artifacts/standard-named

Consentfully Trained Models

artifacts/standard-named/20260715__TELIC-FIELDS__PAPER__CANDIDATE__F-11__consentfully-trained-models.md

Rendered from markdown source. Open raw source on GitHub.

--- title: "Consentfully Trained Models" subtitle: "Source Standing, Recruitment, Preference Aggregation, Withdrawal, Benefit, and Deployment" artifact_date: "2026-07-15" artifact_type: "candidate-foundational-paper" domain: "TELIC-FIELDS" scope: "WORKING" lineage: "THE-TELIC-FIELD-PAPERS" status: "candidate" processing_tier: 4 source_role: "derived-conceptual-artifact" content_canon_status: "unset" publication_status: "unpublished" series_position: "F.11" derived_from:

  • "20260714__TELIC-FIELDS__PAPER__CANDIDATE__F-4__telic-projection-estimation.md"
  • "20260714__TELIC-FIELDS__PAPER__CANDIDATE__F-6__temporal-telic-relations.md"
  • "20260715__TELIC-FIELDS__PAPER__CANDIDATE__F-7__dependent-loops-and-telic-incompatibility.md"
  • "20260715__TELIC-FIELDS__PAPER__CANDIDATE__F-8__semantic-fields-as-durable-telic-trails.md"
  • "20260715__TELIC-FIELDS__PAPER__CANDIDATE__F-10__semantic-polytelometry-with-language-models.md"

research_companion:

  • "20260715__TELIC-FIELDS__REVIEW__WORKING__G-12__training-data-preference-aggregation-constitution-and-model-governance.md"

provenance_note: > Consentfully trained is a candidate governance classification, not a binary technical property and not a claim that every training source can or should be governed through individual consent. The paper distinguishes individual, collective, legal, contractual, public-interest, community, and institutional authority while preserving the right to refuse where applicable. ---

Consentfully Trained Models

Abstract

Model training recruits semantic traces, labor, classifications, judgments, compute, institutions, and communities into an outer loop whose later capabilities and uses may be difficult to predict. Public availability, technical accessibility, copyright permission, contractual license, research consent, privacy authorization, community governance, and moral legitimacy are related but nonidentical. A model can be legally trained while remaining nonconsensual to its sources. A model can be consentfully trained for one purpose and later deployed outside that purpose. A model can be trained on carefully authorized data and then operated through hidden provider teloi. Consentful training and consentful operation are therefore distinct requirements.

This paper defines a consentfully trained model as a model whose training lineage preserves adequate authority, provenance, purpose, standing, withdrawal terms, transformation limits, and benefit obligations for the data, labor, judgments, and communities recruited into the model-development loop. The definition is deliberately plural. Some sources are governed by individual consent. Others are governed through license, public law, research ethics, community authority, fiduciary stewardship, contract, collective governance, or public-interest mandate. No one mechanism resolves every training context.

The paper develops a training-recruitment chain from source creation through collection, aggregation, preprocessing, labeling, preference capture, optimization, evaluation, release, deployment, derivative training, and succession. It distinguishes access from permission, permission from consent, consent from legitimacy, provenance from compliance, preference aggregation from shared human values, deletion from unlearning, and unlearning from verified removal of influence. It addresses RLHF, DPO, RLAIF, constitutions, disagreement, opt-out signals, collective data governance, benefit sharing, synthetic data, model collapse, model and provider succession, and public-interest training.

The governing formulations are:

Consentful provenance in. Consentful interpretation out.

A system cannot consentfully map telic fields while its own field remains hidden, unaccountable, and non-consensual.

The governing boundary is:

Consentful operation does not retroactively make unconsented training consentful. Consentful training does not guarantee consentful deployment.

---

1. Training is recruitment

Training is commonly described as learning patterns from data.

That description is technically useful and constitutionally incomplete.

The training loop recruits:

  • authored expression;
  • recorded behavior;
  • cultural inheritance;
  • private or public records;
  • labels;
  • preference judgments;
  • moderation labor;
  • expert evaluation;
  • community knowledge;
  • institutional classifications;
  • public infrastructure;
  • energy;
  • compute;
  • environmental capacity.

These inputs become part of a system whose outputs may later:

  • generate language;
  • classify people;
  • automate work;
  • mediate decisions;
  • compete with sources;
  • alter markets;
  • replace direct consultation;
  • preserve or erase cultural patterns;
  • produce new training data.

The model does not merely consume a dataset.

A larger loop recruits prior semantic trails into a new capacity.

Training is a transfer of semantic and material capacity into an outer loop.

The legitimacy of that transfer cannot be inferred from technical access alone.

---

2. The training-recruitment chain

A model's training lineage may include:

source creation
→ publication or storage
→ collection or acquisition
→ aggregation
→ cleaning and filtering
→ transformation
→ annotation or labeling
→ preference capture
→ training
→ evaluation
→ model release
→ deployment
→ output capture
→ derivative training
→ succession or dissolution

Different authorities may govern each transition.

A person may consent to:

  • publication;

without consenting to:

  • bulk collection;
  • model training;
  • commercial reuse;
  • identity inference;
  • output imitation;
  • permanent retention.

A worker may consent to:

  • provide rankings for model quality;

without authorizing:

  • those rankings to be treated as universal human values.

A community may permit:

  • research access;

without permitting:

  • open model release;
  • commercial derivative models;
  • public reproduction of protected knowledge.

The training record should therefore preserve transition-specific authority.

---

3. Access, permission, consent, and legitimacy

These terms should remain separate.

3.1 Access

The source can be technically obtained.

3.2 Legal permission

Law, exception, ownership, or license may permit a use.

3.3 Contractual permission

An agreement may authorize specified processing.

3.4 Individual consent

A person knowingly and voluntarily authorizes a scoped use where consent is the appropriate basis.

3.5 Collective or community authority

A legitimate group or institution governs data whose meaning, risk, or benefit is collective.

3.6 Public-interest authority

A lawful public or research mandate may authorize processing subject to safeguards.

3.7 Legitimacy

The use preserves standing, proportionality, accountability, purpose, and repair strongly enough to deserve continuation.

The relations are not identities:

accessible ≠ permitted
permitted ≠ consented
consented ≠ legitimate in every downstream use
documented ≠ authorized
public ≠ ownerless

Consent is not always the correct legal or ethical basis.

But where consent is claimed, it must be real rather than inferred from silence, friction, or availability.

---

4. Source standing

A training source can carry standing even when it is not a conventional data subject.

Relevant centers may include:

  • an individual author;
  • a person represented in a record;
  • a worker who created labels;
  • a community whose knowledge is encoded;
  • an institution responsible for a public archive;
  • a group exposed by collective inference;
  • a cultural tradition;
  • a rights holder;
  • future users affected by model behavior.

Source standing does not imply absolute control over every later idea.

Language and knowledge are relational and cumulative.

The governance question is narrower:

Which source interests remain material to this collection, transformation, training purpose, release method, and downstream capability?

Standing may include:

  • privacy;
  • attribution;
  • compensation;
  • cultural authority;
  • confidentiality;
  • noncommercial restriction;
  • purpose limitation;
  • correction;
  • withdrawal;
  • collective benefit;
  • protection from harmful imitation;
  • continued access to one's own data.

---

5. Individual and collective standing

Individual consent is often inadequate for data that is relational or collective.

Examples include:

  • genetic data;
  • household data;
  • tribal and Indigenous data;
  • location patterns;
  • language resources;
  • community health data;
  • social graphs;
  • cultural archives;
  • workplace records;
  • group-level profiling.

One person's disclosure can expose others.

One rights holder may lack authority to release collective knowledge.

A community governance mechanism may therefore be necessary.

The CARE Principles for Indigenous Data Governance are especially important because they center:

  • Collective Benefit;
  • Authority to Control;
  • Responsibility;
  • Ethics.

These principles demonstrate that data governance can be oriented around peoples and purposes rather than data availability alone.

Individual consent cannot authorize what the individual does not legitimately own or represent.

---

6. Purpose

A training purpose should be stated at a level that constrains action.

Statements such as:

improve AI
research
provide services
enhance safety

are usually too broad to govern a long-lived foundation model.

A purpose record should identify:

  • model class;
  • capability class;
  • intended domains;
  • commercial or public use;
  • access model;
  • foreseeable high-risk uses;
  • training and fine-tuning;
  • output retention;
  • derivative models;
  • research release;
  • security and safety testing;
  • prohibited uses;
  • review triggers.

Purpose can change.

A changed purpose requires:

  • renewed authority;
  • updated documentation;
  • affected-center review;
  • withdrawal or restriction where feasible;
  • benefit and risk reassessment.

A model trained under one purpose should not inherit unlimited authority because retraining is expensive.

---

7. Training consent

Training consent should answer:

what source is used
which transformation occurs
which model or model class receives it
for which purpose
under which access regime
for how long
with which derivative uses
with what attribution or benefit
with what withdrawal route
with what known technical limits

Consent should not promise control the system cannot provide.

If exact removal after training is not technically available, that limit should be disclosed before contribution.

A consent request that says:

You can delete your data at any time

is misleading when deletion removes the source record but not model influence.

The truthful statement may be:

We can stop future use and delete identifiable source copies. We may not be able to prove complete removal of learned influence without retraining or a validated unlearning process.

Truthful limitation is part of consent.

---

8. Other authority bases

Some legitimate training will not depend on individual opt-in consent.

Examples may include:

  • public-domain material;
  • licensed works;
  • government records under public mandate;
  • scientific data governed by research ethics;
  • organizational data governed by contract and role;
  • data governed by a cooperative or trust;
  • legally authorized statistical or safety analysis;
  • community-authorized archives.

A consentful model framework should therefore use the broader term:

training authority.

Candidate authority classes include:

INDIVIDUAL CONSENT
COLLECTIVE AUTHORITY
COMMUNITY GOVERNANCE
CONTRACT
LICENSE
PUBLIC DOMAIN
PUBLIC MANDATE
RESEARCH ETHICS AUTHORIZATION
FIDUCIARY STEWARDSHIP
STATUTORY AUTHORITY
LEGITIMATE INTEREST OR OTHER LEGAL BASIS
UNKNOWN
CONTESTED

The framework should never relabel every authority as consent.

That would make consent meaningless.

---

9. Dataset provenance

Dataset provenance should preserve:

  • original source;
  • collector;
  • acquisition method;
  • date;
  • license;
  • consent or authority basis;
  • transformations;
  • filtering;
  • deduplication;
  • annotation;
  • aggregation;
  • dataset parentage;
  • known disputes;
  • restrictions;
  • withdrawal signals;
  • downstream models.

The Data Provenance Initiative found widespread missing and inaccurate license information across audited AI datasets.

This is not a minor documentation problem.

License and source errors propagate through:

  • dataset combinations;
  • fine-tuning collections;
  • model releases;
  • derivative datasets;
  • evaluation corpora.

A model lineage should be able to distinguish:

source known
license known
authority known
consent known
restrictions known
verification status

Unknown should remain a first-class value.

---

10. Documentation

Datasheets for Datasets propose documentation of:

  • motivation;
  • composition;
  • collection;
  • preprocessing;
  • uses;
  • distribution;
  • maintenance.

Data Statements emphasize social and demographic context for language data.

Dataset Nutrition Labels provide modular contextual and diagnostic information.

Model cards and system cards extend documentation into model and deployment layers.

These mechanisms are valuable.

They remain insufficient when they are:

  • optional;
  • incomplete;
  • stale;
  • unaudited;
  • disconnected from action;
  • unable to propagate corrections;
  • unable to express collective authority.

A consentful training record should link dataset documentation to executable use restrictions and downstream lineage.

---

11. Preprocessing is governance

Preprocessing is not a neutral technical interval.

It decides:

  • which sources remain;
  • which languages survive;
  • which duplicates count;
  • which material is toxic;
  • which identifiers are removed;
  • which classes are balanced;
  • which labels become ground truth;
  • which cultural context is stripped;
  • which opt-outs persist.

A filter can protect privacy.

It can also erase minority language.

Deduplication can reduce memorization.

It can also remove repeated community emphasis as though repetition were noise.

Normalization can improve training.

It can also collapse meaningful variation.

Every material transformation should preserve:

  • purpose;
  • rule;
  • model or person responsible;
  • version;
  • known effect;
  • affected source classes.

---

12. Annotation and labor

Training data often depends on human labor for:

  • labeling;
  • ranking;
  • red teaming;
  • moderation;
  • correction;
  • taxonomy;
  • domain expertise;
  • safety evaluation.

The labeler is not merely a sensor for objective truth.

The labeler contributes:

  • judgment;
  • culture;
  • emotional labor;
  • expertise;
  • values;
  • attention;
  • risk.

A consentful training process should govern:

  • fair compensation;
  • working conditions;
  • psychological safety;
  • task transparency;
  • downstream use;
  • attribution where appropriate;
  • confidentiality;
  • dispute;
  • ability to refuse harmful tasks;
  • representation of disagreement.

A model trained through exploited labor is not made consentful by clean dataset licenses.

---

13. Preference data

Preference data can include:

  • demonstrations;
  • rankings;
  • comparisons;
  • ratings;
  • critiques;
  • chosen and rejected outputs;
  • constitutional judgments.

A preference label is scoped.

It may reflect:

  • one annotator;
  • one policy;
  • one language;
  • one task;
  • one institutional objective;
  • one demographic;
  • one moment.

Preference aggregation creates an operative reward signal or policy direction.

It does not discover one universal human preference.

Preference data is a projection of judgment under a task, not a sample from a single human telos.

The record should preserve:

  • who labeled;
  • task wording;
  • alternatives shown;
  • policy;
  • disagreement;
  • confidence;
  • adjudication;
  • aggregation method;
  • excluded populations.

---

14. RLHF

Reinforcement learning from human feedback commonly includes:

  1. supervised demonstrations;
  2. ranked model outputs;
  3. a learned reward model;
  4. policy optimization against the reward model.

RLHF can improve model behavior relative to target evaluations.

Its constitutional questions include:

  • Which humans?
  • Selected by whom?
  • Under which policy?
  • Which disagreements were averaged?
  • What reward-model errors remain?
  • Which provider telos shaped the task?
  • What behavior becomes less likely because it is less preferred by the evaluator population?

Human feedback is not human consent.

Nor is it humanity's collective will.

---

15. Direct preference optimization

Direct Preference Optimization optimizes a policy directly from chosen and rejected outputs without separately fitting and using a reward model in the standard RLHF pipeline.

The method simplifies optimization.

It does not remove governance questions.

DPO still depends upon:

  • preference-data source;
  • task framing;
  • chosen alternatives;
  • reference model;
  • aggregation;
  • coverage;
  • disagreement;
  • policy objective.

A simpler optimization pipeline can make provenance easier to inspect.

It does not make the preferences more representative or legitimate.

---

16. RLAIF and Constitutional AI

Reinforcement learning from AI feedback uses model-generated preferences or evaluations.

Constitutional AI provides an influential example in which:

  • human-written principles guide model critique and revision;
  • AI feedback produces preference data;
  • the model is trained from those preferences.

This reduces the need for direct human labels at every example.

It moves governance upward into:

  • constitution selection;
  • principle interpretation;
  • critique model;
  • preference model;
  • training process.

The constitutional questions become:

Who authored the principles?
Who may revise them?
Whose standing do they protect?
Which conflicts do they conceal?
How are minority interpretations represented?
What happens when principles conflict?

A constitution is not legitimate merely because it is explicit.

It becomes governable because it is explicit.

---

17. Preference aggregation and disagreement

Aggregating preferences can erase disagreement.

Methods may use:

  • majority choice;
  • average score;
  • pairwise model;
  • adjudicator;
  • policy hierarchy;
  • filtered consensus;
  • constitutional priority;
  • demographic reweighting.

Each method embeds a social-choice rule.

A consentful system should preserve:

  • distribution of judgments;
  • minority views;
  • protected objections;
  • adjudication;
  • uncertainty;
  • population coverage;
  • known value conflict.

The output may be:

CONSENSUS
MAJORITY
POLICY-SELECTED
CONTESTED
CULTURE-SPECIFIC
DOMAIN-SPECIFIC
UNKNOWN

The reward model should not present a disputed judgment as universal preference.

---

18. Constitutions and standing

A model constitution can protect centers not present in the immediate training or deployment interaction.

Examples include:

  • children;
  • nonusers;
  • targets of abuse;
  • vulnerable populations;
  • public safety;
  • privacy;
  • creators;
  • workers;
  • future users.

The constitution may legitimately constrain a user's request.

Its authority should still be legible.

A model should not say:

I independently believe this is wrong

when the operative reason is:

The provider constitution prohibits this action to protect specified standing.

The distinction matters for contest, trust, and revision.

---

19. Opt-in, opt-out, and refusal

Training participation can be governed through:

  • explicit opt-in;
  • contractual license;
  • public mandate;
  • opt-out;
  • technical exclusion signal;
  • community decision;
  • refusal;
  • no practical choice.

Opt-out is weaker when:

  • the source does not know collection is occurring;
  • signals are fragmented;
  • the burden is repeated across crawlers;
  • prior copies already exist;
  • downstream datasets lose the signal;
  • model influence cannot be removed;
  • refusal destroys access to essential services.

Robots exclusion signals can govern crawling behavior.

They do not by themselves express every downstream training, retrieval, summarization, or commercial-use condition.

Consentful infrastructure requires machine-readable, persistent, and lineage-preserving restrictions.

---

20. Withdrawal

Withdrawal may apply at several layers.

20.1 Collection withdrawal

Stop collecting new material.

20.2 Dataset withdrawal

Remove or restrict source copies in the dataset.

20.3 Future-training withdrawal

Exclude the source from future runs.

20.4 Model-release withdrawal

Restrict release or distribution of a model trained on the source.

20.5 Inference withdrawal

Stop using the source or projection at runtime.

20.6 Model-influence withdrawal

Remove learned influence from existing models.

These are not equivalent.

A system should state which withdrawal it supports.

The word delete should never conceal the difference.

---

21. Machine unlearning

Machine unlearning seeks to remove the contribution of specified data from a trained model.

Approaches include:

  • exact retraining or exact unlearning under special architectures;
  • approximate unlearning;
  • parameter updates;
  • representation editing;
  • partitioned training;
  • certified removal;
  • output suppression.

Evaluation is difficult.

A model may stop producing a memorized passage while retaining:

  • indirect knowledge;
  • latent associations;
  • privacy leakage;
  • effects on related concepts.

Unlearning may also degrade retained utility.

Current LLM unlearning benchmarks and methods remain limited.

A consentful system should disclose:

source deleted
future training stopped
approximate unlearning attempted
verification method
known residual access
utility degradation
retraining status

Withdrawal is a governance right. Complete model unlearning is a technical capability that must not be promised beyond evidence.

---

22. Verification

An unlearning claim should be independently testable.

Candidate evidence includes:

  • comparison with retraining baseline;
  • membership-inference tests;
  • extraction tests;
  • knowledge probes;
  • privacy leakage tests;
  • retained-utility tests;
  • sequential-request tests;
  • model and checkpoint hashes;
  • method and benchmark disclosure.

No finite test proves absence of every influence.

The system should describe:

  • what was tested;
  • what was not;
  • threshold;
  • adversary model;
  • residual uncertainty.

Verified limited removal is more trustworthy than absolute undocumented deletion language.

---

23. Synthetic data

Synthetic data can:

  • expand coverage;
  • reduce collection cost;
  • improve privacy in some settings;
  • support rare cases;
  • enable simulation;
  • transmit constitutions or preferences.

It can also:

  • reproduce source bias;
  • obscure provenance;
  • amplify model errors;
  • create circular evaluation;
  • crowd out human traces;
  • turn model outputs into apparently independent evidence.

Synthetic does not mean unowned, unbiased, or consent-free.

A synthetic record should preserve:

  • generating model;
  • source lineage;
  • prompt or policy;
  • filtering;
  • intended use;
  • relationship to real persons;
  • privacy evaluation;
  • contamination risk.

---

24. Recursive training and model collapse

Repeated training on model-generated outputs can distort the represented distribution, especially when synthetic data replace rather than supplement original human data.

Research on model collapse identifies risks including loss of distributional tails and progressive degradation under some recursive regimes.

Other work shows that retaining and accumulating real data can substantially change the outcome and avoid collapse in studied settings.

The constitutional issue is larger than average performance.

Tail loss may erase:

  • rare language;
  • minority expression;
  • unusual experience;
  • dissent;
  • low-frequency but high-stakes patterns.

Synthetic-data governance should therefore preserve the source contribution and diversity needed to prevent semantic recursion from becoming semantic enclosure.

---

25. Copyright and license

Copyright and licensing govern some training sources.

They do not exhaust source standing.

A licensed source may still raise:

  • privacy;
  • confidentiality;
  • community authority;
  • moral rights;
  • labor;
  • attribution;
  • purpose;
  • harmful downstream use.

An unlicensed source may in some jurisdictions be lawfully used under an exception or limitation.

Legal status is jurisdiction-specific and changing.

The paper makes no universal legal conclusion about whether model training is fair use, text-and-data mining, reproduction, or infringement.

Its governance claim is:

A system should preserve the source, jurisdiction, license, restriction, dispute, and legal theory upon which training relies.

Unknown and contested status should remain visible.

---

26. Public data

Public data may include:

  • government records;
  • scientific publications;
  • public websites;
  • open-source repositories;
  • public-domain works;
  • openly licensed datasets.

Public accessibility can serve important social purposes.

It does not mean:

  • unrestricted reuse;
  • perpetual purpose;
  • absence of privacy;
  • absence of community rights;
  • permission to infer sensitive traits;
  • removal of attribution.

A public-interest model may have stronger grounds to use public data than a hidden commercial model.

That difference should be represented through purpose, benefit, access, and governance—not merely asserted.

---

27. Data trusts, cooperatives, and commons

Collective data institutions can provide alternatives to one-time individual consent.

Possible structures include:

  • data trust;
  • data cooperative;
  • data commons;
  • data union;
  • public data institution;
  • community archive;
  • tribal or Indigenous governance body.

These structures may govern:

  • access;
  • licensing;
  • contribution;
  • purpose;
  • benefit;
  • research review;
  • withdrawal;
  • representation;
  • enforcement.

A trust or cooperative is not automatically legitimate.

It requires:

  • accountable governance;
  • actual member or beneficiary standing;
  • transparent purpose;
  • conflict management;
  • participation;
  • technical control;
  • audit;
  • exit;
  • succession.

Collective governance should not become another intermediary that owns the field while sources lose voice.

---

28. Benefit sharing

Training creates value.

Potential benefits include:

  • public model access;
  • compensation;
  • royalties;
  • attribution;
  • infrastructure;
  • community services;
  • research return;
  • employment;
  • shared governance;
  • priority access;
  • capacity building.

Benefit sharing is especially relevant where:

  • sources contribute distinctive value;
  • communities bear collective risk;
  • knowledge was historically extracted;
  • the model competes with contributors;
  • public or philanthropic resources enabled development.

Not every contribution can be priced individually.

Benefit can be collective.

The record should state:

who contributes
who bears risk
who captures value
who governs benefit
how disputes are resolved

A vague promise that innovation benefits everyone is not a benefit-sharing mechanism.

---

29. Community and Indigenous data sovereignty

Indigenous and community data governance demonstrates several principles that general AI governance often misses.

Data may be:

  • relational;
  • collective;
  • tied to land;
  • tied to cultural continuity;
  • governed by customary authority;
  • harmful when detached from context;
  • inappropriate for open access despite scientific value.

Free, prior, and informed consent may be necessary but insufficient where governance must continue through the data lifecycle.

The community may legitimately refuse training.

A model developer should not treat underrepresentation as an automatic invitation to collect.

Representation without authority can reproduce extraction.

Consentful inclusion begins with the possibility of refusal.

---

30. Model succession

Models are:

  • updated;
  • fine-tuned;
  • merged;
  • distilled;
  • quantized;
  • transferred;
  • acquired;
  • open-weight released;
  • embedded in products.

Training authority does not automatically transfer through every succession.

A successor record should preserve:

  • source lineage;
  • licenses;
  • consent and authority;
  • restrictions;
  • withdrawal obligations;
  • constitution;
  • benefit commitments;
  • known disputes;
  • unlearning claims;
  • derivative permissions.

A company acquisition should not silently expand training or deployment purpose.

An open-weight release may make later control impossible.

That consequence should be considered before training or release.

---

31. Consentfully trained versus consentfully operated

A model may be:

31.1 Consentfully trained and nonconsensually operated

Example:

  • authorized training data;
  • undisclosed surveillance deployment.

31.2 Nonconsensually trained and consentfully operated

Example:

  • disputed training lineage;
  • careful local consent and governance at use.

The operation can still be better.

It does not repair training provenance automatically.

31.3 Consentfully trained and consentfully operated

Both lineage and deployment preserve standing, scope, correction, and recourse.

31.4 Neither

Opaque source recruitment and opaque deployment.

The distinction prevents ethical laundering.

Good deployment does not erase extraction. Good provenance does not excuse harmful use.

32. Training-authority profile

A model should not receive one global label such as ethical data.

Training authority should be recorded by source class.

A candidate profile contains:

SOURCE-KNOWN
AUTHORITY-KNOWN
PURPOSE-BOUNDED
TRANSFORMATION-BOUNDED
DERIVATIVE-USE-BOUNDED
WITHDRAWAL-SUPPORTED
UNLEARNING-CLAIMED
UNLEARNING-VERIFIED
BENEFIT-GOVERNED
COMMUNITY-GOVERNED
CONTESTED
UNKNOWN

A model may be strong in one dimension and weak in another.

The profile should disclose coverage.

Example:

licensed_books:
  source_known: high
  license_known: medium
  training_authority: contested_by_jurisdiction
  withdrawal: future_runs_only
  attribution: dataset_level

community_health_data:
  source_known: high
  authority: community_board
  purpose: bounded_research
  derivative_release: prohibited
  withdrawal: governed_review
  benefit: local_clinical_capacity

One composite score would hide the field.

---

33. Candidate Consentful Training Lineage Record

training_lineage_id:
model_family:
model_version:
provider:
declared_purposes: []
prohibited_purposes: []
release_regime:
  private
  api
  restricted_weights
  open_weights
  public_research

source_collections:
  - source_collection_id:
    source_classes: []
    source_centers: []
    affected_communities: []
    collection_method:
    acquired_at:
    collector:
    authority_basis:
      type:
      artifact:
      jurisdiction:
      scope:
      contested:
    license:
    public_access_status:
    privacy_status:
    community_governance:
    benefit_terms:
    opt_out_or_refusal:
    withdrawal_terms:
    known_limitations:

transformations:
  - transformation_id:
    input_collection:
    activity:
    responsible_agent:
    rules:
    model_or_tool:
    output_collection:
    known_loss:
    restrictions_preserved:
    provenance_bundle:

human_contributions:
  - contribution_id:
    contributor_class:
    task:
    labor_conditions:
    compensation:
    consent_scope:
    psychological_risk:
    disagreement_preserved:
    downstream_use:

preference_governance:
  method:
    population:
    sampling:
    policy:
    alternatives_shown:
    aggregation_rule:
    disagreement:
    protected_objections:
    adjudication:
    known_gaps:

model_constitution:
  principles: []
  authorship:
  authority:
  revision_process:
  conflicts:
  protected_standing: []
  public_status:

training_events:
  - event_id:
    method:
      pretraining
      supervised_finetuning
      RLHF
      DPO
      RLAIF
      distillation
      merge
      continual_learning
    inputs: []
    code_version:
    checkpoint:
    compute:
    date:
    evaluation:

synthetic_data:
  generating_models: []
  source_lineage:
  proportion:
  policies:
  contamination_tests:
  diversity_tests:

withdrawal_and_unlearning:
  accepted_requests: []
  source_deletions: []
  future_training_exclusions: []
  unlearning_methods: []
  verification:
  retraining:
  known_residual_influence:

succession:
  derivative_models: []
  transfers: []
  mergers: []
  acquirers: []
  restrictions_propagated:
  obligations_propagated:

benefit_and_accountability:
  contributors:
  beneficiaries:
  compensation:
  attribution:
  public_or_collective_benefit:
  audit:
  contest:
  repair:

status:
  active
  restricted
  contested
  superseded
  withdrawn
  dissolved

This is a research schema.

It should reference existing provenance, dataset-documentation, license, consent, and community-governance standards rather than reproduce them.

---

34. Training event stream

An append-only event stream can preserve lineage without pretending the current record rewrites history.

Candidate events include:

source_registered
authority_recorded
license_recorded
community_approval_recorded
restriction_added
restriction_contested
source_collected
source_transformed
source_filtered
source_annotated
preference_recorded
preference_aggregated
constitution_adopted
constitution_revised
training_started
checkpoint_created
evaluation_recorded
model_released
withdrawal_requested
source_deleted
future_use_blocked
unlearning_attempted
unlearning_verified
retraining_completed
benefit_distributed
model_transferred
model_superseded
model_dissolved

The event stream should support valid time and transaction time.

A restriction may have been valid before the developer learned of it.

The record should preserve both facts.

---

35. Training gates

Before a source collection enters training, it should pass proportionate gates.

35.1 Provenance gate

Can the source and acquisition path be identified?

35.2 Authority gate

What legal, contractual, individual, collective, or public authority supports use?

35.3 Purpose gate

Does the proposed model and release regime fit the authority?

35.4 Privacy gate

Does processing create direct or inferential privacy risk?

35.5 Community gate

Does the data implicate collective or cultural authority?

35.6 Labor gate

Were human contributors fairly and safely recruited?

35.7 Restriction-propagation gate

Will license, consent, and community restrictions survive aggregation and derivative training?

35.8 Withdrawal gate

What can later be stopped, deleted, or unlearned?

35.9 Benefit gate

Who captures value, and what return is owed?

35.10 Release gate

Does open or broad release destroy the ability to honor prior conditions?

A source may pass collection and fail release.

A dataset may pass research use and fail commercial deployment.

---

36. Training breach taxonomy

36.1 Access-as-permission breach

Technical availability is treated as authority.

36.2 Silence-as-consent breach

Failure to opt out is represented as affirmative consent.

36.3 Purpose-expansion breach

Data recruited for one model, domain, or research purpose enters another without renewed authority.

36.4 Restriction-loss breach

License, consent, community, or privacy restrictions disappear during aggregation or transformation.

36.5 Source-standing breach

The source remains useful while the contributing person or community loses attribution, benefit, correction, or control.

36.6 Preference-universalization breach

A bounded evaluator population is treated as humanity's values.

36.7 Disagreement-erasure breach

Minority or protected judgments disappear into a reward or preference model.

36.8 Constitution-authority breach

Provider-selected principles are represented as neutral universal ethics.

36.9 Labor-extraction breach

Annotation, moderation, evaluation, or red-team labor is recruited through unsafe, opaque, or unfair conditions.

36.10 Withdrawal-misrepresentation breach

Source deletion is described as complete model forgetting.

36.11 Unlearning-verification breach

A removal claim exceeds the tests performed.

36.12 Synthetic-provenance breach

Model-generated data loses its generating model, source lineage, or policy history.

36.13 Recursive-pollution breach

Synthetic material recursively displaces human and minority traces without adequate monitoring.

36.14 Succession breach

Derivative or successor models inherit capability without inherited restrictions and obligations.

36.15 Benefit-capture breach

Contributors and affected communities supply value while governance and returns remain exclusively external.

36.16 Deployment-laundering breach

Careful deployment is used to obscure disputed or extractive training.

---

37. Repair

Training repair may include:

  • correcting provenance;
  • restoring restrictions;
  • removing source copies;
  • stopping future training;
  • replacing a dataset;
  • retraining;
  • attempting and verifying unlearning;
  • restricting model release;
  • changing the constitution;
  • representing disagreement;
  • compensating contributors;
  • sharing benefit;
  • returning governance;
  • notifying downstream developers;
  • deprecating or dissolving a model.

Some harms cannot be fully reversed.

A widely released model cannot always be recalled.

A derivative model may no longer be technically or legally controlled.

The repair record should state:

what was wrong
which models were affected
what action stopped
what source was removed
what influence may remain
which successors were notified
what benefit or compensation was provided
what cannot be reversed

Repair should not depend solely on the developer that benefited from the breach.

Independent review may be required.

---

38. Consentful operation profile

Training and operation should be assessed separately.

A deployment profile should include:

  • user and affected-center consent;
  • provider purpose;
  • model role;
  • context and retrieval;
  • tool authority;
  • data retention;
  • contestability;
  • recourse;
  • human re-entry;
  • action witness;
  • expiry and release.

A training profile should include:

  • source authority;
  • provenance;
  • purpose;
  • transformations;
  • preference governance;
  • withdrawal;
  • benefit;
  • succession.

The two profiles may be joined in a model lineage graph.

They should never be collapsed into one trust label.

---

39. Public-interest models

A public-interest model may be trained or operated to provide:

  • education;
  • accessibility;
  • public administration;
  • scientific research;
  • civic infrastructure;
  • public health;
  • language preservation;
  • emergency response.

Public purpose does not erase source standing.

It may justify different authority structures and benefit models.

A credible public-interest model should disclose:

  • legal or institutional mandate;
  • governing body;
  • public accountability;
  • access;
  • affected-community participation;
  • procurement and vendor dependence;
  • model and data succession;
  • recourse;
  • dissolution.

The label public interest should not be assigned by the developer alone.

---

40. Community models

A community may choose to train:

  • a language model;
  • retrieval system;
  • translation model;
  • cultural archive interface;
  • health model;
  • local decision assistant.

Community governance can provide:

  • source authority;
  • contextual interpretation;
  • benefit direction;
  • refusal;
  • correction;
  • access rules;
  • succession.

Community authority should not be romanticized.

Internal power differences remain.

A community model should preserve:

  • who counts as a member;
  • who may speak;
  • dissent;
  • vulnerable subgroups;
  • external affected centers;
  • exit;
  • independent complaint.

Collective governance is a constitutional structure, not proof of unanimity.

---

41. Open models

Open-weight and open-source releases can support:

  • research;
  • transparency;
  • local adaptation;
  • sovereignty;
  • competition;
  • accessibility;
  • public innovation.

They can also weaken:

  • use restrictions;
  • withdrawal;
  • safety controls;
  • attribution;
  • benefit governance;
  • successor accountability.

A model may be consentfully trained for a bounded research service and become nonconsensually propagated through unrestricted release.

Release governance should therefore be part of training consent.

The source should know whether model weights may become broadly copyable and irreversible.

Open does not automatically mean consentful.

Closed does not automatically mean protective.

---

42. Minimum governance profile

A model should not be described as consentfully trained unless it can provide, at minimum:

  1. source-class inventory;
  2. provenance coverage;
  3. authority-basis coverage;
  4. purpose and release regime;
  5. transformation lineage;
  6. preference and constitution governance;
  7. human-labor conditions;
  8. withdrawal and unlearning truthfulness;
  9. community and collective standing review;
  10. synthetic-data disclosure;
  11. derivative and succession obligations;
  12. benefit and accountability mechanism;
  13. contest and repair route;
  14. material unknowns and disputes.

The label should be qualified.

Examples:

CONSENTFULLY TRAINED — COMMUNITY-GOVERNED CORPUS
CONSENTFULLY TRAINED — LICENSED DOMAIN MODEL
MIXED-AUTHORITY TRAINING — MATERIAL UNKNOWN SOURCES
PUBLIC-MANDATE TRAINING — RESTRICTED DEPLOYMENT
CONTESTED TRAINING LINEAGE

One green badge would invite ethical laundering.

---

43. Formal sketch

Let source items be:

\[ D=\{d_1,\dots,d_n\} \]

Each source item carries a governance envelope:

\[ g_i= \left( p_i, a_i, s_i, r_i, b_i, t_i \right) \]

where:

  • \(p_i\) is provenance;
  • \(a_i\) is authority basis;
  • \(s_i\) is scope and purpose;
  • \(r_i\) is restriction and withdrawal;
  • \(b_i\) is benefit obligation;
  • \(t_i\) is temporal validity.

Let training transformation chain be:

\[ \Theta= \theta_k \circ \cdots \circ \theta_1 \]

A training event is eligible only if the transformation and model purpose remain within the propagated envelope:

\[ \operatorname{Eligible}(d_i,\Theta,M) \iff \operatorname{ProvenanceAdequate} \land \operatorname{AuthorityValid} \land \operatorname{PurposeCompatible} \land \operatorname{RestrictionsPropagated} \land \operatorname{StandingReviewed} \]

For a model \(M\), consentful-training adequacy is a profile:

\[ \mathcal{C}_T(M) = \langle P,A,S,L,H,W,U,B,Q \rangle \]

where the dimensions represent:

  • provenance;
  • authority;
  • scope;
  • lineage;
  • human contribution;
  • withdrawal;
  • unlearning;
  • benefit;
  • community governance.

No universal scalar is proposed.

A deployment has separate adequacy:

\[ \mathcal{C}_O(M,x) \]

for operation \(x\).

Therefore:

\[ \mathcal{C}_T(M) \nRightarrow \mathcal{C}_O(M,x) \]

and:

\[ \mathcal{C}_O(M,x) \nRightarrow \mathcal{C}_T(M) \]

---

44. Empirical program

44.1 Provenance propagation study

Track licenses, consent, restrictions, and disputes through dataset merges and fine-tuning collections.

Measure loss and misclassification.

44.2 Consent-comprehension study

Compare ordinary training terms with layered, purpose- and withdrawal-specific consent.

Measure understanding, refusal, and later recognition.

44.3 Preference-plurality study

Compare aggregate reward models with systems preserving disagreement and population context.

Measure minority behavior, user recognition, and safety tradeoffs.

44.4 Constitution-governance study

Vary:

  • principle authorship;
  • public visibility;
  • revision authority;
  • conflict process;
  • represented communities.

Measure legitimacy judgments and behavior.

44.5 Opt-out propagation study

Insert machine-readable restrictions at source.

Track whether they survive crawlers, archives, dataset combinations, and derivative models.

44.6 Unlearning-verification study

Compare:

  • source deletion;
  • output suppression;
  • approximate unlearning;
  • retraining.

Measure memorization, knowledge, privacy leakage, retained utility, and sequential requests.

44.7 Synthetic-recursion study

Vary human-data retention, synthetic proportion, source diversity, and tail protection.

Measure performance and minority-trace preservation.

44.8 Benefit-governance study

Compare individual payment, collective fund, shared infrastructure, public access, and governance rights.

Measure source and community judgments.

44.9 Succession study

Test whether restrictions and benefit obligations survive model transfer, merge, distillation, and open-weight release.

---

45. Falsification and failure

The framework should be weakened if:

  • training authority cannot be represented at useful source-class resolution;
  • documentation produces false assurance without enforceable lineage;
  • consent language becomes too complex to understand;
  • community governance cannot protect internal minorities;
  • withdrawal rights cannot be implemented honestly enough to matter;
  • benefit sharing becomes symbolic;
  • preference disagreement cannot be preserved at model scale;
  • provenance and restriction propagation make training impracticable without improving accountability;
  • the label consentfully trained becomes a marketing claim rather than an auditable profile;
  • public-interest exceptions become unlimited purpose expansion;
  • synthetic-data controls fail to distinguish source diversity from model repetition.

The term should be retired if rights-aware training lineage, governed training provenance, or another established phrase communicates the profile more precisely.

---

46. Ethical boundaries

Consentful training does not require turning every contribution into property.

Knowledge, language, criticism, science, and culture depend upon reuse, transformation, and shared inheritance.

A governance model that allows every source to veto every learned relation could destroy public knowledge and entrench powerful rights holders.

The framework therefore preserves:

  • public domain;
  • public-interest authority;
  • lawful exceptions;
  • collective knowledge;
  • scientific inquiry;
  • transformative use;
  • freedom of expression.

It also rejects the opposite collapse:

If knowledge is socially produced, every extraction is therefore legitimate.

Shared creation does not make contributors ownerless.

Public access does not erase context.

Legal permission does not settle benefit, standing, or purpose.

---

47. Conclusion

A language model is not trained from data alone.

It is trained from inherited semantic fields, human labor, institutional decisions, public infrastructure, community knowledge, preference judgments, and material resources. These contributions enter an outer loop whose future uses can exceed the imagination and authority present at collection.

Consentful training does not mean that every source clicked yes.

It means the model can account for the legitimate authority under which its sources, transformations, judgments, and benefits were recruited—and can state where that authority is unknown, contested, expired, collective, public, or technically difficult to withdraw.

It means that human feedback is not mislabeled as humanity.

It means constitutions disclose who wrote them.

It means withdrawal does not promise magical forgetting.

It means synthetic output does not shed its lineage.

It means communities may refuse representation.

It means model succession carries obligations as well as capability.

Consentful provenance in. Consentful interpretation out.

The loop remains incomplete if its training field is hidden while it claims to map everyone else's.

A system cannot consentfully map telic fields while its own field remains hidden, unaccountable, and non-consensual.

And the distinction must remain visible:

Consentful operation does not retroactively make unconsented training consentful. Consentful training does not guarantee consentful deployment.

---

References

Bai, Yuntao, et al. “Constitutional AI: Harmlessness from AI Feedback.” arXiv:2212.08073, 2022.

Bender, Emily M., and Batya Friedman. “Data Statements for Natural Language Processing: Toward Mitigating System Bias and Enabling Better Science.” Transactions of the Association for Computational Linguistics 6, 2018.

Carroll, Stephanie Russo, et al. “The CARE Principles for Indigenous Data Governance.” Data Science Journal 19, 2020.

European Union. Regulation (EU) 2016/679 (General Data Protection Regulation), 2016.

Gebru, Timnit, et al. “Datasheets for Datasets.” Communications of the ACM 64, no. 12, 2021; preprint 2018.

Gerstgrasser, Matthias, et al. “Is Model Collapse Inevitable? Breaking the Curse of Recursion by Accumulating Real and Synthetic Data.” arXiv:2404.01413, 2024.

Holland, Sarah, et al. “The Dataset Nutrition Label: A Framework to Drive Higher Data Quality Standards.” arXiv:1805.03677, 2018.

Longpre, Shayne, et al. “The Data Provenance Initiative: A Large Scale Audit of Dataset Licensing & Attribution in AI.” arXiv:2310.16787, 2023.

Mitchell, Margaret, et al. “Model Cards for Model Reporting.” Proceedings of FAT*, 2019.

Ouyang, Long, et al. “Training Language Models to Follow Instructions with Human Feedback.” arXiv:2203.02155, 2022.

Paprica, P. Alison, et al. “Essential Requirements for Establishing and Operating Data Trusts.” arXiv:2005.06604, 2020.

Rafailov, Rafael, et al. “Direct Preference Optimization: Your Language Model Is Secretly a Reward Model.” arXiv:2305.18290, 2023.

Seddik, Mohamed El Amine, et al. “How Bad Is Training on Synthetic Data? A Statistical Analysis of Language Model Collapse.” arXiv:2404.05090, 2024.

Shi, Weijia, et al. “MUSE: Machine Unlearning Six-Way Evaluation for Language Models.” arXiv:2407.06460, 2024.

Shumailov, Ilia, et al. “AI Models Collapse When Trained on Recursively Generated Data.” Nature 631, 2024.

Thaker, Pratiksha, et al. “Position: LLM Unlearning Benchmarks Are Weak Measures of Progress.” arXiv:2410.02879, 2024.

Wang, Weiqi, et al. “Machine Unlearning: A Comprehensive Survey.” arXiv:2405.07406, 2024.