Trade secrets in AI training data licenses: what attorneys should flag
Licensing company records as AI training data can put trade-secret status at risk if secret material leaves the company without tight scope, redaction and confidentiality terms; whether it does depends on what is delivered and how it is protected. Counsel typically carves out source code, formulas, pricing logic and similar core secrets first, then limits use, access and onward disclosure.
The short answer: it depends on what is delivered and on what terms
Licensing company records as AI training data does not have to cost a client its trade secrets, but it can. The outcome turns mainly on two things counsel controls: what actually leaves the company, and the confidentiality, use and access terms that travel with it. Records with no secret content raise little trade-secret risk; formulas, source code, pricing logic or customer-specific know-how delivered on loose terms can raise a great deal.
In practice the protective work happens before delivery. Counsel narrows the scope, carves out what the client most needs to keep secret, agrees redaction rules, and writes use limits that stop the licensee from disclosing or exploiting the material beyond the agreed AI-training purpose.
What the law looks at
US trade-secret protection comes from federal and state law, and the wording of the elements varies by jurisdiction. In broad terms, counsel will ask two questions about any record set: does the information have value because it is not generally known, and has the owner taken reasonable steps to keep it secret? A license that hands secret material to a third party without confidentiality obligations makes the second question harder to answer. Confirm the exact test in the statute and case law that govern your client.
Three other bodies of law usually sit beside trade secrets in the same deal:
- Copyright ownership. Ownership of copyright may be transferred in whole or in part, and any of the exclusive rights may be transferred and owned separately, under 17 U.S.C. § 201. That divisibility is what lets a company grant an exclusive AI-training license for a term while keeping ownership of the underlying material.
- Promises to customers. FTC staff wrote in a January 2024 post on privacy and confidentiality commitments that a company's promises not to use customer data for undisclosed purposes, such as training models, are enforceable wherever they were made, including privacy policies, terms of service and marketing. It is staff guidance, not a rule, but it tells you to read what the client promised.
- Personal and health data. California's CCPA requires a written agreement limiting use when a business sells or shares personal information or discloses it to a service provider or contractor (Cal. Civ. Code § 1798.100 et seq.), and HHS describes the two methods for de-identifying protected health information under the HIPAA Privacy Rule in its de-identification guidance.
How it applies in common deal situations
| Situation | What counsel should check | Typical outcome to confirm |
|---|---|---|
| Support tickets describing product workarounds and known defects | Whether any ticket reveals unreleased roadmap or security weaknesses | Exclude security-sensitive categories; keep routine resolution history |
| Engineering repositories, pull requests and issue trackers | Which code embodies core algorithms, and whether credentials sit in config files | Carve out named repositories or modules; scan and strip credentials before delivery |
| CRM and finance records with pricing and margins | Whether pricing models or cost structures are a competitive secret | Redact or aggregate price and margin fields; keep activity and outcome history |
| Email and chat holding third parties' confidential information | NDAs with vendors, partners and customers that restrict onward disclosure | Exclude counterparties whose agreements prohibit disclosure, or obtain consent |
| SOPs and process documents containing formulas or proprietary methods | Which documents the client treats as its core secrets | List excluded documents by name in the dataset schedule |
| Material created by contractors or agencies | Whether assignments or work-for-hire terms exist | Obtain assignments or leave the material out |
| Customer data covered by privacy or confidentiality promises | What the privacy policy, terms and contracts said at collection | Exclude, de-identify or obtain consent as the promises require |
Contract terms counsel typically negotiates
These points come up in most data licenses that touch confidential material. Treat them as a starting list, not a form.
- A dataset schedule. Define exactly which systems, date ranges and record types are licensed, so anything not listed is excluded by default.
- Exclusions and carve-outs. Name the categories that never leave the company, such as core source code, formulas, security documentation and board materials.
- A redaction and de-identification specification. Fix the rules for names, identifiers, prices and third-party information before any preparation work begins.
- Use restrictions. Limit use to the agreed AI training and evaluation purpose for the agreed term, with no onward licensing or disclosure.
- Confidentiality and security obligations. Require stated protective controls and limit access to the licensee's people who need it.
- No residuals clause. Strike language letting the licensee's staff freely use information retained in memory; it undercuts the confidentiality terms.
- Output and extraction safeguards. Ask how the licensee handles the risk of a trained model reproducing distinctive passages, and prohibit attempts to re-identify people or reconstruct delivered records.
- End-of-term handling. Say what happens to delivered data when the term ends, including deletion or return and a certificate.
In a SourceX deal, the company keeps ownership and licenses its records rather than selling them. Redaction and de-identification requirements are agreed with the company before any work begins, and nothing is delivered without an executed agreement and the company's authorization; the how it works page sets out the sequence. The client can walk away at any point before signing.
Disclosure and consent good practice
- Read the client's own commitments first: privacy policy, customer terms, master services agreements and employee notices. The piece on why consent matters in AI data explains why buyers check the same documents.
- Inventory third-party NDAs that could cover information sitting in email, chat or shared drives.
- Keep a written record of the client's protective measures: access controls, confidentiality agreements and the carve-out list. That record supports the trade-secret position if it is ever challenged.
- Bring the client's IT lead in early. Access controls, credential scanning and export logs are technical work; the guide to CIO peer groups shows how IT leaders approach these projects, and an EOS Integrator's responsibilities show who usually runs the internal workstream.
Questions to put to the client before any delivery
- Which five pieces of information would hurt most if a competitor saw them, and where do they live?
- Which systems hold third parties' confidential information under contract?
- Has the company ever promised customers, in writing, that their data would not be shared or used to train models?
- Who created the records: employees, contractors, agencies or clients?
- Who can authorize the license, and who will own the redaction review?
This is general information, not legal, tax or financial advice. Trade-secret, privacy and contract rules vary by jurisdiction and by deal; confirm with your own counsel or professional body before acting.
If you want to introduce a client yourself
Anyone can register as a SourceX partner, but referral compensation for lawyers is governed by each state's version of the professional conduct rules. The ABA's Model Rules of Professional Conduct address fees (Rule 1.5), professional independence (Rule 5.4), payments for recommendations (Rule 7.2) and business transactions with clients (Rule 1.8); check how your state adopted them, and whether client disclosure or consent is required, before accepting anything.
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company, and the reward becomes payable only after the buyer pays and SourceX receives its fee. The reward is never deducted from what the client receives. Partners make introductions and share basic fit information only; they never export or describe a client's confidential records.
Next step
If a client holds years of operational records and the rights to license them, review the baseline on who qualifies. To make introductions, register as a partner; the client can also apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does delivering records under a confidentiality agreement keep them trade secrets?
It can help, but it is not automatic. Trade-secret analysis generally looks at the overall measures an owner took to keep information secret, and a well-drafted agreement with use limits, access controls and return or deletion terms is one of those measures. Delivering core secrets at all remains a business risk, which is why counsel usually carves them out rather than relying on contract terms alone.
Can a trained model leak a client's confidential information?
Models can sometimes reproduce distinctive text they were trained on, which is why counsel asks how the licensee handles memorization and extraction risk. The strongest defenses sit upstream: exclude the most sensitive material, redact identifiers and prices, and prohibit attempts to extract or reconstruct delivered records. Anything the client cannot afford to see reproduced should stay out of scope.
Should source code ever be part of an AI training data license?
Sometimes. Engineering histories, including code reviews, pull requests and issue tracking, are among the records AI developers find useful, but core algorithms and anything containing credentials or security details usually should not leave the company. Counsel and the client's engineering lead can agree which repositories or modules to exclude, then scan everything else for secrets before delivery.
What is a residuals clause, and why do attorneys strike it?
A residuals clause lets the recipient's people use general knowledge, ideas or techniques they retain in unaided memory after seeing confidential information. In a data license it can undercut the confidentiality and use restrictions, because the licensee could argue that knowledge absorbed from the records is free to use. Disclosing parties often strike it or narrow it heavily.
Who decides the redaction and de-identification rules in a SourceX deal?
The company does, with its counsel. De-identification and redaction requirements are agreed with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization. The company keeps ownership of its records and can decline to proceed at any point before it signs.
Can an attorney be a SourceX referral partner?
Anyone can register, but lawyers are bound by their state's rules of professional conduct, which may limit receiving value for recommendations, sharing fees or entering business transactions connected to clients. Read your state's versions of the rules on fees, professional independence and recommendations, consider whether client disclosure or consent is needed, and ask your state bar's ethics counsel before accepting any reward.
Related pages
Free resources
- Business exit readiness assessment — A preliminary exit readiness score and checklist for advisors.
- SDE vs EBITDA calculator — Seller's discretionary earnings next to market-rate EBITDA.
- IRR calculator — Internal rate of return on annual cash flows.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment