Software companies
How to change your terms of service to allow AI training without an FTC problem
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
To change terms of service to allow AI training while limiting FTC risk, apply the new terms only to data collected after the change, give clear and direct notice, get affirmative opt-in before using existing data, align the DPA and privacy statements, and keep a record of who accepted what. Quiet or retroactive changes create most of the risk.
Key takeaways
- FTC staff have warned that a quiet, retroactive change to how collected data is used, including for AI training, may be an unfair or deceptive practice.
- A new AI clause should apply going forward; records collected under older terms need fresh, affirmative consent.
- Continued use after an email notice is weak evidence of consent to reuse existing data.
- The terms, DPA, privacy policy and trust pages must all describe the same data use.
- Licensing your company's own internal records does not require changing customer terms at all.
Why do AI terms changes draw FTC attention?#
AI terms changes draw FTC attention because the FTC Act prohibits unfair or deceptive practices, and FTC staff have said a quiet terms change can be one. On February 13, 2024, FTC staff published a Tech@FTC post titled 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive'. It warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling people only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices.
The post is staff guidance, not a rule, and it speaks about consumers. Business-to-business vendors should not assume they sit outside it, because their customers' employees and end users are often the people described in the data, and state privacy laws and ordinary contract law may apply as well.
The commercial risk can arrive before any regulator does. After backlash over March 2023 changes to its terms, Zoom added a sentence to Section 10.4 in August 2023 saying it would not use audio, video or chat customer content to train its AI models without consent. Later that month, CIO Dive reported, it revised the terms again to say it does not use communications-like customer content to train its own or third-party AI models.
The five-step checklist for an AI terms change#
The five-step checklist for an AI terms change covers timing, notice, consent, document alignment and evidence. Each step addresses a different way the change could later be challenged by a customer, a regulator or an acquirer in diligence.
The steps work together. A prospective clause without notice still surprises customers, and an opt-in without records cannot be proved later. Skipping any one weakens the others.
- Step 1, prospective only: state in the clause itself that the AI training right applies to data submitted after the effective date.
- Step 2, clear notice: tell customers directly, by email and in the product, in plain language that explains what changes, which data is affected and how to object, well before the effective date.
- Step 3, opt-in for existing data: use records collected under earlier terms only after an affirmative choice, such as a signed addendum or an admin setting that defaults to off.
- Step 4, DPA and document alignment: update the data processing agreement, privacy policy, subprocessor list, security page and help center so none contradicts the new terms.
- Step 5, acceptance record: log which customer accepted which version, when, by whom and through what mechanism, and keep it with the contract file.
How do terms changes take effect for different customer types?#
Terms changes take effect differently for self-serve, negotiated and channel customers, so one announcement rarely covers everyone. Map your customer base to these groups before drafting, because each group needs its own mechanism.
Legacy accounts are easy to miss. A customer that signed years ago and never clicked through a later update may still be governed by the version it accepted, which can be narrower than your current terms. Negotiated contracts sit apart as well: Zoom said in 2023 that updates to its online terms do not affect customers who buy directly under separate contracts, such as enterprises and regulated education and healthcare customers.
| Customer type | How terms usually change | What to watch |
|---|---|---|
| Self-serve click-through | Updated terms with notice and acceptance at login or renewal | Whether the old terms permit unilateral changes at all |
| Negotiated enterprise agreement | Written amendment signed by both parties | Existing no-AI-training or no-secondary-use clauses |
| Reseller or partner channel | Through the partner agreement and its customer paper | Who holds the customer relationship and the consent |
| Customers in regulated sectors | Often addenda or sector-specific DPAs | Sector rules that may limit any secondary use |
| Legacy accounts on old versions | May never have accepted recent updates | Records governed by the version actually accepted |
What does clear notice look like?#
Clear notice is a direct, specific message that a reasonable customer admin would read and understand, not a changelog line. The stronger versions in the table are what counsel usually aims for.
Specific wording also protects the vendor. A notice that names the data types and purposes limits later arguments that customers agreed to something broader or narrower than intended.
| Notice element | Weak version | Stronger version |
|---|---|---|
| Channel | A new updated date on the terms page | Email to account admins plus an in-product banner |
| Content | We have updated our terms | A plain statement of which new data will train which AI feature, from a stated date |
| Choice | Continued use means acceptance | An admin setting or addendum the customer actively chooses |
| Scope | Data may be used to improve services | Named data types, purposes and any third parties |
| Timing | Effective immediately | A notice period long enough to review and object |
Illustrative: a scheduling software vendor updates its terms#
Illustrative: a fictional vendor of scheduling and quality inspection software for commercial cleaning companies wants to train an in-product assistant on customer support chats. Its terms date from before generative AI and mention only service improvement.
Counsel drafts a clause that applies to chats submitted after the effective date, sends account admins an email and an in-app notice describing the change, and adds an admin setting that is off by default for historical chats. The DPA and privacy policy change in the same release, and each acceptance event is logged against the account.
Several enterprise customers decline, and their chats are excluded. Separately, the CEO notes that the company's own engineering and product records never depended on customer terms, so a licensing review of those records proceeds on its own track.
Mistakes that turn a terms update into a problem#
The mistakes that turn a terms update into a problem are usually shortcuts taken to avoid a negotiation. The most common is treating continued use after a notice as consent to reuse years of existing records.
Others include burying the change in a privacy policy update, changing the DPA unilaterally when it requires mutual agreement, announcing a broad right to share data with partners without naming AI training, and forgetting legacy customers who never accepted later versions. Each one either weakens the evidence of consent or creates a contradiction a customer can point to later.
A quieter mistake is changing terms when there is no need. If the goal is licensing your company's own records, such as code reviews and internal documentation, customer terms are not the lever; a rights review of those internal records is.
How SourceX approaches terms and consent#
SourceX approaches terms and consent as evidence to document, not something to assume. In the Rights step of the SourceX five-step transaction, each record family is tied to the terms version and any consent that governs it, and records without a clear basis are excluded.
The resulting SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. That mirrors published provenance standards: the Data and Trust Alliance's Data Provenance Standards include a consent documentation location element in their Use metadata. The supplier approves every step, and nothing is shared during the initial assessment.
Frequently asked questions
Can we apply new AI terms to data customers already gave us?
Relying on new terms for existing data is the riskiest path. Most counsel recommend treating previously collected data as governed by the terms in force when it was collected and seeking affirmative consent, such as a signed addendum or an opt-in setting, before any new AI use of it.
Is an opt-out enough for future data?
Sometimes, depending on the data, the customer type and the laws that may apply. For new data under clearly noticed prospective terms, an opt-out can be reasonable in some business-to-business settings. For existing data, sensitive data or regulated customers, opt-in is the safer design. Counsel assesses this case by case.
Do state privacy laws matter for business-to-business terms changes?
They may. Customer data often includes personal information about a customer's employees or end users, and state privacy laws can limit how a service provider uses it beyond the contracted purpose. Whether they apply depends on the data and your role, so review them with counsel.
How long should the notice period be?
No single period fits every case. Counsel weighs the contract's own change-of-terms clause, the significance of the change and how much time customers need to review and object. Longer notice and an easy way to decline reduce risk; an immediate effective date increases it.
Should the AI clause name third parties that may receive data?
If customer data could reach a third party, such as an outside model developer, the clause and the notice should say so plainly, and the subprocessor or recipient list should be updated. A clause permitting training only for your own features does not cover licensing records to an outside developer, which needs its own express permission.
Do we need customer consent to license our own engineering records?
Usually not from customers, because those records belong to your company. You still need to check for customer content pasted into tickets or code, contractor-written code, employee notices and third-party licenses before anything is licensed.
Sources
- On February 13, 2024, FTC staff published 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive', warning that a company that adopts more permissive data practices, such as using consumers' data for AI training, and tells consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
- On August 7, 2023, after backlash over March 2023 changes to its terms, Zoom added to Section 10.4 of its Terms of Service a sentence saying it will not use audio, video or chat Customer Content to train its artificial intelligence models without consent. Source
- CIO Dive reported in August 2023 that Zoom further revised its terms to state that it does not use audio, video, chat, screen sharing, attachments or other communications-like Customer Content to train Zoom's or third-party AI models. Source
- Zoom's blog says updates to its online terms do not affect customers who buy directly under separate contracts, such as enterprises and regulated education and healthcare customers. Source
- The Use group of the Data and Trust Alliance Data Provenance Standards includes elements for consent documentation location, license to use and intended data use. Source
Related resources
- QuestionDo AI labs buy legal documents?
- InsightIs it safe to license company data for AI training?
- InsightHow do I de-identify contracts and legal documents for AI training?
- InsightHow do I de-identify legal briefs and memos for AI training?
- IndustryBPO & contact centers data
- IndustryRecruiting & staffing data
See if your company qualifies
A short company assessment. No data uploads are needed.