Skip to content

Rights and contracts

No-AI-training clauses in customer contracts: what they cover

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A no-AI-training clause in a customer contract bars the vendor from using that customer's data to train AI models, but its reach depends on the wording. Narrow versions cover model training on customer content; broad versions also catch fine-tuning, product analytics, aggregated data and disclosure to outside AI developers, so map each variant before licensing any records.

Key takeaways

  • No-AI-training clauses usually arrive through enterprise redlines, DPAs and AI addenda rather than the public terms of service.
  • The contract's definition of customer data decides which support tickets, logs and attachments a clause reaches.
  • Clauses that also cover de-identified or aggregated data can block records you assumed were safe after preparation.
  • Map each customer account to a clause variant before scoping a license, and exclude restricted accounts at the record level.
  • Engineering records with no customer content usually fall outside these clauses, but pasted logs and screenshots need checking.

Where do no-AI-training clauses appear?#

No-AI-training clauses appear mostly in negotiated enterprise paper: master services agreement redlines, data processing agreements, security addenda, AI addenda and order forms. Procurement questionnaires that a customer later attaches as a contract exhibit can also become binding.

That spread is the practical problem for a software company. The public terms of service may say nothing about AI while your largest accounts each signed a different version. Legal teams at B2B and vertical software companies often see the full picture only when they search every signed contract, not the template library.

Older contracts can carry AI restrictions without using the term. Clauses that bar use of customer data for product development, benchmarking or any purpose other than the services were written before generative AI but can reach the same result, so search for those phrases too.

What do the common clause variants forbid?#

The common clause variants forbid different things, from a narrow ban on training models with customer content to a broad bar on any AI processing at all. Read the verbs and the objects: train, fine-tune, improve, analyze and disclose; customer data, content, usage data and derived data.

The wording patterns below are paraphrases of recurring structures, not quotations from any particular contract. The last column shows the decision suppliers commonly reach for a license to an outside AI developer, which counsel confirms account by account.

What do the common clause variants forbid?
VariantTypical wording patternWhat it forbidsWhat it may leave openUsual licensing decision
Training-only banVendor will not use customer data to train AI or machine learning modelsTraining models on customer contentEvaluation, retrieval and possibly fine-tuningExclude the account from training packages; evaluation-only use is for counsel to judge
Training and fine-tuning banNo training, fine-tuning or other development of modelsAny change to model weights using customer dataAnalytics and aggregated statisticsExclude from training and fine-tuning packages
Sole-purpose limitCustomer data used solely to provide the servicesAny secondary use, AI or notLittle; close to a full barExclude the account from any external license
Aggregated and de-identified banRestrictions apply even in de-identified or aggregated formUse of prepared or aggregated versionsData never derived from that customerExclude, including prepared and aggregated versions
Third-party AI disclosure banNo disclosure of customer data to AI providers or model developersLicensing to outside developersInternal AI features, if otherwise permittedExclude from every license to an outside developer
AI processing banVendor will not process customer data with AI toolsRunning the data through AI systems, including vendor featuresVery littleExclude, and check internal AI tools against the account
Opt-in modelAI use only with the customer's written consentUse without documented consentUse after documented consentExclude unless signed consent names this use

Which of your records does a clause reach?#

A no-AI-training clause reaches whatever the contract defines as customer data, plus anything derived from it if the clause says so. For most software companies the definition covers content customers upload and outputs generated for them, and it may extend to usage data.

The pattern that matters most is quotation. A Jira issue about a sync failure is company work product; the same issue with a customer's CSV pasted into it carries that customer's restriction with it.

  • Support tickets in Zendesk or Intercom: usually reached when they quote customer content, attachments or account details.
  • Jira or Linear issues: reached when they contain pasted customer logs, screenshots or data samples, and often outside the clause otherwise.
  • Slack and Confluence threads: reached where engineers discuss a named customer's data or incident in detail.
  • Pull requests and code reviews in GitHub or GitLab: usually company-owned, unless customer data sits in fixtures or tests.
  • Product analytics and telemetry: reached under broad variants that include usage or aggregated data.

How to map clauses across your customer base#

Mapping clauses across a customer base means turning hundreds of signed documents into one field per account that the preparation team can act on. The sequence below keeps the work proportionate for a general counsel with a small team.

Silent contracts deserve their own label. An account with no AI language is not the same as an account that consented, and other clauses, such as confidentiality and permitted use, still apply to it.

  • Collect signed versions of every MSA, DPA, order form and addendum, including amendments, from the contract system or shared drives.
  • Search them for terms such as artificial intelligence, machine learning, train, model, aggregate and de-identified.
  • Classify each account by clause variant using the table above, marking silent contracts separately from restricted ones.
  • Record the variant against the account in Salesforce or HubSpot so the same account ID can filter records later.
  • Use the account ID to exclude restricted customers' tickets, issues and attachments at the record level before preparation starts.
  • Revisit the map at each renewal, because new redlines frequently add AI terms.

Illustrative: a vertical software company sorts its accounts#

Illustrative: a fictional software company serving regional construction contractors wants to license its support and engineering history. Its standard terms are silent on AI, but its general counsel finds AI language in enterprise redlines, in a DPA template adopted for larger accounts and in a handful of security addenda.

The team classifies every account. Accounts with aggregated-data bans or third-party disclosure bans are excluded entirely, including their tickets and any Jira issues linked to them. Accounts with training-only bans are also excluded, because the planned license is for training. Silent accounts stay in scope only after counsel confirms that their confidentiality and permitted-use terms allow it, and only once personal and customer-identifying details are removed.

The resulting package is smaller than the first inventory, but each remaining record traces to an account whose contract was read, which is what counsel needed before approving it.

Does a no-training clause block your own records?#

A no-training clause does not block records that contain no customer data, so a company's own engineering, product and internal process records usually remain licensable. The clause attaches to the customer's data, not to everything the vendor ever wrote.

The gray areas are aggregated and de-identified data. Some clauses expressly survive aggregation or de-identification; others are silent, which leaves room for argument. Where the contract is unclear, suppliers often choose exclusion over interpretation, because the relationship with a key account usually matters more than one more set of records.

One practical test helps sort the middle ground. If a record still makes sense with every customer name, attachment and pasted sample removed, it is probably your work product. If removing the customer material leaves nothing useful, the record is the customer's data in substance, whatever system it sits in.

How SourceX treats customer AI restrictions#

SourceX handles customer AI restrictions in the Rights step of the SourceX five-step transaction. The supplier identifies restricted accounts, and their records are excluded before Preparation begins, so restricted material is never prepared, sampled or delivered.

The SourceX Evidence Packet then records the licensing rights basis for the package, including how restricted accounts were identified and excluded. The supplier's counsel interprets the clauses; SourceX keeps the record of the result.

Frequently asked questions

Does a recently signed clause apply to older records?

It may. Clauses typically restrict how the vendor uses customer data it holds, not only data collected after signing. Read the clause for any effective-date limit. Without one, assume it covers the customer's full history in your systems, including archived tickets and closed issues.

Can we ask a customer to waive the restriction?

You can, through a written amendment or consent that names the use, the type of recipient and the preparation applied. Customers are more likely to consider a narrow, documented request than a general one. Never treat silence, or a renewal without objection, as consent.

What if a customer contract says nothing about AI?

Silence is not permission. Other clauses still apply: confidentiality, the license grant or permitted use, data processing terms and deletion duties. A contract that limits customer data to providing the service may block licensing even without any AI wording.

Do these clauses limit AI tools we use internally?

Some do. The AI processing variant can restrict running customer data through any AI system, including help desk assistants or coding tools your team uses. Check vendor settings and subprocessors against those accounts, separately from any licensing question.

Should we put similar clauses in our own vendor contracts?

That is a separate question, but the logic carries over. If your records sit in third-party help desks, CRMs or code hosts, their terms may let them use your data for their own AI. Reviewing those terms protects the records you might later choose to license yourself.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify