the vendor's SOC 2 report or ISO 27001 certificate
- Residency and sovereignty
- None unless a contract sets one
ADL-2 Personal
- Logging and retention
- Your retention schedule, with deletion on request
- Training use
- No provider training; your own only for a compatible purpose
- Human review
- A route to a person for decisions with legal or similar effects
- Paperwork
- DPA, record of processing, transfer mechanism, DPIA if high risk
- Residency and sovereignty
- May leave under a lawful transfer mechanism
ADL-3 Sensitive
- Logging and retention
- No provider retention beyond listed safety exceptions; your logs redacted and short-lived
- Training use
- Only on de-identified copies, labelled again
- Human review
- A person checks every output used about a person
- Paperwork
- DPIA, written zero-retention terms, documented legal condition for special data
- Residency and sovereignty
- Stored and processed in the labelled region; no global endpoints
ADL-4 Regulated
- Logging and retention
- As ADL-3, plus audit logs of access to PHI; HIPAA records kept six years
- Training use
- Only as the BAA permits, or on de-identified copies
- Human review
- A qualified person signs off outputs that reach a record or a patient
- Paperwork
- BAA with every vendor in the path, risk analysis, minimum-necessary policy
- Residency and sovereignty
- As ADL-3
ADL-5 Sovereign
- Logging and retention
- Logs and keys stay in the jurisdiction
- Training use
- Only inside the boundary
- Human review
- Reviewers based in the jurisdiction
- Paperwork
- Sovereignty assessment, plus the paperwork the data's laws require
- Residency and sovereignty
- Data, processing, keys, logs and admin access in the jurisdiction
From ADL-2 up, the identifier ends with the data's home jurisdiction as a country code or EU, so ADL-3-EU is sensitive data governed from the EU.
Each level rests on a legal test
We set each level by what the law says, not by how sensitive data feels.
- Public data that names people is not ADL-0. India's DPDP Act excludes personal data that people made public themselves. GDPR has no such exclusion in Article 2, and the European Data Protection Board, or EDPB, treats public availability as one factor. A scrape of public profiles of people in the EU starts at ADL-2.
- ADL-3 requires a DPIA for every use, stricter on purpose than GDPR, which requires one for large-scale processing of its Article 9 special categories, such as health data.
- ADL-4 is defined by an agreement. Under HIPAA, a vendor that creates, receives, maintains or transmits PHI for a covered entity, such as a health plan or health care provider, is a business associate, and so are its subcontractors. Each one needs a BAA.
- ADL-5 turns on sovereignty, meaning whose law can compel access to data, not residency, meaning where it is stored and processed. The US CLOUD Act covers data in a provider's "possession, custody, or control, regardless of whether" it is stored in the United States or abroad. India's DPDP Rules let the government require local storage of certain data held by significant data fiduciaries, the data handlers the government designates.
How to label a dataset and a pipeline
A label is a small file next to the data or a catalog field, as in this synthetic example.
spec: ADL 0.1
level: ADL-3-EU
dataset: claims-notes
regimes: [GDPR]
contains: [personal, health]
source_licenses: []
lowered_from: none
owner: privacy-lead@example.com
next_review: 2027-04-01
Four rules set a pipeline's level. The second is our firmest position. Derived data is as sensitive as its source until a documented step says otherwise.
Four rules that set a pipeline's level
The highest input wins
As in an SPDX AND expression. Inputs include prompts, retrieved documents, tool results and agent memory.
Derivatives keep the level
Outputs, logs, caches, embeddings, search indexes and fine-tuned weights inherit it. Embeddings are the lists of numbers a model uses to compare texts, and Morris and colleagues recovered 92% of 32-token texts exactly from them. The EDPB's Opinion 28/2024 treats a model trained on personal data as anonymous only if identifying those people or extracting their data is very unlikely.
Only a documented step lowers a level
Such as HIPAA de-identification or true anonymization. Pseudonymized data, with names swapped for tokens and the key kept elsewhere, is still personal data under GDPR Recital 26.
Every endpoint carries a clearance
A model gateway, a proxy between applications and models, blocks calls that carry data above it. The open-source LiteLLM gateway routes requests by tags set on keys or teams.
A pipeline label looks like this.
spec: ADL 0.1
pipeline: claim-triage
inputs:
claims-notes: ADL-3-EU
policy-wording: ADL-0
level: ADL-3-EU
endpoints:
summarize: {clearance: ADL-3-EU, kind: own-cloud, region: eu}
outputs: ADL-3-EU
use: decision support with human sign-off
Two worked examples
The level comes from the data, and the use can add rules on top. Both scenarios are synthetic.
A software company drafts release notes from pull requests. Every Git commit records its author's name and email address, so the raw feed is ADL-2. With author fields and quoted customer reports removed, it drops to ADL-1, and a business API on standard terms is enough.
A lender in the EU pre-screens loan applications. Account data makes the label ADL-3-EU. The EU AI Act treats credit scoring as high-risk, so the system must allow effective human oversight. The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the start of these rules to 2 December 2027.
What the levels do not do
The levels are not legal advice. A label records decisions that accountable people make, and does not replace counsel, a DPIA or a HIPAA risk analysis, or decide whether a use is lawful.
Nor does a vendor's audit report. A SOC 2 report is a CPA firm's examination of a service organization's controls, and a type 2 report adds an opinion on whether they operated effectively over a stated period. The report belongs in the vendor file from ADL-1 up, as does an ISO/IEC 27001 certificate. Neither is permission for a use.
The levels do not settle copyright, so check source licenses with tools such as the Data Provenance Explorer. They do not cover every law, such as US state privacy laws, payment card rules or export controls. Vendor terms change, so every label carries a review date.
Name the level before you pick the model
Choosing a model on quality, then checking the data, gets the order wrong. A level named first shrinks the shortlist, because ADL-3-EU data rules out consumer apps and global endpoints, which may process a request in any region.
Counsel starts the agreements while engineers build against cleared endpoints. Auditors can see what data went to which model, where and under which agreement.
The levels also match the data handling our site describes. Client data stays in client accounts wherever possible, AI systems get minimum access, every action is logged, and personal data is masked before models see it.
Start with one test. Label every input of your busiest AI pipeline, take the highest as its level, and compare that with each endpoint's clearance. Any endpoint cleared below it is the first fix.
The levels are free to copy and change. For a second reviewer on your first labels, talk to us.
Sources
Companion post
- extendfuture, What AI providers' data terms allow, which maps consumer apps, business APIs, zero data retention, region-pinned endpoints, BAAs, self-hosted open-weight models and sovereign clouds to these levels.
Prior art and labels
- Shayne Longpre and co-authors, The Data Provenance Initiative: A Large Scale Audit of Dataset Licensing and Attribution in AI, arXiv, October 2023; the Data Provenance Initiative site, home of the Data Provenance Explorer, and its GitHub collection.
- Misha Benjamin and co-authors, Towards Standardization of Data Licenses: The Montreal Data License, arXiv, March 2019. The authors, including Yoshua Bengio, named the AI uses of a dataset, such as research, internal use and model commercialization.
- Responsible AI Licenses, RAIL, which add use restrictions to AI code, data and models and require derivatives to carry them; Carlos Muñoz Ferrandis, OpenRAIL: Towards open and responsible AI licensing frameworks, Hugging Face, August 2022, on the open variant Hugging Face supports.
- Creative Commons, CC licenses, six licenses built from four elements: attribution, share-alike, non-commercial and no derivatives. Creative Commons notes that in many jurisdictions many forms of AI use fall outside copyright, which is why it is building CC Signals.
- Open Data Commons, Licenses, three database licenses called ODbL, ODC-By and PDDL.
- SPDX, License List, version 3.29.0, September 2026; license-list-data on GitHub; SPDX 3.0.1 license expressions, DatasetPackage and ConfidentialityLevelType. Teams that publish SPDX 3.0 documents can add an ADL identifier as an annotation beside the Dataset profile's confidentialityLevel and hasSensitivePersonalInformation fields.
- FIRST, Traffic Light Protocol 2.0, with four labels: TLP:RED, TLP:AMBER, TLP:GREEN and TLP:CLEAR.
- US National Archives, About Controlled Unclassified Information and Limited Dissemination Controls. US agencies mark Controlled Unclassified Information by category and add dissemination controls such as NOFORN, which means no foreign dissemination.
- ISO, ISO/IEC 27001:2022. Certification shows that a company runs a system to manage security risks for the data it holds.
- Git, First-Time Git Setup, which shows that each commit records its author's name and email address.
Law and regulators
- EU, General Data Protection Regulation, Articles 2, 6, 9, 22, 28 and 35, Chapter V and Recital 26. Article 6 requires one of six lawful bases, and Article 28 requires a contract, the DPA, with every vendor that processes personal data for you. Article 35 requires a DPIA before processing that is likely to be high risk, including automated evaluation that leads to decisions with legal effects. Under Article 22, people have the right not to be subject to solely automated decisions with legal or similarly significant effects, and where a contract or explicit consent allows such a decision, the person can still obtain human intervention. Data leaving the European Economic Area needs a Chapter V transfer mechanism.
- European Commission, Adequacy decisions, which for the United States cover only companies in the EU-US Data Privacy Framework, and Standard contractual clauses, which the Commission last updated on 4 June 2021.
- European Data Protection Board, Opinion 28/2024 on AI models and its press release, 18 December 2024.
- EU, AI Act, Regulation (EU) 2024/1689, Articles 14 and 27 and Annex III. Annex III lists credit scoring and risk pricing for life and health insurance as high-risk uses, and deployers of those systems must also run a fundamental rights impact assessment. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended Article 27 so that the assessment can cross-reference the DPIA. European Commission, AI Omnibus enters into force, 27 July 2026; AI Act Service Desk, Timeline for the implementation of the EU AI Act.
- US eCFR, 45 CFR 160.103, which defines PHI as individually identifiable health information in any form; 164.308, risk analysis; 164.312, audit controls; 164.316, six years of retention for required documents; 164.502, business associate agreements and reasonable efforts to use only the minimum necessary PHI; and 164.514, de-identification.
- AICPA and CIMA, SOC 2 reporting guide, on examinations of controls relevant to security, availability, processing integrity, confidentiality or privacy; Journal of Accountancy, Explaining the 3 faces of SOC, June 2016. SOC 2 is not a law.
- Government of India, Digital Personal Data Protection Act, 2023, Sections 3, 9, 10 and 16. The Act requires verifiable parental consent for children's data, and under Section 16 the government may restrict transfers to countries it names by notification. Press Information Bureau, Government notifies DPDP Rules, 14 November 2025, and the DPDP Rules, 2025 backgrounder. Significant data fiduciaries are designated on factors such as data volume and sensitivity.
- US Department of Justice, CLOUD Act Resources, on the Act of March 2018; Cornell Legal Information Institute, 18 U.S.C. 2713. A provider subject to US law must meet its US obligations to preserve or disclose such data.
Research and tools
- Nicholas Carlini and co-authors, Extracting Training Data from Large Language Models, arXiv, December 2020, revised June 2021. The authors extracted training examples from a language model by querying it.
- John X. Morris and co-authors, Text Embeddings Reveal (Almost) As Much As Text, arXiv, October 2023.
- LiteLLM and LiteLLM's tag-based routing documentation.