Skip to content

Engineering and architecture

AI vendor contracts for AEC firms: clauses that stop training on your data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An AI vendor contract that stops training on an AEC firm's data bars the vendor and its subprocessors from using your inputs, files, outputs and anything derived from them for training, fine-tuning, evaluation, benchmarking or model development, except to deliver the service to you. Cover embeddings and logs, and make the restriction survive termination.

Key takeaways

  • Name every prohibited use explicitly: training, fine-tuning, evaluation, benchmarking and model development.
  • Define customer data to include prompts, uploads, outputs, embeddings, vector indexes and logs.
  • Flow the restriction down to every subprocessor and require notice before new ones are added.
  • Website statements are not contract terms; the order form, terms for your plan and the data processing addendum are what bind.
  • A no-training clause keeps the decision about licensing your records with the firm.

What should the training clause in an AI vendor contract say?#

The training clause in an AI vendor contract should say that the vendor may use your data only to provide the service to your firm, and may not use that data, or anything derived from it, for training, fine-tuning, evaluation, benchmarking or model development. Listing each use matters, because a clause that bans only training can leave room for evaluation sets, benchmark suites or improvements to a different model.

For architecture and engineering firms the stakes are specific. The files flowing into AI tools include client drawings, specifications, calculation packages, site photos, proposal text and recorded client meetings. Many may be covered by client confidentiality terms, and some carry security-sensitive building information such as access control layouts or critical equipment locations.

Ask for the restriction to survive termination, to cover data already processed and to come with deletion on request, including copies in backups once they cycle out.

Why standard AI terms often leave room for reuse#

Standard AI vendor terms often leave room for reuse through broad definitions rather than explicit training rights. Phrases such as service improvement, product development or usage data can reach prompts, uploaded files and outputs, while carve-outs for aggregated or de-identified data can take derived material outside the restriction entirely.

Terms also differ between plans. Free and individual accounts commonly carry consumer-style terms, while enterprise agreements may add a data processing addendum and firmer commitments. Staff who sign up with a firm email may expose firm and client files under those weaker terms without IT knowing.

Terms change, too. Many online agreements let the vendor update them by posting a new version, so ask for notice of material changes to data use and a right to terminate if the changes are unacceptable.

The clause checklist#

The clause checklist below is a starting point for review and negotiation with counsel, not a set of terms every contract must contain. Not every vendor will accept every item, and the right trade-off depends on what the tool touches, how widely it is used and which client obligations may apply to the files it receives.

The clause checklist
ClauseWhat to ask forWhy it matters for AEC files
Definition of customer dataInputs, prompts, uploaded files, outputs, embeddings, vector indexes, models tuned for you, and logsSearch and assistant features can turn drawings and specifications into embeddings that may persist after the source file is deleted
Use restrictionNo training, fine-tuning, evaluation, benchmarking or model development, for any model, by the vendor or its affiliatesCloses the gap between not training on your data and testing models on it
Aggregated or de-identified carve-outRemove it, or limit it to usage statistics that contain no contentDe-identified project content can still reveal a client, a site or a design
Logs and telemetryContent in logs follows the same restriction and a stated retention limitPrompts quoting client specifications can end up in logs kept for debugging or abuse monitoring
SubprocessorsSame restrictions flowed down, a current list and notice before changesThe model provider behind a feature is often a separate company with its own data terms
Retention and deletionDeletion at termination and on request, with written confirmationSupports return-or-destroy duties in client agreements
ConfidentialityCustomer data treated as the firm's confidential informationLets client confidentiality obligations flow through to the vendor
Output ownershipThe firm owns outputs, with no vendor license to reuse themGenerated specifications and narratives may become instruments of service
Change of termsNotice of material changes and a right to terminatePrevents a silent widening of data rights
AssuranceA security report or attestation on request, plus breach noticeGives the risk manager evidence rather than promises

Which AI tools to review first#

AEC firms should review first the AI tools that touch client content in bulk or capture conversations. Those carry the most confidentiality risk and are the most likely to have been adopted without a contract review.

For each tool, record the plan the firm is on, who accepted the terms, what data the tool receives and whether a data processing addendum applies. That register is also the backbone of a firm AI policy.

  • Meeting transcription and note-taking tools that join client, consultant and contractor calls.
  • Document and markup assistants inside PDF review tools used for drawings and submittals.
  • BIM and CAD add-ins that send model data to a cloud service.
  • Specification-writing and proposal-writing assistants fed with past project text.
  • AI features inside the common data environment or project management platform.
  • ERP and CRM add-ons that summarize project financials or client histories.
  • General chat assistants that staff use on their own accounts.

Why your own licensing is different from vendor reuse#

Consented data licensing differs from vendor reuse because the firm decides what is included, checks client contracts first, removes personal and confidential details and records the permitted use. Vendor reuse under broad terms skips every one of those steps, usually without compensation.

A no-training clause therefore does not close the door on licensing. It keeps the decision with the firm, so any later license runs through a rights review instead of happening by default.

Why your own licensing is different from vendor reuse
QuestionVendor reuse under broad termsDeliberate data license
Who decidesThe vendor, under terms accepted at sign-upThe firm, through a written license it approves
What is includedWhatever staff upload or say to the toolA scoped package of selected record types
Client contractsNot checkedReviewed project by project before inclusion
Personal and confidential detailsHandled by the vendor, if at allRemoved or masked under an agreed preparation plan
Record of useNone the firm can seeA written permitted use, term and audit trail
CompensationUsually noneAgreed license terms

Illustrative: an MEP engineering firm reviews two AI tools#

Illustrative: a fictional MEP engineering firm wants to roll out a specification-writing assistant and a meeting transcription tool. The digital practice leader collects the terms for both and sends them to outside counsel with the clause checklist.

The specification assistant's enterprise terms already bar training, but they define customer data narrowly and allow de-identified content to be used for product improvement. The transcription tool's team plan permits recordings to be used to improve its models, and several engineers have been using it on client calls through accounts they opened themselves.

The firm negotiates an addendum with the specification vendor that widens the data definition and removes the de-identified carve-out. It pauses transcription on client meetings, moves users to a firm-managed plan with a data processing addendum and adds both tools to its AI policy. Its own specification archive stays under its control for any future licensing decision.

How SourceX approaches vendor terms#

SourceX runs the transaction, and what it may do with the deidentified dataset is defined in the signed agreement; it manages licenses that supplier firms approve. In the Rights step of the SourceX five-step transaction, the review covers client contracts and the terms of the systems the records came from, because a platform's terms can affect what may be exported and licensed.

The SourceX Evidence Packet then records the permitted use agreed with the buyer, alongside provenance, licensing rights, the privacy record and release authorization, so the firm can show exactly what was licensed and for what purpose.

Frequently asked questions

Is a vendor's public promise not to train on our data enough?

No. Statements on a website or in a blog post can change and may not bind the vendor. Look for the commitment in the terms you actually accepted: the order form, the master agreement, the terms of service for your plan or the data processing addendum.

Are clients starting to require these clauses?

Some are. Some owners now ask design firms to disclose AI use, protect confidential information inside AI tools and avoid uploading their documents to services that may train on them. Check new client agreements and flow those requirements into your vendor contracts.

Does a no-training clause stop our firm from licensing its own data?

No. The clause restricts the vendor. Whether your firm can license its own records depends on client contracts, confidentiality obligations and the rights of consultants and contractors whose material appears in the files.

Who should sign off on AI vendor terms?

Typically the CTO or digital practice leader owns the review, counsel reviews the data terms and the risk manager checks fit with client contracts. Some firms also tell their professional liability insurer about tools that shape design deliverables.

What about tools staff already use on personal accounts?

Find them first, then move important use to firm-managed accounts with reviewed terms, or stop it. An AI policy that lists approved tools and banned uses, such as uploading client drawings to unapproved services, closes most of the gap.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify