Most AI companies treat privacy policies and NDAs like they’re the same thing. They’re not. And that confusion could be costing you millions.
The $10 Million Mistake
A tech startup we’ll call “HealthAI” (name changed for legal reasons) thought they were protected.
They had a privacy policy. They had an NDA with their AI vendor. They had lawyers review everything.
Then a competitor somehow got access to their proprietary medical diagnosis algorithm. The vendor had been training on HealthAI’s data — and sharing insights with other clients.
HealthAI sued. They lost.
Why? Because their privacy policy didn’t prohibit data use for training. And their NDA only covered disclosure of information — not what the vendor could do with it internally.
The $10 million they spent developing that algorithm? Wasted.
This story isn’t unique. It’s a pattern.
Why the Confusion Exists
The terms “NDA” and “Privacy Policy” get mixed up because they both deal with information protection. But they protect fundamentally different things:
An NDA (Non-Disclosure Agreement) is about confidentiality. It prevents one party from telling others about your information.
A Privacy Policy is about data rights. It controls what a company can do with your information — including how they use it, store it, and whether they can learn from it.
In the AI context, this distinction is everything.
Your NDA doesn’t stop a vendor from reading your proprietary data to improve their model. It only stops them from telling others about what they read.
That’s not protection. That’s a false sense of security.
What AI Platforms Actually Need
If you’re building with AI, here’s what your contracts actually need to address:
1. Explicit Training Prohibitions
Your privacy policy must explicitly state that your data will NOT be used to train, fine-tune, or improve any AI model — including models shared with other customers.
What most policies say: “We respect your privacy and will not share your personal information.”
What it should say: “User data provided through this service shall not be used for model training, machine learning improvement, algorithmic refinement, or any derivative work. This restriction applies to all models within our platform and any third-party integrations.”
2. Data Isolation Guarantees
Your contracts need to guarantee technical data isolation, not just contractual promises.
Ask for:
- Dedicated tenant isolation (no shared model weights)
- No cross-customer training pipelines
- Verifiable audit logs of data access
- Right to audit vendor practices
3. Derivative Work Definitions
This is the trap most companies fall into. Define “derivative work” broadly:
- Any model trained or fine-tuned on your data
- Any insights derived from analyzing your data
- Any patterns learned that could benefit other customers
- Any embeddings or vector representations created from your content
4. Breach Notification Requirements
When (not if) something goes wrong, you need:
- Immediate notification (within 24 hours of discovery)
- Full disclosure of what happened
- Evidence of what data was affected
- Remediation steps and timeline
5. Data Deletion Guarantees
What happens when you leave? Your contracts must include:
- Complete deletion of your data from all systems
- Verification of deletion
- Deletion from any training data or model weights
- Ongoing deletion obligations (not just at termination)
The AI-Specific Clauses You’re Probably Missing
Beyond standard privacy language, AI platforms need specific provisions:
Model Ownership
Who owns the outputs your AI generates? Who owns the insights? These questions must be answered explicitly.
If you use the AI to analyze your proprietary code, does the vendor have any claim to insights discovered? Can they use patterns from your analysis to benefit other clients?
Get. This. In. Writing.
Prompt and Response Retention
Every prompt you send is potential training data. Every response could contain your proprietary information.
Your contracts should address:
- How long prompts and responses are retained
- Whether they’re reviewed by humans
- Whether they’re used for any AI improvement purposes
- Your right to request immediate deletion
Third-Party Subprocessors
AI platforms rarely build everything themselves. They use other AI providers. Your data likely flows through multiple systems.
You need:
- A complete list of all subprocessors
- Restrictions on how each can use your data
- Right to approve any new subprocessors
- Liability for subprocessors’ actions
Export and Portability
Can you get your data out? Can you export all prompts, responses, and custom configurations? This isn’t just convenient — it’s protection.
If a vendor goes under or raises prices dramatically, you need an exit strategy.
Red Flags to Watch For
Before signing any AI platform contract, watch for these warning signs:
“We may use aggregated data…” Aggregation isn’t anonymization. If they’re aggregating your data with others, there may still be leakage. Ask: what aggregation methods? What’s the minimum dataset size?
“For service improvement purposes…” This usually includes model improvement. Unless you explicitly carve out training prohibition, assume your data is fair game.
“Industry standard practices…” Industry standards for AI data handling are still evolving. Don’t accept vague language. Get specifics.
“Reasonable security measures…” Reasonable is subjective. Ask for their actual security certifications (SOC 2, ISO 27001, etc.) and audit results.
No deletion timeline… If they can’t tell you when they’ll delete your data, assume they never will.
The Contract Checklist You Actually Need
Here’s what to demand in writing before trusting any AI platform with sensitive data:
☑ Explicit prohibition on using my data for AI training ☑ Technical data isolation from other customers ☑ Definition of derivative works (broad scope) ☑ 24-hour breach notification requirement ☑ Complete data deletion upon request/termination ☑ Clear ownership of AI outputs and insights ☑ Prompt/response retention limits ☑ Complete list of all subprocessors ☑ Right to audit security practices ☑ Data export and portability guarantees ☑ Annual compliance certifications
What Good Looks Like: A Sample Clause
Here’s language that actually protects you:
“Provider agrees that Customer Data shall not be used to train, fine-tune, improve, or otherwise develop any machine learning model, artificial intelligence system, or algorithmic process, whether for Provider’s own use or for the benefit of any third party. Provider shall implement and maintain technical and organizational measures to ensure complete data isolation between Customer and all other customers. Upon Customer’s written request or termination of this Agreement, Provider shall permanently delete all Customer Data, including any copies, backups, or derivative datasets, within thirty (30) days and provide written certification of such deletion.”
Notice what’s in there:
- Explicit training prohibition
- Technical isolation requirement
- Clear deletion timeline
- Written certification requirement
This is the level of specificity you need.
The Hard Truth
Most AI vendors won’t offer this language proactively. They’ll push back. They’ll say it’s “industry standard” or “not how our systems work.”
Push anyway.
Because here’s the reality: the AI industry is still in its Wild West phase. Regulations are lagging. Best practices are still being established.
You are responsible for protecting your own data. Not your vendor. Not regulators. You.
So read the fine print. Ask the hard questions. Demand the specific language you need.
Or join the companies learning this lesson the expensive way.
Your Data. Your Responsibility.
Before you sign your next AI platform contract:
- Read the privacy policy (yes, actually read it)
- Ask specifically about training data practices
- Negotiate explicit prohibitions in writing
- Demand audit rights and deletion guarantees
- Walk away if they won’t budge
Your proprietary information is only as safe as the contracts you sign.
Make them count.
Have you encountered confusing or inadequate AI data protection language? Share your war stories in the comments — let’s build better practices together.
Categories: AI Law | Data Privacy | Technology Contracts | Business Strategy
Tags: AI, Privacy Policy, NDA, Data Protection, AI Contracts, Data Privacy, Legal Tech, Startup