Article image
Cover: generated with Midjourney, edited in Photoshop.
 

AI's Black Box Has Entered the Chain of Title

Japan wants providers to reveal how their models were built. Singapore is examining who owns, infringes, or invents what comes out. Between them, provenance stops being an engineering detail and becomes a business requirement.

markus brinsa 2 september 2, 2026 9 9 min read create pdf website all articles

Verified Sources

After an expert panel broadly approved the revised draft on August 18, Japan published its final, nonbinding Principles Code on August 25, asking generative AI providers to disclose how their models were designed and trained. Singapore opened its own consultation the following day, tracing intellectual property through the rest of the AI lifecycle: access to training material, infringing output, human authorship, inventorship, and patent prior art.

Between them, the two initiatives pose a larger question than either country answers alone. Can businesses claim reliable rights in AI-generated value when nobody can establish where the system's knowledge came from, who shaped the result, or which party carried the legal risk along the way?

That question reaches well past copyright litigation. It touches vendor selection, product development, creative ownership, patent strategy, and the valuation of AI-assisted assets. What the market is starting to demand is a defensible record — one that connects inputs, model behavior, human decisions, and commercial output.

Evidence Before Doctrine

Most AI copyright disputes begin with an evidentiary handicap. A rights holder suspects that a work entered a training corpus but cannot inspect the dataset. A developer may know which broad sources or collection methods were used without being able to trace every item. The enterprise customer, further down the chain, usually receives the least information of all.

Japan's code attacks that asymmetry at the provider level. Developers and service providers that accept it are expected to publish an overview of their models — architecture, training methods, categories of training data, and collection practices — with accompanying examples spanning web crawling, externally obtained datasets, model documentation, accountability arrangements, and intellectual property safeguards. It asks for an overview, not a public inventory of every training item. Even so, it drags information that used to live in internal engineering into the governance record.

Singapore approaches the same problem through the lawful-access safeguard attached to its computational data analysis exception. The consultation paper says that users cannot rely on the exception when training material was accessed unlawfully, including by circumventing a paywall or by breaching a database's terms of use. It also acknowledges unresolved questions about how other contractual restrictions should be treated. By contrast, robots.txt currently relies on voluntary compliance and does not itself create a legally binding access restriction.

The two governments are working opposite ends of the same sentence.

Japan asks a provider to describe how it collected the data. Singapore asks what the law should make of that collection. Any honest account of AI training will eventually have to satisfy both.

Japan Places the First Burden on Providers

The code opens two channels for more specific inquiries. A rights holder preparing legal action can identify the URL where a work appeared and ask whether material from that location was used for training. A user who generates a result and then discovers an existing work that looks identical or similar can ask a parallel question, subject to the code's conditions.

Neither channel guarantees forensic certainty.

Datasets change, third-party collectors sit in the middle, and traceability varies from model to model. Confidentiality and commercially sensitive information will further limit what a provider can say. What the code establishes is an expectation — that a provider should be able to answer, or explain why it cannot.

Foreign companies are covered when they offer generative AI systems or services in Japan, or make them available to Japanese nationals. That territorial reach is what gives a voluntary code commercial teeth. No provider can assume that the absence of a Tokyo headquarters keeps the issue off its compliance agenda.

The request also creates an uncomfortable incentive. A detailed answer may hand a rights holder the makings of a claim; a vague one may make the provider look like it has something to hide. Japan has put that tension in public view and left providers to manage it.

Can Voluntary Transparency Survive Legal Exposure?

Providers may comply with the principles or publicly explain why they don't, and those that accept all or part of the code are expected to notify the government and disclose their position. The government plans to begin accepting those notifications in autumn 2026 and to publish a list of the providers that submit them.

The weakness is easy to name. The firms with the cleanest data practices are the ones most willing to raise their hands, while the providers carrying real exposure have every reason to stay outside the system.

A voluntary regime can end up documenting transparency only among the companies that already had good records.

Commercial pressure could rewrite that math. Enterprise customers may begin to treat acceptance of the code as a signal of provider maturity. Investors, insurers, procurement teams, and commercial partners can all ask why a provider declined a principle, or why its explanation reads like an evasion. Soft law hardens the moment the market folds it into diligence.

Singapore is weighing a similar blend of legal clarification and nonbinding technical measures. Its consultation asks how rights owners should be able to express preferences about AI training, how developers ought to respond, and whether the existing safeguards around lawful access are clear enough. It is also examining measures that could lower the chance of a model reproducing protected expression.

The European Union offers the useful contrast. Its AI Act requires providers of general-purpose AI models to keep a copyright-compliance policy and publish a sufficiently detailed summary of training content; the Code of Practice is a voluntary route to demonstrate compliance, but the underlying duties come from legislation. Japan has adopted the disclosure logic without that statutory floor, and Singapore has not yet settled its final mix. Asia, in other words, is testing whether industry practice can mature ahead of hard enforcement.

Who Carries the Output Risk?

Singapore's consultation refuses to stop at training. It asks how existing copyright principles should assign responsibility when an AI system produces infringing material.

Depending on the facts, the exposure may land on the model developer, the company deploying the model, or the person directing it. A model might reproduce protected expression after memorizing material it saw in training. A user might deliberately prompt for a close copy. A deployer might wire a model to a retrieval system that feeds it protected content without adequate controls.

Japan's user channel reaches the same territory from the other side: the question of whether a work's source location appeared in the training data is also, quietly, a question about where output liability begins. Provenance and infringement start to meet in a single inquiry.

A model's training history will not settle every case. Similarity can arise without the work ever sitting in the corpus, and copyright protects particular expression rather than a general style. Still, provenance shapes the credibility of a provider's explanation, the investigation into memorization, and the allocation of risk between commercial parties.

For enterprise buyers, boilerplate is no longer enough.

A warranty is only as good as the operations behind it. The buyer needs to know what the provider records, how it handles rights inquiries, whether output safeguards are actually tested, and what help will arrive if a disputed result reaches the market.

Authorship Becomes a Recordkeeping Issue

Singapore also asks how much human creativity a work must exhibit before copyright attaches. Its consultation examines prompting, iterative refinement, selection, arrangement, and post-generation editing without declaring any of them inherently creative.

That restraint is sensible. A single instruction followed by acceptance of the first result is not the same as a sustained process in which a person shapes the expressive choices visible in the finished work.

Courts and copyright offices in different jurisdictions have already landed in different places on how much weight prompting deserves.

The business problem is immediate. A company can hold the file and the platform license and still have no idea whether copyright exists in the result. Platform terms cannot manufacture statutory protection where the required human authorship simply isn't there.

So companies building valuable AI-assisted material should preserve evidence of the human contribution — drafts, substantive revisions, the reasons particular elements were chosen, the decisions that gave the final work its distinctive expression. Keep it proportionate. Nobody needs a legal dossier for a routine image or an internal summary. High-value assets are another matter.

Japan's focus on training records and Singapore's focus on creative contribution meet at opposite ends of the same commercial claim. A business seeking exclusive rights in an AI-assisted asset may have to show two things at once: that the system was responsibly sourced, and that a human actually authored the protectable expression.

Patent Systems Meet Synthetic Prior Art

Singapore carries the inquiry into patents, where the consequences are quieter but no less disruptive. Its consultation keeps the premise that an inventor must be a natural person, then asks which human contributions qualify when AI helps formulate, evaluate, or refine a technical solution.

Identifying a problem, designing the model, supplying data, writing prompts, selecting an output — these do not carry equal inventive weight, and Singapore is asking companies and researchers how the roles actually play out in real innovation.

A second question concerns AI-generated technical disclosures. Generative systems can spin up large volumes of plausible technical material at almost no cost. Some of it will be too speculative or too thin to teach a skilled person how to perform a claimed invention. Some of it will still enter the public body of knowledge against which novelty and inventive step are judged.

That opens room for strategy. Automated defensive publication could make whole areas of technology harder to patent. Patent searches could grow more expensive as examiners and applicants sift useful disclosures from synthetic noise. A company could find its AI-assisted invention sitting uncomfortably close to material generated and published by someone else's system.

Training provenance won't resolve that, but the governance principle carries straight across. Intellectual-property systems increasingly need evidence of how machine-generated material was created, what human contribution it holds, and whether it should carry legal consequences at all.

A Practical Response for Businesses

The first move belongs in procurement. Companies buying or integrating generative AI should ask providers for exactly the information Japan's code puts on the table, even where the code doesn't formally apply. Model documentation should explain the broad origin of the training material, the use of external collectors, and the provider's approach to rights reservations and contested content.

Contracts then have to connect those representations to remedies a buyer can use. Notification duties, cooperation with rights inquiries, control over model substitutions, and responsibility for customer-supplied retrieval material all need to reflect the actual service architecture. An indemnity offers cold comfort when the provider cannot reconstruct what happened.

Internally, companies should draw a line between routine AI output and assets expected to carry real commercial value.

Important creative or technical work deserves a record of the human decisions behind it.

Legal and product teams also need to know which models serve users in Japan, which activities lean on Singapore's data-analysis exception, and where EU general-purpose AI obligations enter the supply chain.

Rights holders face a parallel task. Access controls, licensing terms, machine-readable preferences, and clean records of publication dates all strengthen a future inquiry. Waiting until a suspicious output surfaces tends to leave the owner with a grievance and no usable evidence.

Watch the Disclosures

Singapore's consultation stays open until October 22, 2026. Japan still has to show how many providers accept its code, how informative their disclosures are, and whether public explanations for noncompliance draw any real commercial scrutiny.

Those results will tell us whether the region is building a durable governance model or another layer of polished policy statements.

The real test will happen inside ordinary transactions. A company will try to license an AI-assisted design, defend a product feature, or claim an invention. Someone across the table will ask where the material came from, who made the decisive contribution, and whether the rights can survive a challenge. The chain of title will have to run back through a machine — and the businesses that cannot trace it will learn that possession of an AI output is a poor substitute for owning it.

About the Author

Markus Brinsa writes about AI failure, enterprise risk, governance, and the structural shifts underneath them — the through-line being the gap between AI governance on paper and what systems actually do at runtime. He created Chatbots Behaving Badly, a publication and podcast investigating real incidents in which AI systems gave bad advice, were manipulated, or failed in ways that mattered. He is the Founder & CEO of SEIKOURI Inc., an international strategy firm that gives enterprises and investors human-led access to pre-market AI — and converts first looks into rights and rollouts that scale. Access creates possibility. Rights create leverage. Scale turns early advantage into durable position. The two halves are the same work from opposite ends: SEIKOURI gets clients to AI early and makes sure what they deploy holds up once it's running. Thirty years bridging technology, strategy, and cross-border growth across the U.S. and Europe. I close the gap between what leaders expect AI to do and what it actually does in the wild.

brinsa.com
©2026 copyright by markus brinsa | brinsa.com™