Guides

    Keeping client material out of training data

    Enterprise clients now require brand assets never enter a training set, and the duty flows through you to every tool. The clause, plus the audit behind it.

    Versely Team9 min read

    The training-data exclusion is the easiest clause in an AI addendum to agree to and the hardest one to honour. It usually arrives from the client's side, already drafted, in a paragraph that reads as unremarkable: Supplier shall not use Client Materials to train, fine-tune or otherwise improve any machine learning model, and shall ensure its subcontractors and vendors do not do so.

    Signing it takes ten seconds. Complying with it means knowing, for every tool that ever touches a client logo, script, product photograph, customer name or voice recording, what that tool does with the upload. Most studios cannot answer that for their own stack, which is not negligence so much as the natural result of a stack that grew one browser tab at a time.

    This is the audit that turns the clause from a promise into a fact, plus the drafting that keeps the promise inside what you can actually verify. Not legal advice; the drafting is a starting point for counsel.

    Why the duty lands on you specifically

    Large clients rarely invent this requirement. They inherit it. Their own customer agreements, their data processing terms, and increasingly their procurement policy carry a commitment about where brand and customer material may go, and that commitment flows down to every supplier in the chain. Your addendum is one link in it.

    Which means two things. The clause is not negotiable in substance, only in scope, and pushing back on the principle reads as a red flag rather than a reasonable position. And the client's compliance team may well ask you to name the tools, because a downstream promise they cannot inspect is worth very little to them. Buyers who already treat training-data provenance as a purchasing criterion will ask this on the first call, not at contract stage.

    The failure mode this prevents is specific and boring. A product photograph under embargo gets uploaded to a background-removal tool on a consumer plan. A customer testimonial transcript goes through whichever web transcriber came up first in search. A pre-launch campaign script gets pasted into a general assistant for a rewrite. None of those feel like data transfers at the time. All of them are.

    Three promises people conflate

    Vendor pages blur these constantly, and the clause you sign should not.

    We do not train on your data. Your inputs are not used to update model weights. This is the promise the clause is about.

    We do not retain your data. Inputs are deleted after some window. Different promise, and a vendor can honestly make the first while retaining content for thirty days, or make the second while a separate abuse-review pipeline sees the content first.

    Your data is not shared with third parties. Says nothing about training or retention, and often coexists with a subprocessor list that includes the model provider doing the actual inference.

    A fourth question sits underneath all of them: human review. Many platforms route a sample of content to human reviewers for safety or quality purposes, which is neither training nor sharing but is very much something a client under embargo needs to know about.

    When you audit, answer all four separately for each tool. And answer them from the provider's current published terms for the plan tier you are actually on, not from memory and not from a summary blog post, because consumer and business tiers routinely differ on exactly this point and because terms change.

    The audit

    Build it once as a spreadsheet, keep it current, and hand a redacted version to clients who ask. It is a surprisingly strong differentiator in a pitch, particularly if you work white-label for other agencies, where you are the subcontractor whose compliance somebody else is warranting.

    Steps:

    1. Enumerate every surface, not every product. Start from the asset, not the vendor list. Trace one real project end to end and write down every place a client file went: generation platform, storage, transcription, captioning, stock library, upscaler, chat assistant, design tool, shared drive, the client-review link, the browser extension that helped somebody grab a reference. The extensions and the assistants are the ones that get missed.
    2. Classify what each surface sees. Brand assets, unreleased product, customer personal data, pricing, script and messaging, voice recordings, likeness. The exposure is not uniform, and neither is the client's concern.
    3. Answer the four questions per surface. Training, retention, sharing, human review. Record the URL of the terms and the date you checked.
    4. Record the plan tier. This is the line that saves you. A tool that is fine on the business tier and not on the personal tier is a compliance risk the moment a freelancer joins on their own account.
    5. Mark the ones you cannot answer. An honest "unknown" drives a decision. A blank cell does not.
    Column Why it earns its place
    Surface Tools, not vendors. One vendor can have several
    Data classes seen Determines which clients care
    Trains on inputs? The clause itself
    Retention window Different promise, asked separately
    Human review? The one clients under embargo ask about
    Plan tier in use Where the answer silently changes
    Terms URL and date checked Makes the row auditable

    The output of the audit is not a clean bill of health. It is a short list of surfaces to remove from client work, a shorter list to upgrade, and a documented position on the rest. That list is the deliverable.

    Fine-tunes, LoRAs and voice models are training data by definition

    The clause usually contemplates inputs flowing into somebody else's foundation model. The awkward case is the one you build yourself.

    A brand-specific LoRA trained on a client's product photography is, definitionally, client material in a training set. So is a fine-tune on their creative archive, and so is a cloned voice built from a spokesperson's recordings. If your addendum says client materials will never be used to train a model, and you then train a brand adapter to keep their product looking consistent, you have breached your own clause unless the contract carves it out.

    The carve-out is straightforward and clients almost always want it, because the adapter is what makes their brand look right. Draft it explicitly:

    The foregoing restriction does not apply to Client-Specific Models trained by Agency solely on Client Materials and used solely to produce Deliverables for Client. Client-Specific Models shall be treated as Client Materials, shall not be used for any other client or purpose, and shall be deleted or transferred to Client on termination.

    Three details in there matter. Sole use, because the entire risk of a brand adapter is it leaking into someone else's campaign. Treating the adapter itself as client material, so ownership is not ambiguous. And a deletion-or-transfer obligation, because a trained adapter is a derived asset that outlives the project.

    Voice cloning carries an extra layer: consent from the individual, in writing, scoped to the uses you actually intend. A company signing on behalf of an employee's voice is not the same as the employee consenting, and turnover makes that gap real within a year or two. Keep the consent with the model.

    Clause language you can satisfy

    The trap in the client's draft is usually the word ensure. You cannot ensure the behaviour of a third-party platform. What you can do is name the surfaces, commit to their terms, and commit to notice on change. That version is narrower, and it is the one you can honour.

    Agency shall not use Client Materials to train, fine-tune or otherwise improve any machine learning model, other than Client-Specific Models as defined above. Agency shall process Client Materials only through the tools listed in Schedule B, shall maintain each such tool on a plan tier whose published terms exclude use of customer content for model training, and shall give Client not less than ten business days' written notice before adding any tool to Schedule B. On termination, Agency shall delete Client Materials and any Client-Specific Models within thirty days and confirm deletion in writing.

    Schedule B is the audit. Keeping it as a schedule rather than body text means you can update it without reopening the contract, and it gives the client the visibility that makes the clause worth having. If you already run content governance at brand level, Schedule B slots into the same review cycle as your brand-safety checks rather than becoming a separate ritual nobody performs.

    One more habit worth building: keep client material in a client-scoped workspace with its own brand assets rather than a shared personal library. It makes the deletion obligation something you can actually execute, instead of a search-and-hope exercise across two years of generations.

    FAQ

    Can I promise a client that no tool in my stack ever trains on inputs?

    Only if you have checked every one and you accept responsibility for terms changing under you. The safer promise is the schedule-based version: these are the tools, these are their current terms, and you get notice before the list changes. It gives the client more actual assurance than a blanket sentence, because it is inspectable.

    What about tools the client asks me to use?

    Carve them out. If the client mandates a platform, the clause should say that Schedule B includes Client-Directed Tools and that Agency makes no representation about their terms. Otherwise you are warranting the behaviour of software you did not choose.

    How does this interact with keeping records for copyright purposes?

    It does not conflict, but the retention periods need to agree with each other. A production log proving human authorship is metadata about the work, and it can be kept after the underlying client assets are deleted. Write the deletion clause so it covers Client Materials and derived models, and expressly permits retention of project records and archival copies required by law. Getting that interaction wrong is the most common drafting error here, and the wider licensing picture is worth reading alongside it.