Research Note · AI · Contracts

AI data rights in enterprise contracts: what vendors won't tell you.

AI vendors retain the right to train on your data by default. Your proprietary inputs, customer records and business logic become fuel for foundational models that are then licensed to your competitors. This note sets out the clauses that matter, how the major vendors actually behave, and the language that secures ownership, deletion and residency in writing.

By James Hill-WoodUpdated Mar 202512 min readAI procurement cluster
Bottom line

In our review of 47 enterprise AI contracts, only 12% explicitly prohibited training on customer data. The default position transfers strategic advantage to the vendor — and to whoever licenses its next model. Treat training use, output ownership, deletion and residency as deal-blocking terms, negotiate them with legal not procurement, and get every guarantee in writing before signature.

01 Key findings

  1. Training rights default to the vendor. Of 47 enterprise contracts reviewed, only 12% contained explicit prohibitions on training use. The other 88% either permitted training by default or used ambiguous language the vendor read as consent.

  2. The enterprise tier is a different contract, not a setting. OpenAI's default terms allow training; its enterprise agreement prohibits it — at a 3–4x pricing premium. Many buyers sign commercial terms without realising the difference.

  3. Product name is not data policy. Microsoft Azure OpenAI carries non-training guarantees; Copilot products are built to train on enterprise usage patterns. Enterprises routinely confuse the two.

  4. "Deletion" rarely means destruction. Vendors retain backups, logs and aggregated analytics for months to years, and often anonymise rather than destroy. Without certified deletion you cannot prove compliance.

  5. Sub-processor chains carry your liability. Under GDPR you answer for every downstream processor. If the contract does not restrict sub-processors, your data flows through parties you never approved — and the fines still land on you.

02 The four data rights

Four categories drive almost every AI data dispute. Each needs distinct contract language. The gap between the vendor's default term and the term you should secure is where the risk — and the negotiation — lives.

Data rightVendor default (weak)Term to secure (strong)
Input trainingInputs usable to train and improve models; opt-out buried or absentExplicit non-training on all inputs, including research and benchmarking
Output ownershipVendor claims ownership or broad licence to outputsCustomer owns outputs; vendor indemnifies against third-party IP claims
Retention & deletionRetained indefinitely; "deletion" means deactivation or anonymisationFixed deletion timeline with signed destruction certificate
Sub-processorsVendor adds sub-processors at will; no approval or listNamed list, approval rights, back-to-back terms, vendor liability

03 How the vendors compare

Leading vendors sit in very different places on data protection — and the same brand can offer opposite terms across products. Verify the specific agreement and product edition, not the marketing.

Vendor / productDefault trainingEnterprise protectionWatch-out
OpenAI EnterpriseCommercial terms allow trainingEnterprise tier prohibits training explicitlyMust select enterprise agreement; 3–4x premium
Google Workspace / Vertex AIWorkspace docs not trained by defaultVertex restrictions exist but need custom contractsDefault position has shifted year to year; review annually
Microsoft Azure OpenAINon-training by defaultGuarantees equivalent to OpenAI EnterpriseNot the same as Copilot — confirm which product
Microsoft CopilotTrains on enterprise usage patternsLimited; built around Microsoft training needsFrequently mistaken for Azure OpenAI terms
Anthropic Claude EnterpriseProhibits training on enterprise dataStandard enterprise contract; no special askAvailability still narrower than OpenAI or Microsoft

04 Traps vendors won't flag

The costly gaps are rarely in the headline clause. They sit in defaults, product editions and sub-processor chains that vendors have no incentive to volunteer.

Trap — the commercial default

Signing the standard tier by accident. Enterprise data protection usually lives in a separate agreement, not a toggle. Default OpenAI terms permit training; the protective version costs a 3–4x premium and must be explicitly selected. Confirm you are on the enterprise contract before integrating anything.

Trap — residency loopholes

"EU residency" that isn't. A vendor can promise data stays in the EU while storing encryption keys or running security processing in the US. Require both contractual and technical controls, and specify where processing, storage and backups each occur.

Trap — the sub-processor chain

Approved vendor, unapproved chain. Your provider relies on cloud infrastructure and processing partners, each with its own data rights. Without approval rights and back-to-back terms, your data reaches parties you never vetted — and under GDPR the liability is yours, not theirs.

05 Retention & deletion reality

Most enterprises assume deleting data from an AI system destroys it. It rarely does. Typical vendor retention runs far longer than the active record — and each layer is separate exposure to breach, audit and secondary use.

Aggregated analytics
Indefinite
Transaction logs
1–2 yrs
Backups
30–90 days
Deletion target
30 days
Require certified destruction

Contract for specific deletion dates across production, backups, archives and disaster recovery; a signed destruction certificate within 45 days; and named carve-outs for anything retained. Without cryptographic proof, "data is deleted" often just means moved to an archive — and you cannot evidence compliance with your own customer or regulatory obligations.

06 The negotiation checklist

Vendors do not volunteer strong protections. Work these four moves in order, and treat any one as deal-blocking if unresolved.

Step 01

Pull the real documents

Request the standard enterprise agreement, AI addendum and data processing terms up front. Understand what is on offer before negotiation opens, then map every gap against your required provisions.

Step 02

Engage early and senior

Data rights are a core contract element, not a procurement detail. Negotiate with the vendor's legal team and make clear the deal does not close until training, deletion, residency and sub-processor terms are resolved.

Step 03

Use precedent and scale

If a competitor accepted non-training language, so can this vendor — say so. Multi-year, multi-product commitments increase leverage; smaller buyers should negotiate through a partner who carries it.

Step 04

Build escape hatches

If the vendor won't commit outright, negotiate an out: the right to audit data use, to terminate if training begins, and to renegotiate annually. Something enforceable beats a silent default.

07 Our recommendation

Audit first
Existing contracts

Review every live AI agreement now against the four data rights. In one Fortune 500 review, two of three vendors held undisclosed training rights — six months of renegotiation and $2.4M to unwind.

Demand the clauses
New contracts

Make non-training, output ownership, certified deletion, residency, sub-processor control and breach notice non-negotiable. Confirm the enterprise edition, not the commercial default, and get technical plus contractual controls.

Cover the regulation
GDPR & EU AI Act

Attach a GDPR-compliant DPA, prohibit personal-data training, and document training-data sources for EU AI Act duties. A missing DPA cost one European firm €800K in remediation after a routine audit.

08 Sequencing the negotiation

How you stage the conversation decides how much you win. Data terms are cheapest to secure before the vendor believes the deal is already closed.

Terms before signature Recommended

Raise training, deletion, residency and sub-processor terms while award is still live and alternatives are credible. That tension is what moves a vendor off its standard paper and onto enterprise protection.

Retrofit after signing Weaker

Discovering the gap post-signature means months of renegotiation, back-fees and, if training already ran, no clean remedy. Leverage collapses the moment the vendor is embedded.

Harden your AI contracts before you sign

Our AI procurement practice reviews vendor paper and negotiates training, deletion and residency terms on your behalf.

AI procurement advisory →

The Licensing Edge

Weekly AI and licensing intelligence for enterprise IT leaders. 3,000+ subscribers.