Vendor drift
Classified material changes to GitLab’s public trust documents, from continuous monitoring.
Data as of 2026-09-10 — refreshed on a rolling bake, not live. · gitlab.com
Prohibits training on customer data
as of 2026-08-20
medium · Terms changed · 2026-09-08 · ai_disclosure
GitLab added a new "AI Ethics Principles for Product Development" page outlining commitments to avoid unfair bias, safeguard against security risks, prevent harmful uses, consider data use, and maintain accountability. This is a new policy disclosure rather than a change to training rights, retention, or subprocessors.
high · Terms changed · 2026-07-01 · ai_disclosure
GitLab published AI Functionality Terms V3 (marked deprecated as of March 31, 2025) introducing significant new restrictions and liability frameworks for AI features. Key changes include: (1) explicit restrictions on using AI Functionality to train competing models (Section 3.3), (2) prohibition on reverse engineering GitLab or customer-integrated models (Section 3.4), (3) limited indemnification for Customer Integrated Models ($1,000 cap), and (4) clarified that Output Claims are covered under the Subscription Agreement's indemnification only for GitLab Integrated Models, with specific carve-outs for modified output or non-compliant input.
high · AI feature launched · 2026-07-01 · ai_disclosure
GitLab published comprehensive AI Functionality Terms (v1) establishing governance for AI-powered features that process customer content as Input and generate Output (code and natural language). The terms permit transmission of Personal Data to GitLab and third-party AI Service Providers listed at about.gitlab.com/privacy/subprocessors/, with restrictions on reverse engineering and competitive model training, but explicitly disclaim liability for unreliable or inaccurate AI-generated output.
high · AI feature launched · 2025-11-13 · ai_disclosure
GitLab has formally disclosed and launched "GitLab Duo AI Terms" (formerly "AI Functionality Terms"), establishing comprehensive terms for AI-powered features that process customer content as Input to generate Output. The terms explicitly permit transmission of Personal Data to GitLab as part of Input to AI Functionality powered by GitLab Models, with sub-processors listed separately, creating a new processing path for customer data through AI systems.
high · AI feature launched · 2025-11-13 · ai_disclosure
GitLab published comprehensive AI Functionality Terms V4 governing customer access to AI-powered features that process customer content as Input to generate Output. The terms establish that GitLab Models are hosted by GitLab or third-party sub-processors, customer data may be transmitted as part of Input, and Output is treated as additional Customer Content, creating a new processing path for customer data through AI systems.
high · AI feature launched · 2024-09-04 · ai_disclosure
GitLab published comprehensive AI Functionality Terms (marked deprecated as of 2023-10-31 but now appearing in current documentation) governing customer use of AI-powered features that process customer content as Input and generate Output. The terms disclose that AI Functionality may be powered by third-party AI Service Providers (listed in docs.gitlab.com) and that customer data may be transmitted to GitLab and subprocessors for AI processing, with restrictions on using AI output to train competing models.
high · AI feature launched · 2024-09-04 · ai_disclosure
GitLab published comprehensive AI Functionality Terms V2 governing new AI-powered features that process customer content (Input) and generate output including code and natural language. The terms establish that AI Functionality may be powered by third-party AI Service Providers and permit GitLab to use sub-processors listed at about.gitlab.com/privacy/subprocessors/, with customer content classified as "Customer Content" under the Subscription Agreement.
high · AI feature launched · 2025-03-31 · ai_disclosure
GitLab published AI Functionality Terms V3 (effective March 31, 2025) establishing comprehensive terms for AI-powered features that process customer content as Input and generate Output. The terms define GitLab Integrated Models (hosted by GitLab or third-party sub-processors) and Customer Integrated Models, with explicit provisions allowing transmission of Personal Data to GitLab as part of Input processing, subject to Data Processing Addendum obligations.
Paste your vendor list, confirm your email, and our engine builds your report automatically — which vendors add AI subprocessors or reserve the right to train on your data, and where your nth-party exposure concentrates. Free, delivered during your working day.