Skip to content
Tech

Before you sign that AI contract, read these data clauses line by line

AI vendors handle your prompts, files and customer data under terms that vary widely. These are the clauses that decide what happens to your company's information.

Hand holding pen signing, illustrating “Before you sign that AI contract, read these data clauses line by line”
Photo: rawpixel (CC0)

The most consequential part of an AI vendor contract is often buried in a section with a title like Use of Customer Data, a few pages after the pricing.

Every prompt an employee types and every file they upload goes to a vendor's systems. What happens next depends on terms that differ between vendors, between pricing tiers of the same vendor and sometimes between versions of the same agreement. A team on a consumer chatbot account and a team on an enterprise contract can be operating under very different rules for identical work.

Training: the clause everyone asks about

Start with whether the vendor can use your inputs and outputs to train or improve its models. Look for clear, affirmative language, such as a statement that customer content is not used to train models. Vaguer wording about improving services or developing new features can be broad enough to cover training.

Check whether the protection is a default or an opt-out. An opt-out setting that an administrator has to find and switch on is easy to miss, and it may not apply to data sent before it was changed. Confirm whether the commitment covers every product you plan to use, including APIs, browser extensions and integrations.

Then check how the vendor can change these terms. The Federal Trade Commission has warned companies that quietly rewriting their terms to expand how customer data can be used may be unfair or deceptive. Your contract should still require notice of material changes and give you a right to terminate if the vendor alters how it handles your data.

Retention, deletion and human review

Not training on your data is not the same as not keeping it. Ask how long prompts, outputs and uploaded files are retained, and for what purposes. Many vendors keep inputs for a period to monitor for abuse, and some allow authorized staff to review flagged content. Some offer reduced or zero-retention arrangements for eligible customers, often only on enterprise plans or by request.

Find out what happens to your data when the contract ends. You want deletion within a defined period, an option to export first and written confirmation on request. Backups often follow a separate, longer schedule, so ask about those as well.

Who else touches the data

AI products are frequently built on other companies' models and cloud infrastructure. The vendor's list of subprocessors tells you who else may process your information and in which countries. Ask for the list, ask how you will be notified when it changes, and check whether data residency commitments are available if your customers or regulators require data to stay in a particular region.

If you will send personal information, you will usually need a data processing agreement. If you handle health information covered by HIPAA, you will need a business associate agreement, and many vendors offer one only on specific plans. If a vendor will not sign the agreement your obligations require, that product is not an option for that data, however good it is.

Outputs, ownership and liability

Read who owns what the model produces. Most business terms assign outputs to the customer, but ownership does not guarantee that an output is free of third-party rights. Some vendors offer indemnities against intellectual property claims arising from outputs, typically with conditions such as using the product as documented and keeping certain safety filters enabled. Know the conditions before you rely on the promise.

Then look at the limitation of liability. Many vendors cap their total exposure at the fees paid over a recent period. For a modest subscription, that cap may be small relative to the harm of a data incident. Enterprise buyers often negotiate a separate, higher cap for breaches of data protection and confidentiality obligations.

Security commitments belong in the same review: breach notification timelines, encryption in transit and at rest, access controls, and independent attestation reports you can request under a nondisclosure agreement.

What to do this quarter

Inventory which AI tools your team already uses, including free personal accounts. Unsanctioned consumer accounts are where much of the exposure sits, because they run on consumer terms nobody at your company negotiated.

Choose approved tools for each kind of work, put them on business or enterprise terms, and tell employees plainly which data may go into which tool. A one-page policy people actually read beats a long one nobody opens.

Keep a short checklist for every new AI vendor: training use, retention period, human review, subprocessors, deletion at termination, output ownership, indemnity conditions and the liability cap. If an answer is not in the contract, get it in writing before you sign.

Map the checklist to a recognized framework if you want a structure for the wider program. The National Institute of Standards and Technology publishes a voluntary AI Risk Management Framework that many companies use as a reference for governing AI use.

Finally, revisit the terms at every renewal. AI vendors update their products and policies often, and the deal you reviewed last year may not be the deal you have now.

This is general information, not legal advice. Speak to a qualified attorney in your jurisdiction before acting on any of it.

Sources

FTC — Artificial Intelligence

NIST — AI Risk Management Framework

Related