AI Tools at Work: What Their Terms Let Them Do With Your Inputs
Check four things: whether your inputs can be used to train the provider's models, how long inputs and outputs are retained, who can access them, and who owns outputs. Business and enterprise plans often exclude training and offer stronger confidentiality than consumer plans. Choose the right plan and set internal rules.
Employees increasingly use AI assistants to draft emails, summarize documents, write code and analyze data. That often means pasting company information, customer data or confidential documents into third-party tools. What the provider may do with that information depends on its terms, and those terms differ widely between consumer and business versions of the same product. This guide explains what to check before your team uses AI tools with company data, and how our guide on SaaS vendors training AI applies to AI-first products.
Have the contract in front of you? You can check your software contract for this clause in a few minutes.
Key takeaways
- Check whether inputs are used for training; business plans often exclude it.
- Review retention, access and subprocessor terms.
- Output ownership in the contract does not guarantee copyright protection.
- Set internal rules on approved tools and what data may be entered.
Training on your inputs
The most important question is whether the provider can use your inputs and outputs to train or improve its models. Consumer plans often allow this by default, sometimes with an opt-out. Business, team and enterprise plans commonly exclude customer data from training by default. Read the specific plan's terms, not general marketing statements.
Retention
Check how long inputs and outputs are stored, whether you can delete them, and whether the provider keeps logs for abuse monitoring or legal reasons. Some business plans offer shorter retention or zero-retention options for certain uses.
Confidentiality and access
- Is your data treated as confidential information under the terms?
- Can provider staff access conversations, and under what conditions?
- Are subprocessors listed, and where is data processed?
- Is there a data processing addendum for personal data?
Ownership of outputs
Many AI terms say the user owns outputs, subject to the provider's rights and third-party rights. But copyright protection for purely AI-generated material is limited under current US Copyright Office guidance, so ownership in the contract does not guarantee copyright protection. If outputs are important to your business, understand these limits and keep human authorship in key work.
Personal and regulated data
Pasting personal data, health information or financial data into AI tools can create obligations under privacy laws, industry rules and your customer contracts. Some customer contracts prohibit sharing their data with third-party processors without consent. Check before using AI tools with such data.
Indemnities and warranties
Some enterprise AI terms offer indemnities against copyright claims arising from outputs, subject to conditions such as using the service as intended and not disabling safety features. Consumer terms rarely do. Warranties about accuracy are usually disclaimed; outputs can be wrong, so human review is necessary.
Set internal rules
- Approve specific tools and plans for work use.
- Say what data may and may not be entered.
- Require human review of outputs used externally.
- Disable training where the setting exists.
- Train staff on the rules.
A worked example
A sales team uses a free AI chatbot to summarize customer contracts. The consumer terms allow inputs to be used to improve the service. The company moves the team to the business plan, which excludes training and includes a data processing addendum, and adopts a rule that customer contracts may only be entered into approved tools.
Sample internal policy wording
"Employees may use only approved AI tools on company-approved plans for work purposes. Do not enter customer personal data, confidential customer documents or trade secrets into any tool not approved for that data. Review all AI outputs for accuracy before external use."
Common mistakes
- Assuming business and consumer plans have the same terms.
- Letting staff use personal accounts for work.
- Entering customer data in breach of customer contracts.
- Relying on outputs without review.
- Assuming AI outputs are fully protected by copyright.
Quick checklist
- Are inputs used for training?
- How long is data retained?
- Is there a data processing addendum?
- Who owns outputs, and are there indemnities?
- Do customer contracts restrict sharing data?
- Is there an internal use policy?
Key terms explained
These terms appear in AI tool terms.
- Inputs: the prompts, files and data you provide.
- Outputs: the content the tool generates.
- Model training: using data to improve the AI model.
- Retention: how long data is stored.
- Subprocessor: a third party that processes data for the provider.
Consumer versus business plans
The same AI product may have very different terms depending on the plan. Consumer terms are often written for individuals and may allow broader data use, including training by default with an opt-out. Business, team and enterprise terms usually include commitments not to train on customer data, a data processing addendum, admin controls, audit logs and stronger confidentiality. They cost more, but for company data they are usually the right choice.
API use versus chat apps
Many providers treat data sent through their API differently from data entered into their consumer chat apps. API terms for business customers often exclude training on inputs by default and may limit retention. If your company builds tools on top of an AI provider, check the API terms and any enterprise agreement, not the consumer app's terms.
AI features inside existing software
Many SaaS products you already use now include AI features. These may be governed by new terms or addendums, and may use third-party AI providers as subprocessors. Check whether your existing agreement covers the AI features, whether your data is sent to other providers, and whether you can switch the features off. Vendors sometimes update terms to allow AI use through continued-use clauses; our guide on continued use as acceptance explains how that works.
Vendor due diligence questions
- Do you train on our inputs or outputs, on any plan we use?
- How long do you keep our data, and can we delete it?
- Which subprocessors process our data, and where?
- Do you offer a data processing addendum and admin controls?
- Do you offer an indemnity for output-related IP claims?
- Can we audit or review your security practices?
Keep up with changes
AI providers update their terms frequently. Assign someone to review terms for approved tools periodically, and to check announcements about training, retention and new features.
Sensitive information to keep out
Unless a tool is approved for it, do not enter passwords, API keys, source code under restrictive licences, unreleased financial results, customer personal data, health information or documents covered by customer confidentiality obligations. When in doubt, remove identifying details first.
A second example: code assistants
A development team adopts an AI coding assistant. The business plan excludes training on customer code and offers an indemnity for output-related copyright claims, but only if a filter blocking suggestions matching public code is left on. The team leaves the filter on, keeps human code review mandatory and records which tool generated significant code. When a customer asks about AI use in their project, the team can explain its controls clearly. Customer contracts increasingly ask about AI use, so knowing your tools' terms helps with sales as well as risk.
Disclosure to customers
Some customer contracts require notice or consent before using AI tools or subprocessors on their data or deliverables. Check your customer agreements and update your subprocessor lists where required.
Review outputs before relying on them
AI outputs can contain errors, invented facts or outdated information. Treat them as drafts. For contracts, legal, financial or customer-facing material, require a qualified person to check the output before it is used, and keep a record of who approved it.
Review AI terms before rollout
AI tool terms change often and differ by plan. Upload the terms or your enterprise agreement to see how inputs, training, retention and output ownership are handled.
Check what your AI tool's terms allow
Upload your AI tool terms and we will flag training, retention and output terms, plus every other risky clause, in plain English, tuned to your state, with a downloadable report and redline.
Frequently asked questions
Do AI tools train on my company's data?
It depends on the plan and terms. Consumer plans often allow it; business plans often exclude it.
Who owns AI-generated outputs?
Terms usually assign them to the user, but copyright protection for purely AI-generated content is limited.
Can employees put customer data into AI tools?
Only if privacy law, customer contracts and the tool's terms allow it. Set clear rules.
Related guides
- Who Owns Your Data in a SaaS Agreement? How to Read the Fine PrintA clear data-ownership clause is one of the most important things in any software contract. Here is how ownership, licenses, and what happens when you cancel actually work, and what to negotiate.
- How to Read a SaaS Contract Before You SignSaaS terms are some of the most one-sided contracts businesses sign. Here’s what to check first.
- Getting Your Data Out When You Cancel a SaaS ContractWhen a software subscription ends, access to your data can end with it. Here is how to check export rights, deletion timelines and formats before you cancel.
- My SaaS Vendor Was Breached. What Does the Contract Actually Cover?When a software vendor suffers a security breach involving your data, the contract decides notification, cooperation and compensation. Here is what to check.
- "Continued Use Is Acceptance": How Vendors Change Contract Terms on YouMany SaaS and online contracts let the vendor change the terms whenever they want, and your continued use is treated as agreement. Here is how the clause works and how to limit it.
- What Is a Data Processing Addendum (DPA), and Do You Need One?A DPA sets the rules for how a SaaS vendor handles the personal data you send it, required under GDPR and central to CCPA compliance. Here are the terms that actually protect you.
This guide is general information from ClauseAudit, not legal advice. Laws vary by state and change, consult a qualified attorney for your situation. Published 2026-05-01; last reviewed 2026-09-25.