FTC algorithmic disgorgement and why AI buyers want licensed, documented data

FTC algorithmic disgorgement is a remedy in which a regulator orders a company to delete models built on improperly obtained data. Buyers therefore insist on documented rights, and suppliers protect themselves by checking privacy promises, excluding third-party records and fixing scope in writing before licensing.

What is algorithmic disgorgement?

Algorithmic disgorgement is a remedy in which a regulator requires a company to delete not only data it should not have used but also the models or algorithms built from it. The Federal Trade Commission has used remedies of this kind in some enforcement orders, and the term is now shorthand for a simple risk: a model trained on improperly obtained data can be ordered destroyed.

For a company that licenses data, the practical point is that buyers care less about the price of a dataset than about whether the rights behind it will hold up. This is general information, not legal, tax or financial advice. Read the FTC's published orders directly, and confirm with your own counsel before relying on any summary.

Why does this make buyers insist on documented rights?

A buyer that trains a model on a dataset takes on the dataset's legal history. If the rights turn out to be defective, the cost is not a refund. It can be retraining from scratch, which means compute, engineering time and delayed products.

That risk shapes what AI labs and data buyers ask suppliers:

  • Who created the records, and who owns them?
  • What did the privacy notices, terms and contracts promise people about use?
  • Were any records collected from third parties, clients or consumers who did not agree?
  • What was excluded, and how was that checked?
  • What does the supplier warrant, and who stands behind the warranty?

These are the same questions SourceX works through with a company during rights review. For the wider buyer logic, see why AI buyers want licensed, consented data.

What has the FTC said about promises and AI?

Two FTC staff posts from early 2024 matter most to suppliers. This is staff guidance, not a rule, and it came from earlier agency leadership, so check for newer positions.

FTC staff pointWhat it means for a supplier
Promises not to use customer data for undisclosed purposes, including training or updating models, are enforceable whether made in privacy policies, terms, promotional material or marketplacesRead every public promise before licensing; a license cannot exceed what customers were told
It may be unfair or deceptive to quietly change terms or privacy policies to allow sharing or AI training, with only a surreptitious, retroactive noticeDo not rewrite terms the week before a deal and treat old records as covered

The takeaway is not that licensing is forbidden. It is that rights have to be real at the time the records were collected, or the company has to obtain them properly.

How a supplier can lower the risk

RiskControl the company can put in placeWhere it fits
Customer data used against a privacy promiseCompare the privacy policy and terms with the proposed use; exclude records the promise coversRights review before inventory is final
Client or third-party data inside internal systemsExclude it unless the client has agreed in writingScoping the dataset
Records of people who never agreed to the useRedact, de-identify or leave out those recordsAgreed with the company before work begins
Scope creep after signingFix the permitted field of use in the agreement; see field-of-use restrictionsContracting
Re-identification of delivered dataContract terms; see the page on no-re-identification clausesContracting

Roles also matter. Whether a recipient is a service provider or a third party changes what the contract must say; the comparison of CCPA service provider, contractor and third party sets this out.

How this connects to the EU rules

Buyers selling into Europe face their own governance expectations. The questions they pass back to suppliers are summarized in the page on EU AI Act Article 10 data governance questions. A supplier that already holds a short rights file answers all of these faster.

What a referral partner needs to know

Partners do not review data or give legal advice. The reason to understand this topic is to answer one sponsor question accurately: why does SourceX ask so many rights questions? The honest answer is that buyers will not take a dataset whose rights they cannot document, and a clean process protects the company too.

Nothing is binding until the company agrees price and terms and signs. Companies keep ownership; data is licensed, not sold, and delivery follows an executed agreement and the company's authorization.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; no reward is guaranteed.

When the honest answer is not yet

Pause an introduction if any of these apply.

  • The privacy policy or terms promise that customer data will not be used for model training.
  • Terms were widened recently and the company wants old records treated as covered.
  • Counsel has not read the policy and terms for each year the records span.
  • Nobody can say which systems hold content written by customers rather than employees.
  • The sponsor wants to skip rights review to move faster.

Illustrative scenario

Illustrative and fictional: a regional logistics software company wants to license ten years of support tickets. Its privacy policy says customer content is used only to provide and improve the service. Counsel reads "improve the service" narrowly and advises excluding tickets that contain customer-authored content, keeping only internal resolution notes and structured fields such as category, priority and outcome.

The dataset is smaller, but the company can say exactly what it contains and why. A buyer's reviewer can check each exclusion against the policy. That is the kind of record that survives a later challenge.

What to say to a sponsor who asks about risk

Questions a buyer's reviewer is likely to ask

Expect the review to touch each of these points, so have the answer ready before the inventory is submitted.

  1. Which privacy policy and terms versions applied in each year of the records?
  2. Did any version change to widen permitted uses, and how were customers told?
  3. Which systems contain content written by customers or clients rather than by employees?
  4. Who at the company can confirm the exclusions were applied before delivery?
  5. Is there anything in a client contract that restricts reuse of work product?

Next step

Run a preliminary screen with the company fit checker and read how the process works. If you know a US company with 50+ full-time employees at peak (contractors excluded) that holds its own rights, register as a partner and introduce it.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does algorithmic disgorgement apply to every AI developer?

The remedy is a tool the FTC has used in some orders; it is not an automatic consequence. Whether it is ordered depends on the facts, the conduct and the agency's view of the harm. The practical lesson for buyers is that defective data rights create a risk that models built on the data must be deleted.

Why would a buyer care about my privacy policy?

Because a buyer inherits the promises made when the records were collected. If a policy said customer data would not be used for model training, using it that way may be unfair or deceptive. Buyers therefore ask for the policies and want exclusions where a promise conflicts with the planned use.

Is licensing data safer than scraping it?

Licensed data comes with a written grant, defined scope and warranties, so the buyer can document where it came from. That does not remove all risk, since the rights must still be genuine. Documentation makes the position far easier to defend than data of unclear origin.

Can a company fix a weak privacy policy before licensing?

Updating policies for future records is good practice, but the FTC staff post warns against quiet retroactive changes to permit new uses of old data. The safer path is to exclude records covered by earlier promises or to obtain proper consent, with counsel guiding the approach.

Should a referral partner raise these risks with a sponsor?

Briefly, yes. Explain that buyers ask for documented rights and that SourceX handles rights review with the company. Do not offer legal conclusions or ask to see confidential records. If the sponsor is worried, point them to their own counsel and the company fit checker.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment