Leadership and readiness
Contract language that stops vendors training AI on your data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Contract language stops a vendor training AI on your data only when it covers five points: a broad definition of your data, a ban on training and fine-tuning, limits on embeddings and logs, deletion on a set schedule, and the same duties flowing to subprocessors. A one-line ban fails if a service-improvement clause elsewhere overrides it.
Key takeaways
- Define customer data to include prompts, outputs, files, metadata, logs and anything derived from them, or the ban will not reach them.
- Prohibit training, fine-tuning, evaluation and benchmarking of any model offered to other customers, not only training.
- Service improvement, aggregated data and feedback clauses are the usual back doors, so limit them in the same agreement.
- An admin opt-out setting helps, but only a contract term binds the vendor through product updates.
- Subprocessors, including the model providers a vendor relies on, must accept the same restrictions in writing.
What does a no-training clause need to cover?#
A no-training clause needs to cover what the vendor receives, everything derived from it, and everyone the vendor passes it to. A clause that says only that the vendor will not use customer data to train AI leaves gaps in the definitions, in derived data such as embeddings, and in subprocessors.
Read the clause together with the rest of the deal. Order forms, online terms incorporated by link, AI feature addenda, data processing addenda and acceptable use policies all speak to data use. When documents conflict, the order-of-precedence clause decides which wins, so the no-training language belongs in a document that ranks above terms the vendor can update on its website.
Clause checklist with plain-English explanations#
The clause checklist covers training, embeddings, logs, retention and subprocessors, plus the three clauses that most often undo them. Use it to mark up a vendor's paper or to brief outside counsel before a renewal call.
| Clause | What it should say in plain English | Gap it closes |
|---|---|---|
| Definition of customer data | Everything we submit or generate in the service: prompts, outputs, files, records, metadata, logs and derived data | Vendor arguments that outputs or usage logs belong to the vendor |
| Training prohibition | No training, fine-tuning, retraining, evaluation or benchmarking of any model offered to anyone but us | Narrow bans that cover training but not evaluation or fine-tuning |
| Embeddings and indexes | Embeddings and search indexes built from our data serve only our account and are deleted with it | Vector stores that outlive the contract or feed shared features |
| Logs and telemetry | Logs containing our content are used only for security, support and billing, and kept only as long as those uses need | Prompt and output logs quietly used as a training source |
| Retention and deletion | Our data, embeddings and logs are deleted within an agreed period after termination, with written certification | Indefinite retention in analytics stores and backups |
| Subprocessors | Every subprocessor, including a model provider, is bound by the same limits; we get notice of new AI subprocessors and a right to object | Restrictions that stop at the vendor's own door |
| Aggregated and de-identified data | Usage statistics only, never record content, and never for training | Content reused under an anonymization label |
| Feedback | Covers only product suggestions we choose to send, not our data | Feedback clauses broad enough to swallow inputs |
| Changes to terms | Changes to data-use terms need our written agreement | Silent changes through a web page update |
Sample language you can adapt#
Sample language gives counsel a starting point, not a finished clause. Match the defined terms to the agreement, set the deletion period in the order form, and have counsel confirm the wording works under the contract's governing law.
Notice the exception in the first item. Many products use a model to deliver the service itself, such as summarizing your own tickets, and a clause that bans all model use can make the product unusable. The exception permits that use while blocking any model offered to others.
- No training: Vendor will not use Customer Data, or any data derived from Customer Data, to train, fine-tune, retrain, evaluate or benchmark any artificial intelligence or machine learning model, except a model used solely to provide the Services to Customer and not made available to any other person.
- Derived data: Embeddings, indexes, features, summaries and other representations generated from Customer Data are Customer Data and are subject to the same restrictions, including deletion.
- Logs: Vendor may process logs containing Customer Data only for security, fraud prevention, support and billing for Customer's account, and will not use those logs for any purpose barred under No training.
- Deletion: Within the period stated in the order form after termination, Vendor will delete Customer Data, including derived data and logs, from active systems and certify deletion in writing on request; backups will expire on their normal rotation and will not be restored for any other use.
- Subprocessors: Vendor will impose these restrictions in writing on every subprocessor that receives Customer Data, will notify Customer before adding a subprocessor that provides AI models, and remains responsible for subprocessor compliance.
- Precedence: This section controls over any conflicting term, including online terms, product terms and policies incorporated by reference.
Where vendors keep training rights without saying so#
Vendors usually keep training rights through clauses that never mention AI: service improvement, aggregated data, feedback and the right to update online terms. Each can be reasonable on its own, and each can be drafted broadly enough to reach your records.
Service improvement language lets a vendor use customer data to develop and improve its products. Before generative AI features, that mostly meant bug fixes and capacity planning; read today, it can cover model training. Aggregated or anonymized data clauses let a vendor keep data once identifiers are stripped, but support tickets, CRM notes and job records carry their value in the text, so removing names does not stop them being useful training material.
Account type changes the answer too. GitHub's Terms of Service, for example, grant GitHub a license to use inputs and outputs of its AI features to train models, which users can opt out of in account settings, while customers under a GitHub Customer Agreement or volume licensing agreement are excluded from that training license. The same product can therefore carry different training rights for a self-serve account and a negotiated enterprise contract, so check which paper each team actually signed.
Watch for AI feature addenda that appear at renewal or when an admin switches on a new assistant. Some products ask an administrator to accept separate terms inside the console, which can change the data-use position without legal review. Route those acceptances to whoever owns vendor contracts.
Negotiating with a vendor that pushes back#
Negotiating with a vendor that pushes back works best when you know which fallback you can accept before the call. Large vendors may refuse to edit their paper but offer an addendum or a setting; smaller vendors often accept a clause if it is short and clear.
Keep a record of each vendor's final position. It helps at renewal, in answering customer security questionnaires, and when your own customers ask whether their information reaches an AI model.
| Vendor position | Fallback you might accept | Line worth holding |
|---|---|---|
| We do not edit our standard terms | A signed AI addendum or order-form clause that takes precedence | Precedence over online terms the vendor can change |
| Training is already off in settings | The setting plus a written commitment that it stays off for your account | A promise that survives product updates |
| We need aggregated data for analytics | Usage statistics with no record content | No content reuse under an aggregation label |
| Our model provider has its own terms | Flow-down of the same restrictions to that provider | The vendor stays responsible for its subprocessors |
| We cannot purge backups early | Expiry on the normal backup rotation, with no restores for other uses | Certified deletion from active systems |
Illustrative: a 3PL tightens its WMS renewal#
Illustrative: a fictional third-party logistics company runs its warehouses on a cloud WMS, plans loads in a separate TMS and answers shipper questions in a help desk. At renewal, the WMS vendor adds an AI assistant and an addendum allowing customer data to be used to improve its services, including its models.
Counsel returns three changes: a definition of customer data that includes scan events, exception notes, EDI messages and user comments; a training prohibition covering any model offered to other customers; and deletion of embeddings when the assistant is switched off. The vendor accepts the definition and the prohibition and keeps the right to use usage statistics with no record content.
Counsel then checks the shipper contracts, several of which restrict onward use of shipment data, and confirms the new clause satisfies them. Operations keeps the assistant off until the addendum is signed. The company now knows its exception history stays its own, whether it keeps that history in house or later licenses a prepared set.
Why the clause matters if you may license records later#
The clause matters for licensing because records a vendor has already trained on are less distinctive, and a supplier may struggle to show it controls them. In the SourceX Enterprise Data Value Framework, uniqueness and rights increase value, exclusivity increases price and reproducibility reduces value; uncontrolled vendor training works against all of them.
In the Rights step of the SourceX five-step transaction, the supplier's counsel reviews vendor terms alongside customer contracts and employee notices, and the result is recorded in the SourceX Evidence Packet. A no-training clause signed today makes that review simpler, and nothing is shared during the initial assessment.
Frequently asked questions
Is an opt-out setting enough without contract language?
A setting helps immediately, but it is a product feature the vendor can rename, move or reset in a new release. A contract term binds the vendor through those changes. Use both: switch the setting off, keep dated evidence that it is off, and put the obligation in a document that ranks above the vendor's online terms.
Can we add a no-training clause to a contract mid-term?
Yes, by amendment, if the vendor agrees. Vendors are often more flexible at renewal, during an upsell or when a new AI feature needs your consent, because those moments already involve paperwork. If the vendor will not amend, check whether the current terms already limit data use and log the gap for the next renewal.
Does the clause cover tools employees sign up for themselves?
No. A clause binds only the vendor that signed it. Free and self-serve tools run on click-through terms that may allow broad data use. Find them through single sign-on logs, expense reports and browser extension reviews, then move important work to accounts covered by negotiated terms or restrict the tools.
Will a strict clause stop us licensing our own data?
A vendor no-training clause restricts the vendor, not you. Check that the drafting does not accidentally limit your own use of exports, and confirm separately that the vendor's terms let you export records for your own purposes. That export question differs from the training question and deserves its own review.
Should the clause also protect our customers' information inside the vendor's system?
Usually it should, because your customer contracts may promise that their information will not reach third-party models. Make sure the customer data definition covers records about your customers and their staff, not only files you upload. Then compare the clause against your strictest customer commitments so the vendor paper does not fall short of them.
Sources
- GitHub's Terms of Service (Section J, AI features) grant GitHub a license to use AI-feature inputs and outputs to train AI models, which users can opt out of in account settings, and customers under a GitHub Customer Agreement or volume licensing agreement are excluded from this training license. Source
Related resources
- InsightOpt-in vs opt-out for AI training in B2B SaaS contracts
- InsightAI vendor contracts for AEC firms: clauses that stop training on your data
- InsightDoes AIA B101 let an architect license project records for AI?
- IndustryBPO & contact centers data
- IndustryRecruiting & staffing data
- DataSales call transcripts
See if your company qualifies
A short company assessment. No data uploads are needed.