When a business pays for an AI tool, it hands over some of the most sensitive material it has: sales calls, client meetings, internal chat, draft contracts. Too often, the default setting lets the vendor use that material to improve its own AI, unless someone at the customer finds the switch and turns it off. Our view is simple. For tools that businesses pay for, training on customer content should be off until the customer turns it on. An opt-out buried in a settings page or a privacy policy is not consent, and it is not good enough.
What "default" looks like in practice
The practice is not hypothetical, and the companies concerned have described it in their own words.
Otter's privacy policy says the company trains its proprietary AI "on de-identified audio recordings and on transcriptions (which may contain Personal Information)", citing consent or legitimate interests as the legal basis. Fathom's security help page says it uses de-identified customer data to improve its own models, with an opt-out in account settings that team admins can apply to a whole organisation. Slack, for its predictive features, says in its privacy principles that its systems analyse customer data, and that to opt out a workspace owner must email its customer experience team with the subject line "Slack Global model opt-out request".
LinkedIn shows how an opt-out works once training has begun. Its help page on generative AI training says members can opt out using the "Data for Generative AI Improvement" setting, and that opting out "does not affect training that has already taken place". Whatever went into the model before you found the switch stays there.
These are not hidden: each company publishes its policy. Our objection is to where the default sits, not to whether the words exist somewhere.
Regulators have already drawn the line on how changes are made
In February 2024 the US Federal Trade Commission published a warning titled "AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive". It said it "may be unfair or deceptive" for a company to start using data for AI training and to inform consumers only "through a surreptitious, retroactive amendment to its terms of service or privacy policy", and that a business which collected data under one set of privacy commitments "cannot then unilaterally renege on those commitments".
In the UK, the Information Commissioner's Office said in September 2024 that it was pleased LinkedIn had suspended training on UK users' data after the regulator raised concerns, and stressed the importance of "a clear and simple route for users to object to the processing". A year later, in September 2025, the ICO said LinkedIn had improved its transparency material, made it simpler to object through opt-out settings and given users a longer window to do so, and that LinkedIn would resume its plans.
Notice what both regulators focused on: transparency and a route to object. That is a floor, not a standard of good practice. Meeting it still leaves the burden on the customer to notice, understand and act.
The industry has shown that opt-in is possible
The strongest evidence that defaults can be set the other way comes from companies that have done it. When Zoom's terms drew criticism in August 2023, CNBC reported on the dispute over what the wording allowed, and Zoom rewrote the clause. Its current terms of service state that Zoom "does not use any of your audio, video, chat, screen sharing, attachments or other communications-like Customer Content (such as poll results, whiteboard and reactions) to train Zoom or third-party artificial intelligence models." Slack's privacy principles now say it "will not use Customer Data to train generative AI models unless Customer provides affirmative opt-in consent". MeetGeek states plainly: "We never use your recordings, transcripts or summaries to train AI models, ours or anyone else's."
These companies still ship AI features. Opt-in did not stop them building products. It changed who decides.
The strongest case for the default
The fair counter-argument deserves a proper hearing. Speech recognition, summarisation and search get better with real-world examples, and the most useful examples are exactly the messy, accented, jargon-heavy conversations that customers produce. If training were opt-in, most customers would never switch it on, not because they object but because nobody changes defaults. The result could be models trained on a narrow, unrepresentative slice of users, which would make the product worse for everyone else, including the people who are already served badly by speech technology.
Vendors also point out that much of this training uses de-identified data, that their AI sub-processors are often contractually barred from training on it, and that cheaper or free plans are partly paid for by the product improvements that data enables. Some customers genuinely would rather share data than pay more.
We take those points seriously, and they do not change our conclusion. De-identification is not a guarantee: Otter's own policy notes that transcriptions used for training "may contain Personal Information". The people in a recorded meeting are often not the customer at all. They are the customer's clients, candidates and suppliers, and they never saw the vendor's privacy policy. A default that is reasonable for one person's own notes is much harder to justify for a conversation with someone outside the company. And if a model genuinely needs representative data, vendors can ask for it openly, explain what it is for and offer something in return. That is a business decision for them to make, not a cost to push quietly onto customers through a settings page.
What we think good practice looks like
- Off by default on paid business plans. Training on customer content should require an affirmative choice by an administrator.
- One clear switch, in the product. Not an email to a support address, not a clause in a policy.
- Plain answers to three questions on one page: is customer content used for training, is it de-identified first, and can a model "unlearn" data after an opt-out.
- Advance notice of any change, with the new default applying only to data collected after the customer agrees.
What buyers can do meanwhile
Until defaults change, the responsibility sits with the buyer. Before rolling out any AI tool, read the training section of its privacy policy, not just the marketing page. Find the opt-out before the first meeting is recorded, apply it at the organisation level where possible, and write down who owns that setting. Ask vendors in writing whether customer content is used for training, and keep the answer. When two tools are otherwise close, the one that asks permission first has told you something about how it will treat the rest of your data.
AI vendors want businesses to trust them with their most sensitive conversations. Asking before using those conversations is the least that trust should cost.