Products

AI training audit

AI transparency is no longer voluntary. In Australia, California, the EU, and New Zealand it is now mandatory for companies to disclose how they train their AI systems and how data moves through them. Any company operating across borders must answer to all of these regimes at once. But a published disclosure is just a claim. The question that matters is whether the model and the data behind it actually match what was declared.

We provide an independent testing service which determines whether a company’s AI practice matches its stated policies—in the jurisdictions where it operates, as well as the ones in which it sells its products. Using the same detection technology we built to detect creative works inside training datasets and models, we provide detailed and transparent audit reports for regulators and rights organizations tasked with evaluating a provider’s claims, as well as for companies verifying their own compliance—or a vendor’s—before someone else does.

Features

Verify disclosures

Check what a company has published against what its models and datasets actually contain.

  • Compare a provider’s published training-content summary—like the one the EU AI Act now requires—against independent evidence of what the model was trained on.
  • Test California-style dataset disclosures for completeness: sources, copyrighted material, and personal information that the documentation should have declared.
  • Probe for material the disclosure doesn’t mention—works, datasets, and data categories that show up in model behavior but not in the paperwork.
  • Document every gap with reproducible evidence, so a finding of “the disclosure is incomplete” is a demonstration, not an opinion.

Test policies in practice

Stated policies are promises. We test whether day-to-day practice keeps them.

  • Check whether rights reservations are honored: when creators and publishers opt out of text-and-data mining, does the provider’s data pipeline actually respect it?
  • Test cross-jurisdiction consistency—whether the practice a company follows at home holds up against the disclosure and data-policy rules of the markets it sells into.
  • Trace how scraped and indirectly collected data is handled against the notification and privacy-policy duties now arriving in Australia and New Zealand.
  • Monitor over time: disclosures must be kept current as models are retrained, and we re-run the audit as models, datasets, and obligations change.

Standards we audit against

European Union

AI Act, Article 53

General-purpose AI providers must publish a sufficiently detailed summary of training content—using the AI Office’s mandatory template—and maintain a copyright policy that respects rights reservations. In force since August 2025, with AI Office enforcement and fines from August 2026.

European Union

DSM Copyright Directive, Article 4

Text-and-data mining is only permitted where rights holders haven’t reserved their rights. A provider’s copyright policy is testable: either reserved works stay out of the training pipeline, or they don’t.

California

AB 2013: Training Data Transparency

Since January 2026, developers of generative AI systems available in California must publicly document their training datasets—sources, copyrighted material, and personal information included—and keep the disclosure current as systems change.

Australia

Privacy Act reforms

From December 2026, organizations covered by the Australian Privacy Principles must disclose in their privacy policies the kinds of personal information used in substantially automated decisions—and the Privacy Commissioner’s guidance sets clear expectations for AI data governance today.

New Zealand

Privacy Act 2020 & IPP 3A

New Zealand’s privacy principles apply across the AI lifecycle, and from May 2026 the new IPP 3A requires agencies that collect personal information indirectly—the way training data is typically gathered—to tell people about it.

The rulebook is still growing, and we track it as it does. As with all our work: we provide independent technical findings, not legal advice—your counsel and compliance teams decide what to do with them.

How it works

1

Define the audit

The company or model in question, the jurisdictions that apply, and the disclosures and policies to test—whether you’re a regulator, a rights organization, or the company itself.

2

We test claims against reality

We review the published disclosures, search the underlying datasets, and probe the models—independently checking whether stated policy matches observed practice.

3

Get the audit report

Findings mapped to each jurisdiction’s requirements, with reproducible evidence for every gap—and ongoing monitoring as models and obligations change.

Trust, but verify

Whether you’re checking a provider’s claims, a vendor’s pipeline, or your own compliance before regulators do—an independent audit starts with a conversation.