Skip to content

Rights and contracts

Customer lawsuits over AI use of their data: patterns from 2024-2026

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Lawsuits over companies using customer data to train AI have clustered around a few patterns since 2024: terms changed quietly to permit training, conversations recorded or analyzed by AI vendors without clear consent, and customer content reused beyond the purpose it was given for. The disputes usually turn on what the company told customers, and when.

Key takeaways

  • The recurring claims are breach of contract, privacy and wiretap statutes, deceptive practices and unjust enrichment.
  • Retroactive terms changes draw close scrutiny, because customers shared their data under the earlier terms.
  • Calls and chats captured or analyzed by outside AI vendors raise consent questions under federal and state wiretap laws.
  • A company's own operational records, prepared and licensed under clear terms, carry a different risk profile from customer content.
  • Prevention is mostly documentation: dated terms, clear notice, honored opt-outs and removal of personal information.

What are customers suing over?#

Customers suing over AI use of their data are usually objecting to one of three things: a company used their content or conversations to train models without clear permission, a company let an outside AI vendor capture or analyze their communications, or a company changed its terms to allow training after the data was collected. Plaintiffs range from individual consumers in proposed class actions to business customers and content creators.

The cases are spread across many courts and many remain at early stages, so outcomes are still forming. This analysis describes recurring patterns in the allegations rather than cataloguing individual cases or predicting results. The allegations are also what a company can act on now, because each one points to a document or a consent flow it controls.

Which patterns recur across the cases?#

Six patterns recur in complaints over AI use of data, most of them brought against software companies, platforms and service businesses. Each row lists what plaintiffs typically allege, the data involved and where the dispute tends to turn.

Which patterns recur across the cases?
PatternTypical allegationData involvedWhere it tends to turn
Quiet terms changeTerms or a privacy policy were changed to permit AI training without adequate notice or consentUser content, messages and filesWhether notice was clear and whether stored data was swept in
Third-party listeningAn AI vendor captured or analyzed calls or chats as an undisclosed partyCall recordings and chat transcriptsConsent under wiretap laws and the vendor's own use of the data
Purpose creepData given for one service was reused to build products for othersSupport content, uploaded documents and codeContract scope, DPA limits and privacy notices
Copied contentCreators allege their published work was copied into training sets without a license, mostly in suits against AI developersPublished text, images and codeCopyright, terms of use and fair use; less often aimed at the companies supplying records
Weak de-identificationRecords described as anonymized could still identify peopleLocation, account and behavioral dataHow the data was prepared and what recipients may do with it
Mismatched promisesPublic statements about data use did not match practiceAny customer dataThe exact wording of policies, settings pages and marketing

Plaintiffs rely on a handful of legal theories, often stacked in one complaint so that the case survives if one theory fails. Knowing the theories helps a company see which of its own documents would matter if it were ever challenged.

Comprehensive state privacy laws are a weaker route for private plaintiffs than many expect, because most are enforced mainly by regulators; the CCPA's private right of action, for example, is limited to certain data breaches. That pushes plaintiffs toward contract, wiretap and consumer protection theories, where the company's own words and consent flows become the central evidence.

  • Breach of contract: the terms, DPA or a negotiated clause limited use of the data, and training went beyond it.
  • Wiretap and eavesdropping statutes: a vendor intercepted or recorded communications without the consent the law requires.
  • Unfair or deceptive practices: public promises about data use did not match what the company did.
  • Unjust enrichment: the company profited from data it had no right to use that way.
  • Copyright: protected content was copied into training sets without a license.

Why do terms changes draw close scrutiny?#

Terms changes draw close scrutiny because customers handed over their data under the earlier terms. A change that applies going forward, with clear notice, is one thing; a change that reaches back to years of stored conversations is another, and plaintiffs frame it as a broken promise.

The FTC Act prohibits unfair or deceptive practices, and the FTC has publicly cautioned companies that quietly or retroactively changing their terms to allow AI training could fall foul of it. In some past FTC settlements involving data the company was not entitled to use, the remedy has included deleting models or algorithms built from that data. State consumer protection laws may add parallel exposure, assessed case by case with counsel.

For business-to-business companies the same logic runs through contracts. If a negotiated subscription agreement limited use to providing the service, a later click-through update may not amend it at all, whatever the website now says.

What do the patterns mean for a company licensing its own records?#

For a company licensing its own records, the patterns draw a line between company-authored operational records and customer content. Engineering history, internal notes, dispatch decisions and resolved workflows written by employees avoid most of the patterns above, though employee privacy and customers' confidential details inside the text still need attention.

The ratings below are relative, not a measure of legal risk for any specific company. They show where scrutiny has concentrated and what to check first.

What do the patterns mean for a company licensing its own records?
Record typeRelative exposureWhat to check first
Company-authored workflow recordsLowerEmployee notices and confidential customer details inside the text
Support conversations with business usersModerateContract license, DPA limits and no-AI-training clauses
Consumer messages and chatsHigherPrivacy notices, state privacy laws and opt-outs
Call recordingsHigherRecording consent and the wiretap laws that may apply
Customer-uploaded files and contentHighestExpress permission; usually excluded

What prevents these disputes?#

Disputes like these are prevented mostly by documentation and restraint rather than by new technology. None of the steps below is novel; the allegations in the table describe what tends to follow when they are skipped under pressure to ship.

  • Keep dated copies of every version of the terms, privacy policy and DPA, and map records to the version in force when they were collected.
  • Do not apply new AI-use terms to stored data without fresh, clear consent from the affected customers.
  • Enforce negotiated no-AI-training clauses and enterprise opt-outs in the data pipeline, not only in the contract file.
  • Find out whether any vendor records, transcribes or analyzes calls and chats, and how consent is obtained.
  • Remove personal and confidential details before records leave the company, and check the removal by sampling.
  • Make public statements about data use match practice, including settings pages and sales materials.
  • Record who approved each release and exactly what was released.

Illustrative: a field service app rethinks its terms update#

Illustrative: a fictional field service scheduling app drafted a terms update that would let it use all customer content, including technician photos and customer chats, to train its own AI features and to license to outside developers. The draft applied to everything already stored.

After mapping the draft against the patterns above, the company split the plan. Its own features would use customer content only under a new opt-in setting, and only for data collected after the change. For outside licensing it limited scope to its own resolved support cases and engineering records, prepared to remove personal and customer-identifying details, and left customer uploads out entirely.

How SourceX approaches litigation exposure#

SourceX treats litigation exposure as a scoping question in the Rights step of the SourceX five-step transaction. Record families that depend on customer content, recorded communications or retroactive terms are flagged early, and many suppliers choose to start with company-authored operational records.

Each release is documented in a SourceX Evidence Packet, so the supplier can show which terms applied, what was removed and who approved the release. Which laws may apply is a question for the supplier's counsel, deal by deal.

Frequently asked questions

Are business customers suing as well as consumers?

Yes, though business disputes often surface as contract claims, renegotiations or terminations rather than class actions. Enterprise customers increasingly negotiate no-AI-training clauses, and a vendor that breaches one faces a contract dispute even where no privacy statute applies.

Does anonymizing data before training end the exposure?

It reduces privacy exposure but not every claim. Contract limits, copyright in content and deceptive-practice theories can apply even to de-identified data, and weak de-identification is itself a recurring allegation. Treat preparation as one control among several.

Are AI vendors or their business customers named as defendants?

Both appear. Some complaints name the business that deployed an AI tool, others name the vendor that processed the data, and some name both. A company using an AI vendor on customer calls or chats should review the vendor's data-use terms and its own consent flows.

Can a regulator require a company to delete a model trained on customer data?

It has happened. In some past FTC settlements, companies were required to delete not only improperly obtained data but also models or algorithms built from it. That remedy is one reason to document the permission behind every training set before it is used, rather than reconstructing it after a complaint.

Should we stop all AI use of customer data until the law settles?

Not necessarily. Many uses rest on clear contracts and notice. The practical step is to sort uses by data type and permission, proceed where the basis is documented, and pause where a use depends on retroactive terms or on recorded communications without consent.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify