Introduction
Two years ago you evaluated a vendor. You looked at their security documentation, checked their certifications, asked where your data would live, and signed an agreement you were comfortable with. That review was thorough, and at the time it was accurate.
The product you approved doesn’t exist in that form anymore.
Your CRM now summarizes customer calls. Your helpdesk drafts responses automatically. Your accounting platform flags anomalies using a model that wasn’t there last year. None of these arrived as a new contract or a renegotiation. They showed up as product updates, announced in a release note or a banner in the corner of a dashboard, and your team started using them the same week.
You approved a vendor. You didn’t approve a vendor plus a model, and in most cases nobody asked whether you wanted to.
The Update That Changes the Agreement
Here’s what makes this different from ordinary feature releases. When a vendor adds AI to a product, the data your business already handed over frequently becomes an input to something new. Support tickets, customer records, uploaded documents, and internal notes all become material a model can process, and sometimes material it can learn from.
Vendors have largely handled this through terms-of-service updates rather than negotiated contract amendments. That’s an efficient approach for them and an easy one to miss on your end, since revised terms tend to arrive by email among dozens of other notices and take effect whether or not anyone opens them. The language that permits it is usually already in your agreement. Clauses allowing a vendor to process customer data to “improve” or “enhance” their services were written long before generative AI existed, and they’re now doing work nobody anticipated when they were signed.
The scale of this isn’t small. An analysis of contract data by TermScout, working with Stanford Law School’s CodeX center, found that 92 percent of AI contracts claim data usage rights beyond what’s needed to deliver the service, compared with a market average of 63 percent across software agreements generally. Some even permit customer data to be used for competitive intelligence.
This Isn't Hypothetical
Two well-known cases show how visible this has become. Adobe faced significant customer backlash after updated terms appeared to grant broad rights over user content, and the company ultimately clarified its policies and committed not to train AI systems on customer data. Figma was hit with a proposed class action in late 2025 alleging it used customer designs to train generative tools without permission, a claim the company denied.
Both involved large vendors with sophisticated legal teams and attentive customer bases. The interesting question isn’t what happened at Adobe or Figma. It’s what’s happening at the fifteen smaller vendors your business uses that nobody is watching as closely.
Five Questions You Should Ask Your Top Vendors
You don’t need to interrogate every vendor. Start with the handful that hold your most sensitive data, which for most businesses means five or six relationships. Ask each one:
- What AI features have been added to our account in the past year, and are any enabled by default?
- Is our data used to train or fine-tune any model, including third-party models you rely on?
- If AI features process our data, is it retained afterward, and for how long?
- Which third-party AI providers, if any, does our data pass through?
- How will you notify us when this changes?
The last question matters more than it looks. A vendor who commits in writing to advance notice has given you something the others haven’t, which is time to make a decision rather than discovering a change after the fact.
What to Fix at Renewal
Contract language is where this gets resolved, and renewal is when you have leverage. The practical asks are narrow: an explicit prohibition on using your data for model training without written consent, a requirement that new AI features be disclosed before activation, and clarity on who owns the outputs generated from your data.
Vendors won’t always agree, and a refusal is informative on its own. Where a vendor won’t commit to opt-in, the common middle ground is zero-retention processing, meaning your data can be used to generate output but isn’t kept for any training purpose. That’s a reasonable landing spot, and most established vendors can accommodate it.
This is the same discipline that applies to any vendor relationship holding your customers’ data. AI just changed what’s at stake without changing the paperwork.
Final Perspective
Most businesses have spent the past two years thinking carefully about the AI tools they chose to adopt. Far fewer have looked at the AI that arrived inside software they’d already bought, which is now the larger share of it.
The businesses handling this well aren’t blocking AI features or treating vendors as adversaries. They’re asking straightforward questions, getting answers in writing, and fixing the contract language at renewal instead of after an incident.
At Secutor, we help organizations review their vendor relationships, understand where AI has entered their supply chain, and put the right terms in place before the next renewal cycle. If you’re not sure which of your vendors are processing your data through a model, that’s a good conversation to start.
You can’t govern what you don’t know you’ve agreed to.
Connect with an Expert for a Free Consultation
Secutor is your team of world-class problem solvers with vast expertise and experience delivering complete solutions keeping your organization protected, audit-ready, and running smoothly. Use the form below to contact us for a free consultation.

