Buying guides

Data licenses for AI. Name the level before you pick the model.

  • Every dataset that feeds an AI system should carry a named level, the way open-source code carries a named license.
  • We propose six AI Data Levels, ADL-0 to ADL-5. Each says which model deployments may use a dataset under privacy, residency and sovereignty rules.
  • A pipeline takes the level of its most sensitive input, and everything derived from it keeps that level until a documented step lowers it.
  • Name the level before you pick the model. It shrinks the shortlist and tells counsel which agreements to start.

We think every dataset that feeds an AI system should carry a named level, the way open-source code carries a named license. The level decides the model shortlist, the contracts to sign and the evidence an auditor will ask for, so naming it first makes delivery and audits faster.

We propose six AI Data Levels, ADL-0 to ADL-5. Each says which model deployments may use a dataset under privacy, residency and sovereignty rules. A model deployment is a way of running a model, such as a vendor's API or your own servers.

Our companion post, What AI providers' data terms allow, checks provider terms against each level. This is a proposal for discussion.

Classification schemes answer the wrong question

Company schemes such as public, internal and confidential say who may read a file. None of the common ones says which AI deployment may process it, so every project argues the point again.

Dataset licenses are unreliable too. When the Data Provenance Initiative audited more than 1,800 text datasets used in AI in 2023, licenses on widely used hosting sites were missing over 70% of the time and wrong over 50% of the time.

Existing labels, and the question none of them answers

SPDXRAILTLPAI Data Levels
What it isAn open standard whose License List gives each license an identifier, such as Apache-2.0Responsible AI Licenses for AI code, data and modelsFIRST's Traffic Light Protocol, with four sharing labelsSix levels, ADL-0 to ADL-5
What it setsWhich licenses apply. License expressions join identifiers with AND, OR and WITH, and AND means a user must comply with every license namedUse restrictions that derivatives must carrySharing limits, which SPDX 3.0 reuses as a dataset's confidentiality levelWhich model deployments may use the data
Says which deployment may process data under privacy lawnononoyes
  • SPDX

    What it is
    An open standard whose License List gives each license an identifier, such as Apache-2.0
    What it sets
    Which licenses apply. License expressions join identifiers with AND, OR and WITH, and AND means a user must comply with every license named
    Says which deployment may process data under privacy law
    no
  • RAIL

    What it is
    Responsible AI Licenses for AI code, data and models
    What it sets
    Use restrictions that derivatives must carry
    Says which deployment may process data under privacy law
    no
  • TLP

    What it is
    FIRST's Traffic Light Protocol, with four sharing labels
    What it sets
    Sharing limits, which SPDX 3.0 reuses as a dataset's confidentiality level
    Says which deployment may process data under privacy law
    no
  • AI Data Levels

    What it is
    Six levels, ADL-0 to ADL-5
    What it sets
    Which model deployments may use the data
    Says which deployment may process data under privacy law
    yes

TLP itself says it "was not designed to handle licensing terms, nor information handling or encryption rules." AI Data Levels borrow SPDX's identifiers and RAIL's derivative rule and apply them to handling rules.

Six levels, and the rules at each

We keep three decisions apart. The level sets the deployment boundary, the data's laws set the paperwork, and the use sets the human review. A DPA is the data processing agreement GDPR requires with each vendor that handles personal data for you, and a DPIA is a data protection impact assessment. A BAA is the business associate agreement HIPAA requires, and PHI is protected health information.

A higher number means tighter rules

  1. ADL-0Public

    Public, licensed for the use, no personal data.

    DeploymentsAny, including consumer apps.

  2. ADL-1Internal

    Business-confidential data with no personal data.

    DeploymentsBusiness terms with no training on your content.

  3. ADL-2Personal

    Ordinary personal data.

    DeploymentsBusiness terms under a DPA.

  4. ADL-3Sensitive

    Special categories, criminal records, children's data, account and ID numbers.

    DeploymentsZero-retention endpoints with in-region processing, your own cloud account, or self-hosted.

  5. ADL-4Regulated

    Data a sector law ties to a signed agreement, such as PHI.

    DeploymentsFeatures covered by a signed BAA, or self-hosted.

  6. ADL-5Sovereign

    Data that must stay under one jurisdiction's control.

    DeploymentsSelf-hosted or a sovereign cloud inside the jurisdiction.

The other rules at each level

ADL-0 PublicADL-1 InternalADL-2 PersonalADL-3 SensitiveADL-4 RegulatedADL-5 Sovereign
Logging and retentionAs the source license allowsProvider's standard abuse-monitoring retentionYour retention schedule, with deletion on requestNo provider retention beyond listed safety exceptions; your logs redacted and short-livedAs ADL-3, plus audit logs of access to PHI; HIPAA records kept six yearsLogs and keys stay in the jurisdiction
Training useAllowed if the source license allowsNo provider training; your fine-tunes stay ADL-1No provider training; your own only for a compatible purposeOnly on de-identified copies, labelled againOnly as the BAA permits, or on de-identified copiesOnly inside the boundary
Human reviewNot requiredNot requiredA route to a person for decisions with legal or similar effectsA person checks every output used about a personA qualified person signs off outputs that reach a record or a patientReviewers based in the jurisdiction
PaperworkSource and license recordNo-training terms; the vendor's SOC 2 report or ISO 27001 certificateDPA, record of processing, transfer mechanism, DPIA if high riskDPIA, written zero-retention terms, documented legal condition for special dataBAA with every vendor in the path, risk analysis, minimum-necessary policySovereignty assessment, plus the paperwork the data's laws require
Residency and sovereigntyNoneNone unless a contract sets oneMay leave under a lawful transfer mechanismStored and processed in the labelled region; no global endpointsAs ADL-3Data, processing, keys, logs and admin access in the jurisdiction
  • ADL-0 Public

    Logging and retention
    As the source license allows
    Training use
    Allowed if the source license allows
    Human review
    Not required
    Paperwork
    Source and license record
    Residency and sovereignty
    None
  • ADL-1 Internal

    Logging and retention
    Provider's standard abuse-monitoring retention
    Training use
    No provider training; your fine-tunes stay ADL-1
    Human review
    Not required
    Paperwork
    No-training terms; the vendor's SOC 2 report or ISO 27001 certificate
    Residency and sovereignty
    None unless a contract sets one
  • ADL-2 Personal

    Logging and retention
    Your retention schedule, with deletion on request
    Training use
    No provider training; your own only for a compatible purpose
    Human review
    A route to a person for decisions with legal or similar effects
    Paperwork
    DPA, record of processing, transfer mechanism, DPIA if high risk
    Residency and sovereignty
    May leave under a lawful transfer mechanism
  • ADL-3 Sensitive

    Logging and retention
    No provider retention beyond listed safety exceptions; your logs redacted and short-lived
    Training use
    Only on de-identified copies, labelled again
    Human review
    A person checks every output used about a person
    Paperwork
    DPIA, written zero-retention terms, documented legal condition for special data
    Residency and sovereignty
    Stored and processed in the labelled region; no global endpoints
  • ADL-4 Regulated

    Logging and retention
    As ADL-3, plus audit logs of access to PHI; HIPAA records kept six years
    Training use
    Only as the BAA permits, or on de-identified copies
    Human review
    A qualified person signs off outputs that reach a record or a patient
    Paperwork
    BAA with every vendor in the path, risk analysis, minimum-necessary policy
    Residency and sovereignty
    As ADL-3
  • ADL-5 Sovereign

    Logging and retention
    Logs and keys stay in the jurisdiction
    Training use
    Only inside the boundary
    Human review
    Reviewers based in the jurisdiction
    Paperwork
    Sovereignty assessment, plus the paperwork the data's laws require
    Residency and sovereignty
    Data, processing, keys, logs and admin access in the jurisdiction

From ADL-2 up, the identifier ends with the data's home jurisdiction as a country code or EU, so ADL-3-EU is sensitive data governed from the EU.

Each level rests on a legal test

We set each level by what the law says, not by how sensitive data feels.

  • Public data that names people is not ADL-0. India's DPDP Act excludes personal data that people made public themselves. GDPR has no such exclusion in Article 2, and the European Data Protection Board, or EDPB, treats public availability as one factor. A scrape of public profiles of people in the EU starts at ADL-2.
  • ADL-3 requires a DPIA for every use, stricter on purpose than GDPR, which requires one for large-scale processing of its Article 9 special categories, such as health data.
  • ADL-4 is defined by an agreement. Under HIPAA, a vendor that creates, receives, maintains or transmits PHI for a covered entity, such as a health plan or health care provider, is a business associate, and so are its subcontractors. Each one needs a BAA.
  • ADL-5 turns on sovereignty, meaning whose law can compel access to data, not residency, meaning where it is stored and processed. The US CLOUD Act covers data in a provider's "possession, custody, or control, regardless of whether" it is stored in the United States or abroad. India's DPDP Rules let the government require local storage of certain data held by significant data fiduciaries, the data handlers the government designates.

How to label a dataset and a pipeline

A label is a small file next to the data or a catalog field, as in this synthetic example.

spec: ADL 0.1
level: ADL-3-EU
dataset: claims-notes
regimes: [GDPR]
contains: [personal, health]
source_licenses: []
lowered_from: none
owner: privacy-lead@example.com
next_review: 2027-04-01

Four rules set a pipeline's level. The second is our firmest position. Derived data is as sensitive as its source until a documented step says otherwise.

Four rules that set a pipeline's level

  1. The highest input wins

    As in an SPDX AND expression. Inputs include prompts, retrieved documents, tool results and agent memory.

  2. Derivatives keep the level

    Outputs, logs, caches, embeddings, search indexes and fine-tuned weights inherit it. Embeddings are the lists of numbers a model uses to compare texts, and Morris and colleagues recovered 92% of 32-token texts exactly from them. The EDPB's Opinion 28/2024 treats a model trained on personal data as anonymous only if identifying those people or extracting their data is very unlikely.

  3. Only a documented step lowers a level

    Such as HIPAA de-identification or true anonymization. Pseudonymized data, with names swapped for tokens and the key kept elsewhere, is still personal data under GDPR Recital 26.

  4. Every endpoint carries a clearance

    A model gateway, a proxy between applications and models, blocks calls that carry data above it. The open-source LiteLLM gateway routes requests by tags set on keys or teams.

A pipeline label looks like this.

spec: ADL 0.1
pipeline: claim-triage
inputs:
  claims-notes: ADL-3-EU
  policy-wording: ADL-0
level: ADL-3-EU
endpoints:
  summarize: {clearance: ADL-3-EU, kind: own-cloud, region: eu}
outputs: ADL-3-EU
use: decision support with human sign-off

Two worked examples

The level comes from the data, and the use can add rules on top. Both scenarios are synthetic.

A software company drafts release notes from pull requests. Every Git commit records its author's name and email address, so the raw feed is ADL-2. With author fields and quoted customer reports removed, it drops to ADL-1, and a business API on standard terms is enough.

A lender in the EU pre-screens loan applications. Account data makes the label ADL-3-EU. The EU AI Act treats credit scoring as high-risk, so the system must allow effective human oversight. The AI Omnibus, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and moved the start of these rules to 2 December 2027.

What the levels do not do

The levels are not legal advice. A label records decisions that accountable people make, and does not replace counsel, a DPIA or a HIPAA risk analysis, or decide whether a use is lawful.

Nor does a vendor's audit report. A SOC 2 report is a CPA firm's examination of a service organization's controls, and a type 2 report adds an opinion on whether they operated effectively over a stated period. The report belongs in the vendor file from ADL-1 up, as does an ISO/IEC 27001 certificate. Neither is permission for a use.

The levels do not settle copyright, so check source licenses with tools such as the Data Provenance Explorer. They do not cover every law, such as US state privacy laws, payment card rules or export controls. Vendor terms change, so every label carries a review date.

Name the level before you pick the model

Choosing a model on quality, then checking the data, gets the order wrong. A level named first shrinks the shortlist, because ADL-3-EU data rules out consumer apps and global endpoints, which may process a request in any region.

Counsel starts the agreements while engineers build against cleared endpoints. Auditors can see what data went to which model, where and under which agreement.

The levels also match the data handling our site describes. Client data stays in client accounts wherever possible, AI systems get minimum access, every action is logged, and personal data is masked before models see it.

Start with one test. Label every input of your busiest AI pipeline, take the highest as its level, and compare that with each endpoint's clearance. Any endpoint cleared below it is the first fix.

The levels are free to copy and change. For a second reviewer on your first labels, talk to us.

Sources

Companion post

  • extendfuture, What AI providers' data terms allow, which maps consumer apps, business APIs, zero data retention, region-pinned endpoints, BAAs, self-hosted open-weight models and sovereign clouds to these levels.

Prior art and labels

Law and regulators

  • EU, General Data Protection Regulation, Articles 2, 6, 9, 22, 28 and 35, Chapter V and Recital 26. Article 6 requires one of six lawful bases, and Article 28 requires a contract, the DPA, with every vendor that processes personal data for you. Article 35 requires a DPIA before processing that is likely to be high risk, including automated evaluation that leads to decisions with legal effects. Under Article 22, people have the right not to be subject to solely automated decisions with legal or similarly significant effects, and where a contract or explicit consent allows such a decision, the person can still obtain human intervention. Data leaving the European Economic Area needs a Chapter V transfer mechanism.
  • European Commission, Adequacy decisions, which for the United States cover only companies in the EU-US Data Privacy Framework, and Standard contractual clauses, which the Commission last updated on 4 June 2021.
  • European Data Protection Board, Opinion 28/2024 on AI models and its press release, 18 December 2024.
  • EU, AI Act, Regulation (EU) 2024/1689, Articles 14 and 27 and Annex III. Annex III lists credit scoring and risk pricing for life and health insurance as high-risk uses, and deployers of those systems must also run a fundamental rights impact assessment. Regulation (EU) 2026/1744, the Digital Omnibus on AI, amended Article 27 so that the assessment can cross-reference the DPIA. European Commission, AI Omnibus enters into force, 27 July 2026; AI Act Service Desk, Timeline for the implementation of the EU AI Act.
  • US eCFR, 45 CFR 160.103, which defines PHI as individually identifiable health information in any form; 164.308, risk analysis; 164.312, audit controls; 164.316, six years of retention for required documents; 164.502, business associate agreements and reasonable efforts to use only the minimum necessary PHI; and 164.514, de-identification.
  • AICPA and CIMA, SOC 2 reporting guide, on examinations of controls relevant to security, availability, processing integrity, confidentiality or privacy; Journal of Accountancy, Explaining the 3 faces of SOC, June 2016. SOC 2 is not a law.
  • Government of India, Digital Personal Data Protection Act, 2023, Sections 3, 9, 10 and 16. The Act requires verifiable parental consent for children's data, and under Section 16 the government may restrict transfers to countries it names by notification. Press Information Bureau, Government notifies DPDP Rules, 14 November 2025, and the DPDP Rules, 2025 backgrounder. Significant data fiduciaries are designated on factors such as data volume and sensitivity.
  • US Department of Justice, CLOUD Act Resources, on the Act of March 2018; Cornell Legal Information Institute, 18 U.S.C. 2713. A provider subject to US law must meet its US obligations to preserve or disclose such data.

Research and tools

· views
Amol PatilFounderFounded extendfuture in 2019. Has shipped computer vision, voice and agentic systems into production across ten industries. Amol Patil on LinkedIn

Working on something in this territory?

Tell us what you are trying to win. We answer within one business day, from the people who build.