The scope of the problem remains partially opaque. While no single vendor has been publicly identified as the primary offender, the pattern is industry-wide: most vendors default to opt-out rather than opt-in consent structures for model training, treating customer data as a free resource. The EU AI Act and NIST AI Framework have established baseline standards for government contracts, but commercial MSAs lack equivalent protections—including guarantees for data export in open formats within 30 days of termination.
Counsel should treat this as an immediate contract review priority. The compliance gap between regulated government contracts and commercial agreements creates exposure for companies operating under AI legislation or in regulated jurisdictions. At the next renewal cycle, legal teams must update RFPs to mandate AI disclosure and data-use transparency before contract awards. Failure to add specific AI provisions risks unauthorized training on proprietary and privileged information. The shift from passive "service improvement" language to active AI exploitation represents a fundamental redefinition of data ownership—one that now requires explicit contractual guardrails.