AI data controls
What the model sees, keeps and learns from
What it is
AI data controls answer the questions every enterprise legal team now asks. Is our data used to train models? Which model providers see it, and do they keep it? Can we switch AI features off, or keep processing in our region? The answers live partly in contracts with model providers, partly in settings customers control, and partly in how the system is built.
It's often the first AI question in procurement, and a vague answer stalls the deal. Some companies block AI features entirely until these controls exist.
What it takes
About 3–6 engineer-weeks to build in-house.
Answer these first
- Legal: Is customer data ever used to train or improve models, ours or a provider's?
- Legal: Which AI providers are subprocessors, and what do they retain?
- Product: When an admin turns AI off, does all data stop flowing to models?
- Engineering: Where are prompts, context and outputs stored, and for how long?
- Security: Could one customer's data influence another customer's answers?
- Sales: How many deals now include AI restrictions in the contract?
This page works best with JavaScript on. Every answer also has its own address, like /what/scim.