You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 15, 2026

Synthetic Data in AI Model Training: Legal Challenges and Intellectual Property Risks

Dow Jones Risk Journal

The surge in AI development has led to a desperate demand for large, high-quality training data. However, real-world data can be expensive to collect, difficult to access, and often subject to strict privacy and regulatory constraints.

Synthetic data, which consists of artificially generated records that replicate the statistical properties of real-world data without reproducing specific individuals’ information, provides an appealing solution by generating artificial datasets at scale without relying on identifiable personal information. It combines speed, cost efficiency, and regulatory compliance, making it a sensible alternative for organizations seeking to reduce risks while maintaining data utility. When properly anonymized, synthetic datasets may fall outside the scope of laws such as the EU’s General Data Protection Regulation (GDPR) or Thailand’s Personal Data Protection Act (PDPA), reducing compliance burdens while still supporting high-quality model training.

However, relying on synthetic data without rigorous legal due diligence could be a strategic mistake. It replaces one set of known risks (scraping, direct privacy liability) with a new set of complex liabilities. The narrative that synthetic data is a “silver bullet” for privacy and IP compliance is dangerous and could be misleading.

While synthetic data addresses data scarcity, it also introduces new legal uncertainties. Legal counsel should anticipate downstream risks arising from compromised data sources. Models trained on unlawfully obtained data may need to be decommissioned, even if their outputs appear lawful.

What is synthetic data?

Synthetic data refers to artificially generated information created using AI techniques such as deep learning and generative models. Instead of copying real records, it reproduces the statistical patterns and relationships found in the original dataset.

Synthetic data generally falls into three categories:

  • Fully synthetic data – Entirely new data points generated from learned patterns. The model studies the structure of the original data and produces records that resemble real-world behavior without replicating any specific individual.
  • Partially synthetic data – Real datasets in which sensitive fields (names, ID numbers, contact details) are replaced with artificial values while nonsensitive attributes remain intact.
  • Hybrid synthetic data – A combination of real and synthetic records, often used where some genuine information must be retained for accuracy or operational purposes.

The appeal of synthetic data lies in its protection of privacy and its operational efficiency. Properly generated synthetic datasets exclude real personal identifiers and can often be used for development, testing, analytics, and model training without exposing the information of actual individuals. In highly regulated sectors such as healthcare and financial services, synthetic data allows organizations to work with large, realistic datasets while minimizing the legal and operational constraints associated with using real customer or patient information.

Synthetic data is often used in the following sectors:

  • Healthcare: Synthetic patient records and images for safe model development.
  • Finance: Simulated transactions for fraud detection and risk modeling.
  • Mobility and autonomous vehicles: Generated driving scenarios to train for rare or dangerous events.

Each of these sectors leverages synthetic data to accelerate AI innovation. It provides realistic, varied training examples without leaking sensitive details.

Intellectual Property considerations

Despite the clear benefits of using synthetic data, its use for AI training may still give rise to intellectual property risks. The main concerns relate to possible infringement and whether synthetic data can be protected by copyright.

Infringement Risks Arising from the Source Data

Although synthetic data can reduce privacy exposure, it does not eliminate IP risks. Every synthetic dataset starts with the same foundational step: an AI model must first access, copy, and analyze the original “source data.” If that source data is protected by copyright or contractual terms, training on it without permission may constitute infringement.

Some stakeholders adopt a more permissive view of AI training, characterizing it as a form of computational analysis that extracts abstract statistical patterns rather than protected expressive content, and therefore does not constitute infringement. However, this view reflects a policy-based interpretation rather than settled law.

Courts and regulators have increasingly indicated that using copyrighted works for AI training may amount to prima facie infringement, unless a specific legal exception applies. Developers often invoke defenses such as U.S. fair-use principles, but these are narrow, fact-dependent, and unsettled in the context of AI.

Recent U.S. cases, such as Bartz v. Anthropic and Thomson Reuters v. ROSS, have so far found fair use only where the underlying materials were lawfully acquired and the secondary use was genuinely transformative. Conversely, they have rejected fair use where the model was trained on pirated or unauthorized copies. In practice, this means that organic (real) data collected without permission still presents a significant copyright risk for model developers.

Copyrightability of Synthetic Data: Lack of Human Authorship

Even when synthetic data does not copy any specific protected work, it raises a different issue: copyright protection generally requires human authorship. Many copyright systems require a work to result from a human’s creative expression. Authorities in the U.S., U.K. and Thailand take a similar approach: the U.S. Copyright Office has repeatedly rejected registrations for fully AI-generated works on the basis that they lack human authorship. As a result, a fully synthetic dataset produced without meaningful human creative input may not be protected by copyright at all, meaning third parties could potentially reuse it freely. Nevertheless, when meaningful human judgment is involved in designing, selecting, or arranging synthetic samples, copyright may protect that creative selection or arrangement even if the individual records themselves are not protected.

Copyrightability of Synthetic Data: Originality and the Creativity Threshold

Aside from the issue of human authorship, synthetic data often fails the originality requirement. Modern copyright law does not protect works based solely on labor or investment (“sweat of the brow doctrine”). Courts require at least a minimal degree of creativity.

In the U.S., Feist Publications v. Rural Telephone Service Co. confirmed that originality requires independent creation plus a “modicum of creativity.” EU courts apply a similar test, requiring that a work reflect the author’s “own intellectual creation.”

For synthetic data producers, this creativity threshold is difficult to meet. Many synthetic outputs simply replicate statistical patterns without meaningful human creative contribution, leaving them ineligible for copyright protection. Developers should not assume that large or expensive synthetic datasets are automatically protected. To secure such copyright protection, it is necessary to clearly document the human creative decisions involved in designing or curating the synthetic data.

Compliance considerations

Synthetic data should not be presumed to fall outside privacy regulation. Under laws such as the EU’s General Data Protection Regulation and Thailand’s Personal Data Protection Act, information still qualifies as personal data if it relates directly or indirectly to an identifiable individual. Synthetic data may still fall within this scope when it is:

  • Generated from real individuals’ records,
  • Capable of being linked to a person when combined with other available information, or
  • Structured in a way that allows specific traits or behaviors of an individual to be inferred.

In these situations, regulators are likely to treat the synthetic dataset as containing personal data, meaning full compliance obligations still apply.

Ensuring true anonymization is technically challenging. Studies have repeatedly shown that even heavily anonymized datasets can be re-identified with the original individuals with high accuracy using only a few demographic attributes such as age, gender, and ZIP code. The same risks apply to synthetic datasets that replicate the structure of real-world data, especially in domains involving rare characteristics.

Therefore, anonymization cannot be treated as a single, conclusive action. As computational methods advance, datasets considered anonymous today may become identifiable tomorrow. Synthetic data remains a valuable tool, but organizations should deploy it with a realistic understanding of these evolving risks.

 

This article was originally published by Dow Jones Risk Journal in April 2026.

RELATED INSIGHTS​ 

December 15, 2023
Vietnam’s new Law on Electronic Transactions No. 20/2023/QH15 (LOET 2023) was promulgated by the National Assembly on June 22, 2023, and will replace the existing Law on Electronic Transactions No. 51/2005/QH11 (LOET 2005) when it enters into effect on July 1, 2024. The LOET 2023 is aimed at facilitating transactions carried out in an electronic environment in all sectors. Derived from the fundamental principles of the LOET 2005, the LOET 2023 is similarly considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). The main points of interest of the LOET 2023 are summarized below. 1. Scope of Application Unlike the LOET 2005, which explicitly excludes certain areas such as the issuance of certificates of land use rights and birth certificates from the scope of application, the LOET 2023 covers all areas without exception. However, the LOET 2023 will still not interfere with the regulations of substantive laws that stipulate the content, conditions, and forms of transactions in their respective areas (Article 1.2). The LOET 2023 also provides that it will only be applicable if other laws either allow or remain silent on the electronic execution of transactions; otherwise, if another law specifically does not permit a transaction to be carried out electronically, such law shall apply (Article 1.3). This emphasizes that the applicability of the LOET 2023 depends on the electronic readiness of specific sectors. 2. Enabling E-Transactions in All Sectors For traditional transactions or contracts to be legally valid, they typically require written documentation, the signatures of the involved parties, and the seals of organizations or companies, if required by substantive laws or common practice. Additionally, certain sectors mandate further steps like notarization or certification, such as in property transactions like house sales or inheritance
December 8, 2023
In a significant development on December 5, 2023, the Central Bank of Myanmar (CBM) issued Letter No. FE-1/2937 granting authorized dealer licensed banks (ADLBs) the authority to freely transact in foreign currency trades, buying and selling at the market exchange rate for Myanmar kyat (MMK) as proposed by buyers and sellers through online trading platforms. Offshore remittances, however, must comply with the remittance criteria set by the Foreign Exchange Supervisory Committee. The online trading platform Refinitiv, initiated in June 2022 under the CBM’s guidance, facilitates the buying and selling of foreign currency between ADLBs and between banks and customers. The initiative was implemented in accordance with CBM Letter No. FE-1/789, dated June 21, 2023. The platform’s inception saw the exchange rate set at over MMK 2,900 per USD 1. Then, in August 2023, the CBM ordered banks and traders to limit foreign exchange transactions to an approved online trading platform, again with the exchange rate fixed at MMK 2,900 per USD 1. Transactions outside of online trading platforms continue to be governed by the exchange rate set by the CBM of 2,100 MMK per USD 1. Conversion Rules for Exporters On December 6, 2023, the CBM issued Notification No. 26/2023 lowering the percentage of Myanmar companies’ export earnings in foreign currency subject to mandatory conversion into MMK from 50% to 35% at the current official exchange rate set by the CBM at USD 1 to MMK 2,100. This mandatory conversion must follow the requirements for mandatory conversion of foreign currency, which remain in effect. For more details on foreign exchange developments, or on any aspect of financial regulations in Myanmar, please contact Tilleke & Gibbins at [email protected].
November 27, 2023
The emergence of generative artificial intelligence (AI) has transformed the landscape for innovators and creators. As many legal practitioners have pointed out, it’s imperative for both developers of AI and artists using generative AI to understand the intricacies of intellectual property (IP) strategies so they can navigate this evolving terrain successfully. This article lays out some essential considerations relating to the major types of IP for both developers and creators in the realm of generative AI. IP Strategies for Developers of Generative AI Developers of generative AI technologies play a pivotal role in the innovation landscape. There are three overarching IP-related issues to consider: protecting their own intellectual property, mitigating the risk of violating other people’s IP rights, and IP commercialization. Key aspects of these concerns, along with suggested approaches for developers, are outlined below. Protecting IP Copyrights. One of the primary considerations for AI developers is the protection of AI-generated works, such as art and source code. The good news is that in most countries, these creations enjoy copyright protection without the need for registration. As a result, the works are automatically protected from the moment of creation. However, it’s crucial to maintain comprehensive records of your work to establish your ownership. Trademarks. Trademarks are vital for AI developers looking to establish and protect their brand. Pay close attention to Nice classifications, particularly class 9 (for software), class 35 (for business management and online marketing), and class 42 (for software design and development). Registering trademarks in these classes can provide robust protection for your brand and products. Patents. For truly innovative AI algorithms, techniques, or processes, consider the option of patenting. Patents offer strong protection, but they require a thorough application process and the documentation of your innovation, including evidence that the invention is novel, non-obvious, and practically
November 27, 2023
Thailand’s Electronic Transaction Development Agency (ETDA) has released two new subordinate regulations under the Royal Decree on Digital Platform Services: one detailing the assessment of digital platform services (DPSs) that will be deemed “high-risk” and subject to additional obligations, and another setting guidelines on user verification and authentication for all DPSs. The two subordinate regulations are summarized below. Impact Assessment of DPS Operations Under the Royal Decree on Digital Platform Services, DPS operations that have the risk of seriously impacting financial and commercial security, reliability and credibility of data message systems, or the general public are subject to additional obligations. The first subordinate regulation mentioned above (officially titled Notification of the Electronic Transactions Commission Re: Criteria for Impact Assessment on Operation of Digital Platform Services) outlines the criteria for the ETDA to determine which DPSs are “high-risk.” DPSs falling under this designation include: DPSs whose total value of transactions conducted through the platform in Thailand exceeds THB 100 million (approx. USD 2.8 million) per year; DPSs whose operators have not registered their entities with the Department of Business Development (DBD)—notably overseas operators—and that have 100 or more merchants or business users in Thailand or total users in Thailand between 5 and 10 percent of the country’s population (i.e., approx. 3.3–6.1 million users, calculated using official 2022 figures); DPSs that allow their users to freely post certain messages, or do certain acts, that may affect the public in certain cases, such as: (1) unlawful messages or acts; (2) messages or acts that may affect a child’s rights or people’s fundamental rights; and (3) messages or acts that may negatively affect political opinions of Thai citizens (whether before or after an election) or statements or actions likely to negatively affect other individuals due to gender differences or sexual violence. After considering