The most valuable asset in an enterprise AI contract is no longer the customer’s to protect — and in the strongest terms reviewed, no longer the customer’s at all. That is the central finding of The Grove Foundation’s quarterly Λ (Lambda) Standings, published today at the-grove.ai, analyzing enterprise terms across six leading AI coding and agentic platforms over 14 months.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260721428902/en/
“Usage Data” historically meant operational exhaust — uptime, latency, crash reports. The same contractual category now carries the reasoning trace: the record of how employees think through problems with AI — which suggestions are accepted, edited, or rejected, and the execution paths behind them. In the most striking case, the definition of Usage Data stayed word-for-word identical across the 14-month window while the surrounding terms added an outright ownership claim — “all right, title, and interest” — and flipped model training from opt-in to opt-out.
Because these agreements carve Usage Data out of the Customer Data category enterprises actually negotiate, deletion rights, training opt-outs, and zero-retention commitments don’t reach it. Where the terms assert ownership, no opt-out exists at any tier — you cannot opt out of someone else’s property.
The transfer mechanism is de-identification — long sold as a privacy protection. Across multiple providers, de-identified content is exempt from deletion commitments, survives plaintext erasure as embeddings and metadata, or exits the privacy policy entirely. Retention is live exposure: a federal court this year ordered one provider to preserve and produce roughly 20 million de-identified consumer conversation logs.
“For two years, enterprises negotiated training opt-outs. Meanwhile, vendors rewrote what counted as the customer’s data in the first place,” said Jim Calhoun, Founder and Executive Director of The Grove Foundation. “When a vendor says ‘we don’t train on your data,’ the statement is accurate — under definitions the vendor wrote. The right question is no longer whether they train on your data. It’s who owns the record of how your company thinks when the contract ends.”
The analysis reviewed public terms from Anthropic, Cognition, Cursor, GitHub, OpenAI, and Replit; postures vary materially, and findings here are unattributed. The full report — provider-level findings, verbatim clauses, and archive links — along with the Foundation’s open countermeasure standard, the Autonomaton Pattern (GRV-001, CC BY 4.0), is available at the-grove.ai. The analysis is technical, not legal advice.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260721428902/en/
"We don't train on your data" is technically true. Leading AI vendors quietly redefined what counts as yours — documented in their own terms, 30 primary sources.
Contacts
Media Contact
Jim Calhoun
press@the-grove.ai
317-556-4797