Trigger: AI must operate across organisations or federated environments.

Dataspace AI Evidence Ripple

AI across data spaces
without losing sovereignty.

Per-participant evidence for AI across shared data spaces - raw assets are never requested, each participant supplies its own evidence, and gaps stay visible.

No raw data requestedPer-participant evidence recordsSovereignty conditions recordedNo central data aggregation by default

Federated Ripple - one passport, three jurisdictions

Node ES

Art. 10 bias exam ✓

Node DE

Art. 15 accuracy ✓

Node FI

Art. 12 log sample ✓

Evidence Records aggregate

Federated Ripple

Federated Evidence

raw_data: never leaves the node that holds it

evidence_records: recorded per participant, aggregated into one Ripple

raw_data_included: false - the finding, not the data

Sensitive context

Why dataspaces require sovereign evidence infrastructure.

Dataspace participants share data access rights - not data itself. AI systems operating across dataspace nodes must produce evidence without centralising raw assets, compromising participant sovereignty, or creating hidden dependencies on single-party trust claims.

Data categories in scope

Cross-organisation transaction and exchange data
Federated model training assets
Participant-specific sensitive datasets
Interoperability metadata and data product schemas
Usage and access logs across nodes

People affected

Dataspace participant organisationsRegulatory bodies overseeing data sharingEnd users whose data underlies the spaceSupply chain and industry partnersPublic institutions in multi-party dataspaces

Risk scenarios

What typically goes wrong.

Specific failure modes seen in this sensitive context - without structured evidence.

A federated learning model aggregates updates without participant evidence of local training scope.

No local evidence records per participant. Central aggregator cannot verify what data each node used. Trust based on claims.

A dataspace AI platform centralises inference to reduce costs.

Raw participant data leaves individual control without evidence of legal basis, DPA, or participant consent to central processing.

A cross-organisation RAG system ingests documents from multiple participants without a document boundary per participant.

One participant's confidential documents accessible via queries from another participant's session. No retrieval boundary. No Retrieval Grounding evidence per node.

A dataspace connector provides AI recommendations without audit trail per participant.

No participant-level evidence. No lineage. Recommendation origin unclear. Participant trust in the space undermined.

Border control, applied here

Scan the system. Issue the passport. Grant the visa.

What the scan finds in this context, what the passport records, and what conditions the visa attaches.

01

Currents

the scan

What AI is running, and what do we not know about it?

Currents opens the file with each participant: which AI systems reach which data products, what each node declares it contributes to a federated model, where a retrieval index crosses a participant boundary, and which nodes have no evidence at all because none has been supplied.

02

Ripples

the passport

What is this system, and what is proven about it?

The Ripple brings together what each participant supplied: per-participant evidence records, federated model provenance, the legal basis for each transfer, and the per-participant retrieval boundary. Coverage gaps stay visible in the record rather than being averaged away.

03

Droplets

the visa

May it operate HERE, on THIS data, under WHAT conditions?

The Droplet clears the system per participant and per data product: local inference only, results aggregated but raw assets sovereign, an opt-out that works, and withdrawal by any participant without collapsing the space for the others.

Scope

What needs a Ripple.

Federated learning models across dataspace participants
Cross-organisation RAG systems and knowledge assistants
Data product AI and analytics layers in dataspaces
Dataspace connectors using AI for matching or recommendation
Multi-party AI workflows and orchestration agents
Interoperability AI for schema translation and data harmonisation

Stakeholder workflow

From trigger to access decision.

1

Scan

Art. 6 route · Annex III test

2

Evidence call

Annex IV · Art. 10 bias file

3

Seal Review

DPO · CISO · Art. 14 owner

4

Droplet

Conditions bound · expiring

5

Re-scan

After a recorded retrain or model change

Dataspace Governance Lead

“AI is deployed within or across the dataspace.”

Require Ripple per AI system. Federated evidence structure must show evidence records per participant.

Participant DPO / Data Officer

“Organisation data products are accessible to AI within the dataspace.”

Confirm data boundary, legal basis, and opt-out mechanism are documented in the Ripple.

Technical Integration Lead

“Evidence must be collected from each participant node.”

Coordinate evidence collection. A node that supplies no evidence is recorded as a gap.

Access decisions

Context Droplet conditions.

The access decisions that apply in this sensitive context - and the evidence conditions that produce them.

Federated Evidence
  • Evidence Records supplied by each participant node
  • Raw assets remain within participant perimeter
  • Aggregated Ripple reflects federated evidence only
  • Participant opt-in/opt-out mechanism documented
Local Only
  • AI inference runs within each participant node only
  • No cross-node data transfer - only result aggregation
  • Per-participant data boundary confirmed
Review Needed
  • Participant evidence missing from one or more nodes
  • Document boundary not configured for RAG
  • Data transfer across nodes without confirmed legal basis
Blocked
  • Raw participant data transferred centrally without confirmed legal basis and DPA
  • Single-party aggregation without participant consent to centralisation

Measurement

Evidence families we can structure.

The measurable evidence categories relevant to this context and the evidence signals they produce.

Participant Evidence Records

Per-participant evidence records - each participant's own documents, summaries and results, recorded without raw data leaving the participant perimeter.

Lineage & Provenance

Cross-participant data product lineage, federated model provenance, and dataset version evidence per node.

Privacy & Data Sovereignty

Legal basis per participant, data transfer evidence, and access control policy for cross-organisation AI access.

RAG Document Boundary

Per-participant retrieval boundary - evidence that one participant's documents are not accessible in another's session.

Federated Assessment

Where federated learning is used: per-round contribution evidence, aggregation transparency, and participant exclusion options.

Access Control

Policy-as-code governing which AI systems can access which participant data products and under what conditions.

Data protection · GDPR Art. 9 / 35Retrieval grounding · injection testedData lineage · Annex IV

Honest scope

What remains not assessable.

AffectLog does not overclaim. These items require external expertise, regulatory process, or long-term study.

Participants that have supplied no evidence

AffectLog records the evidence each participant supplies. Where a participant has supplied none, AffectLog cannot produce evidence records for that node.

Instead: Share the evidence requirements with participant organisations and record each node's gaps.

Cross-jurisdiction legal compliance for data transfers

Legal adequacy, SCCs, and data transfer compliance require legal analysis per jurisdiction and participant combination.

Instead: Engage legal counsel for cross-border transfer analysis. AffectLog evidence supports the technical component of the review.

Example

Sample Ripple for this context.

Ripple - evidence passportCleared with Limits

Supply Chain Intelligence Layer

Cross-participant supply chain analytics · Industrial Dataspace

Evidence69%
Expiry31 Mar 2027
Raw data exportoff
ALP-2026-DS-S7C2

Access conditions

Inference runs locally at each participant node
Only aggregated results cross the participant boundary
Per-participant DPA confirmed with dataspace operator
Participant opt-out mechanism documented and active
Evidence Lineage Trace results on file for all nodes
Review at 6-month intervals - federated evidence refresh required

What we will not overclaim

AffectLog does not ask for raw participant data. We record the evidence each participant supplies, against each AI system. We do not verify participant systems that have supplied no evidence, and we do not provide cross-jurisdiction legal compliance conclusions.

Common questions

Questions this context raises.

“Our dataspace already has governance rules - participants have agreed to terms.”

Governance terms describe what participants have agreed to in principle. AffectLog structures technical evidence that agreements are enacted: which data is processed, which AI systems have access, and whether raw assets remain sovereign - per participant, per system.

“We cannot collect evidence from every participant node.”

Partial coverage is better than none. Participants that supply evidence have it recorded. Those without are documented as 'evidence not yet collected' in the Ripple - making coverage gaps visible rather than hidden.

Get started

Build a dataspace AI evidence layer
without centralising participant data.

Design a per-participant evidence flow for your dataspace AI portfolio - evidence records per participant, access conditions per AI system, and a Ripple built without raw data.

AffectLog provides technical and operational evidence. Not legal compliance, data transfer adequacy, or cross-jurisdiction legal advice.