Skip to content

Software companies

Opt-in vs opt-out for AI training in B2B SaaS contracts

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

For AI training in B2B SaaS contracts, opt-in gives the clearest rights to license customer content, while opt-out and silent contracts usually leave third-party licensing in doubt. Opt-in means the customer agrees first; opt-out allows use unless it objects; silence means no AI terms. A default prohibition with signed opt-in yields less volume at first but stronger evidence of permission.

Key takeaways

  • Opt-in produces the smallest initial dataset but the strongest evidence of permission for third-party licensing.
  • Opt-out clauses usually describe improving the vendor's own services, which is narrower than licensing content to an outside AI developer.
  • Silence in a contract is not permission; data use is often limited to providing the services.
  • Updated online terms may not override a negotiated enterprise MSA with an order of precedence clause.
  • An opt-in only helps if a system flag ties each customer's choice to the export filter.

What do opt-in, opt-out and silent contracts actually say?#

Opt-in, opt-out and silent contracts differ in who has to act before customer content can be used for AI training. Under opt-in, the customer signs an addendum, ticks an order form box or enables an admin setting, and nothing is used until it does. Under opt-out, the terms grant the vendor a right to use content for training unless the customer sends notice or switches a setting off. A silent contract has no AI language at all.

Silent contracts are the most common starting point for software companies that signed customers before AI training was a live question. Their data use language usually limits processing to providing, supporting and securing the services, and their data processing addendum often adds that the vendor acts only on the customer's instructions.

Between these sits a common hybrid: an opt-out for aggregated usage statistics combined with an opt-in for customer content. The split mirrors how customers weigh risk, since ticket text, documents and chat messages carry details about their own customers and staff, while counts of feature use usually do not.

How do opt-in, opt-out and silence compare?#

Opt-in, opt-out and silent contracts trade usable volume against certainty of permission: opt-in gives the smallest dataset with the strongest record, while opt-out offers more data on paper with weaker proof. The comparison below assumes the goal is licensing de-identified customer content to an outside AI developer, which is a stricter use than improving the vendor's own features.

How do opt-in, opt-out and silence compare?
FactorOpt-inOpt-outSilent
Customer trustHighest; the customer choseMixed; some customers learn of it lateNeutral until the vendor acts
Legal exposureLowest, if scope is clearModerate; notice and scope can be disputedHighest if content is used beyond the services
Usable volume at startSmallLarge on paperUsually none for third-party licensing
Evidence for a buyerSigned record per customerTerms version plus absence of objectionNone
Enterprise procurement reactionOften accepted with limitsOften struck in negotiationNot raised
Revocation handlingDefined in the addendumOften undefinedNot applicable

Why opt-out is weaker than it looks for third-party licensing#

Opt-out clauses are weaker than they look because most were written for internal product improvement, such as training a ticket classifier inside the vendor's own help desk. Licensing content to an outside AI developer discloses it to a third party for that party's purposes, which many opt-out clauses do not mention.

Enterprise contracts add a second problem. A negotiated MSA usually says it prevails over online terms, so a revised terms of service page that adds an opt-out may not bind those customers at all. Privacy laws such as GDPR and CCPA may also limit a processor or service provider from using customer personal data for its own purposes, which is assessed deal by deal with counsel.

Buyers notice the difference in diligence. An opt-out record proves that a terms version existed, not that a customer saw it. A signed opt-in proves both.

What a defensible opt-in record contains#

A defensible opt-in record names exactly what the customer agreed to, who agreed, and how the choice reaches the export pipeline. Provenance standards already expect this kind of record: the Data & Trust Alliance's Data Provenance Standards include metadata for consent documentation location, license to use and intended data use.

  • Signed addendum or order form clause, executed by someone with authority to bind the customer.
  • Data categories in scope, such as ticket text and chat transcripts, and categories out of scope, such as attachments and call audio.
  • Permitted uses spelled out, including licensing to third parties for AI training and evaluation if that is intended.
  • The vendor's de-identification commitment and the standard it will apply.
  • Date range covered: future content only, or historical content as well.
  • Revocation terms, including what happens to content already delivered.
  • A CRM field, such as an account flag in Salesforce or HubSpot, that the export job reads.

Illustrative: a property management SaaS moves from silence to opt-in#

Illustrative: a fictional property management software company holds years of Zendesk tickets and in-app chat from its customers' leasing teams. Its MSA is silent on AI, and the product team proposes adding an opt-out to the online terms.

The general counsel reviews the customer base and finds that most revenue sits on negotiated MSAs with an order of precedence clause, so an online change would not reach them. The company instead offers an AI training addendum at renewal, records each signature as an account flag in Salesforce, and changes the Zendesk export job to pull tickets only from flagged accounts.

The first package is smaller than the full archive, but every ticket in it traces to a signed permission, and customers who declined are excluded automatically at each export.

Which model fits which customer segment?#

The right consent model depends on how each customer segment signed. Many SaaS companies end up running more than one model, with the export filter respecting the strictest applicable rule for each account.

Apply the filter at the level where consent was given. If an enterprise signs the addendum for its parent entity but its subsidiaries run separate workspaces, confirm whether the addendum covers each workspace before the export job treats them as flagged.

Which model fits which customer segment?
Customer situationModel to considerWatch for
Enterprise accounts on negotiated MSAsOpt-in addendum at renewalOrder of precedence and DPA instructions
Self-serve accounts on clickwrap termsOpt-in admin setting with a logged recordTerms versioning and notice records
Customers in regulated sectorsExclude by defaultSector rules and customer audit rights
Former customersUsually excludeWhat the original terms allowed and deletion duties at termination
Accounts already under opt-outConvert to opt-in before licensingWhether the opt-out scope covered third parties

SourceX reviews customer contract categories in the Rights step of the SourceX five-step transaction, after Supply and before Preparation, Approval and Delivery. Silent and opt-out cohorts are usually scoped out or referred to the supplier's counsel, and signed opt-in cohorts form the core of a package.

The consent records relied on are documented in the SourceX Evidence Packet under licensing rights and permitted use, so a buyer sees which customer permissions support each record family. The supplier approves the scope at every step.

Frequently asked questions

Does an opt-in for product improvement cover licensing to an AI developer?

Usually not on its own. Product improvement wording points to the vendor's own features. Licensing to an outside developer is disclosure to a third party for that party's purposes, so the opt-in should say so expressly. If existing opt-ins are narrower, a short amendment is cleaner than a stretched reading.

What happens if a customer revokes an opt-in after delivery?

That depends on the addendum. Common approaches stop future exports immediately and leave already delivered de-identified content with the licensee, or require the licensee to remove it from future training runs. Whatever the rule, write it into both the customer addendum and the license so the two match.

Do we need consent from our customers' end users as well?

In B2B SaaS the customer usually controls the content its users create, so the customer's agreement is the main permission. End users' personal data inside tickets still triggers privacy obligations, which is why de-identification and notice questions are assessed with counsel for each deal.

Can we offer customers something in return for opting in?

Some vendors pair an opt-in with a service credit or a feature. That can work, but it should be documented in the addendum and should not make the opt-in look coerced. Keep the record clear that the content is licensed with permission, and that the customer can decline without losing core service.

How long does a signed opt-in remain valid?

As long as the addendum says. Many tie it to the MSA term and renewals, so it ends when the customer churns. Check that your export filter reads the current flag each time rather than a snapshot taken when the program started.

Is an opt-in statement in our privacy policy enough?

No. A privacy policy describes practices to individuals; it is not a contract with the business customer. For B2B content, the permission that matters sits in the MSA, order form or addendum the customer signs. Update the privacy policy so it stays consistent, but do not treat it as the permission itself.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for consent documentation location, license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify