Leadership and readiness
An AI company wants your data free 'for research': what to consider
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
When an AI company asks for your data free 'for research,' treat the request as a no-fee license, not a donation. The records leave the company either way, so settle permitted use, publication rights, whether research can turn into a product, and how deletion is proven. Free changes the price, not the rights, privacy or confidentiality exposure.
Key takeaways
- A no-fee request still needs a written license with permitted use, confidentiality, security and deletion terms.
- 'Research' has no fixed meaning in a data request, so pin down whether it means academic publication, internal evaluation or product development.
- Commercial use creep is the main risk: research models, benchmarks and datasets can move into products.
- Decide in advance what may be published, including excerpts, examples, statistics and your company's name.
Why free does not mean low risk#
Free does not mean low risk, because the exposure in a data license comes from records leaving the company, not from the payment. Customer details, supplier terms, staff messages and internal decisions carry the same obligations whether the recipient pays or not.
A no-fee request also tends to arrive with lighter paperwork: an email, an online request form or a data use agreement written for public datasets. Those documents often assume low-sensitivity data. Operational records from a help desk, ERP or project system rarely fit that assumption.
Contracts can recognize forms of value other than money, such as early access to results or a strategic relationship. If the requester is offering that kind of value, name it in the agreement so both sides know what was exchanged.
Ask also who inside the requester will touch the records. A request signed by a researcher may still route files through a data engineering team, an outside annotation vendor or a cloud workspace shared with product staff.
What does 'for research' actually cover?#
The phrase 'for research' can cover anything from a peer-reviewed academic study to a product team's experiments, so the first step is to get the requester's meaning in writing. The phrases below are common, and each hides a different question.
If the requester cannot say what output the research will produce, who will see it and whether any product could follow, the request is not yet specific enough to evaluate. Ask for a one-paragraph research plan before anything else; a serious team can usually write one quickly, and the answer tells you which rows of the table apply.
| Phrase in the request | What it can cover | What to pin down |
|---|---|---|
| Research purposes | Academic study, internal R&D or early product development | Who does the work, what the output is and whether a commercial product may follow |
| Non-commercial use | Use without a direct sale, which can still feed a commercial model | Whether models or features trained on your records may later be sold |
| Evaluation or benchmarking | Testing models against your records | Whether the benchmark will be published or shared with other developers |
| Aggregate insights | Statistics drawn from your records | Which statistics may be published and whether your company is named |
| Collaborators | Partner labs, universities or contractors | Who may receive copies, and under what terms |
A checklist before you say yes#
A checklist before saying yes keeps a friendly request from becoming an open-ended grant. Each item should end up as a clause in the agreement, not as a reassurance on a call.
If the requester resists putting these points in writing, treat that as information about how the records would be handled later. A team that plans to honor the terms rarely objects to writing them down, and the drafting conversation itself shows how carefully your records would be handled.
- Permitted use: one stated purpose, with everything else excluded.
- Commercial use: whether models or tools trained on the records may be sold or built into products.
- Derived data: who controls annotations, extracted facts, embeddings and synthetic records built from your data.
- Publication: what may appear in papers, blogs or talks, and your right to review before release.
- Onward sharing: no transfer to collaborators, affiliates or acquirers without your written consent.
- Security: where copies are stored, who can access them and how a breach is reported.
- Term and deletion: an end date, deletion of copies and derived datasets, and written certification.
- Attribution: whether your company is named, thanked or kept anonymous.
How commercial use creep happens#
Commercial use creep happens when research outputs move into products without anyone revisiting the original permission. A model trained for a study becomes the base for a feature, a benchmark becomes a sales asset, or the research team is acquired along with everything it holds.
Startups are especially exposed because research and product teams are often the same people. A requester can be entirely sincere today and still sit inside a company whose priorities change after its next financing or sale.
The protection is in the drafting: define research narrowly, state that any commercial use needs a new written agreement, and make the license non-assignable with a change-of-control clause, so it does not pass to an acquirer without your consent. Have counsel review the wording, because how these clauses work depends on the agreement and the governing law.
Illustrative: an engineering firm and a request for RFI logs#
Illustrative: a fictional structural engineering firm is asked by the research group of an AI startup for its requests for information, submittal reviews and response logs, free of charge, to study how engineers resolve design questions. The group offers to thank the firm in a paper.
The managing principal checks the request against the checklist. Many of the RFIs sit in Procore projects run by general contractors, where the firm was an invited collaborator rather than the account owner, and many reference drawings the clients own. The startup's draft terms allow use for research and related purposes with sharing among collaborators, and the paper could quote RFI text. The firm declines the free request, says it would consider only a scoped license limited to records it controls, after a rights review, and logs the request with its reasons.
When can a no-fee arrangement make sense?#
A no-fee arrangement can make sense when the use is narrow, the records are low sensitivity and the company receives something it values, such as findings relevant to its own operations. Even then, the same documentation applies.
If most signals land in the right-hand column, a no is reasonable. It is also fair to answer that the company licenses records only on commercial terms, which keeps every conversation on standard documents.
| Signal | Leans toward considering it | Leans toward declining |
|---|---|---|
| Records | Internal, low sensitivity and already prepared | Customer communications, client deliverables or code |
| Use | A defined study with no product path | Open-ended research and related purposes |
| Publication | Aggregate findings, with your right to review | Excerpts or worked examples from your records |
| Recipient | A named team with no onward sharing | Collaborators, affiliates and successors |
| Exit | Deletion with certification on a fixed date | Retention for reproducibility with no end date |
How SourceX approaches research requests#
SourceX does not treat a research label as a reason to shorten the process. A package moves through the SourceX five-step transaction only with the supplier's approval at each step, and the permitted use is written down before anything is released.
That permitted use sits in the SourceX Evidence Packet next to the licensing rights and release authorization. If research use later drifts toward a product, the supplier can point to the exact wording that was agreed.
Frequently asked questions
Is a university lab different from a startup's research team?
The questions are the same, but the paperwork differs. University data use agreements often focus on publication and academic freedom, while startup terms tend to focus on product rights. In both cases, check who controls derived models, what may be published and whether the agreement follows the team if it moves elsewhere.
Should we ask for payment instead?
You can. Saying that the company licenses records only on defined commercial terms is a clear position, and it filters out requests that depend on free access. Whether a requester will pay depends on its needs and the records, so do not assume a free request will turn into a paid one.
What if they offer co-authorship or an acknowledgment?
Acknowledgment has some value, but it also names your company publicly as a data source, which may prompt questions from customers or employees. Decide whether you want to be named at all, and if so, review the exact wording and context before anything is published.
Do we need to tell customers or employees?
That depends on what the records contain, your privacy notices and your contracts. If customer communications or employee messages are in scope, the rights review should check notices and agreements first. Excluding those records is often simpler than communicating about them for a no-fee request.
Can the research team keep the data after the study for reproducibility?
Some researchers ask to keep data so results can be verified. If you agree, limit retention to one defined copy under the same security and confidentiality terms, with no new uses and a final deletion date. Open-ended retention is one of the most common gaps in no-fee agreements.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.