Skip to content

Data licensing for AI training

License term, perpetual rights and territory for AI training data

Quick answer

A training data license should not have one term. Split it into three clocks: a finite access period during which the supplier delivers and you may copy the data, a use period during which you may train new models on it, and perpetual, irrevocable, worldwide rights to keep and commercially use models already trained. Territory should attach to where the data is processed, not to where models are served, because a deployed model cannot be geofenced the way a file can [1][2].

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Why "perpetual" means three different things in a data license

A perpetual grant only protects you if the contract says what is perpetual: the data, the right to train, or the trained model. Practitioner guidance recommends a perpetual, worldwide license for training and for use of models trained during the term, with a finite license for ongoing dataset access [1]. Vendor material describes the opposite risk: term-limited licenses that may oblige the buyer to retrain or "unlearn" a model after expiry [2].

Search results for "perpetual license training data" also surface consumer terms of service in which a platform takes a perpetual training license over user uploads [7]. That is a platform-to-user grant, not a negotiated B2B data license, and it should not anchor your expectations. In a commercial deal, perpetual model rights are a bargained term priced into the fee, which is why the overall term structure belongs in your AI data license term sheet from the first draft.

The three-clock term structure buyers should propose

The safest structure separates access, training use and model rights, each with its own start, end and survival language. Treat each clock as a defined term so that termination, renewal and audit clauses can refer to it precisely.

Illustrative example: invented to show structure; it does not describe an available dataset.

ClockWhat it coversTypical buyer positionSupplier concernSurvival on termination
Access PeriodDelivery of records, refreshes, API or share access, copying into buyer storage1 to 3 years, renewable; refreshes listed by cadenceData leaking beyond the deal; stale copiesEnds; deletion or return of raw copies per the deletion clause
Training Use PeriodRight to train, fine-tune, evaluate and build new model versions on the licensed recordsCoterminous with access plus a wind-down (for example, 90 days to finish in-flight runs)Unlimited future models on one paymentEnds for new training; in-flight runs completed or abandoned
Model RightsUse, host, distribute and sublicense models and weights trained during the Training Use Period, plus outputsPerpetual, irrevocable, worldwide, survives expiry and termination except for uncured material breach defined narrowlyModel memorization or verbatim regurgitation of recordsSurvives; supplier remedy is damages, not model destruction
Compliance RecordsProvenance files, manifests, consent and de-identification evidenceRetained for as long as any model trained on the data is in serviceCopies of raw data kept under a compliance labelSurvives, limited to metadata and audit evidence

Two drafting details decide whether this works. First, define "Trained Model" to include checkpoints, distilled students and fine-tunes of those models, or link the definition to your derivative and successor model rights language. Second, state that expiry of the Access Period does not, by itself, require retraining, unlearning or destruction of any Trained Model.

Where model rights should survive and where they should not

Model rights should survive expiry and ordinary termination, and they should fail only in narrow, defined cases. Commentary on AI contracts notes that termination clauses often address data return but leave the fate of the model unaddressed, which is where disputes start [3].

Reasonable carve-outs a supplier may ask for, and that a buyer can usually accept, include:

  • Proven unlicensed use. Models trained on records outside the licensed scope (for example, a different business unit's data delivered by mistake) can be excluded from survival.
  • Regurgitation remedy. Instead of destruction, commit to output filters or a retrain on the next scheduled version if the model reproduces licensed records verbatim above an agreed test threshold.
  • Third-party claims. If a rights holder succeeds in a claim against the supplier's chain of title, survival may be conditioned on the supplier's indemnity process rather than ending automatically; see IP indemnities for licensed training data.

The consequences of termination for models already in production are covered in depth in what happens to trained models when a data license ends. This page is about setting the clocks at signing so that question rarely arises.

How long the access and training periods should be

Access and training periods should match the data's refresh value and your model release cadence, not an arbitrary one-year default. If you release a major model version every 9 to 12 months, a 12-month access period can leave you with one training window before renewal pressure starts.

Use these inputs to size the term:

  1. Refresh cadence. Operational data such as support tickets, CRM activity or engineering issue history decays in value; a monthly or quarterly refresh justifies a longer access period with a per-refresh price.
  2. Training pipeline lag. Allow for the time between delivery and the training run: ingestion, de-duplication, quality filtering and evaluation set construction often take several months.
  3. Evaluation reuse. Held-out evaluation splits are often used for years. Either put them inside Model Rights or give them their own survival clause.
  4. Renewal mechanics. Avoid evergreen auto-renewals without a price cap and a notice window long enough to run procurement; see the negotiation checklist with fallback positions.

Delivery method changes what "end of access" means in practice. With a live share such as Snowflake Secure Data Sharing, consumers query read-only objects and no data is copied between accounts, so the provider can end access by revoking the share [8]. Consumers can still copy query results into their own tables, so the contract should say whether such copies are allowed. With file delivery to your bucket, the Access Period ends contractually but the copies persist until deletion, which is why the deletion clause and audit rights must reference the same defined periods; see deletion and return clauses.

Territory: why worldwide model rights matter for globally served models

Model and output rights should be worldwide, because a model served from one cloud region answers users everywhere and weights move across borders through replication, edge inference and customer self-hosting. A territory clause written for traditional database licenses ("licensee may use the Data in the United States") either becomes unenforceable in practice or quietly puts a global model in breach.

Copyright and database rights are territorial, so suppliers sometimes limit territory because they only hold rights in certain countries. That is a chain-of-title question, not a commercial preference, and you should ask it directly: in which countries does the supplier own or control the rights it is granting? If the honest answer is "US only," a worldwide grant is a warranty the supplier cannot back.

EU obligations also follow the model, not the data's origin. Providers of general-purpose AI models placed on the EU market must keep a copyright policy and publish a summary of training content under Article 53 of the AI Act [4], using the template the AI Office published on 24 July 2025 [5]. As of October 2026, those duties have applied since 2 August 2025 and AI Office enforcement powers apply from 2 August 2026 for new models and 2 August 2027 for models already on the market, so a license that bars you from naming the source category in that summary creates a direct conflict, and one that bars EU distribution of the model shuts you out of that market. Draft a clause that allows disclosure of the data source type and license basis as required by law.

Deployment territory versus processing location

Separate two concepts that territory clauses often merge: where the model and outputs may be offered (deployment territory) and where raw licensed records may be stored and processed (processing location). Deployment territory should be worldwide; processing location can reasonably be restricted.

Processing restrictions are legitimate when they track legal obligations. Personal data transfers are a privacy question governed by data protection law, and sector rules can limit reuse no matter what the contract term says; for example, US rules limit redisclosure and reuse of nonpublic personal financial information received from a financial institution [9]. Handle these in a data processing or transfer schedule, and link to de-identified vs anonymized legal definitions when deciding whether the delivered data is personal data at all.

For buyers outside the US licensing US-held data, the owner question on licensing data to a non-US lab covers the cross-border side. Typical processing clauses name approved cloud regions, list approved subprocessors and require notice before moving raw records to a new country.

Red flags when comparing offers

Compare offers on the clocks, not just the headline term. These patterns deserve pushback:

  • "License term: 2 years" with no survival clause. Model rights silently end with the license.
  • Termination for convenience by the supplier. Combined with no model survival, this lets the supplier reprice your production model.
  • Territory defined as the buyer's country of incorporation. Breached the first time a customer in another country calls your API.
  • Perpetual data rights offered at a low price. Check chain of title; a supplier granting more than it holds exposes you to third-party claims, and copyright exposure over training materials can be large: the $1.5 billion Bartz v. Anthropic class settlement received final approval [6].
  • "Unlearning" as the default remedy. Vendor material raises unlearning as a post-expiry obligation [2], but machine unlearning is not yet a reliable, verifiable procedure for large models; prefer retraining on the next scheduled version or output filtering.

For a wider view of rights, pricing and grant language, start from the AI training data licensing hub and the AI training rights grant clause guide. The owner page on AI data license terms: use, exclusivity and deletion summarizes the related terms.

How SourceX handles term and territory in licensed datasets

SourceX sources operational datasets from US companies on request and manages the commercial process, including licensing agreements and ongoing purchases. Each dataset is rights-reviewed for ownership and consents and delivered under a license that defines the records, allowed uses, term and delivery, with terms agreed per deal. Nothing is contracted until the supplying company agrees, and SourceX serves AI teams wherever they are based. Buyers can describe the data they need on the SourceX buyers page.

Request training data with defined term and territory

If you need operational data such as support histories, engineering records or finance and legal workflows under a license that states term, allowed uses and delivery, describe the data rather than the businesses that might hold it. SourceX looks for US companies that hold it, and every release is approved by the supplying company; a request does not guarantee a match. Start at sourcex.si/buyers.

Sources

  1. Terms.law, "AI and Data Licensing memo: making an AI training data license usable". https://terms.law/insights/ai-training-data-licensing-usable-agreement.html
  2. Depositphotos, "AI training data licensing (vendor blog)" (2026). https://blog.depositphotos.com/rights-cleared-ai-data-licensing.html
  3. Reed Smith, "Entertainment and media guide to AI: contractual considerations for security, performance and termination". https://www.reedsmith.com/articles/entertainment-and-media-guide-to-ai/contractual-considerations-security-performance-and-termination/
  4. Official Journal of the EU, via EUR-Lex, "Regulation (EU) 2024/1689 (AI Act), consolidated text of 27 July 2026". https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02024R1689-20260727
  5. European Commission (AI Office), "Explanatory Notice and Template for the Public Summary of Training Content for general-purpose AI models" (2025). https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models
  6. Authors Guild, "Court grants final approval of Anthropic copyright settlement" (2026). https://authorsguild.org/news/court-grants-final-approval-anthropic-copyright-settlement/
  7. ConductAtlas, "Suno Terms of Service: perpetual AI training license over user submissions". https://conductatlas.com/platform/suno/suno-terms-of-service/perpetual-ai-training-license-over-user-submissions/
  8. Snowflake Documentation, "About Secure Data Sharing". https://docs.snowflake.com/en/user-guide/data-sharing-intro.html
  9. Consumer Financial Protection Bureau, "12 CFR 1016.11 Limits on redisclosure and reuse of information". https://www.consumerfinance.gov/rules-policy/regulations/1016/11/

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data