Copyright and Generative AI: Proving the Origin of Datasets with V-PROOF

Copyright and Generative AI: Evidence of Data Set Origins with V-PROOF, V-PROOF Journal
AI Regulation & Copyright

Copyright and Generative AI: Proof of Origin as a Legal Defense

EU Directive 2019/790 and Article 53 of the EU AI Act converge on the same point: without cryptographic traceability of the training data, there is no possible legal defense.

Published July 2026 Reading time: 8 min EU AI Act Copyright EU GenAI Dataset

Key Findings

  • More than 30 active lawsuits against LLM models in the U.S. and Europe (NYT vs. OpenAI, Getty vs. Stability AI, Universal Music vs. Anthropic). The common thread: What data was used, and with what authorization?
  • EU Directive 2019/790, Article 4, allows for an exception regarding text mining but recognizes the rights holder's right to "expressly reserve" the right to use the data, thereby creating a retroactive legal liability for models that have already been trained.
  • EU AI Act, Art. 53(1)(d), requires GPAI providers to publish a "sufficiently detailed summary" of the training data, including identification of sources and licenses.
  • Without cryptographic " hash " of the dataset from the time of ingestion, it is technically impossible to prove exactly which version of the data was used, when it was used, and whether the data subject's opt-out request had already been recorded.
  • V-PROOF Generates an SHA-256 hash of the entire dataset at the time of ingestion, which is timestamped in Base L2 before the first training cycle, creating evidence prior to the process, not after it.

Two standards, the same problem with evidence

The training of generative AI models is under legal scrutiny on both sides of the Atlantic. In Europe, the framework is built on two mutually reinforcing pillars.

EU Directive 2019/790 · Copyright
Text and Data Mining: An Exception with Conditions
Article 3 establishes an exception for mining in research. Article 4 extends the exception to commercial uses, but recognizes the right of the copyright holder to exclude their works through a machine-readable opt-out mechanism.
Practical Implications If a data subject submitted an opt-out request before the training session and the system cannot verify when the data was processed, the exception does not apply.
EU AI Act · Art. 53 · GPAI
GPAI Suppliers: Data Transparency Requirements
Art. 53(1)(b): technical documentation of the training datasets. Art. 53(1)(c): active policies to comply with copyright law. Art. 53(1)(d): published summary of sources and licenses.
Deadline Effective for GPAI models starting in August 2025. Fines of up to 15 million euros or 3% of global revenue.
Recital 107 · EU AI Act
The documentation must be verifiable
The regulations do not merely require a statement of compliance; they require technical documentation that allows the IA Office to verify compliance. A claim without technical evidence has no value to an auditor.
V-PROOF 's Unique Selling Proposition The evidence at hash and timestamp can be verified by third parties without access to internal systems.
Active Cases 2024–2026
Case law is accelerating
NYT v. OpenAI (NY, 2023), Getty v. Stability AI (UK/US, 2023), class-action lawsuits filed by authors against Meta, Anthropic, and Google. The emerging standard: without verifiable proof of the dataset, there is no presumption of innocence.
Trend Courts are beginning to request technical evidence regarding the dataset, not just usage policies.

Why Internal Logs Are Not Enough

The typical response of organizations to an audit is to submit system logs, contracts with data providers, and internal compliance statements. None of these elements can withstand rigorous adversarial analysis for three fundamental reasons.

The Problem of Mutability

Internal logs can be modified by the system operator. They do not have an external timestamp. They do not generate a verifi hash. In the event of a dispute, the other party may question their integrity without any technical evidence to refute it.

The second loophole is more subtle: the time of capture. An opt-out notice published by a rights holder on March 15 is legally valid if the model began training on March 20. But if the system cannot accurately demonstrate when it processed the specific data, the opt-out applies by default.

The third gap concerns the exact version of the dataset. Datasets evolve: they are cleaned, filtered, and new sources are added. Without version- hash, it is not possible to prove that the model was trained on the cleaned, post-filtering version, rather than on the previous version that contained protected content.

The auditor's question

"Can you verify which exact version of the dataset was used, the exact time it was processed, and that at that time there were no opt-out requests on record from the data subjects included?" · If the answer cannot be verified by an independent third party, the legal risk remains unresolved.

Origin Evidence Pipeline, V-PROOF

V-PROOF It generates cryptographic evidence of the dataset at the time of ingestion, prior to any training process. The chain is immutable and verifiable by third parties without the need for access to internal systems.

Technical Visualization
Dataset Fingerprinting Pipeline
📂
Dataset
training_v2.4
12.8 GB · 4.2M documents
INTAKE
⚙️
SHA-256
a3f8c...
HASH
🔗
IPFS CID
QmX9f2...
IPFS
⛓️
L2 Base
Block #,
TIMESTAMP
◈
V-SEAL
Verifiable
with no middleman
EVIDENCE
< 200ms
hash 's time by file
SHA-256
NIST Standard Cryptographic Algorithm
Ethereum L2
Public network · verification without access
∞
Permanence, unchanging once sealed

The result is a dataset “V-SEAL ”: a record that includes the exact version of the dataset, the complete SHA-256 “ hash,” the IPFS CID, the block number in Base L2, and the precise “ timestamp ” of the operation. This record can be verified by any auditor or court without requiring access to the organization’s internal systems.

Covered Articles, EU AI Act & Copyright Policy

Article Obligation Evidence V-PROOF Modules
EU Directive 2019/790 · Copyright in the Digital Single Market
Article 3 Text mining for research: demonstrating that the use falls within the exception ✓ Hash of the dataset + source classification upon ingestion SHA-256 IPFS
Article 4 Commercial use: demonstrate that there was no opt-out option at the time of processing ✓ The timestamp records the exact time, either before or after the exclusion L2 Base V-SEAL
EU AI Act · GPAI models (effective August 2025)
Art. 53(1)(b) Technical documentation for the training datasets used ✓ Complete record: version, sources, hash, timestamp Governance IPFS
Art. 53(1)(c) Policies Implemented to Comply with Copyright Laws During Training ~ V-PROOF documents the process; the exclusion policy is set by the operator Governance
Art. 53(1)(d) Publish a sufficiently detailed summary of training data (sources + licenses) ✓ Verifiable export of the dataset record with license metadata V-SEAL API
Art. 55(1)(a) GPAI Models of Systemic Risk: Risk Assessment Including a Dataset ✓ Full traceability for audits by the EU Intellectual Property Office L2 Base V-SEAL
Strengths V-PROOF

Why V-PROOF is the correct technical answer

Key advantages of the cryptographic approach outlined in * V-PROOF * compared to declarative compliance approaches.

01
Evidence prior to the proceedings, not after
The dataset’s SHA-256 h hash e is generated at the time of ingestion, before the first training cycle. This is not a retroactive declaration of compliance: it is technical evidence that precedes the process to be certified. This reverses the burden of proof in a legal dispute.
EU AI Act Art. 53(1)(b) · maximum probative value
02
Immutability guaranteed by public network consensus
Immutability does not depend on the integrity of the operator or on V-PROOF: it is upheld by the distributed consensus of the Ethereum Layer 2 base layer. No entity, including the issuing organization itself, can modify a confirmed block on the chain.
Ethereum L2 Layer · distributed consensus · tamper-proof
03
Verifiable by any auditor without internal access
Any auditor, court, or regulatory authority can verify the existence of hash and timestamp directly at basescan.org, without requiring access to the organization’s systems or the servers at V-PROOF. Public and perpetual verifiability.
basescan.org · verification without an intermediary · permanent
04
SHA-256: NIST standard supported in more than 40 jurisdictions
SHA-256 is the cryptographic hashing algorithm specified in the NIST SP 800-107 standard, which is adopted by default in legal proceedings in the U.S., the EU, the UK, and most international cybersecurity frameworks. There is no risk that the algorithm will be challenged in court.
NIST SP 800-107 · global standard
05
IPFS: Permanent Distribution of Hashed Data
The dataset's IPFS CID is a deterministic address derived from the content: the same dataset will always produce the same CID. This property of content addressing makes it possible to verify that the data has not been altered without having to store the original dataset in a centralized location.
IPFS content addressing · distribution without a central server
06
Verifiable export for the EU IA Office
The dataset V-SEAL generates an exportable record that includes the dataset version, hash SHA-256, IPFS CID, block number, and timestamp. This format precisely meets the requirements for a “sufficiently detailed summary” under Article 53(1)(d) of the EU AI Act, verifiable by the EU AI Office without intermediaries.
EU AI Act Art. 53(1)(d) · EU IP Office · export audit
Tags
EU AI Act EU Copyright 2019/790 GenAI Dataset Traceability AI Intellectual Property SHA-256 IPFS L2 Base Digital Evidence GPAI AI Governance
V-PROOF

Does your GPAI model include evidence of the dataset's origin?

V-PROOF 's Strategic Assessment evaluates your legal Exposure at EU AI Act under Article 53 and the Copyright Directive, and outlines a plan for implementing cryptographic evidence within 4 weeks.

Request a Diagnosis →

© 2026 V-PROOF Protocol · Journal · vproofprotocol.com

This article is for informational purposes only and does not constitute legal advice. Please consult with your legal team regarding how this applies specifically to your organization.

Previous
Previous

V-PROOF: Software Lifecycle Traceability in the Era of the EU Cyber Resilience Act

Next
Next

FFUUSS · OTS GROUP: AI compliance under five concurrent ISO certifications, without a single nonconformity