Resources
A training-rights clause governs whether a vendor may train AI models on your data. Here's how to find, read, and monitor it across your vendors.
Published 2026-07-21
A training-rights clause is the language in a vendor's terms, privacy policy, or DPA that governs whether the vendor — or its AI subprocessors — may train machine-learning models on the data you submit. In the AI era it is one of the highest-signal clauses in any vendor agreement.
Before generative AI, "how a vendor uses your data" was mostly about analytics and product improvement. Now it can mean your data becoming training input for a model whose outputs you cannot control or recall. A permissive training-rights clause can turn confidential inputs into a permanent contribution to someone else's model.
Look for whether training is on by default or opt-in, whether it applies to customer content or only aggregated data, whether it extends to subprocessors, and whether enterprise plans carve it out. The same vendor often treats free, pro, and enterprise tiers differently.
A training-rights posture is not static — vendors add AI features and revise these terms frequently. Tracking it once is not enough; you need to know when it changes. Driftline extracts each vendor's training-rights posture from their live documents and alerts you when it shifts, so "who can train on our data" is a question you can answer at any moment, not reconstruct during an incident.
Send us your vendor list and we'll map — free, within 48 hours — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates.