Can a company use customer data to train AI under its customer contracts?

Companies generally cannot use customer data to train AI unless the customer contract or a separate written consent allows it. Most B2B MSAs treat customer data as the customer's confidential information, usable only to deliver the services. The company's own operational records, such as internal tickets, SOPs and decision logs, are a different category and often remain licensable.

The short answer: only where the contract or the customer allows it

A company can use customer data to train AI only where its customer contracts, its privacy commitments and any separate consents permit that use. In most B2B master services agreements (MSAs), customer data is defined as the customer's confidential information and may be used solely to provide the services, which rules out licensing it to AI developers without fresh written permission.

That is why SourceX treats customer-owned content as usually out of scope for a data license. For most sellers the opportunity sits in the company's own operational records: how its people resolved tickets, ran projects, wrote procedures and made decisions. For an M&A advisor, the useful skill is telling those two categories apart before anyone mentions licensing to a client.

What regulators and the law actually say

No single rule answers the question for a specific contract. Three sources frame where to look, and a fourth explains why internal documents start on the company's side of the line.

  • Promises are enforceable. FTC staff wrote in January 2024 that a company's commitments not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether they appear in a privacy policy, terms of service or promotional material (FTC staff post on confidentiality commitments).
  • Quiet, retroactive changes are risky. In February 2024 FTC staff added that adopting more permissive data practices, such as using consumer data for AI training, and disclosing them only through a surreptitious, retroactive amendment to the terms or privacy policy could be unfair or deceptive (FTC staff post on terms changes). Both posts are staff guidance, not rules.
  • State privacy law adds consumer rights. Where records hold personal information about California residents, the California Consumer Privacy Act gives consumers rights to know, to delete and to opt out of the sale or sharing of their information, for businesses that meet the law's thresholds (California Attorney General CCPA overview).
  • Employee work starts with the employer. The Copyright Office explains that a work prepared by an employee within the scope of employment is a work made for hire owned by the employer, while commissioned work from a contractor qualifies only in listed categories and with a signed written agreement (Copyright Office Circular 30). Contractor material therefore usually needs a written assignment before it can be licensed.

Which MSA clauses decide whether customer data can train AI

Read these clauses in the company's standard MSA, its data processing addendum (DPA) and its largest negotiated contracts. Big customers often redline the data-use language, so the paper behind the top accounts matters more than the template.

ClauseWhat to look forWhat it usually means for licensing
DefinitionsIs customer data defined broadly, covering content, files, communications and outputs?Anything inside the definition is presumptively the customer's
Use restrictionWording such as 'solely to provide the Services' or 'for no other purpose'Licensing customer data to a third party falls outside the permitted use
Aggregated or usage dataA right to use de-identified, aggregated or usage data for product improvementNarrow; improving your own service is not the same as licensing to others
AI or machine learningAn express clause allowing or forbidding model trainingThe clearest answer either way, when it exists
ConfidentialityDuration, survival after termination and what counts as confidentialRestrictions often outlive the contract
Return and deletionA duty to return or delete customer data at terminationData that should already have been deleted cannot be licensed
Work product and IPWho owns deliverables, reports and custom code under each SOWClient-owned deliverables are out; internal tools and know-how may be in

Which records stay licensable and which usually do not

The split rarely follows system boundaries. A helpdesk can hold both a customer's attachments and the company's own resolution notes, so the review has to go record type by record type.

Record typeTypical ownerLicensing outlook
Files, data and content customers upload to a SaaS productThe customerUsually out of scope without customer consent
Client deliverables under a consulting or IT services SOWOften the client, per the SOWUsually out unless ownership stayed with the firm
Internal ticket threads, escalation notes and resolution stepsThe company, though they quote customer detailsOften licensable after agreed redaction and de-identification
SOPs, runbooks, playbooks and training material written by staffThe companyUsually the strongest candidates
Internal email, Slack or Teams threads about how work gets doneThe companyLicensable subject to employee notices and redaction
Code, pull requests and design reviews for the company's own productThe companyLicensable if contractor contributions were assigned
Recorded customer callsShared, with consent rules attachedCase by case, depending on notices and consent

The guide to separating company data from customer-owned data works through the borderline cases in more depth.

How this plays out in situations M&A advisors see

SituationWhat to checkTypical outcome to confirm with counsel
SaaS client whose value sits in customer usage dataMSA use restriction, any aggregated-data clause, privacy policy historyProduct data usually out; engineering, support and go-to-market records may qualify
IT services or systems integration firmSOW ownership terms and client environment access rulesClient systems out; internal project methods and ticket histories may qualify
Contact center or BPO serving a client's customersClient contracts and call recording noticesMostly client data; often fails the rights test
Company that rewrote its privacy policy recentlyWhat the policy said when the records were collectedRecords collected under the old promise follow the old promise
Seller in a live sale processDiligence disclosures and purchase agreement covenantsA license is possible only with deal counsel involved

Businesses whose records mostly belong to their clients, such as many agencies and outsourcers, are a common reason an introduction stops at the rights review. The SaaS sale guide and the IT consulting sale guide show where the licensable records tend to sit in those two business models.

Disclosure and consent good practice

  • Map each record type to the contracts that govern it before anyone discusses price or scope.
  • Never rely on a quiet change to the terms of service to create a training right after the fact.
  • Get written customer consent for any customer content that stays in scope, or leave it out.
  • Agree de-identification and redaction rules with the company before any preparation work starts.
  • Keep the advisor's role to the introduction itself; a referral partner never exports, uploads or describes confidential records.

Questions to ask counsel before a license is scoped

  1. Which contracts define customer data broadly enough to capture the records we want to license?
  2. Does any customer contract, privacy policy or marketing page promise that data will not be used for AI or model training?
  3. Did contractors or agencies create material we plan to include, and do we hold written assignments for it?
  4. Which records contain personal information about California residents or other consumers, and what notices covered their collection?
  5. What redaction or de-identification standard should apply to internal records that quote customers?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Next step

Run the client through the company fit checker and compare the result with the who qualifies baseline. If the company's own records look deep and its rights are clean, register as a partner so you can submit the company once the owner agrees. Advisors weighing the program as a whole can start with how referrals work for M&A advisors.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does de-identifying customer data make it available for AI training?

Not on its own. De-identification reduces privacy risk, but a confidentiality clause or use restriction in the MSA can still forbid using the data for anything other than delivering the services, whether or not individuals can be identified. The contract question and the privacy question have to be answered separately, and either one can block a license.

Can a company change its terms of service now so it can train AI on customer data?

It can update its terms going forward, but FTC staff have warned that adopting more permissive data practices through a quiet, retroactive change can be unfair or deceptive. Records collected under an earlier promise generally follow that earlier promise. Any change should be prospective, clearly communicated and reviewed by counsel before anyone relies on it.

Are support tickets customer data or company data?

Usually both. The customer's attachments and the personal details they share belong to the customer or are protected, while the agent's diagnosis, escalation path and resolution notes reflect the company's own work. Many ticket histories can become licensable once the company agrees redaction rules that remove customer identities and content it does not own, but the contracts behind each queue decide it.

Should an M&A advisor read the client's customer contracts before making an introduction?

No. The advisor's job is to make the introduction and share basic fit information. The company and its counsel review contracts during qualification, and SourceX's rights review asks the same questions. An advisor can help by asking the owner, in general terms, whether customer contracts restrict data use, which is enough to decide whether an introduction is worth making.

Will a buyer of the company care whether customer data was licensed?

It should be expected. Diligence questionnaires can ask what data a target has shared and on what terms, and a license that used customer data without permission can surface as a breach of contract or a privacy problem. Licensing only the company's own records under a signed agreement, and disclosing that license during a sale, keeps the issue manageable.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment