How to stop employees selling your company's work files to AI firms
Remind staff in writing what they agreed to, update confidentiality and acceptable-use policies, restrict bulk export rights and watch downloads at offboarding. Company work product is generally the employer's, so an individual cannot authorize a sale. The legitimate route is a company license approved by an authorized sponsor.
How do you stop employees selling company documents to AI firms?
Remind staff in writing what they agreed to, tighten the confidentiality and offboarding rules, and watch for bulk downloads when people leave. The company's own work product is generally the company's to license. An individual employee has no authority to sell it, and the legitimate route is a company license approved by an authorized sponsor.
AI data firms can approach individual professionals for materials from previous jobs. Whether or not an offer ever reaches your people, the protective steps are the same and cheap to do now.
Who owns the documents in question
Under copyright law, a work prepared by an employee within the scope of employment is a work made for hire, and the employer is the author and owner. The Copyright Office explains this, and the statutory definition is in 17 U.S.C. section 101. Work by contractors may not be owned by the company unless it is assigned in writing.
Copyright is only part of the picture. Documents can also carry confidentiality duties to clients, trade-secret status and contractual limits that an employee cannot waive. Which rules apply depends on the facts and the state. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Prerequisites: know what you hold
Before changing policy, find out what exists and who can reach it. You need an inventory of core systems (email, chat, shared drives, CRM, ticketing, code repositories), a list of who has bulk export rights, and copies of current employment, contractor and confidentiality agreements.
The 7-step protection plan
- Read the paper. Pull the confidentiality, invention-assignment and acceptable-use agreements employees actually signed. Note gaps, such as contractors with no assignment clause.
- Update the policy. State plainly that company documents, messages and work product may not be shared with or sold to any outside party, including AI data buyers or brokers, without written approval.
- Tell people. Send a short notice to staff and contractors that restates the rule and names the approval route. Keep a record of delivery and acknowledgment.
- Limit export rights. Review who can download whole mailboxes, bulk-export Slack or Teams history, or clone every repository. Remove rights nobody needs.
- Add offboarding checks. Alert on bulk downloads and forwarding in the weeks before departure. Hold an exit conversation that restates continuing duties and collects devices.
- Create the legitimate route. Name who can approve an outside license. If the company wants to explore one, an authorized sponsor, such as the owner, CEO, CFO or authorized representative, leads it.
- Escalate quickly. If you learn of an offer or a sale, preserve evidence and bring in counsel before contacting anyone.
Signs that outside offers are reaching your people
You rarely hear about these approaches directly. Watch for patterns instead, then ask questions calmly before assuming bad faith.
- Staff mention recruiters or "research platforms" asking for samples of past work.
- Someone requests an unusual export of old tickets, proposals or chat threads with no business reason.
- A departing employee forwards mail or syncs a personal drive in the final weeks.
- Clients ask whether their documents could end up in an AI dataset.
- Professional networks start circulating posts about paid "work sample" programs.
Treat each as a prompt to restate the policy, not as proof of wrongdoing. Most employees simply do not know that selling a past employer's files can breach their agreements.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| Relying on a handbook line nobody signed | Hard to enforce | Get signed acknowledgments and refresh them yearly |
| Ignoring contractors | They may own what they produce | Add written assignment and confidentiality clauses |
| Letting everyone export everything | One departure can copy years of records | Restrict bulk export; log it |
| Reacting only at exit | Copies are already made | Monitor in the notice period, not just on the last day |
| Saying "never" with no alternative | Staff and clients get confused | Publish the approval route for outside requests |
| Treating the offer as harmless | Client confidentiality duties may be breached | Review client contracts with counsel |
What to say to staff
Illustrative scenario
Illustrative: a fictional 120-person IT services firm learns a departing account manager has asked a recruiter about "selling samples of past project work." The firm restates the signed confidentiality agreement, checks the manager's export logs, and asks counsel to write to the individual. Separately, the CEO asks whether the firm should explore a licensed deal on its own terms. The two decisions are independent.
Why the authorized route is different
A company license is a scoped transaction: the company keeps ownership, sets scope and exclusions, agrees de-identification and redaction rules with the buyer before any work begins, and delivers data only after an executed agreement and the company's authorization. It is nothing like an individual passing along files. Owners weighing it can read how to sell data to AI companies and what an AI buyer does with licensed records.
An employee's side is covered in what to do when an AI data firm offers to buy your client work files, and the platform angle in whether Slack's API policy stops a company licensing its history. Staff morale is covered in what employees will think if the company licenses records, and the investor view in portfolio data licensing and reputational risk.
What to do the day an offer surfaces
- Do not confront anyone yet. Write down who, what and when.
- Preserve logs, messages and the agreement the person signed.
- Ask counsel whether client contracts require notice.
- Then have a documented conversation that restates the duties and asks what, if anything, was shared.
When this plan is not enough
If an offer has already led to a sale, or client data left the building, this is a legal and incident-response matter. Stop and call counsel. A policy refresh will not fix it.
Next step
If the company holds years of records and the owner wants to explore a licensed route the company controls, register as a partner to introduce it, or have the company apply at sourcex.si/apply. To see how the partner reward works, use the referral earnings calculator; more answers are in the FAQ.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can an employee legally sell documents they wrote at work?
Generally not. Work prepared by an employee within the scope of employment is usually a work made for hire owned by the employer, and documents may also carry confidentiality duties. Contractors are different if no written assignment exists. Facts and state law vary, so ask counsel about a specific case.
What should an offboarding checklist include?
Restate continuing confidentiality duties, collect devices, revoke access promptly, review logs for bulk downloads and mail forwarding in the notice period, and get a signed acknowledgment. Keep the record. The goal is to catch copying before it happens rather than after documents have left.
Does a company license make this problem worse?
No. A company license is a controlled transaction approved by an authorized sponsor, with scope, exclusions and redaction rules agreed before any work begins and delivery only after an executed agreement. It gives the company a legitimate answer to outside requests instead of leaving staff to improvise.
What if a former employee has already been approached or has sold something?
Preserve evidence, stop discussing it informally and contact counsel. Depending on what was taken, client contracts, trade-secret protections and notification duties may be involved. A policy update helps for the future but does not resolve a sale that has already occurred.
Who should approve an outside license of company records?
An authorized sponsor, such as the owner, CEO, CFO or another authorized representative. Name that route in your policy so employees know where requests go. Nothing is binding on the company until it agrees price and terms and signs.
Related pages
- SourceX referral program frequently asked questions
- Portfolio data licensing and reputational risk: a sponsor's guide to doing it cleanly
- How to sell data to AI companies
- An AI data firm offered to buy my client work files. Should I sell them?
- Do Slack's API terms stop a company from licensing its own Slack history?
- What does an AI buyer actually do with licensed company records?
Free resources
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment