> ## Content Index
> Fetch the complete content index at: https://www.realaigovernance.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What Your AI Vendor's Terms of Service Don't Tell You About Your Client Data
- URL: https://www.realaigovernance.com/what-your-ai-vendors-terms-of-service-dont-tell-you-about-your-client-data/
- Published: 2026-08-08T13:00:34.000Z
- Updated: 2026-08-08T13:00:33.000Z
- Description: You need three questions answered before adoption: does this vendor retain our inputs, for how long, and can we contractually opt out of training use.
- Author: Robert T. Boyer Ph.D.
- Tags: AI risk, Client Data, Vendor TOS, AI Governance, Governance Debt Monthly, Curiosity Gap

Most firms treat an AI vendor's terms of service the way they treat a software EULA: skim, accept, move on. That habit is now a governance gap.  
  
Here's what's easy to miss. Many AI tools, especially ones adopted informally by individual attorneys rather than procured through IT or risk, reserve broad rights to log inputs, retain them for "service improvement," and share them with subprocessors the firm has never vetted. None of that requires a breach to become a problem. It only requires a client asking, during an engagement letter negotiation or a security questionnaire, "where does our information go once it's typed into this tool?" If the honest answer is "we're not sure," that's a professional responsibility issue, not just an IT one.  
  
Consider a firm running document review through a general-purpose AI assistant that associates signed up for individually, bypassing procurement entirely. The vendor's consumer-tier terms permit use of submitted content to train future models unless the firm opts into a paid enterprise tier with different terms, a distinction most users never check. Nothing malicious happened. No one was hacked. But privileged and confidential client material now sits inside a vendor's infrastructure under contract language nobody reviewed with that use in mind.  
  
The usual objection: "we don't have time to have counsel review every AI tool's terms." Fair, but you don't need to review every tool. You need three questions answered before adoption: does this vendor retain our inputs, for how long, and can we contractually opt out of training use. That's a checklist, not a legal project.  
  
The firms getting ahead of this aren't the ones with the most sophisticated AI strategy. They're the ones who added AI vendor terms to the same intake process they already use for any third party touching client data.  
  
Before the next AI tool gets approved, or before you find out an associate already adopted one, put these three questions to your vendor in writing. The answer belongs in your file, not just your inbox.