You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 15, 2026

Synthetic Data in AI Model Training: Legal Challenges and Intellectual Property Risks

Dow Jones Risk Journal

The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints.

Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training.

However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading.

While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful.

What is synthetic data?

Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset.

Synthetic data generally falls into three categories:

  • Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world behavior without replicating any specific individual.
  • Partially synthetic data – Real datasets in which sensitive fields (names, ID numbers, contact details) are replaced with artificial values while nonsensitive attributes remain intact.
  • Hybrid synthetic data – A combination of real and synthetic records, often used where some genuine information must be retained for accuracy or operational purposes.

The appeal of synthetic data lies in its protection of privacy and its operational efficiency. Properly generated synthetic datasets exclude real personal identifiers and can often be used for development, testing, analytics, and model training without exposing the information of actual individuals. In highly regulated sectors such as healthcare and financial services, synthetic data allows organizations to work with large, realistic datasets while minimizing the legal and operational constraints associated with using real customer or patient information.

Synthetic data is often used in the following sectors:

  • Healthcare: Synthetic patient records and images for safe model development.
  • Finance: Simulated transactions for fraud detection and risk modeling.
  • Mobility and autonomous vehicles: Generated driving scenarios to train for rare or dangerous events.

Each of these sectors leverages synthetic data to accelerate AI innovation. It provides realistic, varied training examples without leaking sensitive details.

Intellectual Property considerations

Despite the clear benefits of using synthetic data, its use for AI training may still give rise to intellectual property risks. The main concerns relate to possible infringement and whether synthetic data can be protected by copyright.

Infringement Risks Arising from the Source Data

Although synthetic data can reduce privacy exposure, it does not eliminate IP risks. Every synthetic dataset starts with the same foundational step: an AI model must first access, copy, and analyze the original “source data.” If that source data is protected by copyright or contractual terms, training on it without permission may constitute infringement.

Some stakeholders adopt a more permissive view of AI training, characterizing it as a form of computational analysis that extracts abstract statistical patterns rather than protected expressive content, and therefore does not constitute infringement. However, this view reflects a policy-based interpretation rather than settled law.

Courts and regulators have increasingly indicated that using copyrighted works for AI training may amount to prima facie infringement, unless a specific legal exception applies. Developers often invoke defenses such as U.S. fair-use principles, but these are narrow, fact-dependent, and unsettled in the context of AI.

Recent U.S. cases, such as Bartz v. Anthropic and Thomson Reuters v. ROSS, have so far found fair use only where the underlying materials were lawfully acquired and the secondary use was genuinely transformative. Conversely, they have rejected fair use where the model was trained on pirated or unauthorized copies. In practice, this means that organic (real) data collected without permission still presents a significant copyright risk for model developers.

Copyrightability of Synthetic Data: Lack of Human Authorship

Even when synthetic data does not copy any specific protected work, it raises a different issue: copyright protection generally requires human authorship. Many copyright systems require a work to result from a human’s creative expression. Authorities in the U.S., U.K. and Thailand take a similar approach: the U.S. Copyright Office has repeatedly rejected registrations for fully AI-generated works on the basis that they lack human authorship. As a result, a fully synthetic dataset produced without meaningful human creative input may not be protected by copyright at all, meaning third parties could potentially reuse it freely. Nevertheless, when meaningful human judgment is involved in designing, selecting, or arranging synthetic samples, copyright may protect that creative selection or arrangement even if the individual records themselves are not protected.

Copyrightability of Synthetic Data: Originality and the Creativity Threshold

Aside from the issue of human authorship, synthetic data often fails the originality requirement. Modern copyright law does not protect works based solely on labor or investment (“sweat of the brow doctrine”). Courts require at least a minimal degree of creativity.

In the U.S., Feist Publications v. Rural Telephone Service Co. confirmed that originality requires independent creation plus a “modicum of creativity.” EU courts apply a similar test, requiring that a work reflect the author’s “own intellectual creation.”

For synthetic data producers, this creativity threshold is difficult to meet. Many synthetic outputs simply replicate statistical patterns without meaningful human creative contribution, leaving them ineligible for copyright protection. Developers should not assume that large or expensive synthetic datasets are automatically protected. To secure such copyright protection, it is necessary to clearly document the human creative decisions involved in designing or curating the synthetic data.

Compliance considerations

Synthetic data should not be presumed to fall outside privacy regulation. Under laws such as the EU’s General Data Protection Regulation and Thailand’s Personal Data Protection Act, information still qualifies as personal data if it relates directly or indirectly to an identifiable individual. Synthetic data may still fall within this scope when it is:

  • Generated from real individuals’ records,
  • Capable of being linked to a person when combined with other available information, or
  • Structured in a way that allows specific traits or behaviors of an individual to be inferred.

In these situations, regulators are likely to treat the synthetic dataset as containing personal data, meaning full compliance obligations still apply.

Ensuring true anonymization is technically challenging. Studies have repeatedly shown that even heavily anonymized datasets can be re-identified with the original individuals with high accuracy using only a few demographic attributes such as age, gender, and ZIP code. The same risks apply to synthetic datasets that replicate the structure of real-world data, especially in domains involving rare characteristics.

Therefore, anonymization cannot be treated as a single, conclusive action. As computational methods advance, datasets considered anonymous today may become identifiable tomorrow. Synthetic data remains a valuable tool, but organizations should deploy it with a realistic understanding of these evolving risks.

 

This article was originally published by Dow Jones Risk Journal in April 2026.

RELATED INSIGHTS​ 

May 3, 2024
Vietnam’s Ministry of Public Security (MPS) recently published on its website a dossier of the Draft Law on Data (the “Draft Law”) for public feedback, initiating a consultation period from February 26 to March 26, 2024. The dossier comprises a Policy Impact Assessment Report and a Summary Report on the implementation of existing legal documents governing data. An outline of the Draft Law was later circulated to relevant organizations for their input and commentary. The MPS drafted this legislation with several objectives, including bolstering national data infrastructure, advancing digital government while streamlining administrative procedures, fostering growth in the digital economy and building a digital society, and establishing a National Data Center. Comprising 65 articles across 6 chapters, the Draft Law is slated for implementation on January 1, 2026. The Draft Law currently is very preliminary, resembling a framework document. It features numerous provisions akin to policy mandates, yet only presents introductory concepts without further elaboration. Scope of Application The Draft Law applies to agencies, organizations, and individuals involved in data activities in Vietnam. This scope of application appears excessively broad and ambiguous, without a clear definition of “data activities”, leaving uncertainty regarding the breadth of this term’s coverage. Key Policy Groups The Draft Law focuses on four key policy groups: 1. Regulations on development, processing, and management of data This policy group focuses on matters relating to the collection, digitalization, and creation of data; assurance of data quality; data classification; data storage; data combination, adjustment, and updating; data strategy; data management; data sharing; provision of data to state agencies; data analysis and synthesis; data verification and authentication; data disclosure; access and retrieval of data; data encryption and decryption; data copying, transmission, and transfer; data revocation, deletion, and destruction; application of science and technology in data processing; identification and management
April 30, 2024
On March 25, 2024, Thailand’s Securities and Exchange Commission (SEC) published an amendment to its Notification re: Public Digital Token Offering to strengthen governance for initial coin offerings (ICOs). The amendments took effect on April 16, 2024, and reflect the SEC’s commitment to creating a safer and more transparent ICO environment, enhancing investor protection, and building confidence in ICOs as a fundraising tool. The key changes are outlined below: New Checks and Balances Requirements The new regulations require digital token issuers to implement checks and balances to protect investor rights—including an annual audit requirement and measures to prevent and manage conflicts of interest. These measures must be clearly disclosed in the ICO filing documents. In addition, certain project-related decisions must be approved by the issuer’s board of directors, which is also responsible for the accountability of such decisions. Improved Rules Concerning Voting Rights The SEC has introduced rules concerning voting rights and procedures for digital token holders, particularly for token types that previously lacked regulatory clarity. These rules specify the procedures for soliciting votes, the rationale behind vote requests, and the criteria for determining voting outcomes. The new rules, however, do not apply to real estate-backed tokens or infrastructure-backed tokens. Enhanced Advertising Regulations The SEC has revised advertising guidelines to ensure that investors receive essential information. The updated rules now require all ICO advertising to be fair and informative and to avoid misleading content. Advertisements must include appropriate risk warnings and a credible source for any claims made. The notification also stresses that it is the responsibility of digital token issuers to strictly supervise and ensure that those who create advertisements with or for an issuer comply with all relevant advertising regulations, including the following: Warning of investment risk: Advertisements must include warnings about investment risks and contact information
April 5, 2024
On March 15, 2024, Thailand’s Board of Investment (BOI) updated its investment incentives for software development and data centers by issuing a regulation replacing the previous categories of software or platforms for digital services or content (category 8.1) and data centers (category 8.2.1). The new and updated categories are detailed below. Software and Platform Development Under the new promotion policy, the BOI has made separate subcategories for “development” and “improvement” of software or platforms, each with its own set of incentives. The BOI is expected to clarify the characteristics of these two activities in a forthcoming announcement. Qualifying development activities are eligible for a corporate income tax (CIT) exemption for eight years (capped), while improvement activities are not eligible for any CIT exemption. A number of adjustments have been made to the eligibility criteria for development of software and platforms for digital services or content. These include the following: Salary expenditures for Thai information technology (IT) personnel hired temporarily after applying for investment promotion can now be included in the calculation of total salary expenditures for Thai IT personnel hired subsequent to applying for investment promotion. Previously, only salary expenditures for permanently employed personnel could be included in this figure. The minimum salary expenditures for each project remain unchanged at THB 1.5 million per year. Similarly, salary expenditures for temporary hiring of Thai IT personnel can be included in calculating the actual expenditures in the year that the project would like to benefit from the CIT exemption. Projects must commence operations within 12 months of the promotion certificate being issued. No extensions are allowed. Projects are no longer allowed to extend the machinery importation period. The other eligibility criteria for development of software and platforms for digital services or content remain unchanged. Projects in the new BOI subcategory for
April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].