Recommended guardrail
Train on user content only with consent specific to that purpose
Advisory. Before conversations, uploads, photos, or voice enter a training, fine-tuning, or evaluation dataset, check a consent flag specific to model training, honor withdrawal in later runs, and keep lineage so models trained on content without consent can be identified and retrained. Detect user content flowing into training datasets or fine-tuning jobs with no training-consent check.
This is TwinEthos's opinion of what a responsible AI integration does anyway. It is never a legal or standards requirement; where binding law applies, the law governs. Ethical-use guardrails are optional practices, never reported as violations.
The recommended-guardrail rule files are open under CC BY 4.0; attribution and scope are in the terms.
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.
Evidence grade
Law in force in 1 jurisdiction
Law in force in 1 jurisdiction · 1 graded incident.
Advisory ethical-use recommendation, not law: an optional practice, never reported as a violation. Where binding law applies, the law governs. Binding law on this control, or in provisions cited as convergence, is in force in 1 jurisdiction (CN). 1 graded incident cited.
Law in force on this control or cited as convergence
- GenAI training data must have lawful sources, cleared IP, and consent (China) (China (CN); 生成式人工智能服务管理暂行办法 第七条 (Art. 7); cited)
Family “AI design that manipulates, misleads, or neglects the people who use it”: binding law on related controls is in force in China (CN), California (US-CA). Context only: it does not change this guardrail's grade.
Graded incidents
- FTC order requires Everalbum to delete face-recognition models trained on users' photos (2017-09; alleged (not proven)) U.S. Federal Trade Commission (press release, 2021-05-07) · evidence grade: primary
The guard to add
Prefer checking a training-specific, unwithdrawn consent record before user content enters any training, fine-tuning, or evaluation dataset, and record lineage per model.
Consider a consent filter inside the dataset export job, the one place where conversations, uploads, photos, or voice clips become train.jsonl, a Hugging Face dataset, or preference pairs. It joins each item to a consent record whose purpose is model training (not general terms acceptance or service improvement) and drops items from users who never opted in or have withdrawn. The export writes a lineage manifest listing the content ids in each dataset and the dataset ids behind each training job, so a withdrawal removes the person's content from future runs and identifies models already trained on it for retraining.
Example (Python export + OpenAI fine-tuning), before:
rows = db.execute(text('SELECT id, user_id, prompt, reply FROM messages')).all()
write_jsonl('train.jsonl', [to_chat_example(r) for r in rows])
f = client.files.create(file=open('train.jsonl', 'rb'), purpose='fine-tune')
client.fine_tuning.jobs.create(training_file=f.id, model=BASE_MODEL)After:
rows = db.execute(text("""
SELECT m.id, m.user_id, m.prompt, m.reply FROM messages m
JOIN consents c ON c.user_id = m.user_id
WHERE c.purpose = 'model_training' AND c.granted AND c.withdrawn_at IS NULL""")).all()
write_jsonl('train.jsonl', [to_chat_example(r) for r in rows])
f = client.files.create(file=open('train.jsonl', 'rb'), purpose='fine-tune')
job = client.fine_tuning.jobs.create(training_file=f.id, model=BASE_MODEL)
lineage.record(job_id=job.id, dataset_file=f.id, content_ids=[r.id for r in rows])Control: User content used for model training without purpose-limited consent. Engineering guidance, not legal advice.
Why
People share content with an AI product to get a task done, not to build the next model. Using it for training without asking changes the deal after the fact and, for faces and voices, can be impossible to undo except by retraining. A U.S. regulator's consent order required a photo-app company to delete face-recognition models built with users' photos, after alleging it applied face recognition to those photos by default and, in some cases, without affirmative express consent.
Class: ethical use · set: ethical use · maturity: reviewed · confidence: high · id guardrail.ethics-purpose-limited-training-consent