← All insights
EU AI ActCopyrightPolicyDSM Directive

Europe gave you the right to say no to AI training. It didn't give you the receipt

Slava Spitsyn · June 17, 2026 · 3 min read

Europe took the opposite path from Japan. Instead of waving AI training through, it gave rightsholders a way to opt out — and told AI makers they have to respect it. That sounds like a win for creators. The catch is in what the law gives you, and what it quietly leaves out.

What's new

  • The EU AI Act (Regulation 2024/1689) entered into force in August 2024, with obligations for general-purpose AI (GPAI) models applying from August 2025.
  • Article 53(1)(c) requires GPAI providers to put in place a policy to comply with EU copyright law — and specifically to identify and respect reservations of rights expressed under Article 4(3) of the 2019 DSM Directive.
  • In other words: if you've reserved your work from text-and-data mining, the model's makers are legally expected to honor that reservation.

How it works

The right itself comes from the earlier DSM Directive (2019/790):

  • Article 4 created a text-and-data-mining exception — anyone can mine publicly available content — unless the rightsholder has reserved that use.
  • For content made available online, the reservation must be made "in an appropriate manner, such as machine-readable means."

The AI Act then bolts an obligation onto that right: GPAI providers must respect those machine-readable reservations, and they must have a copyright policy to back it up. A 2025 Code of Practice spells out how providers are expected to comply in practice.

So the chain is: you reserve → they must respect → the regulator can ask how.

Behind the news

Here's the gap nobody puts on the slide. The law gives you the right to reserve and the expectation that it's honored. It does not give you a way to see whether it was.

  • The reservation is a one-way signal. You raise the flag and hope it was read.
  • A crawler that ignores it leaves the same trace as one that respected it: a line in a server log, an anonymous IP, no record of what was taken.
  • By the time your work surfaces inside a model, the crawl is months old and unprovable.

A right you can't observe being broken is a right you can't enforce.

Why it matters

Rights and enforcement are two different layers, and Europe has only legislated the first one well. The reservation is the declaration. What's missing for most site owners is the record — the receipt that says who came, when, and what they took.

Without that record, "respect for rights reservations" is a promise made to a regulator, not a fact you can hold in your own hands.

How I see it

This is exactly the seam WARD is built into. The EU did the hard part — it established the right and named machine-readable reservation as the way to express it. The piece left on the table is verification.

The way I see it, you need both halves to actually hold ground:

  • Declaration — state, machine-readably, how your content may be used. This is the language the EU already recognizes.
  • Visibility — a clean log of who accessed what, and when, so a reservation isn't just raised but checked.

Where the law gives you a right, the protocol gives you the receipt.

getward.org

WARD is an open standard for AI access control on the web.

Declare how AI may use your content — and keep a record of who came, when, and what they took.