← All insights
EU AI ActCopyrightPolicyDSM Directive

Europe gave you the right to say no to AI training. It didn't give you the receipt

Slava Spitsyn · June 17, 2026 · 3 min read

Europe took the opposite path from Japan. Instead of waving AI training through, it gave rightsholders a way to opt out — and told AI makers they have to respect it. That sounds like a win for creators. The catch is in what the law gives you, and what it quietly leaves out.

What's new

  • The EU AI Act (Regulation 2024/1689) entered into force in August 2024, with obligations for general-purpose AI (GPAI) models applying from August 2025.
  • Article 53(1)(c) requires GPAI providers to put in place a policy to comply with EU copyright law — and specifically to identify and respect reservations of rights expressed under Article 4(3) of the 2019 DSM Directive.
  • In other words: if you've reserved your work from text-and-data mining, the model's makers are legally expected to honor that reservation.

How it works

The right itself comes from the earlier DSM Directive (2019/790):

  • Article 4 created a text-and-data-mining exception — anyone can mine publicly available content — unless the rightsholder has reserved that use.
  • For content made available online, the reservation must be made "in an appropriate manner, such as machine-readable means."

The AI Act then bolts an obligation onto that right: GPAI providers must respect those machine-readable reservations, and they must have a copyright policy to back it up. A 2025 Code of Practice spells out how providers are expected to comply in practice.

So the chain is: you reserve → they must respect → the regulator can ask how.

Behind the news

Here's the gap nobody puts on the slide. The law gives you the right to reserve and the expectation that it's honored. It does not give you a way to see whether it was.

  • The reservation is a one-way signal. You raise the flag and hope it was read.
  • A basic server log rarely connects the crawler claim, policy version, and response decision in one record.
  • By the time your work surfaces inside a model, the crawl is months old and unprovable.

A right is harder to operationalise when the technical decision is not observable.

Why it matters

Rights, preference expression, origin enforcement, and downstream use are different layers. The reservation is the declaration. A gateway receipt can record the identity confidence, policy version, and origin decision—but not later training.

Without that record, "respect for rights reservations" is a promise made to a regulator, not a fact you can hold in your own hands.

How I see it

This is the seam WARD is testing: translate a machine-readable signal into an explicit origin action and evidence record. WARD is experimental and not an officially recognised compliance mechanism.

The way I see it, you need both halves to actually hold ground:

  • Declaration — state, machine-readably, how your content may be used. This is the language the EU already recognizes.
  • Visibility — a clean log of who accessed what, and when, so a reservation isn't just raised but checked.

Where a site expresses a rule, the gateway can record how it acted on that rule.

getward.org

WARD is an open-source alpha for AI access decisions at the web origin.

Declare how AI may use your content — and keep a record of who declared itself, which policy matched, and what the origin decided.