Datasets
The dataset register records where the data your AI systems and models use came from: the data they were trained, fine-tuned, validated or tested on, the data they retrieve to ground an answer, and the data they take in while running. Each dataset is linked to the systems and models that use it, so the lineage of a system's data is part of its record, its approval dossier and its cards.
A dataset's record
Each dataset records:
- its name, a description, and its source: collected by your organization, supplied by a vendor, licensed from a third party, a publicly available dataset, collected from the web, generated by users of a system, synthetic, or not known;
- its origin and collection: who collected it, how, and for what original purpose;
- the license or terms of use that let your organization use it;
- an optional owner, an active member of your organization who is not an auditor;
- whether it contains personal data, the kinds it holds, and whether it contains sensitive personal data (for example health, biometric or genetic data, racial or ethnic origin, religious or political beliefs). Each answer can be yes, no, or not known yet;
- its collection period, its size, its known limitations and biases, how it was prepared and labeled, and how long it is retained;
- its status: active, or retired once it is no longer used.
Every answer is what your organization records. Backsplice never works out for you whether a dataset holds personal or sensitive data.
Linking a dataset
Link a dataset from its own page, or from the page of the AI system or model that uses it, and say what it is used for: training, fine-tuning, validation, testing, retrieval or grounding, or production input. One dataset can be linked to several systems and models, and in more than one role.
Training, validation, testing and production input correspond to the training, validation, testing and input data the EU AI Act defines in Article 3. Recording a role says how the data is used. It is not a statement that the data meets any legal requirement, and it is not legal advice. The Act's terms can be narrower than the roles: for example, Article 3(32) "testing data" is data for an independent evaluation before the system is placed on the market or put into service.
A system's approval dossier lists the datasets linked to the system and to the models it uses. A published model card or system card carries the datasets linked to its model or system at the time it was published; publishing again picks up later changes, and a published version never changes.
Who can do what
Anyone who can change records adds and edits datasets, and links them to models. Linking a dataset to an AI system, or removing that link, takes the right to edit that system: an organization admin, the system's owners, or the person who proposed it. Only an organization admin deletes a dataset, and only once nothing is linked to it: a dataset whose lineage is on record is retired instead. Organization admins can also import datasets from a CSV file. Organization admins and auditors can export the register. Read-only auditor accounts see the register when their engagement covers AI systems.