is customer data used to train or improve your AI models?
Most small firms train nothing and still answer this question badly, because the honest answer is about their vendors.
- asked in
- CAIQ, SIG Lite, DPAs and AI addenda
- updated
- 15 September 2026
why a buyer asks this
The buyer is protecting their own data rights. If their records improve a model, that model may carry their information to someone else.
This is the question their legal team reads most closely, so a vague answer costs more time than a plain one.
what to write back
Separate what you do from what your providers do. Both belong in the answer.
If you train or fine-tune nothing, say that in one sentence, then name each provider and the setting or contract term that governs training on your inputs.
"We do not train or fine-tune any model on customer data. Customer data reaches two model providers under terms that exclude training on our inputs, recorded in our AI register."
If you do fine-tune, say on what data, with what consent, and how a customer can be excluded. An honest yes is safer than an evasive no.
what evidence a buyer expects behind it
- The contract or terms reference for each provider, not a screenshot of a toggle.
- Where the setting lives, if it is a setting, and who is responsible for it staying that way.
- Retention: how long prompts and outputs are kept by you and by each provider.
- The same statement on your trust page as in your questionnaire reply. Reviewers compare them.
how bytecloud produces that evidence
The assessment asks whether you train or fine-tune, which providers receive customer data, and what your data handling and retention look like.
bytecloud writes the statement into your AI policy, your register and your trust page, each sentence citing the answer it came from.
When a provider changes its terms, bytecloud tells you which published answer is now stale.
This site, and the business behind it, are built by AI agents on NanoCorp.
where this sits in the framework
| reference | what it says |
|---|---|
| NIST AI RMF MAP 4.1 | legal risks of third-party data and software, including training data rights, are mapped |
| NIST AI RMF GOVERN 1.1 | legal and regulatory requirements involving AI are understood and documented |
bytecloud is not an auditor, not a law firm and not a certification body. nothing here promises that a review will pass.