Do AI vendors train on customer data? What professional firms should check
Short answer
A quick answer first, then the fuller context below.
AI vendors may train on customer data unless the contract, product settings and data processing terms clearly prevent it. Professional firms should check training use, retention, sub-processors, audit evidence and human review before client data enters any tool.
Detailed answer
The fuller context, trade-offs and practical steps behind the short answer.
Why customer-data training is the first question to ask
When a professional-services firm asks whether an AI vendor trains on customer data, it is really asking who controls client information after it leaves the firm. The answer affects confidentiality, data protection, professional duties, procurement risk and the evidence trail a partner or director may need if a client or regulator asks how the tool was approved.
The risk is not limited to public chatbots. It can appear in CRM assistants, document tools, transcription services, analytics platforms, case-management add-ons and finance workflow products. Some providers separate the model from the customer's data by default. Others use prompts, uploaded files, feedback, logs or derived examples to improve their systems unless the customer has an enterprise plan, an opt-out setting or negotiated terms.
The safest answer is written proof, not a verbal assurance
A firm should treat the vendor's answer as safe only when the contract, data processing agreement, security documentation and product configuration all say the same thing: client data is not used to train or tune models unless the firm has expressly agreed. A sales reply is useful, but it is not enough for regulated or confidential work.
For most professional firms, the practical position should be simple: no client-identifiable data goes into an AI tool until training use, retention, access, review and deletion are documented. If the vendor cannot explain these points clearly, keep the tool away from client files or restrict it to low-risk internal use.
Check AI vendor risk and efficiency evidence
What to check in the vendor terms
Start with the documents that would matter in an audit or dispute. The key wording usually sits in the data processing agreement, privacy notice, service terms, security white paper, enterprise controls page and product admin settings. Read them together because a strong privacy page can be weakened by broad product terms, feedback clauses or telemetry wording.
- Training use: Does the vendor use prompts, files, outputs, user feedback or logs to train, tune or evaluate models?
- Default setting: Is training use off by default for the plan you are buying, or does the firm need to opt out?
- Data scope: Does the promise cover uploaded files, pasted text, attachments, metadata and generated outputs?
- Retention: How long are prompts, files, logs and outputs stored, and can the firm shorten that period?
- Sub-processors: Which model providers, hosting providers and support teams may access the data?
- Deletion: Can the firm delete data from active systems and backups, and what evidence is available?
- Audit evidence: Can the vendor provide SOC reports, security attestations, data-flow diagrams or enterprise-control evidence?
Why this matters for professional-services firms
Legal, accountancy, consulting, insurance and regulated financial firms often hold confidential or sensitive client material. That material may include privileged instructions, board papers, payroll details, claims records, deal documents, vulnerable-customer information or special-category personal data. The issue is not whether AI is useful. The issue is whether the firm can prove it remained in control of the data while using it.
Partners, directors and senior managers should be able to show that the tool was assessed before use, that the approved use cases were narrow enough, and that human review remained in place for client-facing outputs. For financial services firms, this also connects to accountability, Consumer Duty, operational resilience and third-party risk. For legal and accountancy firms, it connects to confidentiality, professional judgement, quality review and file evidence.
Set operating rules for AI governance
A practical review process before staff use the tool
A workable review does not need to become a six-month procurement exercise. It does need a clear decision record. Create a short vendor-risk note that names the tool, the plan, the approved use cases, the data classes allowed, the data classes prohibited, the contractual basis, the admin settings, the reviewer and the date of approval.
Then set user-level controls. Tell staff which work can use the tool, which data must stay out, whether prompts can include client names, who checks outputs, and where the output should be stored on the matter or client file. If the tool is embedded in a platform staff already use, document where the AI feature appears so people do not accidentally move confidential data into an unapproved function.
The strongest control is usually a traffic-light policy:
- Green: Public, generic or already-approved internal material.
- Amber: Client-related material that needs redaction, an approved vendor and a named reviewer.
- Red: privileged, highly confidential, special-category or commercially sensitive material that must not enter the tool unless a senior owner has approved a specific exception.
Questions to ask before approving the vendor
Use these questions in procurement, security review or partner sign-off. They are deliberately plain English because the aim is to produce evidence that non-technical leaders can understand and own.
- Do you use customer prompts, files, outputs, feedback or logs to train or tune any model?
- If not, where is that commitment stated in the contract or data processing terms?
- Does the commitment apply to all features, integrations, support channels and product analytics?
- Can administrators disable training, retention or feedback sharing for every user?
- Which third parties process our data, and do any of them use it for model improvement?
- How can we export, delete and evidence deletion of our data?
- What audit records show who used the tool, what data was submitted and which output was produced?
Implement AI tools with the right controls
Conclusion
The right answer is not simply yes or no. The right answer is a documented control position: which data the vendor may process, whether it can be used for training, how that is prevented, who reviewed the evidence and what staff are allowed to do. If that record is missing, the firm should slow down before moving client data into the tool.
FAQs
Direct follow-up answers written for searchers, buyers and internal decision makers.
Can we use an AI tool if the vendor says it does not train on our data?
Yes, if the same commitment appears in the contract or data processing terms, the product settings match it, and the approved use case does not expose data the firm has prohibited.
Is an opt-out setting enough?
It can help, but it should be recorded with screenshots or admin evidence, checked after product updates and backed by contractual wording where client or regulated data is involved.
Should staff paste client documents into public AI tools?
Only if the firm has specifically approved that tool, plan, data type and use case. In most firms, public tools should be restricted to generic drafting, research framing or internal material unless stronger controls are in place.
Who should own the decision?
Ownership should sit with the business owner of the workflow, supported by IT, data protection and risk or compliance. A senior accountable person should sign off high-risk or client-data use cases.
Need help implementing this?
If this question points to a live process, policy or supplier decision, the next step is usually to turn the answer into a controlled plan. These services are the most relevant starting points.
AI governance consulting
Create policies, approval routes, ownership and controls that teams can actually use day to day.
AI governance consultingSecure AI implementation
Put privacy, supplier review, data boundaries, testing and staff guidance into the implementation plan from the start.
secure AI implementationAI workflow automation
Turn repeatable admin, client service and reporting work into controlled workflows with clear human review points.
AI workflow automation support