Rights and contracts
Changing your terms to allow AI use: what the FTC has warned
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In a February 2024 staff post, the FTC warned that quietly changing terms of service or a privacy policy to use already-collected data for AI training may be unfair or deceptive. The working rule: material changes applied to data you already hold generally need affirmative express consent, and prospective changes need clear notice before they take effect.
Key takeaways
- FTC staff guidance from February 2024 targets changes that apply new, less protective practices to data collected under older promises.
- Affirmative express consent, not a banner or a new effective date on a policy page, is the standard for material retroactive changes.
- A prospective change still needs notice that a reasonable user would actually see before new data is collected.
- B2B software contracts add a second layer: the amendment clause and the DPA decide whether customers must sign.
- Many companies avoid the question by licensing their own operational records instead of customer data.
What has the FTC warned about changing terms for AI?#
The FTC has warned, through a February 13, 2024 staff post titled AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive, that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling people only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices. The post is staff guidance from the agency's technology office, not a rule or an enforcement action, but it signals how the agency reads the FTC Act.
The underlying position is not new. The agency has long said that a company cannot apply a materially different privacy practice to information collected under an earlier promise without the person's affirmative express consent. AI training gives companies a fresh reason to want that kind of change, which is why the post drew wide attention among technology lawyers.
None of this means terms can never change. It means the method, the scope and the data a change reaches all matter, and counsel should assess each against the FTC Act and any state privacy laws that may apply.
Which changes count as material and retroactive?#
A material change is one likely to affect a person's decision to use a service or share data, and expanding data use to train AI models generally fits that description. A retroactive change is one that applies the new practice to data collected before the change took effect.
Labels do not decide the category. Calling an update minor, burying it in a long list of edits or changing only the last-updated date does not make a material change immaterial.
| Type of change | Example | What it generally requires |
|---|---|---|
| Clarification with no new use | Rewording an existing analytics section for readability | Ordinary update and notice practices |
| Prospective material change | Training AI on data collected after a stated future effective date | Clear, prominent notice before the change applies, plus any consent state law may require |
| Retroactive material change | Training AI on records collected under a policy that promised no such use | Affirmative express consent from the people affected |
| New sharing with third parties | Licensing user content to an outside model developer | Close scrutiny of notice, consent and contract terms |
| Change to a negotiated B2B contract | Adding an AI training right to an enterprise MSA | A written amendment the customer agrees to, under the contract's amendment clause |
Why quiet updates create risk#
Quiet updates create risk because regulators look at what a reasonable person would understand, not at whether new words were technically posted. A policy that changed overnight, with no email, no in-product message and no consent prompt, can leave users relying on promises that no longer describe what the company does.
The risk compounds with AI training because training is hard to undo. Once records have shaped a model, honoring a later objection may require retraining or other remedies, and regulators have in some cases required companies to delete models and algorithms built from improperly obtained data.
Quiet changes also weaken the commercial case. A buyer licensing data wants a clean notice and consent history, and a dataset that depends on a disputed policy change is harder to license, harder to defend in diligence and harder to keep in a buyer's training mix.
What recent AI terms changes at software companies show#
Recent AI terms changes at software companies show that the commercial reaction often arrives before any regulator does. Neither episode below involved an FTC action; they matter because they show how customers read ambiguous AI language and how quickly a company may have to reverse it.
Both companies narrowed their wording rather than defend it. For a B2B software company, the second Zoom point is the more useful one: changing online terms may not reach customers who signed separate contracts, so those customers need an amendment, not a posted update.
| Company and date | What happened | Lesson for your own terms change |
|---|---|---|
| Zoom, March to August 2023 | After criticism of March 2023 terms changes, Zoom added on August 7, 2023 a sentence saying it would not use audio, video or chat customer content to train its AI models without consent | Vague AI wording can force a public correction before any training happens |
| Zoom, August 2023 | Zoom said updates to its online terms do not affect customers who buy under separate contracts, such as enterprises | Negotiated customers sit outside posted terms and need signed amendments |
| WeTransfer, July 2025 | After user backlash, it revised terms due to take effect on August 8, 2025, removing language about using uploaded content to improve machine learning models | Advance notice gives users time to object, and objections can arrive within days |
How the warning applies to B2B SaaS companies#
For a B2B SaaS company, the FTC warning sits on top of a contract question: whether the company may change its customer terms at all. Negotiated master agreements usually require a signed amendment, and online terms that allow unilateral updates may still face enforceability limits, especially for changes that reach data already collected.
Business platforms also hold personal information about their customers' employees and end users. Where the platform acts as a service provider or processor, the data processing agreement typically limits use to the customer's instructions, so a terms update aimed at AI training can conflict with commitments the customer relies on for its own compliance.
Many software companies therefore separate two tracks. Customer data inside the product is handled prospectively, through consent and contract amendment. The company's own operational records, such as support tickets, Jira issues and code reviews, are assessed on their own rights and confidentiality terms, with no policy change needed.
A checklist for a compliant terms change#
A compliant terms change for AI use starts by asking whether the change is needed at all, then makes the new practice visible and, where earlier promises or the law require, optional.
- Inventory current and past versions of your terms, privacy policy and DPA, with the dates each applied.
- Write down the exact new use: improving your own features, training third-party models, or licensing data to outside developers.
- Apply the change only to data collected after a future effective date, unless you will obtain affirmative consent for older data.
- Give direct notice by email and in-product message, not only by updating a policy page.
- Use opt-in for any retroactive use and for sensitive categories, and store each consent with a timestamp.
- Amend negotiated contracts by signature and update the DPA if processing purposes change.
- Tag records by consent status so data without consent never enters a dataset.
- Have counsel review the notice wording against the FTC Act and any state privacy laws that may apply.
Illustrative: a scheduling software company rethinks a policy update#
Illustrative: a fictional field service scheduling platform drafts a privacy policy update that would let it train models on all customer job notes and license de-identified versions to outside developers. The draft is set to post with a new effective date and no other notice.
Its general counsel stops the release. The revised plan applies AI use only to job notes created after a future effective date, asks existing customers to opt in through an admin setting, and amends enterprise contracts by signature. In parallel, the company looks at a package that needs no policy change at all: its own Zendesk tickets and Jira issues about scheduling bugs, prepared with customer details removed. That package moves first.
How SourceX approaches notice and consent history#
SourceX reviews notice and consent history during the Rights step of the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, before any data is prepared. A supplier describes which policies and contract versions applied to each record family, and nothing is shared during the initial assessment.
When a package proceeds, the SourceX Evidence Packet records the permitted use and the privacy record for each record family, including the policy version and consent basis that applied. Record families whose collection terms do not support the intended use are carved out of the package.
Frequently asked questions
Does the FTC warning matter for business customers, or only consumers?
The FTC staff post speaks about consumers, but B2B platforms hold personal information about the individual people who use them. Business customers also have their own contract rights, which often matter more in practice. Treat the warning as relevant to any platform holding personal data, and assess scope deal by deal with counsel.
Is an opt-out enough for a new AI use?
For data collected under an earlier promise that excluded the new use, the FTC's long-standing position points to affirmative express consent, which an opt-out does not provide. For data collected after a clearly noticed prospective change, an opt-out may be acceptable in some contexts, but state privacy laws and sensitive data rules can require opt-in.
What if our old privacy policy said nothing about AI?
Silence is not permission. The question is whether the old policy's stated uses and sharing practices would lead a reasonable user to expect AI training or licensing to outside companies. Broad phrases such as improving our services tend to be read narrowly when the new use differs materially from what users expected.
Can we license data collected before the change if it is de-identified?
Possibly, depending on what was promised and how well the data is de-identified, but it is not automatic. Some policies restrict sharing of anything derived from user information, and de-identified text can still carry confidential business details. Review the original promise, the method and any contract terms first.
How long should we keep records of notices and consents?
Keep them for as long as the data they cover is in use, including in any licensed dataset, and for any further period your retention schedule or counsel recommends. A buyer may ask for the consent basis during diligence, and you may need it if a regulator or customer raises a question later.
Sources
- On February 13, 2024, FTC staff published 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive'. It warned that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
- On August 7, 2023, after backlash over March 2023 changes to its terms, Zoom added to Section 10.4 of its Terms of Service the sentence: "Notwithstanding the above, Zoom will not use audio, video or chat Customer Content to train our artificial intelligence models without your consent." Source
- Zoom's blog says it made the no-training statement explicit in an August 2023 update to its online terms, and that updates to the online terms do not affect customers who buy directly under separate contracts, such as enterprises and regulated education and healthcare customers. Source
- In July 2025, after user backlash, WeTransfer revised updated Terms of Service that were due to take effect on August 8, 2025, removing language referring to using uploaded content to improve machine learning models, and stated that it does not use customer content to train AI models (reported by the BBC). Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.