Is it legal to license business data to AI developers in the US?

Licensing business data to AI developers can be lawful in the US, but it depends on three things: whether the company owns the records, whether its contracts and privacy promises allow the use, and whether privacy or sector laws such as the CCPA, HIPAA or GLBA apply. Rights review and de-identification come before any delivery.

The short answer

It can be, and whether it is depends on the records rather than the idea. A data license is a contract: the company grants an AI developer permission to use a defined set of records on agreed terms. Three layers decide whether a particular company may grant that permission for a particular dataset: who owns the records, what its contracts and privacy promises allow, and which privacy or sector laws apply to what the records contain.

Records that employees created in the ordinary course of business, about business activity, with personal details removed, are the most straightforward case. Records held for clients, consumer personal data, patient information and call recordings need more work, and some cannot be licensed at all.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Layer one: does the company own the records?

For staff work, generally yes; for contractors, not automatically. Under US copyright law, work an employee prepares within the scope of employment is a work made for hire, and the employer is treated as its author and owner, as the Copyright Office explains in Circular 30. Commissioned work from contractors counts as made for hire only if it falls into one of the categories listed in 17 U.S.C. section 101 and both parties signed a written agreement saying so; otherwise ownership turns on any written assignment.

In practice:

  • Internal email, reports, SOPs, tickets and code written by employees are the easiest to establish.
  • Deliverables from freelancers, contractors and agencies need their contracts checked for assignment language.
  • Third-party material in your systems, such as purchased research, vendor manuals or a client's own files, is not yours to license.

Layer two: what do contracts and privacy promises allow?

Ownership is not enough if the company promised not to use material this way. Review client contracts, NDAs and data processing agreements, which often limit how client information may be used or disclosed, and check the vendor terms for the systems you would export from.

Privacy promises matter too. FTC staff wrote in January 2024 that promises not to use customer data for undisclosed purposes, such as training models, are enforceable, and in February 2024 that adopting more permissive data practices, such as using consumers' data for AI training, while telling consumers only through a quiet, retroactive change to terms of service or a privacy policy could be unfair or deceptive. Both are staff posts, not rules, but they show how a regulator reads the question.

Layer three: which privacy and sector laws apply?

That depends on whose information sits inside the records. The table covers common situations.

SituationWhat to checkTypical outcome to confirm with counsel
Staff-written email, documents and tickets about business activityEmployment and contractor agreements; names and personal details in the textLicensable after agreed redaction of personal details
Records you hold for clients as an agency, MSP or outsourcerClient contracts and written consentExcluded unless the clients agree
Personal information of California consumersWhether the CCPA applies to the company, and consumers' rights to know, delete and opt out of the sale or sharing of their informationDe-identify or exclude consumer data
Patient or health plan informationHIPAA status and the de-identification standard, either Expert Determination or Safe Harbor removal of 18 identifiers, described in HHS guidanceOnly properly de-identified or authorized data; often excluded
Customer financial information at a lender, broker or finance companyThe Gramm-Leach-Bliley Act privacy notices and opt-out rights before sharing with certain nonaffiliated third partiesExclude or de-identify customer-level data
Recorded sales or support callsFederal law allows recording by a party to the call, or with one party's prior consent, under 18 U.S.C. section 2511(2)(d); California requires all parties' consent for confidential communications under Penal Code section 632Licensable only where the required notices and consents were in place, state by state
Personal data of people in the EUWhether the GDPR reaches the company because it offers goods or services to, or monitors the behavior of, people in the EUAnonymize or exclude EU personal data

Other states have their own privacy and recording laws, and they differ in detail, so counsel should check each state where the company has customers or staff.

How do rights review and de-identification happen before delivery?

In a SourceX license the legal questions are settled before any data moves:

  1. Qualification. SourceX asks about size, history, data breadth and rights, and confirms an authorized sponsor: the owner, CEO, CFO or another authorized representative.
  2. Inventory. The company lists each system, the years it covers and what it contains, which shows where client, consumer, health or financial information sits.
  3. Scope and redaction rules. De-identification and redaction requirements are agreed with the company before any work begins. Systems or fields that cannot be cleared stay out.
  4. Agreement. Price and terms are agreed and signed. The company keeps ownership; the data is licensed, not sold.
  5. Delivery. Data is prepared and delivered only after the executed agreement and the company's authorization.

Referral partners take no part in this. They make the introduction and never export, upload or describe confidential records. For how the commercial side of these deals compares with publisher licensing, see enterprise AI data licensing deals.

Disclosure and consent good practice

  • Read the privacy policy and customer terms that applied when the data was collected before scoping anything.
  • Do not rewrite policies or terms retroactively to fit a license.
  • Leave out any system holding client records unless those clients consent in writing.
  • Check recording notices for each state where callers and staff are located.
  • Keep a written record of what was excluded and why; a future acquirer or auditor may ask.

Advisors walking a client through these steps will find more in helping clients license business data to AI labs.

Questions to ask your counsel

  • Do our employment and contractor agreements give the company ownership of the work product we plan to license?
  • Do any client contracts, NDAs or data processing agreements restrict this use?
  • What did our privacy policy and notices promise when the data was collected?
  • Do the CCPA, HIPAA, GLBA or the GDPR apply to any part of the dataset, and which de-identification standard should we use?
  • Were call recordings made with the consents our states require?
  • Does an exclusive AI-training license conflict with any license or commitment we already have?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Next step

Before engaging a lawyer, check whether the company fits at all with the 10-question self-check or the company fit checker, and read how it works to see where rights review sits. Companies can apply directly at sourcex.si/apply. Advisors who want to introduce a client should register as a partner.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Is licensing data different from selling it under privacy law?

Commercially, yes: a license grants defined rights for an agreed purpose and term, and the company keeps ownership. Legally, privacy laws can define selling or sharing personal information broadly, so a license that includes personal information may still count as a sale or sharing under a given law. That is one reason personal details are redacted or excluded before delivery. Ask counsel how your state's law applies.

Do we need employees' consent to license internal email?

Not necessarily for ownership, since work employees create in their jobs generally belongs to the company. Notice and consent questions still arise because email names employees, customers and other individuals. In a SourceX license, redaction of personal details is agreed before any work begins, and counsel should check what your employee monitoring notices said. Rules differ by state, so confirm the approach.

Our customers are businesses, not consumers. Does privacy law still matter?

Yes. Records about business customers still name individual people, with email addresses, phone numbers and sometimes personal details inside message threads. Client contracts and NDAs often restrict how client information may be used, and for a B2B company they can matter as much as privacy law. Expect personal details to be redacted and client agreements reviewed before a dataset is scoped.

Who is responsible if a problem surfaces after delivery?

That is set by the signed license agreement, including its warranties, indemnities and limits on liability. Because the company makes promises about its rights to the data, counsel should review those clauses against the inventory and the agreed redaction rules before signing. Nothing is binding until the company agrees the price and terms and signs.

Can a company that has shut down still license its records legally?

Possibly. Wound-down and acquired companies can qualify if the records still exist and someone with authority can approve the license. If a court, trustee or assignee for the benefit of creditors controls the assets, that party must be involved, and privacy promises made to customers still matter. Counsel familiar with the proceeding should confirm what approvals are needed.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment