Can a company use customer data to train AI under its customer contracts?
Companies generally cannot use customer data to train AI unless the customer contract or a separate written consent allows it. Most B2B MSAs treat customer data as the customer's confidential information, usable only to deliver the services. The company's own operational records, such as internal tickets, SOPs and decision logs, are a different category and often remain licensable.
The short answer: only where the contract or the customer allows it
A company can use customer data to train AI only where its customer contracts, its privacy commitments and any separate consents permit that use. In most B2B master services agreements (MSAs), customer data is defined as the customer's confidential information and may be used solely to provide the services, which rules out licensing it to AI developers without fresh written permission.
That is why SourceX treats customer-owned content as usually out of scope for a data license. For most sellers the opportunity sits in the company's own operational records: how its people resolved tickets, ran projects, wrote procedures and made decisions. For an M&A advisor, the useful skill is telling those two categories apart before anyone mentions licensing to a client.
What regulators and the law actually say
No single rule answers the question for a specific contract. Three sources frame where to look, and a fourth explains why internal documents start on the company's side of the line.
- Promises are enforceable. FTC staff wrote in January 2024 that a company's commitments not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether they appear in a privacy policy, terms of service or promotional material (FTC staff post on confidentiality commitments).
- Quiet, retroactive changes are risky. In February 2024 FTC staff added that adopting more permissive data practices, such as using consumer data for AI training, and disclosing them only through a surreptitious, retroactive amendment to the terms or privacy policy could be unfair or deceptive (FTC staff post on terms changes). Both posts are staff guidance, not rules.
- State privacy law adds consumer rights. Where records hold personal information about California residents, the California Consumer Privacy Act gives consumers rights to know, to delete and to opt out of the sale or sharing of their information, for businesses that meet the law's thresholds (California Attorney General CCPA overview).
- Employee work starts with the employer. The Copyright Office explains that a work prepared by an employee within the scope of employment is a work made for hire owned by the employer, while commissioned work from a contractor qualifies only in listed categories and with a signed written agreement (Copyright Office Circular 30). Contractor material therefore usually needs a written assignment before it can be licensed.
Which MSA clauses decide whether customer data can train AI
Read these clauses in the company's standard MSA, its data processing addendum (DPA) and its largest negotiated contracts. Big customers often redline the data-use language, so the paper behind the top accounts matters more than the template.
| Clause | What to look for | What it usually means for licensing |
|---|---|---|
| Definitions | Is customer data defined broadly, covering content, files, communications and outputs? | Anything inside the definition is presumptively the customer's |
| Use restriction | Wording such as 'solely to provide the Services' or 'for no other purpose' | Licensing customer data to a third party falls outside the permitted use |
| Aggregated or usage data | A right to use de-identified, aggregated or usage data for product improvement | Narrow; improving your own service is not the same as licensing to others |
| AI or machine learning | An express clause allowing or forbidding model training | The clearest answer either way, when it exists |
| Confidentiality | Duration, survival after termination and what counts as confidential | Restrictions often outlive the contract |
| Return and deletion | A duty to return or delete customer data at termination | Data that should already have been deleted cannot be licensed |
| Work product and IP | Who owns deliverables, reports and custom code under each SOW | Client-owned deliverables are out; internal tools and know-how may be in |
Which records stay licensable and which usually do not
The split rarely follows system boundaries. A helpdesk can hold both a customer's attachments and the company's own resolution notes, so the review has to go record type by record type.
| Record type | Typical owner | Licensing outlook |
|---|---|---|
| Files, data and content customers upload to a SaaS product | The customer | Usually out of scope without customer consent |
| Client deliverables under a consulting or IT services SOW | Often the client, per the SOW | Usually out unless ownership stayed with the firm |
| Internal ticket threads, escalation notes and resolution steps | The company, though they quote customer details | Often licensable after agreed redaction and de-identification |
| SOPs, runbooks, playbooks and training material written by staff | The company | Usually the strongest candidates |
| Internal email, Slack or Teams threads about how work gets done | The company | Licensable subject to employee notices and redaction |
| Code, pull requests and design reviews for the company's own product | The company | Licensable if contractor contributions were assigned |
| Recorded customer calls | Shared, with consent rules attached | Case by case, depending on notices and consent |
The guide to separating company data from customer-owned data works through the borderline cases in more depth.
How this plays out in situations M&A advisors see
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| SaaS client whose value sits in customer usage data | MSA use restriction, any aggregated-data clause, privacy policy history | Product data usually out; engineering, support and go-to-market records may qualify |
| IT services or systems integration firm | SOW ownership terms and client environment access rules | Client systems out; internal project methods and ticket histories may qualify |
| Contact center or BPO serving a client's customers | Client contracts and call recording notices | Mostly client data; often fails the rights test |
| Company that rewrote its privacy policy recently | What the policy said when the records were collected | Records collected under the old promise follow the old promise |
| Seller in a live sale process | Diligence disclosures and purchase agreement covenants | A license is possible only with deal counsel involved |
Businesses whose records mostly belong to their clients, such as many agencies and outsourcers, are a common reason an introduction stops at the rights review. The SaaS sale guide and the IT consulting sale guide show where the licensable records tend to sit in those two business models.
Disclosure and consent good practice
- Map each record type to the contracts that govern it before anyone discusses price or scope.
- Never rely on a quiet change to the terms of service to create a training right after the fact.
- Get written customer consent for any customer content that stays in scope, or leave it out.
- Agree de-identification and redaction rules with the company before any preparation work starts.
- Keep the advisor's role to the introduction itself; a referral partner never exports, uploads or describes confidential records.
Questions to ask counsel before a license is scoped
- Which contracts define customer data broadly enough to capture the records we want to license?
- Does any customer contract, privacy policy or marketing page promise that data will not be used for AI or model training?
- Did contractors or agencies create material we plan to include, and do we hold written assignments for it?
- Which records contain personal information about California residents or other consumers, and what notices covered their collection?
- What redaction or de-identification standard should apply to internal records that quote customers?
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Next step
Run the client through the company fit checker and compare the result with the who qualifies baseline. If the company's own records look deep and its rights are clean, register as a partner so you can submit the company once the owner agrees. Advisors weighing the program as a whole can start with how referrals work for M&A advisors.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does de-identifying customer data make it available for AI training?
Not on its own. De-identification reduces privacy risk, but a confidentiality clause or use restriction in the MSA can still forbid using the data for anything other than delivering the services, whether or not individuals can be identified. The contract question and the privacy question have to be answered separately, and either one can block a license.
Can a company change its terms of service now so it can train AI on customer data?
It can update its terms going forward, but FTC staff have warned that adopting more permissive data practices through a quiet, retroactive change can be unfair or deceptive. Records collected under an earlier promise generally follow that earlier promise. Any change should be prospective, clearly communicated and reviewed by counsel before anyone relies on it.
Are support tickets customer data or company data?
Usually both. The customer's attachments and the personal details they share belong to the customer or are protected, while the agent's diagnosis, escalation path and resolution notes reflect the company's own work. Many ticket histories can become licensable once the company agrees redaction rules that remove customer identities and content it does not own, but the contracts behind each queue decide it.
Should an M&A advisor read the client's customer contracts before making an introduction?
No. The advisor's job is to make the introduction and share basic fit information. The company and its counsel review contracts during qualification, and SourceX's rights review asks the same questions. An advisor can help by asking the owner, in general terms, whether customer contracts restrict data use, which is enough to decide whether an introduction is worth making.
Will a buyer of the company care whether customer data was licensed?
It should be expected. Diligence questionnaires can ask what data a target has shared and on what terms, and a license that used customer data without permission can surface as a breach of contract or a privacy problem. Licensing only the company's own records under a signed agreement, and disclosing that license during a sale, keeps the issue manageable.
Related pages
- How to distinguish company data from data owned by its customers
- How to sell a SaaS company, and what to do with the records beyond ARR
- How to sell an IT consulting or systems integration firm, records included
- Check Company Fit for Data Licensing
- Which US businesses are a fit for a SourceX data licensing introduction
- Referral opportunities for M&A advisors
Free resources
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment