Legal
Legal AI training data
Case law, contracts, briefs and filings — assessed for chain of custody, licensing, copyright, and attorney–client privilege. Driver: EU AI Act Article 53, now in force.
The ATAR AI Certification Standard · v1.0
ATAR AI does not invent standards. We certify compliance with the standards that already exist in law — the EU AI Act, GDPR, HIPAA and sector regulation — for the training datasets used where provenance carries real consequence: legal, finance, and health.
In force now. EU AI Act Article 53 — the GPAI training-data documentation obligation — became enforceable on August 2, 2026. The Standard is the independent measure of what that obligation requires of a dataset.
One standard and one tamper-proof registry, applied to the domains where training-data provenance carries real legal and human consequence. The core checks are shared; the compliance criterion is assessed by a reviewer qualified in each field.
Legal
Case law, contracts, briefs and filings — assessed for chain of custody, licensing, copyright, and attorney–client privilege. Driver: EU AI Act Article 53, now in force.
Finance
Market, credit and transaction data — assessed for data-licensing terms, fair-lending bias, and exclusion of material non-public information. Driver: EU AI Act high-risk classification and bank model-risk rules.
Health
Clinical records and medical text — assessed for consent, de-identification, and demographic representativeness. Driver: HIPAA, GDPR special-category data, and EU AI Act / medical-device rules.
Provenance & Compliance
Chain of custody, clean licensing, freedom from unlicensed or copyrighted content, and compliance with GDPR, CCPA, and the EU AI Act.
Quality & Integrity
Structural health, annotation accuracy, diversity balance, and the absence of duplication and adversarial data poisoning.
Security & Safety
Verified anonymization, no leaked PII or privileged client information, and no structural backdoors or toxic content.
| Criterion | What we verify | Regulatory basis |
|---|---|---|
| Provenance | Origin and chain of custody of all data | EU AI Act Art. 10, 53 |
| Regulatory Compliance | Licensing, copyright, and the sector rules for the dataset's field | EU AI Act Art. 10; GDPR; sector law |
| Annotation Accuracy | High accuracy, verified by domain experts | EU AI Act Art. 10 |
| Fitness for Purpose | Dataset matches its intended use case | EU AI Act Art. 13 |
| Anonymization | Personal data removed to the applicable standard | GDPR; HIPAA; sector law |
Certification combines independent software checks, documentary evidence, and a binding attestation — so a certificate means something the moment it is issued and remains meaningful afterward.
An automated audit flags unlicensed-scraping signals and licensing gaps, and a content copy-checker matches the dataset against a reference library of known unlicensed, copyrighted, and public-domain works — surfacing copied passages the paper trail alone would hide.
The vendor formally attests that the data was lawfully acquired and that they hold the rights to use it, and provides supporting evidence for the criteria that require human judgment.
The auditor runs inside the vendor's own environment and returns only a signed attestation — scores and a cryptographic fingerprint, never the content. ATAR AI certifies the data without taking custody of it.
Each certificate is bound to a Merkle fingerprint of the exact dataset. If a single document changes afterward, the certificate breaks — and datasets are re-certified as they evolve.
An ATAR AI certificate reflects the vendor's binding attestation, the evidence provided, and ATAR AI's independent checks — assessed against this Standard at the time of certification and bound to the certified dataset's fingerprint. It is an independent, verifiable statement that no disqualifying issue was identified, not a guarantee of any outcome. Certification does not transfer the vendor's own legal responsibility for its data.
Certify against the Standard