You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 15, 2026

Synthetic Data in AI Model Training: Legal Challenges and Intellectual Property Risks

Dow Jones Risk Journal

The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints.

Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training.

However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading.

While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful.

What is synthetic data?

Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset.

Synthetic data generally falls into three categories:

  • Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world behavior without replicating any specific individual.
  • Partially synthetic data – Real datasets in which sensitive fields (names, ID numbers, contact details) are replaced with artificial values while nonsensitive attributes remain intact.
  • Hybrid synthetic data – A combination of real and synthetic records, often used where some genuine information must be retained for accuracy or operational purposes.

The appeal of synthetic data lies in its protection of privacy and its operational efficiency. Properly generated synthetic datasets exclude real personal identifiers and can often be used for development, testing, analytics, and model training without exposing the information of actual individuals. In highly regulated sectors such as healthcare and financial services, synthetic data allows organizations to work with large, realistic datasets while minimizing the legal and operational constraints associated with using real customer or patient information.

Synthetic data is often used in the following sectors:

  • Healthcare: Synthetic patient records and images for safe model development.
  • Finance: Simulated transactions for fraud detection and risk modeling.
  • Mobility and autonomous vehicles: Generated driving scenarios to train for rare or dangerous events.

Each of these sectors leverages synthetic data to accelerate AI innovation. It provides realistic, varied training examples without leaking sensitive details.

Intellectual Property considerations

Despite the clear benefits of using synthetic data, its use for AI training may still give rise to intellectual property risks. The main concerns relate to possible infringement and whether synthetic data can be protected by copyright.

Infringement Risks Arising from the Source Data

Although synthetic data can reduce privacy exposure, it does not eliminate IP risks. Every synthetic dataset starts with the same foundational step: an AI model must first access, copy, and analyze the original “source data.” If that source data is protected by copyright or contractual terms, training on it without permission may constitute infringement.

Some stakeholders adopt a more permissive view of AI training, characterizing it as a form of computational analysis that extracts abstract statistical patterns rather than protected expressive content, and therefore does not constitute infringement. However, this view reflects a policy-based interpretation rather than settled law.

Courts and regulators have increasingly indicated that using copyrighted works for AI training may amount to prima facie infringement, unless a specific legal exception applies. Developers often invoke defenses such as U.S. fair-use principles, but these are narrow, fact-dependent, and unsettled in the context of AI.

Recent U.S. cases, such as Bartz v. Anthropic and Thomson Reuters v. ROSS, have so far found fair use only where the underlying materials were lawfully acquired and the secondary use was genuinely transformative. Conversely, they have rejected fair use where the model was trained on pirated or unauthorized copies. In practice, this means that organic (real) data collected without permission still presents a significant copyright risk for model developers.

Copyrightability of Synthetic Data: Lack of Human Authorship

Even when synthetic data does not copy any specific protected work, it raises a different issue: copyright protection generally requires human authorship. Many copyright systems require a work to result from a human’s creative expression. Authorities in the U.S., U.K. and Thailand take a similar approach: the U.S. Copyright Office has repeatedly rejected registrations for fully AI-generated works on the basis that they lack human authorship. As a result, a fully synthetic dataset produced without meaningful human creative input may not be protected by copyright at all, meaning third parties could potentially reuse it freely. Nevertheless, when meaningful human judgment is involved in designing, selecting, or arranging synthetic samples, copyright may protect that creative selection or arrangement even if the individual records themselves are not protected.

Copyrightability of Synthetic Data: Originality and the Creativity Threshold

Aside from the issue of human authorship, synthetic data often fails the originality requirement. Modern copyright law does not protect works based solely on labor or investment (“sweat of the brow doctrine”). Courts require at least a minimal degree of creativity.

In the U.S., Feist Publications v. Rural Telephone Service Co. confirmed that originality requires independent creation plus a “modicum of creativity.” EU courts apply a similar test, requiring that a work reflect the author’s “own intellectual creation.”

For synthetic data producers, this creativity threshold is difficult to meet. Many synthetic outputs simply replicate statistical patterns without meaningful human creative contribution, leaving them ineligible for copyright protection. Developers should not assume that large or expensive synthetic datasets are automatically protected. To secure such copyright protection, it is necessary to clearly document the human creative decisions involved in designing or curating the synthetic data.

Compliance considerations

Synthetic data should not be presumed to fall outside privacy regulation. Under laws such as the EU’s General Data Protection Regulation and Thailand’s Personal Data Protection Act, information still qualifies as personal data if it relates directly or indirectly to an identifiable individual. Synthetic data may still fall within this scope when it is:

  • Generated from real individuals’ records,
  • Capable of being linked to a person when combined with other available information, or
  • Structured in a way that allows specific traits or behaviors of an individual to be inferred.

In these situations, regulators are likely to treat the synthetic dataset as containing personal data, meaning full compliance obligations still apply.

Ensuring true anonymization is technically challenging. Studies have repeatedly shown that even heavily anonymized datasets can be re-identified with the original individuals with high accuracy using only a few demographic attributes such as age, gender, and ZIP code. The same risks apply to synthetic datasets that replicate the structure of real-world data, especially in domains involving rare characteristics.

Therefore, anonymization cannot be treated as a single, conclusive action. As computational methods advance, datasets considered anonymous today may become identifiable tomorrow. Synthetic data remains a valuable tool, but organizations should deploy it with a realistic understanding of these evolving risks.

 

This article was originally published by Dow Jones Risk Journal in April 2026.

RELATED INSIGHTS​ 

March 18, 2025
On February 6, 2025, the prime minister of Vietnam, Pham Minh Chinh, chaired an online meeting to review the progress of Vietnam’s digital transformation agenda. The meeting assessed achievements under the National Digital Transformation Program and Project 06 on the development and application of population data, electronic identification, and authentication for national digital transformation for the period 2022-2025, with a vision to 2030, approved by the prime minister in 2022. The meeting also outlined key legislative and regulatory priorities for 2025, as set forth in Notice No. 56/TB-BPCP issued by the Government Office on February 23, 2025 (Notice 56). One of the central focuses of the 2025 digital transformation agenda is the development and issuance of laws and regulations governing digital technology, data management, and cybersecurity. Below are the key legal developments provided in Notice 56 that stakeholders should anticipate in the coming months. 1. Law on Digital Technology Industry The Ministry of Information and Communications (MIC) has been tasked with finalizing the draft Law on Digital Technology Industry (DTI Law) for submission to the National Assembly at its 9th session in May 2025. This law is expected to establish a comprehensive legal framework for the digital technology sector, addressing regulatory gaps in emerging fields such as artificial intelligence (AI), Internet of Things (IoT), cloud computing, big data and platform services to promote innovation, ensure data security, and support the growth of the digital economy in Vietnam. Concurrently, the MIC will expedite the issuance of guiding decrees to ensure the swift implementation of the DTI Law once enacted. 2. Law on Personal Data Protection and regulations guiding implementation of Data Law The Ministry of Public Security (MPS) is making efforts to finalize the long-anticipated Law on Personal Data Protection (PDPL)—data protection is currently governed by Decree No. 13/2023/ND-CP on
March 17, 2025
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia. The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others. In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context. The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
March 13, 2025
Vietnam’s Ministry of Finance has released a draft Decree on Tax Administration for E-Commerce and Digital Platforms (“Draft Decree”), introducing significant tax compliance obligations that could reshape how digital platforms, and individuals and business households conducting business through the platforms, manage their tax responsibilities. Aimed at strengthening tax enforcement, the Draft Decree requires e-commerce and digital platforms to actively track and withhold taxes from business households and individual sellers, and remit payments to tax authorities. While it has not yet been promulgated, the Draft Decree is expected to take effect on April 1, 2025, leaving platforms with a limited window to prepare for compliance. Who Is Affected by the New Tax Rules? The Draft Decree significantly broadens the tax administration scope beyond traditional e-commerce platforms to cover a wide range of digital economy participants. Specifically, the Draft Decree places direct tax-related responsibilities on two major categories (collectively, “Regulated Operators”): E-commerce and digital platforms with payment functions (e.g., platforms that process buyer payments via e-wallets, bank transfers, cards, or cash-on-delivery); and Other digital-economy players that enable e-commerce transactions, including (i) intermediary service platforms connecting service providers with consumers, (ii) digital content platforms, (iii) online advertising providers, (iv) cloud computing and data storage providers, (v) social media platforms engaged in business activities (e.g., live-stream, in-app transactions), (vi) online education, gaming, and digital entertainment platforms generating revenue from digital transactions, (vii) Vietnam-based partners of foreign digital service providers facilitating local payments for overseas platforms, and (viii) intermediary payment service providers handling financial transactions for e-commerce activities. Under the Draft Decree, Regulated Operators will be required to track, report, and enforce tax compliance for both resident and nonresident individuals and households conducting business through their platforms (“Sellers”). What New Tax Obligations Do Platforms Face? Onshore platforms For the first time, Regulated Operators will
March 10, 2025
Thailand’s Securities and Exchange Commission (SEC) will officially add USD Coin (USDC) and Tether (USDT) to its list of approved cryptocurrencies for use in digital asset transactions on March 16, 2025. The addition is a significant move that expands Thailand’s digital asset market, aiming to enhance market flexibility and provide more payment options for investors and traders in Thailand’s digital asset ecosystem. Under the SEC regulations, digital asset operators, including digital token issuers, ICO portals, and digital asset exchanges, are only permitted to accept, conduct transactions with, and use “approved cryptocurrencies” as trading pairs. After the addition of USDC and USDT, the full list of approved cryptocurrencies will include: Bitcoin (BTC) Ethereum (ETH) Ripple (XRP) Stellar (XLM) Tether (USDT) USD Coin (USDC) Other cryptocurrencies used for testing programmable payments under the enhanced regulatory sandbox in accordance with the Bank of Thailand’s rules and conditions. For more information on these new additions, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].