Access to a dataset or model is not the same as unrestricted permission to use it. A project review should connect each important input to its source, terms and responsible owner.
Document the source and intended use
Record how data was obtained and the use contemplated by the project. Consider whether sensitive information is involved and which agreements or permissions need examination. Public availability alone is not enough to resolve all questions about permissible use.
Separate the layers of control
Model weights, software, datasets and generated outputs can be governed by different terms. Distinguish ownership, permission to use and the practical ability to maintain a system. The rights to research outputs should be checked in the relevant agreements rather than inferred from who financed the work.
Plan for changes in dependencies
Ask what happens if access is withdrawn, terms change or an upstream service ends. Keep an inventory of critical dependencies and unresolved questions. This is a research checklist, not a legal conclusion about any dataset, licence or jurisdiction; specific rights require document-based review.

