The Protocol Is the Border

The Sovereign Stack · Part Six
Fifty-nine people lent their voices to teach a machine Dholuo, on the condition that no one clone them. Nothing shows whether that holds once the recordings leave the platform.
September 27, 2026

The download button is easy to find. The condition above it belongs to every person whose voice is inside the file, and it is the easiest thing on the page to miss.

DhoNam is a Dholuo speech dataset stewarded by the Maseno Centre for Applied Artificial Intelligence in Kenya and hosted on Mozilla Data Collective. Released on 20 December 2025, it holds 26,091 clips from 59 speakers: just over 51 hours of people reading sentences aloud so software can learn the shape of the language. Most clips last a few seconds. The listing names seven reviewers. The prompts cover general speech as well as agriculture, healthcare, news, and technology. The listing names the licence as NOODL-1.0, the Nwulite Obodo Open Data Licence. Beside that licence, under “Forbidden Usage”, are two restrictions published on the same page and not written into the NOODL text itself: do not try to identify the speakers, and do not clone their voices or train models that imitate them.

The line the speakers drew is not complicated. A person can lend a voice so a machine learns Dholuo without agreeing to let it borrow that voice and say things they never said, in a way their own family would recognise. The recordings were collected through a platform where a speaker reads a displayed sentence. Maseno built the set with researchers at Strathmore University’s Centre for Intellectual Property and Information Technology Law. CIPIT says MCAAI became the first community to put NOODL into practice in 2025. What the listing cannot show is a named speaker, or what happens after the 2.49-gigabyte archive leaves Kenya.

Mozilla Data Collective checks agreement at the point of access. Its current terms require a downloader to review and accept the provider’s licence before accessing the dataset. Its API documentation says the caller must already have satisfied the dataset’s access requirements, including the terms agreement and any required approval, before the system returns a download link, and refuses the request otherwise.

The check is real, and it ends at the download. Once the recordings are unzipped onto a recipient’s servers, handed to a contractor, or poured into a training run, the promise on the listing is a long way behind them. Whether the restrictions travel with the files, whether any training system stops to read them, the public documentation reviewed for this article cannot say. It shows the terms neither broken nor honoured. That gap, between the click and the training run, is what this piece is about.

Diagram tracing DhoNam's no-voice-cloning condition from publication to the Mozilla Data Collective listing and download agreement; whether recipients honour it is not established by the public record.
DhoNam’s listing prohibits voice cloning and speaker imitation alongside its NOODL licence. Whether recipients honour that once the archive is downloaded, the reviewed material cannot establish. Graphic: Guzangs.

Part Five argued that permissioned data becomes a saleable asset when the work arrives with an authoritative account of who made it, who may license it, and on what terms. This instalment follows those terms out of the listing and into the systems expected to act on them. A person reading a certificate fills in what it does not say. A machine cannot, so the record has to say it outright: the permitted use, any expiry, and proof that whoever granted the licence had the standing to grant it, all in a form software can read. The licence beside DhoNam’s download is the beginning of that chain, not the end.

Four different failures can break the chain, and each calls for a different repair. A condition may lack an agreed form that software can read: a vocabulary problem. The form may exist and go unread: an implementation problem. Two parties may each claim the right to grant permission: an authority problem. Or the machinery may cost more than a language project can carry: a participation problem.

DhoNam gives one condition to follow. A photograph of Guinean léppi shows why authority is the hardest of the four to settle. Copyright in the image, the interests of the Groupement Représentatif du Textile Léppi de Guinée as the registered geographical-indication holder, and any community protocol are three different claims. Putting them in a single record does not decide which one a given use must answer to.

Common standards can spare everyone much of this work. If each platform demanded a private side letter, African operators would spend the decade in email. Shared rules make exchange possible, but a shared field is not yet a shared obligation. The harder questions are who writes the field, who has authority to fill it, and what the receiving system must do when it arrives.

What the systems can and cannot do

Content Credentials let a recipient check a signed record of a file’s history: the device that captured it, the software that edited it, and the changes recorded along the way. The Coalition for Content Provenance and Authenticity develops the standard, and it has been blunt about the limit. In a 22 January 2026 clarification, C2PA stated that its core specification contains no standard assertion for text-and-data-mining reservations and no standard assertion for digital rights management. Content Credentials record where a file came from and how it changed. What they do not do is restrict how it gets used.

A DhoNam clip could therefore carry a valid credential and still say nothing about whether voice cloning was allowed. Validation checks that the signed history is intact and belongs to the file. It does not establish that the account is complete, or that the signer had the right to authorise the next use. The format is extensible: a third-party profile could add a training reservation, and a custom assertion could in principle carry a policy written in ODRL. The receiving system would still have to open that policy and act on it, and nothing in the core format compels it to.

ODRL, the Open Digital Rights Language, is the vocabulary built for the job C2PA’s core leaves alone. Version 2.2 became a W3C Recommendation in February 2018. It names an asset, the party setting the terms and the party receiving them. It can express a prohibition, a duty such as attribution, a limit such as an expiry date, and a duty to obtain consent from a named party. Community and sector profiles can add more specific uses.

ODRL makes a crucial distinction between validating a policy (checking that it is well formed) and evaluating it against a proposed use. The standard alone does not make a training pipeline run that second check. Nor does naming an “assigner” settle a quarrel between a speaker, a steward and a platform. Someone still has to establish that the named body is entitled to give consent, and that the consultation behind it was real.

Local Contexts approaches the same problem from the community’s side, through Traditional Knowledge and Biocultural Labels. Each Label carries a persistent identifier, and software connected to the Local Contexts Hub can fetch the community’s current text. That live connection lets an updated notice reach a system set up to listen for it. Local Contexts is clear, however, that a Label is informational and educative, not a licence or a lock, and updating one does not by itself revoke an earlier permission.

DhoNam’s condition can therefore be encoded three ways: written in ODRL, announced more softly as a Label, or placed in a C2PA extension. None of them proves a training system will stop before cloning a voice.

Comparison of C2PA, ODRL 2.2 and Local Contexts: file history, machine-readable terms and community notices, each with limits on enforcing permission.
C2PA validates provenance without establishing permission. ODRL can express a policy, while Local Contexts Labels communicate community expectations. Whether a receiving system checks and acts on those conditions depends on its workflow. Graphic: Guzangs.

Who gets to change the rule

A field starts doing real work only when receiving software implements it. C2PA’s specification is open and royalty-free, so a developer in Nairobi or Kisumu can write code to read its records. Deciding what those records should contain is a different kind of access.

As of September 2026, C2PA’s steering committee had eleven members: Adobe, Amazon, the BBC, Google, Meta, Microsoft, OpenAI, Publicis Groupe, Sony, TikTok and Truepic. No African cultural ministry, regional intellectual-property body or rights collective sat among them. That roster does not prove why any feature was adopted or dropped.

Participation also has a price. Under C2PA’s trust programme, a product that wants a Claim Signing Certificate must pass evaluation and obtain a certificate from an approved authority, and those authorities set their own fees. An archive running an existing conforming tool is in one position; a lab building its own is in another, paying to sustain what it is free to read.

NOODL puts a different set of priorities into the licence itself. CIPIT describes its development as a collaboration among its Data Science Law Lab, the Distributed Systems and Security Initiative and members of Africa’s data community, with Chijioke Okorie as lead author. The licence distinguishes among users in different economic settings and asks how benefit should find its way back to the people who made the data. On the DhoNam listing, users in developing countries are invited to share resulting materials under a similar licence, while users in developed countries are encouraged to establish partnerships with the dataset’s maintainers. Those are invitations, not an automatic royalty. Turning them into a software check requires decisions about which use triggers an obligation, what the recipient must do, and who confirms that it has been done.

No camera signature can make those decisions. It preserves a faithful record of what happened to a file without being able to tell a buyer who is entitled to license the voice in a recording, or the pattern in a photograph of léppi.

Where shared standards help

The gains are real. Leica, Canon, Nikon and Sony have announced credentials written at the moment of capture, and Adobe carries them through editing. Google, OpenAI and Meta have adopted provenance measures for synthetic output. With compatible tools, a photographer in Lagos can send an image whose credential an editor in London can check without a phone call to reconstruct its history. Shared rules remove that friction, and the case for them holds.

Article 50 of the EU AI Act adds a regulatory push. Its transparency obligations began applying on 2 August 2026. Providers of generative AI systems placed on the market before that date have until 2 December 2026 to meet Article 50(2)’s machine-readable marking and detection requirements. C2PA can contribute to that marking. The obligation does not prescribe it as the single technology, and it does not fall the same way on everyone who moves media.

The trouble begins when a provenance check is mistaken for a permission check. An unbroken account of what happened to DhoNam’s files after collection would still say nothing about whether cloning those voices was allowed. A careful buyer may walk away because the permissions look murky. A less careful one may simply take the file. For an automated workflow to honour a prohibition, it needs a check that can halt the proposed use or hand it to a person who can decide.

What has to survive the download

The available tools can describe a condition and name the people behind it. For that condition to survive the download, it needs two more things: a way into the recipient’s software, and an institution that can answer the questions the software cannot.

One concrete step is to give the record a durable link to the community’s own registry, so a receiving system can pull the current terms and find the body responsible for them. The Africa PID Alliance’s DOCiD documentation includes structured fields for Traditional Knowledge Labels and biocultural protocols, while describing direct Local Contexts integration as still in progress. Those fields do not prove that any recipient has fetched them or acted on them. They give a system a place to look.

African-authored ODRL profiles, paired with a rights extension that receiving products actually evaluate, would make conditions like DhoNam’s easier to carry. Regulation could go further and require systems to inspect declared rights, much as Article 50 now requires machine-readable marking of synthetic output; that is a policy choice, and provenance standards do not make it on their own.

Every part of that chain needs a budget. A registry that goes quiet when a twelve-month grant ends leaves every system that depends on it stranded. Someone has to keep the service answering, field the requests, and handle disputes after the launch is forgotten.

The South African San Council’s 2017 research ethics code shows what sustained authority asks of an institution, and where it stops. The code requires researchers to come through the community’s own process and seek approval. It lets the council refuse future work with anyone who breaks it, and says a public listing of unethical researchers might be considered in the worst cases, though none of this on its own creates a court order. In the separate matter of rooibos, whose knowledge the San and Khoi share, benefit-sharing rests on South African law. The council’s own guidance says it cannot approve work with San communities outside South Africa. A record would have to carry that scope, whom the body speaks for, and how far, rather than flatten it into a field marked “owner”.

Connecting an institution like that to a training system takes more than publishing an address. The system must know when to ask and what to do with the answer. The office needs people who can respond, and some way to pursue a refusal that gets ignored. Keeping that office open is part of the engineering, even though it never appears in the specification. None of this makes the San Council the authority for Dholuo recordings. It shows the institutional weight a condition needs if it is to mean anything after the file moves.

Return to the recordings. DhoNam sets one plain condition for its speakers: do not clone or imitate their voices. Once the files reach a system no one at Maseno can see, nobody has shown whether that condition still holds.

Making the condition hold means identifying someone at the receiving end who can be asked, giving that person a way to check a doubtful use, and paying to keep the body that answers alive. For someone who sat and read a sentence into a microphone, that is not a large thing to want. They lent their voice. The promise attached to it should still be worth something after the download.

The Sovereign Stack is a Guzangs research series on the data engines, machine-learning pipelines and transactional architectures shaping the future of the African and diaspora creative economy.

This is what we publish. Every week.

Original reporting on the designers, institutions, and economies defining African creativity, delivered to your inbox.

A weekly letter on African fashion, art, and design, and the people making the work. Reported properly, and worth your time.

By signing up, I agree to the Terms of Use (including the dispute resolution procedures) and have reviewed the Privacy Notice.