Nobody can verify that the output of an LLM isn’t from its training data except those with access to its training data.