Summary
- Revision 08 of the AIPREF vocabulary expressly makes the Search category override uses that would otherwise count as AI Training or AI Use.
search=ycan therefore coexist withtrain-ai=n, but only for models and outputs used exclusively to select assets and direct users to their original location under the draft’s Search conditions.- The rule does not permit general-purpose training, generated summaries or unrelated AI products, and it supplies neither enforcement nor legal effect.
- The text is an active working-group draft whose own notice says it does not reflect IETF consensus in whole or in part.
The apparent contradiction is deliberate
Suppose a publisher sends two preferences: do not train an AI model on this page, but do allow search. A simple “most restrictive signal wins” reading would make the second preference nearly useless for any search engine whose ranking or retrieval pipeline contains machine learning. Revision 08 of the AIPREF vocabulary, posted on 14 September, now resolves that collision directly.
The draft defines AI Training as using an asset to modify the learned parameters of a generative-AI model. It defines AI Use separately, covering an asset supplied to a generative model when a user did not provide that asset directly. Search has another test: the primary purpose must be to select assets and send users to the assets’ original location. Direct links are required, excerpts may help show relevance, and generated summaries are outside the category.
Within that boundary, Search can include internal processing that trains or uses AI models. The qualification carries the weight: those models and their outputs must be used exclusively under the Search conditions. The draft then says Search overrides activity that would otherwise fall under AI Training and AI Use. An affirmative search preference is consequently a narrow exception to a negative general preference, not a contradiction the recipient is free to ignore.
The revision 07 text described internal model processing but did not state the cross-category priority as directly. The official diff also shows the addition of ai-use, a definition of generative AI and the explicit override. This is a semantic change in how a combination of preferences is read, not merely a renamed token.
One category is restrictive; categories are not flat
The distinction is easier to miss because the draft also contains a restrictive conflict rule. For multiple applicable statements about the same category, n wins; absent a negative, y wins; absent either, the result is unknown. That rule operates category by category. Search’s priority over Training and Use is a separate cross-category rule.
The vocabulary serializes these choices as train-ai, ai-use and search, with y or n values. RFC 9651 provides the Structured Fields machinery beneath that expression. It does not decide what Search includes, police recipients or confer a right to reuse content.
Transport sits in a companion document. Revision 05 of the attachment draft describes a Content-Usage response header and a robots directive; its Datatracker record identifies the current work. The vocabulary supplies meaning while attachment supplies places to carry it. Neither proves a crawler read the signal, interpreted the combination correctly or confined a model to the permitted purpose.
That last boundary is operationally substantial. A ranking model used only to select links can fit the exception. A model whose learned parameters later support an answer engine, a writing assistant or a general training corpus does not become permissible merely because search was somewhere in its data path. Generated summaries also fail the draft’s current Search test. The recipient needs purpose separation that can be explained and audited, not a search label attached after the fact.
Editor intent is evidence, not adoption
The change answers a question already raised in the working-group discussion. Alissa Cooper asked whether search=y lets a search application train or use models when the resulting presentation remains within the Search conditions. Martin Thomson replied that this understanding was correct and pointed to clarifying work.
Those messages help establish the intended reading of the editor’s change. They are not a vote, adoption notice or substitute for working-group review. The draft’s front matter is unusually plain: its contents do not reflect working-group consensus, in whole or in part. The document page, revision history and AIPREF charter should be read as the record of active standards work, not as proof that the rule has become IETF policy.
There are unresolved edges as well. Issue 249 asks when a URL or reference means an asset was supplied directly by a user for the purpose of ai-use. Revision 08 also marks its new language on conveying training preferences with distributed models for further working-group discussion. A precise Search override does not make the whole classification complete.
The draft itself says a preference does not ensure compliance and leaves recipients to decide whether and how to follow it. Contracts or other specific arrangements may override the machine-readable preference. The vocabulary requests no IANA action and does not claim to be a security mechanism. Its achievement is smaller and useful: it exposes a policy choice that might otherwise be hidden inside a search provider’s implementation.
Sources
- AIPREF vocabulary revision 08
- AIPREF vocabulary revision 07
- Official revision diff
- Current vocabulary status
- Vocabulary revision history
- AIPREF working-group charter
- Attachment draft revision 05
- Current attachment status
- Alissa Cooper’s search question
- Martin Thomson’s reply
- Open issue 249
- RFC 9651
- Minimum Initial Specification
- Why BTW exists
- The Policy Mirror
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

