Skip to content

Software companies

Can you license transcripts from your AI support agent?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

AI support agent transcripts can sometimes be licensed, but each conversation holds three kinds of content with different rights: customer messages, bot replies and human handoffs. Customer turns raise privacy and contract questions, bot turns depend on your AI vendor's output terms, and handoffs are often the cleanest and most useful part of the record.

Key takeaways

  • Treat customer turns, bot turns and human agent turns as separate rights questions.
  • AI vendor terms may restrict using bot outputs to build competing models, even when they assign ownership to you.
  • Handoffs, where a human corrects or completes the bot's work, are often the most useful records.
  • Chat transcripts need de-identification plus human review, because automated detection alone misses things.

What is actually in an AI support agent transcript?#

An AI support agent transcript is more than a chat log. Behind the visible messages sit the help center passages the bot retrieved, the actions it took such as looking up an order or resetting a password, its routing decision, the point where a human took over, the human's reply, the resolution and whether the customer came back.

Where those records sit depends on how the agent was built. An AI add-on inside a support platform such as Zendesk, Intercom or Salesforce stores conversations in that platform, under its terms. An agent your team built on a model provider's API keeps logs wherever your engineers put them, under the provider's terms and your own.

Platform terms and export limits shape the answer before any rights review starts. Intercom's Additional Product Terms, for example, treat content submitted to its AI products and the output they generate as Customer Data. Zendesk's export documentation says AI agent tickets cannot be exported through its account export tools, so check early whether the bot side of the record can be retrieved at all.

Either way, at least two contracts sit behind every bot reply, and both need reading.

Who holds rights in each turn of the conversation?#

Rights in a bot conversation differ by turn type, so each turn type is its own question.

In B2B software, customer messages are often defined as customer data in your master agreement and data processing addendum, which can limit your role to providing the service. In consumer-facing products, privacy notices and state privacy laws may apply. Either way, the analysis is done deal by deal with counsel.

Who holds rights in each turn of the conversation?
Turn typeMain rights questionTypical starting position
Customer messagesPrivacy notice, customer contracts, consentLicensable only after de-identification and contract review
Bot repliesSupport platform and model provider output termsDepends on the vendor; competing-model limits are common
Retrieved help center passagesYour content, or partner documentation you republishUsually yours; check embedded third-party docs
Bot actions and system lookupsYour systems, but they expose account dataYours after account details are removed
Human agent replies and notesEmployee work productUsually company-controlled
Handoff, resolution and reopen dataYour operational recordsOften the cleanest part of the record

Why do bot replies need a separate check?#

Bot replies need a separate check because they come from someone else's model under someone else's terms. Many AI vendor terms assign outputs to the customer but restrict using them to develop competing models, and a training license to an AI developer can fall squarely inside that restriction.

Support platforms add a second layer. Some platform terms let the platform use customer conversations to improve its own AI features, often with an admin opt-out. If that applies, the platform may already be learning from the same transcripts, which affects any exclusivity you could offer and what you can honestly say about the data.

The decision rule: if bot outputs are restricted, scope customer and human turns plus resolution labels, and either drop bot turns or replace each with a short neutral marker, such as a note that the bot suggested an article and the customer asked for a person.

Why are handoffs the strongest records?#

Handoffs are the strongest records because they show exactly where automation fell short and how a person fixed it. An escalated conversation pairs a customer's real problem with a failed automated attempt and an expert resolution, which is useful for evaluating support AI as well as training it.

Keep the metadata that makes handoffs readable: the reason for escalation, the queue it went to, the time to resolution, whether a refund or credit was issued, and whether the ticket was reopened. Without those fields a transcript is just text; with them it is a labeled outcome.

Handoffs also show your support process at its most specific. The human reply usually cites internal policy, product limits or workarounds that never made it into the help center, which is why these records are worth the extra preparation.

How should bot transcripts be prepared?#

Bot transcripts are prepared like any chat log, with extra attention to the structured actions that expose account data.

Automated tools help but are not enough on their own. The open-source Presidio project, for example, warns in its own documentation that because it uses automated detection, there is no guarantee it will find all sensitive information, and that additional protections should be used.

  • Export conversations with channel, timestamps, handoff point, resolution and reopen flag.
  • Remove names, email addresses, phone numbers, street addresses, order and account numbers, and payment details.
  • Remove or generalize customer company names in B2B conversations.
  • Check free text and attachments for pasted screenshots, logs and documents.
  • Strip identifiers from bot action payloads, such as lookup results and API responses.
  • Run automated detection, then human review of a sample from every batch.
  • Record what was removed, how and by whom in the privacy record.

Which conversations should be left out entirely?#

Some conversations should be left out of any scope no matter how well they are de-identified, because the content itself is the risk. Filtering them out early saves review time and keeps the remaining set easier to defend.

Build the exclusion filter from fields you already have, such as ticket category, queue, tags and customer account, and check a sample by hand. Categories drift over time, so a security conversation can hide under a billing tag.

  • Account security: identity verification, password resets with security answers and suspected account takeovers.
  • Payment disputes, chargebacks and anything quoting card or bank details.
  • Legal complaints, threats, harassment reports and requests from regulators or law enforcement.
  • Conversations where customers volunteered health, family or other sensitive personal details.
  • Conversations from customers whose contracts prohibit reuse, or from regions you have chosen to exclude.
  • Any conversation under a legal hold.

Illustrative: an accounting software company reviews its bot transcripts#

Illustrative: a fictional accounting software company for small firms runs an AI agent inside its support platform. Customers ask about bank feeds, invoice templates and payroll errors, and conversations the bot cannot resolve escalate to human specialists.

The general counsel finds two issues. The platform's terms allow it to use conversations to improve its AI features unless the account opts out, and the underlying model terms restrict using outputs for competing models. Customer messages are also covered by the company's data processing addendum.

The company opts out of platform model improvement, scopes only escalated conversations, keeps de-identified customer turns, human replies and resolution data, and replaces bot turns with neutral markers. Customer contracts are reviewed before anything moves forward, and the remaining scope is small but well documented.

How SourceX reviews AI agent transcripts#

SourceX reviews AI agent transcripts turn type by turn type within the SourceX five-step transaction. In the Rights step, support platform terms and model provider terms are read alongside customer contracts and privacy notices; in Preparation, personal and confidential details are removed and the work is recorded.

The SourceX Evidence Packet states which turn types are included, under what permitted use and with what privacy record, and the company approves each step before anything is released. As with any rights question, this is general information rather than legal advice, and each deal is assessed with counsel.

Frequently asked questions

Are bot transcripts more useful than human-only transcripts?

They are useful for different reasons. Human-only transcripts show expert resolution from start to finish. Bot transcripts with handoffs show where automation failed and how a person recovered, which suits evaluation of support AI. Usefulness depends on resolution data and linkage, and no value can be stated until a buyer reviews a specific package.

Do we own the bot's replies if we wrote its prompts and knowledge base?

Not automatically. Your system prompts, instructions and help center articles are your content, but ownership of each generated reply depends on the vendor's output terms, and those terms may restrict certain uses even when they assign ownership to you.

Does our support platform already use these transcripts?

Possibly. Some platforms' terms permit using customer conversations to improve their AI features, sometimes with an opt-out in admin settings. Check your order form, the platform's AI terms and your settings. The answer affects exclusivity and what a licensee can rely on.

Can we license transcripts if our privacy notice never mentioned AI?

It depends on what the notice says about purposes, sharing and de-identified data, and on which privacy laws may apply. Some companies update notices for future data and limit any license to properly de-identified records. Assess this with counsel before scoping.

Are voice bot calls treated differently?

Voice adds recording consent rules, which vary by state, including whether every party must agree. Transcripts derived from recordings carry the same questions as the audio, so check how callers were notified before treating voice transcripts like chat.

Sources

  • Presidio's own documentation warns that "because it is using automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information. Consequently, additional systems and protections should be employed." Source
  • Intercom's Additional Product Terms treat content submitted to its AI products, such as conversation data, and the output those products generate as Customer Data. Source
  • Zendesk states that AI agent tickets cannot be exported. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify