Skip to content

Rights and contracts

How to stop software vendors from training AI on your company data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

To stop software vendors from training AI on your company data, list every tool that holds your records, read the data-use terms and admin settings for each, switch off training where a setting exists, and negotiate a no-training clause where it does not. Settings help immediately; only the contract binds the vendor through later product changes.

Key takeaways

  • Vendor training rights usually sit in service improvement, aggregated-data or license clauses, not in a section labeled AI.
  • Admin settings can switch off some training, but only a contract clause binds the vendor across product changes.
  • Ask for no training on customer data or anything derived from it, including de-identified and aggregated versions, unless you opt in.
  • Re-check terms at renewal and whenever a vendor launches an AI feature.
  • Keeping vendors from training on your records preserves your own option to license them on your terms.

Where do vendors get the right to train on your data?#

Software vendors get the right to train AI on your data from the agreements and settings you accepted, usually through clauses that never mention AI. The common sources are a service improvement clause, a right to create aggregated or de-identified data, a broad license to customer data, and product-specific AI terms that sit outside the main agreement and are incorporated by link.

Separate customer content from usage data when you read. Many terms treat telemetry, metadata and how your team uses the product as the vendor's own information while protecting the content you store, so the training answer can differ for each.

Where do vendors get the right to train on your data?
Where to lookWhat to look for
Master agreement or online termsA license to customer data beyond providing the service; improvement and development rights
Data processing agreementWhether processing is limited to your instructions, and exceptions for the vendor's own purposes
AI or product-specific termsSeparate terms for AI features, often incorporated by a link
Privacy policy and trust pagesStatements about model training, retention and use of usage data
Admin consoleWorkspace-level switches for AI features, model improvement and data sharing
Order forms and renewalsUpdated terms pulled in at renewal

Which tools should you review first?#

The tools to review first are the ones holding your most distinctive operating records: CRM, helpdesk, email and chat, document storage, code hosting, call recording and meeting transcription, and your ERP or field service platform. These hold the history of how your company actually works, which is the kind of material model developers look for.

Build the list from single sign-on applications, accounts payable vendors and expense reports rather than memory. Teams often buy transcription, note-taking and writing tools on a company card, and those tools can end up holding client calls, pricing discussions and internal strategy.

How do you switch off training where a setting exists?#

Switching off training where a setting exists starts in the admin console, not in individual user profiles. Look for workspace-level controls over AI features, model improvement and data sharing, record what each setting says and the date you changed it, and save a screenshot to the contract file.

Settings are a partial fix. A vendor can rename, move or redefine a setting in a later release, and switching one off does not always reach data already used. Treat the setting as the immediate step and the contract as the lasting one.

What should a no-training clause say?#

A no-training clause should state that the vendor may not use your data, or anything derived from it, to train, tune or improve models for anyone other than you without your prior written consent. The table shows the main points and the fallback vendors commonly offer.

Fallbacks are negotiable. A large customer can often get the stricter version; a smaller one may accept the vendor's standard enterprise terms if those already exclude training on content and flow the restriction down to model providers.

What should a no-training clause say?
Clause pointWhat to ask forCommon vendor fallback
No trainingNo use of customer data to train, tune or evaluate models beyond your accountNo training on content, but usage data allowed
Derived dataDe-identified and aggregated derivatives covered by the same restrictionAggregated statistics allowed if they do not identify you
SubprocessorsThe restriction flows down to any model provider the vendor usesReliance on the model provider's standard terms
Change of termsAdvance notice and the right to reject AI-related changesNotice by posting an update online
ExitDeletion when the contract ends, plus written confirmation of whether any data was used for trainingDeletion under the standard retention schedule

Why vendor training can breach your own commitments#

Vendor training can breach your own commitments because much of the data in your tools belongs to, or describes, your customers. If your contracts or DPAs promise customers that their data is used only to serve them, and a vendor you chose trains on that data, the gap sits between you and your customer, not just between you and the vendor.

Check three places: the confidentiality and data-use clauses in your customer contracts, the subprocessor list you publish or share, and your privacy notice. A vendor that uses data for its own model training may not fit the processor or service provider role you described, which can turn a procurement oversight into a notice or contract problem.

The safest order is to fix the vendor terms first, then confirm that what you tell customers matches what your vendors are actually allowed to do.

How do you keep the protection current?#

Protection stays current only when someone owns it, because vendor terms and features change after signature. Fold the checks into processes that already exist, such as procurement, renewals and security reviews, rather than running a one-time audit.

  • Add an AI and data-use check to procurement and renewal reviews.
  • Assign a named owner to watch terms-change notices for critical tools.
  • Re-check settings whenever a vendor launches an AI feature.
  • Publish an employee policy on which AI tools may receive company and customer data.
  • File the review record with the contract: terms version, settings, date and reviewer.

Illustrative: a consulting firm reviews its stack#

Illustrative: a fictional management consulting firm finds that several partners use a meeting transcription tool on client calls, bought on personal cards. The tool's terms let the vendor use de-identified content to improve its models, and the firm's client agreements promise confidentiality.

The firm moves the tool to an enterprise plan with training switched off and a no-training clause, asks the vendor to delete transcripts already stored, and adds the tool to an approved list. Its review of the CRM, document storage and proposal archive finds no training rights. The firm's proposals and engagement playbooks stay under its own control, which keeps open the option of licensing prepared versions of that internal knowledge later.

Why are your records worth protecting?#

Your records are worth protecting because the operating history in them, how problems were diagnosed, how jobs were scoped and how exceptions were resolved, is the kind of material model developers seek to license. A vendor whose terms let it train on those records captures that value without a separate agreement, a defined scope or any payment to you.

SourceX helps companies license prepared records on their own terms through the SourceX five-step transaction; the company signs off at each step, and the records are licensed, not sold. The SourceX Enterprise Data Value Framework helps a company judge which record families matter most before deciding what to protect and what it might license.

Frequently asked questions

Do vendors need our permission to train on our data?

It depends on the agreements you accepted. If the terms grant improvement or aggregated-data rights, the vendor may argue permission already exists. Negotiated enterprise terms often narrow those rights. Counsel should read the full set of incorporated documents, not just the main agreement.

Is it safe to let vendors use aggregated or de-identified data?

Aggregated statistics about product usage are usually low concern. De-identified content is different: it can still reveal your processes, pricing logic or client situations, and de-identification of free text is imperfect. Decide separately for usage statistics and for content.

Does a no-training clause cover the AI model providers our vendor uses?

Only if it says so. Many vendors call an outside model provider to run AI features. Ask that the restriction flow down to those subprocessors and that the vendor confirm the provider does not retain or train on your data.

Can we stop a vendor using data it already trained on?

Usually not fully. A trained model cannot simply forget specific records, and vendors rarely retrain to remove one customer. Focus on stopping future use, deleting stored copies and getting written confirmation of what was used.

Do these steps apply to free tools employees use?

Yes, and free tools often carry the broadest training rights. An acceptable-use policy, an approved tool list and enterprise plans for tools that handle client or company data are the main controls.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify