Agent, workflow and domain-reasoning data
Collecting computer-use demonstrations at work: consent, monitoring law and capture design
Quick answer
To collect computer use demonstrations from employees, the employer that hosts the capture must meet state monitoring-notice statutes such as New York's, Connecticut's and Delaware's, and should give each worker a notice that names AI model training as a purpose and make participation genuinely optional. The recorder should capture only allow-listed applications, mask credentials and customer data, and let workers pause and review sessions. As the buyer, you write these conditions into the statement of work and check the evidence before accepting data.
By SourceX Editorial · Updated
Who does what when capture happens at someone else's company
The supplying employer, not the buyer, owns the employment relationship, so it gives the notices, collects acknowledgments and answers to regulators; your leverage is the contract and the acceptance criteria. Commissioned capture is one of several routes to the data covered in the agent training data hub, and it involves four parties.
| Party | Role in the project | What you need from them |
|---|---|---|
| Supplier (employer) | Employs the demonstrators; party to contracts with its own customers | Notice versions, acknowledgment logs, worker locations, confirmation that customer contracts allow capture |
| Capture vendor | Runs the recorder and processes sessions for the supplier | Recorder configuration, masking test results, storage location, subprocessors, deletion logs |
| Demonstrators | Employees or contractors recorded while working | Opt-in record, a working pause, session review, a way to withdraw |
| Buyer (you) | Commissions the work and receives the data, usually as model developer | Agreed use restrictions and inputs to your own disclosures |
Your own disclosure duties are a reason to insist on these records. California's AB 2013 requires developers of generative AI systems offered to Californians to post training-data documentation, including whether datasets contain personal information and whether they were purchased or licensed [1]; see what to collect from suppliers for AB 2013 disclosures. If you would rather describe the work you need recorded than find host companies yourself, SourceX's buyer page explains how a data request works.
Step 1: Decide whose work is recorded, and on which systems
This choice sets the legal surface: employees doing production work carry the most obligations, while scripted sandbox tasks, or contractors on their own machines, carry fewer but produce less natural behavior. The wider choice between licensing, commissioning and synthesizing is covered in licensed workflow records vs commissioned demonstrations vs synthetic trajectories, and recordings that already exist in licensed screen recordings.
| Capture setup | Realism | Main legal and data issues | Evaluation and precedent |
|---|---|---|---|
| Employees on production systems during normal work | Highest: real interruptions, exceptions and application switching | Monitoring and privacy law; live customer data on screen; union or works-council input | No reset to a known start state, so tasks are hard to replay |
| Employees on scripted tasks in a sandbox tenant with seeded records | High for interface skill, lower for task mix | Monitoring and privacy law still apply; little customer data | Tasks can be reset and scored by script, as OSWorld does with task setup and execution-based evaluation [2] |
| Contractors on their own computers | Depends on recruiting; no access to the supplier's internal systems | Contributor agreements and privacy law rather than employer monitoring-notice duties | OpenCUA's AgentNet Tool, installed on annotators' own computers, recorded 22.6K trajectories across Windows, macOS and Ubuntu [3] |
| Crowdworkers on public websites | Real sites, invented tasks | Site terms; little personal data if accounts are synthetic | Mind2Web collected crowdsourced action sequences on 137 real websites [4] |
One workable design pairs scripted sandbox tasks for coverage with a smaller production sample for a realistic task mix. Fix the mix before legal review, because each row needs different notices.
Step 2: Map monitoring-notice and privacy law to each worker's location
Obligations follow where each demonstrator works, so get a roster by state or country before any software is installed. The employer's existing monitoring notice is rarely enough: employer monitoring long predates AI training, as GAO's 2002 review of companies storing employees' email, websites visited and file activity shows [5], and notices written for security and compliance seldom anticipate model training.
These are the US provisions a capture plan most often has to satisfy, with status as of October 2026:
| Law | What triggers it in a capture project | What the employer must do |
|---|---|---|
| New York Civil Rights Law § 52-c (in force since 7 May 2022) | Monitoring employees' telephone, email or internet access or usage | Prior written notice on hiring, a written or electronic acknowledgment, and a notice posted conspicuously [6][7] |
| Connecticut Public Act 26-73, replacing Gen. Stat. § 31-48d (signed 4 June 2026, effective 1 October 2026) | Electronic monitoring of employees | Commentators describe an expanded law; the former § 31-48d required prior written notice of the types of monitoring and a posted notice. Check the enacted text before capture starts [8][9] |
| Delaware, 19 Del. C. § 705 | Monitoring employees' telephone, email or internet usage | An electronic notice each day the employee uses employer email or internet, or a one-time notice the employee acknowledges in writing or electronically [10] |
| California Consumer Privacy Act | California-resident employees of businesses that meet CCPA thresholds; the employee-data exemption became inoperative on 1 January 2023 [11] | A notice at collection listing categories and purposes; no new incompatible purpose without new notice; collection limited to what is reasonably necessary and proportionate [11]. A keystroke log that captures an account log-in with its password collects sensitive personal information [12] |
| California Penal Code § 632 | Audio of confidential conversations, such as softphone calls or a narrated session with a colleague | Consent of all parties [13] |
| Illinois BIPA (740 ILCS 14) and Texas Bus. & Com. Code § 503.001 | Webcam or voice capture used to derive face geometry or voiceprints, for example to verify who is demonstrating | Illinois: written notice of purpose and retention period, plus a written release, before collection [14]. Texas: notice and consent before capture for a commercial purpose [15] |
For demonstrators in the EU, the GDPR applies [16]. Article 88 lets member states, including through collective agreements, set more specific rules for employee data, so national labor law and any works-council agreement shape what is allowed [16]. The Article 29 Working Party, the body that preceded the European Data Protection Board, asked employers in Opinion 2/2017 to test any workplace monitoring for necessity, legal basis, fairness, proportionality and transparency [17]. Ask the supplier for its data protection impact assessment, or its documented reason for not doing one.
Step 3: Make participation voluntary and the notice specific
US monitoring statutes require notice rather than consent, but for training data you want an opt-in that workers can refuse without consequence, because it is the evidence a rights review will look for. In the EU, consent is a weak basis: the GDPR's recitals say consent should not be relied on where there is a clear imbalance between the person and the controller [16], and WP249 treats employee consent as rarely freely given [17]. EU employers therefore usually rely on another Article 6(1) basis, typically legitimate interests, which requires weighing the employer's interests against workers' rights and freedoms [16]; WP249 accepts employee consent only in exceptional cases where refusing has no consequences at all [17].
A project-specific notice should state, in plain terms:
- that sessions are recorded to train and evaluate AI agents, and which category of recipient receives them;
- exactly what is captured: screenshots or video, mouse and keyboard events, window titles, URLs, accessibility-tree snapshots, and whether audio or webcam is on;
- which applications are in scope and how to pause;
- that recordings will not be used for performance evaluation, discipline or productivity scoring;
- how long raw recordings and processed trajectories are kept, and how to withdraw a session.
Where staff are represented by a union or works council, new capture tooling can bring bargaining or consultation duties, so build that lead time into the schedule; the guide to licensing data with a union workforce lists the questions to ask. Participant-facing wording is covered in consent language for commissioned AI data collection, and filming workers themselves in recording employees on video for AI datasets.
Step 4: Clear the customer and colleague data that appears on screen
A demonstrator's agreement covers the demonstrator, not the customers, patients and colleagues whose records and messages appear in the CRM, ticket queue, EHR or chat pane. Before production capture, confirm that the supplier's contracts with its own customers allow their data to be recorded and passed to a third party for model training; enterprise agreements often limit a vendor to processing for service delivery, the problem covered in client data held by service providers.
Sector rules narrow the options further:
- Health care. EHR screens show protected health information. HIPAA recognizes two de-identification methods, Safe Harbor and Expert Determination [18], and live EHR video is hard to bring under either. For health records, SourceX requires HIPAA de-identification before anything is considered for a license. A sandbox populated with synthetic patients is usually the workable route.
- Financial services. When customer nonpublic personal information leaves a financial institution, Regulation P limits how the recipient may reuse and redisclose it [19].
- Internal messages. Slack, Teams and email panes expose colleagues' words; see whether employee consent is needed to license Slack messages.
Where production data cannot be cleared, record in a staging tenant of the same applications with seeded records, which also gives evaluation tasks a known start state; see seed data and state snapshots for enterprise agent sandboxes.
Step 5: Configure the recorder so the notice stays true
Recorder settings turn legal promises into technical facts: if the notice says personal browsing is not recorded, the recorder must enforce an allow-list rather than rely on workers to pause. Require these controls, and ask the vendor to demonstrate each on a test machine:
- Application and domain allow-list. Record only named executables and URL domains, such as the ERP client, the CRM domain and the spreadsheet; anything else produces no frames and no events.
- Auto-pause and hotkey. Pause automatically on password managers, personal email, banking and HR self-service, with a one-key pause and a visible recording indicator.
- Secure-field masking at the source. Drop characters typed into password fields (HTML
input type="password"and fields the accessibility API marks as secure), log a placeholder typing action, and blur those fields in frames. - Designated-field masking. Mask card numbers, Social Security numbers and patient identifiers by selector or screen region, on the device rather than a server.
- Worker review before upload. Let the demonstrator replay a session and delete segments or all of it.
- Task boundaries. A start and stop control that records the task instruction, so sessions become episodes rather than hours of unsegmented video.
- Audio and webcam off by default. Enable them only with separate consent, given the recording and biometric rules above.
- Encryption and retention. Encrypt on the device and in transit, and delete raw video on a fixed schedule once trajectories are extracted.
What each processed step record must contain is defined in computer-use trajectory data: what every step record must contain. Masking at capture reduces, but does not remove, the need for a second pass; see PII redaction for screen recordings and computer-use trajectories and how to de-identify workflow and screen activity data.
Step 6: Write the evidence into the statement of work
Acceptance should depend on documents as well as data, because a trajectory set without notice versions, opt-in records and masking evidence cannot pass a rights review later. Use this checklist when drafting the statement of work for a custom data collection:
- Worker roster by state or country, matched to the notice version each person received
- Copies of every notice version with the date each took effect
- Per-worker acknowledgment and opt-in records with timestamps, plus a withdrawal path that deletes that worker's sessions
- Written commitment that capture data will not be used for performance evaluation or discipline
- Supplier confirmation that its customer contracts permit the capture, or that only seeded data appears
- Recorder configuration (allow-list, blocked list, masking rules) delivered with each batch
- Masking test results: canary values, such as fake card numbers and passwords planted in test accounts, absent from every frame, event and OCR output
- Worker-review and deletion logs per session
- Raw-video retention period, storage location and subprocessor list
- Union or works-council sign-off where the workforce is represented
- Inputs for your own disclosures: collection dates, whether personal information remains, and the license terms
Red flags in a vendor proposal: repurposed employee-monitoring software built for oversight, whole-desktop recording with redaction "later", raw keystroke text in the output, consent buried in an employment contract or acceptable-use policy, and no link from a session to the notice its worker saw. Keep the evidence in the form described in consent and notice records for AI training data.
Illustrative capture session manifest
A per-session manifest ties each trajectory to the notice, scope and masking that governed it, which is what a reviewer checks when the dataset is audited.
Illustrative example: invented to show structure; it does not describe an available dataset.
{
"session_id": "cap-000418",
"worker_ref": "w-7f3a",
"work_location": "US-NY",
"engagement": "employee",
"participation": { "basis": "opt_in", "opt_in_at": "2026-09-14T15:02:11Z", "withdrawn": false },
"notice": {
"version": "capture-notice-v3",
"names_ai_training": true,
"acknowledged_at": "2026-09-14T15:01:40Z",
"statutory_notices": ["NY Civil Rights Law 52-c"]
},
"environment": { "type": "sandbox_tenant", "records": "seeded_synthetic", "os": "Windows 11" },
"scope": {
"allowed_apps": ["erp-client", "crm-web", "spreadsheet"],
"allowed_domains": ["crm.sandbox.example.test"],
"auto_pause_on": ["password_manager", "personal_email", "unlisted_browser_tab"]
},
"capture": { "screenshots": "on_action", "video": false, "input_events": true,
"accessibility_tree": true, "audio": false, "webcam": false },
"masking": { "secure_field_text": "dropped", "regions": ["card_number", "ssn"],
"applied": "on_device", "canary_test": "passed" },
"worker_review": { "reviewed_at": "2026-09-14T16:40:05Z", "segments_deleted": 1 },
"retention": { "raw_frames_delete_after_days": 30 },
"use_restrictions": ["no_performance_evaluation"],
"episodes": 6
}
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Commissioning computer-use capture at US businesses?
If you need demonstrations on real business software and would rather not recruit host companies yourself, describe the tasks, systems and capture conditions you need. New recordings of hands-on work are among the kinds of data SourceX sources: it looks for US businesses that hold the data you describe, every release is approved by the supplying company, and each dataset goes through rights review that checks required consents are in place before delivery under a license. A request does not guarantee a match. Specify the work you need recorded.
Sources
- California Legislature, "AB-2013 Generative artificial intelligence: training data transparency (Chapter 817, Statutes of 2024)" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- Xie et al., "OSWorld: Benchmarking Multimodal Agents for Open-Ended Tasks in Real Computer Environments" (2024). https://arxiv.org/abs/2404.07972v2
- Wang et al., "OpenCUA: Open Foundations for Computer-Use Agents" (2025). https://arxiv.org/abs/2508.09123
- Deng, Su et al., "Mind2Web: Towards a Generalist Agent for the Web" (2023). https://arxiv.org/abs/2306.06070v1
- U.S. General Accounting Office, "Employee Privacy: Computer-Use Monitoring Practices and Policies of Selected Companies (GAO-02-717)" (2002). https://www.govinfo.gov/content/pkg/GAOREPORTS-GAO-02-717/html/GAOREPORTS-GAO-02-717.htm
- New York State Legislature, "Assembly Bill A430 (2021): notice of electronic monitoring of employees (Civil Rights Law section 52-c)" (2021). https://legislation.nysenate.gov/pdf/bills/2021/a430
- Holland & Knight, "New York Law Requires Notice of Employees' Electronic Monitoring Effective May 7, 2022" (2022). https://hklaw.com/en/insights/publications/2022/05/new-york-law-requires-notice-of-employees-electronic-monitoring
- Connecticut General Assembly, "Public Act No. 26-73 (SB 472), An Act Concerning the Electronic Surveillance of Employees" (2026). https://prdext2.cga.ct.gov/2026/act/Pa/pdf/2026PA-00073-R00SB-00472-PA.PDF
- Workplace Privacy Report, "Deadline imminent for Connecticut's expanded electronic monitoring law" (2026). https://www.workplaceprivacyreport.com/2026/09/articles/monitoring-2/deadline-imminent-for-connecticuts-expanded-electronic-monitoring-law/
- State of Delaware, "Delaware Code Title 19, Chapter 7, Subchapter I (including section 705)". https://delcode.delaware.gov/title19/c007/sc01/index.html
- California Privacy Protection Agency, "California Consumer Privacy Act of 2018 (statute text, as amended)". https://cppa.ca.gov/regulations/pdf/ccpa_statute.pdf
- California Legislature, "California Civil Code section 1798.140 (California Consumer Privacy Act definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- California Legislature, "California Penal Code section 632". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=PEN§ionNum=632
- Illinois General Assembly, "Biometric Information Privacy Act (740 ILCS 14/)". https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3004
- Texas Legislature, "Texas Business and Commerce Code section 503.001 - Capture or Use of Biometric Identifier". https://statutes.capitol.texas.gov/Docs/BC/htm/BC.503.htm
- European Parliament and Council of the European Union (Official Journal of the EU, via EUR-Lex), "Regulation (EU) 2016/679 (General Data Protection Regulation)" (2016). https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Article 29 Data Protection Working Party, "Opinion 2/2017 on data processing at work (WP249)" (2017). https://ec.europa.eu/newsroom/article29/items/610169
- U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
- Consumer Financial Protection Bureau, "12 CFR 1016.11 Limits on redisclosure and reuse of information (Regulation P)". https://www.consumerfinance.gov/rules-policy/regulations/1016/11/
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.