CrawlCheck

Glossary · area 18 of 19

Governance and rights

Who may use content for what: rights reservations, opt-outs, licences, model documentation and the accountability vocabulary around them.

30 terms. Each opens its own page with what it can and cannot support, how the scanner measures it, and where it comes up in the guides.

30terms in this area
1with a live finding rate

Text and data mining

Automated analysis of digital text and data to generate information such as patterns, trends, and correlations. Depending on jurisdiction and material, access does not automatically settle reproduction or extraction rights.

Rights reservation

A rightsholder’s expression that specified uses are not authorized under an otherwise available exception or default. Its legal effect depends on jurisdiction, scope, and appropriate communication.

Machine-readable opt-out

A structured signal reserving rights or requesting exclusion from an automated use. It supports detection by systems that read it; it does not technically prevent copying.

Measured: AI_OPTOUT_SET 6.3%

Usage preference

A machine-readable statement of desired conditions for collection, training, retrieval, or other processing. Preference is not authentication, authorization, licensing, or enforcement.

Content-Usage header

A proposed HTTP response header associating AI-use preferences with delivered content. Draft status and voluntary implementation prevent it from functioning as universal control.

AI training license

Permission defining whether and how content may be used to train models. A crawler’s technical access does not establish that a license exists.

Dataset license

Terms governing use, modification, redistribution, or commercial exploitation of a dataset. It may not clear rights in every underlying work or personal record.

Open license

Standardized permission allowing specified reuse under stated conditions. “Open” does not always mean unrestricted, public domain, attribution-free, or suitable for model training.

Public domain

Material not protected by copyright or whose copyright has expired under the applicable law. Status can differ by jurisdiction, edition, restoration, and incorporated material.

Fair use

A United States doctrine evaluating unlicensed use through context-specific statutory factors. It is a legal defense or limitation, not a crawler setting or automatic category.

Transformative use

A fair-use consideration asking whether a use adds a different purpose, character, or meaning. Technical transformation alone does not settle the legal analysis.

Training-data summary

A public description of the main content and sources used to train a general-purpose AI model under the EU framework. It is a summary obligation, not a file-by-file disclosure.

General-purpose AI model

An AI model with significant generality that can competently perform a wide range of tasks and integrate into downstream systems. The legal definition is not interchangeable with every generative model.

Foundation model

A broadly trained model adaptable to many downstream tasks. The term describes role and training breadth, not a single architecture, legal category, or safety level.

Systemic risk

Risk at broad scale arising from highly capable or widely deployed AI systems. A legal designation depends on the governing framework rather than ordinary software severity labels.

Model card

Documentation describing a model’s intended uses, limitations, evaluation, and other relevant facts. It is publisher disclosure and should not be treated as independent audit evidence.

Data sheet

Structured documentation of how a dataset was created, composed, processed, and intended to be used. Missing records cannot be reconstructed merely by documenting the final dataset.

Data lineage

The recorded path of data through sources, transformations, versions, and destinations. It supports accountability only when transformations and identifiers are captured consistently.

Lawful basis

The legal justification relied upon for processing personal data under an applicable privacy regime. Business usefulness alone is not a lawful basis.

Data controller

The party determining purposes and essential means of personal-data processing under privacy law. Contract labels do not override the party’s actual role.

Data processor

A party processing personal data on behalf of a controller. A processor can become a controller for uses it independently determines.

Subprocessor

Another processor engaged by a processor to handle personal data. A public vendor list supports transparency but does not demonstrate compliant processing.

Algorithmic transparency

Disclosure enabling affected parties to understand system purpose, inputs, governance, or behavior. Publishing source code is neither always required nor sufficient for meaningful transparency.

Explainability

Methods or disclosures intended to make a model output or system decision understandable. An explanation can be useful without being a faithful account of internal causation.

Accountability

Assignment of responsibility for system decisions, controls, evidence, and remediation. Logging an action does not identify who had authority or duty to prevent it.

Risk assessment

A documented evaluation of foreseeable harms, likelihood, impact, and controls. It is a decision aid rather than proof that residual risk is acceptable.

Impact assessment

A structured examination of how a system affects people, rights, operations, or environments. Its quality depends on affected groups, evidence, and follow-up rather than template completion.

Red teaming

Adversarial testing designed to expose failures, misuse, or control weaknesses. It samples attack space and cannot certify that no undiscovered vulnerability remains.

← Security and privacy  ·  Accessibility and provenance →

All 668 terms across 19 areas.