You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 15, 2026

Synthetic Data in AI Model Training: Legal Challenges and Intellectual Property Risks

Dow Jones Risk Journal

The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints.

Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training.

However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading.

While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful.

What is synthetic data?

Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset.

Synthetic data generally falls into three categories:

  • Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world behavior without replicating any specific individual.
  • Partially synthetic data – Real datasets in which sensitive fields (names, ID numbers, contact details) are replaced with artificial values while nonsensitive attributes remain intact.
  • Hybrid synthetic data – A combination of real and synthetic records, often used where some genuine information must be retained for accuracy or operational purposes.

The appeal of synthetic data lies in its protection of privacy and its operational efficiency. Properly generated synthetic datasets exclude real personal identifiers and can often be used for development, testing, analytics, and model training without exposing the information of actual individuals. In highly regulated sectors such as healthcare and financial services, synthetic data allows organizations to work with large, realistic datasets while minimizing the legal and operational constraints associated with using real customer or patient information.

Synthetic data is often used in the following sectors:

  • Healthcare: Synthetic patient records and images for safe model development.
  • Finance: Simulated transactions for fraud detection and risk modeling.
  • Mobility and autonomous vehicles: Generated driving scenarios to train for rare or dangerous events.

Each of these sectors leverages synthetic data to accelerate AI innovation. It provides realistic, varied training examples without leaking sensitive details.

Intellectual Property considerations

Despite the clear benefits of using synthetic data, its use for AI training may still give rise to intellectual property risks. The main concerns relate to possible infringement and whether synthetic data can be protected by copyright.

Infringement Risks Arising from the Source Data

Although synthetic data can reduce privacy exposure, it does not eliminate IP risks. Every synthetic dataset starts with the same foundational step: an AI model must first access, copy, and analyze the original “source data.” If that source data is protected by copyright or contractual terms, training on it without permission may constitute infringement.

Some stakeholders adopt a more permissive view of AI training, characterizing it as a form of computational analysis that extracts abstract statistical patterns rather than protected expressive content, and therefore does not constitute infringement. However, this view reflects a policy-based interpretation rather than settled law.

Courts and regulators have increasingly indicated that using copyrighted works for AI training may amount to prima facie infringement, unless a specific legal exception applies. Developers often invoke defenses such as U.S. fair-use principles, but these are narrow, fact-dependent, and unsettled in the context of AI.

Recent U.S. cases, such as Bartz v. Anthropic and Thomson Reuters v. ROSS, have so far found fair use only where the underlying materials were lawfully acquired and the secondary use was genuinely transformative. Conversely, they have rejected fair use where the model was trained on pirated or unauthorized copies. In practice, this means that organic (real) data collected without permission still presents a significant copyright risk for model developers.

Copyrightability of Synthetic Data: Lack of Human Authorship

Even when synthetic data does not copy any specific protected work, it raises a different issue: copyright protection generally requires human authorship. Many copyright systems require a work to result from a human’s creative expression. Authorities in the U.S., U.K. and Thailand take a similar approach: the U.S. Copyright Office has repeatedly rejected registrations for fully AI-generated works on the basis that they lack human authorship. As a result, a fully synthetic dataset produced without meaningful human creative input may not be protected by copyright at all, meaning third parties could potentially reuse it freely. Nevertheless, when meaningful human judgment is involved in designing, selecting, or arranging synthetic samples, copyright may protect that creative selection or arrangement even if the individual records themselves are not protected.

Copyrightability of Synthetic Data: Originality and the Creativity Threshold

Aside from the issue of human authorship, synthetic data often fails the originality requirement. Modern copyright law does not protect works based solely on labor or investment (“sweat of the brow doctrine”). Courts require at least a minimal degree of creativity.

In the U.S., Feist Publications v. Rural Telephone Service Co. confirmed that originality requires independent creation plus a “modicum of creativity.” EU courts apply a similar test, requiring that a work reflect the author’s “own intellectual creation.”

For synthetic data producers, this creativity threshold is difficult to meet. Many synthetic outputs simply replicate statistical patterns without meaningful human creative contribution, leaving them ineligible for copyright protection. Developers should not assume that large or expensive synthetic datasets are automatically protected. To secure such copyright protection, it is necessary to clearly document the human creative decisions involved in designing or curating the synthetic data.

Compliance considerations

Synthetic data should not be presumed to fall outside privacy regulation. Under laws such as the EU’s General Data Protection Regulation and Thailand’s Personal Data Protection Act, information still qualifies as personal data if it relates directly or indirectly to an identifiable individual. Synthetic data may still fall within this scope when it is:

  • Generated from real individuals’ records,
  • Capable of being linked to a person when combined with other available information, or
  • Structured in a way that allows specific traits or behaviors of an individual to be inferred.

In these situations, regulators are likely to treat the synthetic dataset as containing personal data, meaning full compliance obligations still apply.

Ensuring true anonymization is technically challenging. Studies have repeatedly shown that even heavily anonymized datasets can be re-identified with the original individuals with high accuracy using only a few demographic attributes such as age, gender, and ZIP code. The same risks apply to synthetic datasets that replicate the structure of real-world data, especially in domains involving rare characteristics.

Therefore, anonymization cannot be treated as a single, conclusive action. As computational methods advance, datasets considered anonymous today may become identifiable tomorrow. Synthetic data remains a valuable tool, but organizations should deploy it with a realistic understanding of these evolving risks.

 

This article was originally published by Dow Jones Risk Journal in April 2026.

RELATED INSIGHTS​ 

July 28, 2023
Myanmar’s Ministry of Commerce (MOC) issued three notifications related to e-commerce on July 21, 2023, classifying online retail businesses as essential services, requiring them to register with the relevant authorities, and setting the criteria for their registration. Under Notification No. 49/2023 the MOC authorized the Department of Trade (DOT) to issue notifications, orders, and directives relating to online retail businesses. This was followed by Notification No. 50/2023, which classifies online retail businesses as essential services under the Essential Supplies and Services Law and requires them to register with the DOT within six months of the issuance of the notification (i.e., by January 21, 2024). Failure to register within the specified period will be punishable by imprisonment for six months to three years and a fine of up to MMK 500,000 (approx. USD 238). Finally, under Notification No. 51/2023, the MOC set out the criteria and requirements for the registration of online retail businesses by entities, business institutions, and individuals, as well as the duties and liabilities of sellers and consumers. Pursuant to this notification, registration should be completed via the DOT’s online system, fees must be paid digitally, and electronic registration certificates will be issued. Certificates are initially valid for two years, and can be renewed. The MOC will provide information at a later time on the prescribed forms, certificate format, registration and online fees, and online registration portal. In applying for registration, an entity or business institution established under the Myanmar Companies Law, Special Company Act, Co-operative Society Law, or any other existing Myanmar laws must have a website with its own domain name or an online channel with an exact address that is used for online sales and a registered business address within Myanmar. Individual applicants must be at least 18 years old, reside in Myanmar, and
July 26, 2023
Thailand’s Electronic Transactions Development Agency (ETDA) held a briefing session on July 20, 2023, laying out the changes and new requirements in draft sublaws under the Royal Decree on Digital Platform Services. These sublaws are expected to be announced in August 2023. The key changes and new requirements are listed below. The ETDA has drafted guidelines on the methods for identifying active users to give digital platform service operators a better understanding of the calculation methods. The definition of “users” for calculating annual monthly active users (AMAUs) has been reduced in scope to cover only users in Thailand. E-marketplace digital platform services that will suspend or terminate operations for specific users must inform the affected users and provide a period for them to challenge the suspension or termination. Digital platform service operators cannot use the requirements to identify their active users as a legal basis for processing users’ personal data, especially for profiling and tracking activities. The sublaws on announcement of terms and conditions (T&Cs) and changes to T&Cs, once issued, will take effect on January 3, 2024, while the other sublaws will take effect immediately (i.e., August 21, 2023). This shows that the ETDA has acknowledged the private sector’s feedback that the requirements on T&Cs will take more time for operators to comply with. The requirements for changing T&Cs have been adjusted. Under the current draft, the required advance notification period can be exempted if a change in the T&Cs is for the purpose of, for example, rolling out new products or services and improving the platform. Required submissions under the Royal Decree for Digital Platform Services and its sublaws will be made through the ETDA’s online portal. There will likely be no extensions granted for compliance with the Royal Decree for Digital Platform Services and its sublaws
July 14, 2023
The Bank of Thailand (BOT) has issued new notifications amending regulations for payment businesses that fall under the Payment Systems Act B.E. 2560 (2017) to promote transparency and good governance in the payment industry. Notification No. SorKorChor 2/2566 (“Notification 2”) increases the required qualifications for applicants seeking a license to provide payment services designated as being under the BOT’s supervision, and Notification No. SorKorChor 4/2566 (“Notification 4”) stipulates additional duties and exemptions for certain types of business operators. The notifications were published in the Government Gazette on July 7, 2023, and came into effect the following day. Additional Qualifications Notification 2 expands the list of prohibited characteristics for business operators applying for a license or registration to engage in a designated payment service, and their directors. For example, applicants must not have been ordered to suspend or cease their operations, and their registration or license to engage in financial business or operate a designated payment system or service must not have been revoked. The notification defines “financial business” as including financial institutions, credit card business, personal loan business, securities business, and so on. In addition, applicants’ directors and management must not have prohibited characteristics, such as being involved in the management of a financial business or designated payment system or service that was ordered to suspend or cease its operations. The applicable registration or license also must not have been revoked. Reporting Requirements During the application process, Notification 2 requires applicants to disclose information on shareholders and related parties (including spouses) who hold an aggregate 10 percent or more of the total paid-up shares. Notification 4 imposes this same reporting duty regarding shareholders and related parties but applies it to licensed operators in an ongoing manner. Existing payment service operators must make their first report of this information to
July 12, 2023
On June 30, 2023, Vietnam’s Ministry of Information and Communications (MIC) issued Circular No. 06/2003/TT-BTTTT to provide implementing guidelines for Decree 71 on editing, ratings, and warnings for video on demand (VOD) sports and entertainment content provided over radio and TV services. Circular 06 will take effect on August 15, 2023. Because Decree 71 allows VOD providers to self-edit and self-rate this type of content, it is important for them to know how the process is regulated in order to fully comply before providing VOD sports and entertainment programs to Vietnamese users. Under Circular 06, radio and TV service providers are required to display ratings and warnings on their programs, following the principles set out in the circular. These service providers must also compile dossiers in a stipulated form on the editing, ratings, and warnings of their programs for reporting to the authority and inspection. The main contents of Circular 06 are as follows. 1. Content Editing The main principles for editing VOD sports and entertainment programs include: Protection of children and other vulnerable people from inappropriate or potentially harmful content. Removal of all illegal/prohibited content, as well as content related to controversial issues or issues not recognized by Vietnamese law. Removal of content or dialogue that disparages the origins of others or makes fun of others’ physical weaknesses, and content that is contrary to Vietnamese culture, morality and fine customs and traditions; Removal of programs if it is discovered during the editing process that in the program or at the venue of the event, there are images or activities violating the prohibitions of the law, violating Vietnamese fine customs and traditions, or containing sensitive political elements. In addition to compliance with the above-mentioned principles, sports and entertainment programs related to health, education, and online gaming must additionally meet