security

Training Data Opt-Out

A training data opt-out is the commitment that a vendor will not use a customer's inputs and outputs to train or fine-tune its models. It has become the single most asked question in AI tool procurement, because the data a team puts into an AI product is rarely trivial: it is source code, customer records, contracts, unreleased strategy, support transcripts. The distinction that matters most is between consumer and business plans of the same product. Many vendors train on data from free and individual tiers by default while excluding business, team and API tiers contractually — same interface, same model, entirely different data commitment. That difference is the reason shadow AI is a governance problem rather than a preference: an employee using a personal account is on the training-enabled side of the line whether or not anyone intended it. Read for four things rather than accepting a headline. Scope: does the exclusion cover both prompts and generated outputs, and does it extend to files, attachments and connected data sources? Default: is it off by default on your plan, or a toggle somebody must find and set — and can an individual user re-enable it? Retention: opting out of training is not the same as not storing your data; vendors typically retain inputs for a period for abuse monitoring and support, and zero-retention arrangements are usually a separate, negotiated commitment. And subprocessors: if the vendor routes requests to a third-party model provider, the opt-out has to hold at that layer too, which is where it is most often assumed rather than verified. Get the answer in the contract or DPA rather than from a help-centre article, because a documentation page can change without notice and a contract term cannot.

Related terms

More Security & Compliance terms