AI Training Data Provenance: The $1.5B Lesson | Elacity
A court called AI training fair use, yet Anthropic still paid $1.5 billion for how the books were taken. Law can price the taking. It cannot un-copy the file. Elacity seals the work instead.
Anthropic Paid $1.5 Billion for the Taking. The File Was Still Taken.
Your work can be copied into a training set before you ever hear about it. The best case, years later, is a check cut by someone else's lawyers, sized to the harm after the harm is done. That is the shape of ownership when the thing you own is a file that can be taken first and argued about later.
This year gave that shape a number. A federal court called training on books fair use, and Anthropic still agreed to pay $1.5 billion. The payment was not for the learning. It was for how the books were obtained.
Provenance, Not Usage, Drew the Line
Judge William Alsup ruled that training a model on legally acquired books was fair use, and that keeping a library of pirated copies was not. The doctrine that decided the case was AI training data provenance: where the data came from, and whether it was taken cleanly.
The settlement, which resolves claims over pirated copies of the books, won final approval in July as the largest of its kind. Authors whose works sat in the pirated set became a class, paid per work. Ownership arrived as a distribution, not as control.
Read the holding closely and the line is honest. Usage was permitted. Acquisition was the wrong. The law could name the wrong and price it. It could not reach back and un-copy the file.
What Law Can Do, and What It Cannot
This is not a complaint about the ruling. Fair use is genuinely unsettled, and careful people read the same books-into-a-model question in opposite directions. A court weighing provenance against transformation is doing hard, legitimate work. This gap between what rules decide and what they can enforce runs through our Ecosystem and Governance writing.
But every version of that work happens after the taking. A filing, a class, a settlement, an appeal: each is a way to measure a loss, not to prevent it. Once a readable copy exists somewhere an adversary can reach, the copy is the event. Everything after is accounting.
Provenance is a fact about the past. It tells you where a file has been. It does not stop the next copy, and it cannot make a leaked file behave. A record of the taking is not a wall against it.
The settlement fund proves the point in reverse. It exists because the books already moved. A sum that large is a measure of how much value left the owners before anyone could act, converted after the fact into a one-time payout that ends the claim. It buys closure, not a standing right you keep.
Move the Line Into the Asset
There is a different place to draw the line: not in a courtroom after the copy, but inside the file, before it.
This is what Elacity's decentralized DRM is built to do. A song, a manuscript, a dataset, or a model is packaged into a Wealth Capsule: an encrypted, programmable good that carries its own rights and royalties. It stays encrypted everywhere except a sealed moment of use.
At that moment the key exists in the clear for a split second, inside a sealed sandbox, welded to one transaction, then wiped. The key is used, never owned. It is split across independent machines that each re-check on-chain rights before releasing a share, so no single operator, Elacity included, holds it.
An AI agent can pay to use such a good and get exactly what it needs to run: the inference, the stream, the working output. It never receives a loose copy it could keep. There is no pirated library to build, because there is no step where the file is handed over in the clear.
Put an author back in that story. Instead of a manuscript that leaks into a training set and resurfaces years later as a line in a class list, the manuscript ships as a sealed good. A model that wants to learn from it pays at the gate, on the author's terms, and the text is used under encryption without ever landing as a file the lab keeps. The royalty is written into the asset, not chased through a court after the value is gone.
This does not settle what counts as fair use, and it is not trustless. A colluding quorum could in principle reconstruct a key, which is why the honest word is trust-minimised. What it changes is the default. Today the work leaks first and the law arrives later. Sealed at the source, the work is paid for at the moment it is used, on terms the owner set.
Property You Can Enforce
A $1.5 billion settlement is what accountability looks like when it can only arrive after the taking. Property you can enforce looks different: the work stays usable and valuable, and never becomes yours to lose in the clear. The same limit showed up in the Suno licensing fight, where a ruling can set the rule but cannot enforce your license. Sealing the asset is where that argument leads. Follow Elacity on X to watch the ownership layer take shape.