Skip to content

Leadership and readiness

Are your SaaS vendors training AI on your data? How to check and opt out

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

To check whether a SaaS vendor is training AI on your data, read four places: the subscription agreement, the data processing addendum, any AI-specific terms and the admin console's AI settings. Look closely at service improvement and aggregated data language. Opt out where offered, get written confirmation, and log each system's answer in one register.

Key takeaways

  • Vendor AI use is defined across several documents, so the admin setting alone rarely gives the full answer.
  • Service improvement, aggregated data and feedback clauses are where broad AI rights usually sit.
  • An opt-out may cover only future data, a single feature or one workspace, so confirm its scope in writing.
  • Keep a register of each vendor's AI terms, setting status and confirmation, and recheck it at every renewal.

Where to look for a vendor's AI training terms#

A vendor's AI training terms are usually spread across the subscription agreement, the data processing addendum, a separate AI or machine learning addendum, the privacy policy and the documentation for each AI feature. Reading only one of them gives a partial answer.

Start with the contract your company actually signed or accepted, including its version date, because online terms change and order forms can override them. Then check the vendor's trust center for any statement on model training, and the admin console for settings that turn AI features or data sharing on and off.

Separate three things a vendor might do: train general models used by all its customers, run AI features on your content for your account only, and use aggregated or de-identified data to improve its service. The first matters most if you care where your support tickets or call transcripts end up.

Contract terms that signal AI use#

Contract terms that signal AI use often never mention AI. Broad rights tend to sit in clauses written long before current AI features shipped, and they are easy to skim past.

This article describes clause types in general, not any particular vendor's terms. Each vendor's current documents are the only reliable answer for that vendor.

Contract terms that signal AI use
Clause or phraseWhat it can allowQuestion to ask the vendor
Service improvementUse of customer content to build or improve featuresDoes improvement include training models used for other customers?
Aggregated or de-identified dataUse of data stripped of identifiers, often without other limitsHow is de-identification done, and can it include text from our records?
Usage data or telemetryUse of information about how the product is usedDoes usage data include message content, transcripts or attachments?
FeedbackUse of anything users submit as feedback, including ratings of AI outputDo rating or correction actions send our content into training sets?
SubprocessorsSharing content with third-party model providersWhich model providers process our content, and under what training terms?
Beta or preview featuresDifferent, often broader terms for early featuresDo preview terms apply to us, and who enabled them?

Audit table by system category#

An audit by system category keeps the review proportionate: start where your most sensitive and most valuable records live. The table shows where the answer usually sits and what to record for each category.

A mid-sized company can usually cover its main systems with the IT lead and one business owner per category. Counsel only needs to read the clauses the register flags as unclear.

Each register row needs only a few fields: system and vendor, the contract or terms version and date, AI features enabled, the clause that governs training, opt-out status and scope, the date and form of the vendor's confirmation, the internal owner and the renewal date. A spreadsheet is enough, as long as one person keeps it current.

Audit table by system category
System categoryRecords at stakeWhere to lookWhat to document
Help desk and chat supportTickets, chat transcripts, macros and internal notesAI feature settings, AI addendum, DPASetting status, opt-out confirmation and content scope
CRMNotes, emails, call logs and opportunity historyAdmin AI settings and the subscription agreementWhich objects AI features read, and the training terms
Meeting recorders and notetakersRecordings, transcripts and summariesWorkspace and user settings, privacy policyWhether individual users can enable recording outside policy
Documents and wikisPlaybooks, specifications and proposalsAI feature terms and the admin consoleWhether workspace content is used beyond your account
Code hosting and developer toolsSource code, issues and code reviewsProduct AI terms and organization settingsRepository exclusions and differences between plans
ERP, field service and industry platformsOrders, jobs and quality recordsContract data-use clauses and benchmarking programsAny participation in data pooling or benchmarking

How to opt out and make it stick#

An opt-out sticks only when the setting, its scope and the vendor's confirmation are all recorded. Many teams flip a toggle and assume the question is closed, then find a new feature enabled by default at the next release.

Where a vendor offers no opt-out, the decision becomes a business one: accept the terms, limit what goes into the system, or plan a move. Ask counsel to read any clause the register marks as unclear before you decide.

  • Find the setting in the admin console and record who changed it and when.
  • Check whether it applies to the whole account, one workspace, one feature or one user.
  • Ask the vendor in writing whether the opt-out covers data already collected or only new data.
  • Request written confirmation that your content is excluded from models used for other customers.
  • Where no setting exists, ask for contract language at renewal or in an amendment.
  • Limit which users can enable new AI features or connect third-party AI apps.
  • Put each vendor's renewal date on a calendar to recheck its terms.

Why vendor AI terms matter if you may license records later#

Vendor AI terms matter for licensing because a buyer will ask whether anyone else already has rights to use the same records. If a help desk vendor may train on your ticket history, you cannot describe that history as unused, and exclusivity becomes harder to offer.

Vendor terms also govern exports. Some subscriptions limit export volume, API access or use of exported data, so the same review should record how full history can be retrieved and whether anything restricts what the company does with it afterward.

Recording the vendor position now also saves time later. If a licensing conversation ever starts, the register already answers the first rights questions a buyer will ask about each system.

Illustrative: a consulting firm audits its tools#

Illustrative: a fictional management consulting firm learns that consultants have been running an AI notetaker on client calls, and that both its CRM and its document workspace have shipped new AI features. The COO and the IT lead work through the audit table across the firm's systems.

They find the notetaker running under individual consultants' own accounts, the document tool's AI feature switched on by default under a service improvement clause, and CRM terms that limit AI processing to the firm's own account. The firm moves the notetaker to a managed account with recording rules, opts out in the document tool and obtains written confirmation, and starts a vendor AI register reviewed at each renewal. Client deliverables are marked as client-controlled in the firm's records inventory.

How SourceX looks at vendor terms#

SourceX reads vendor terms during Rights, the second step of the SourceX five-step transaction, because they decide whether exports are permitted and whether a vendor already holds rights to use the same records.

Those findings go into the licensing rights section of the SourceX Evidence Packet. Where a vendor's rights are unclear, the usual answer is to narrow the scope to records the vendor's terms clearly leave with the company, which is why a register built for this audit shortens any later rights review.

Frequently asked questions

Does an opt-out remove data a vendor already used for training?

Not necessarily. Many opt-outs apply going forward, and removing information from a model that has already been trained is technically difficult. Ask the vendor directly what happens to content collected before the opt-out and whether it was used in any model shared with other customers, and keep the written answer.

Are AI features in our tools the same as training on our data?

No. A feature can use a model to process your content for your account without that content training models for anyone else. The questions are which model provider processes the content, whether it is retained and whether it feeds training. Feature terms usually answer these separately.

Which executive should own the vendor AI review?

Usually the COO or CTO, with IT administering settings and counsel reading unclear contract language. The owner should also hold the register, so new tools, renewals and newly released AI features are all checked against the same standard.

What about free tools employees sign up for themselves?

Personal and free accounts often come with broader data-use terms and no admin controls. A short policy listing approved tools, with managed company accounts for anything that touches customer or company records, closes most of the gap without banning useful tools.

Should we tell customers about our vendors' AI use?

That depends on your privacy notice, customer contracts and the data involved. If vendors process customer content with AI, check whether your notices and data processing commitments cover that use, and update them with counsel's help where they do not.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify