
Key Takeaways
- A vendor’s promise not to train AI models on customer data addresses one concern but does not explain the full lifecycle of information submitted to the service.
- Companies should understand what data an AI tool receives, how long it is retained, who can access it, and when it is deleted before approving its use.
- Third-party providers, contractors, cloud services, and other downstream organizations can create additional data-handling considerations that companies should review.
- Sensitive or regulated information may require stronger contractual protections, security measures, and agreements tailored to the type of data involved.
- Clear contract terms and internal usage rules can give employees practical boundaries for using AI tools while reducing uncertainty around data privacy.
James Sheets is a Des Moines, Iowa-based attorney, educator, and consultant with more than twenty years of experience across business, higher education, and legal studies. As an attorney and expat educator, James Sheets has taught business systems, international law, and business law at universities in the United States and abroad, including postings in Bosnia, China, and Riyadh, and his recent research has focused on data privacy, comparative legal systems, and international law. Earlier in his career, James Sheets Iowa served as an attorney associate handling commercial contracts and later worked in corporate compliance and global distribution for a major manufacturing company. He has advised executives and business managers on warranty clauses, escalation clauses, joint venture agreements, and intellectual property rights.
That same compliance-minded perspective informs how companies should approach a vendor’s promise not to train its AI models on their data.

Companies often hear a promise when they review an AI tool: the vendor will not train its model on the company’s data. That promise matters because it limits one possible use of the information. Before approval, the company should still understand what data the service receives, how long it keeps that data, who may access it, and when it is deleted.
Training means using data through machine-learning techniques to improve an AI system’s performance. A no-training promise means the vendor says it will not use customer data to train or update the model. An AI model is a core component of an AI system that makes inferences from inputs to produce outputs such as content, predictions, recommendations, or decisions.
First, check the data the company plans to enter. A draft marketing sentence creates a different concern from customer records, health information, pharmacy-related records, financial or billing details, or other personal data. Before approval, the company should identify which data fields the tool will receive and whether the task requires each field.
Next, the company should ask what the vendor keeps. Retention concerns how long customer information remains with the service and the purposes for which it is kept. A vendor may avoid model training but still retain prompts, uploaded files, outputs, account information, or other operational records.
The review should separate short-term records from data kept for permitted purposes.
Human access involves people inside the vendor’s organization. Vendor employees, contractors, or support teams may need limited access for troubleshooting, security, or customer service. The vendor should define that access before approval.
The company should know who may view submitted data, why, and how the vendor limits authorized access.
Third-party access involves organizations outside the vendor. Many services rely on cloud hosting, analytics support, IT support, cross-border processors where applicable, or other subcontractors. The company should check whether the vendor identifies those parties and explains each role.
The review should also ask whether the vendor handles data only under the customer’s instructions or makes its own decisions about use.
Regulated data raises the review standard. If the tool handles protected health information, pharmacy-related data, financial information, consumer data, or other sensitive records, standard software terms may not address contract, security, and use limits.
A health-data vendor may need a Business Associate Agreement, which limits how a vendor may use protected health information and requires safeguards.
Outputs require separate company review. Staff may use AI-generated content, predictions, recommendations, or other outputs in later business activity or decision-making.
A no-training commitment does not by itself resolve whether generated outputs may expose sensitive information or create other risks. The company should therefore decide how staff will review, monitor, and use those outputs when problems are identified.
Contract terms turn privacy expectations into operating rules. A no-training clause should not stand alone because retention, deletion, access, third-party use, security, and incident reporting address different parts of the data-handling relationship.
Depending on the service and applicable rules, the agreement may need to address permitted uses, retention and deletion, access controls, downstream providers, incident reporting, evaluation rights, and return or destruction of data at termination.
Those terms can help the company test whether the vendor’s no-training promise matches its broader data practices.
A careful review gives teams usable boundaries before daily use begins. Employees know which information they may submit, when they should escalate sensitive records, and which vendor practices the agreement allows.
That clarity lets the company use the tool with less guesswork when privacy questions arise.

FAQs
What does an AI vendor’s no-training promise mean?
A no-training promise generally means the vendor agrees not to use customer data to train or update its AI models. However, the commitment does not necessarily address retention, human access, third-party providers, security, deletion, or other ways data may be handled.
What should companies ask about before submitting data to an AI tool?
Companies should identify what information the service will receive and determine whether every data field is necessary for the task. They should also ask how long the vendor retains prompts, files, outputs, account information, and other operational records.
Why does third-party access matter when reviewing an AI vendor?
AI services may rely on cloud hosts, analytics providers, IT companies, or other subcontractors that can become part of the data-handling chain. Companies should understand which third parties may access their information, what each party does, and whether the vendor controls those uses.
How should companies handle sensitive or regulated data in AI tools?
Sensitive information may require additional contractual, security, and compliance protections beyond standard software terms. Depending on the information involved, agreements such as a Business Associate Agreement may also be necessary to establish appropriate restrictions and safeguards.
What should an AI data agreement include?
A comprehensive agreement may address permitted data uses, retention and deletion, access controls, downstream providers, security, incident reporting, evaluation rights, and the return or destruction of information when the relationship ends. These provisions can help ensure that a no-training commitment fits within a broader set of practical data-handling rules.
About James Sheets
James Sheets is a Des Moines, Iowa-based attorney, educator, and consultant with more than twenty years of experience in business, higher education, and legal studies. He has served as in-house counsel for major U.S. corporations, including Rite Aid, Acoustic LP, and Genuine Parts Company, drafting agreements involving data privacy, SaaS platforms, and regulatory compliance. Licensed in several jurisdictions, James Sheets Iowa has also taught international and business law at universities in the United States, Bosnia, China, and Saudi Arabia.

