Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Our Client Contracts Say Their Data Cannot Go to Third-Party AI. Can We Still Use AI on It?
Problems We Solve

Our Client Contracts Say Their Data Cannot Go to Third-Party AI. Can We Still Use AI on It?

When contracts stop client data going to OpenAI or similar, AI can still work on it. We design AI on private data that stays inside your own environment.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Often yes, but only with the right design. Depending on what the contract actually says, AI can run on a model hosted inside your own cloud tenancy or on your own hardware, or through a provider in a named region under terms your clients accept. Start with the contract wording, then map where each piece of data would go, then choose the model and hosting to fit.

Every useful idea hits the same clause

Your team could save hours summarising case files, drafting reports from client data, or searching years of project records. Every time someone suggests AI for it, the same objection comes up: our client agreements say their data must not be shared with third parties, must stay in the UK, or must not be used with AI services without consent.

So the AI work stops at the ideas stage. Meanwhile competitors seem to be using AI, and some of your own staff may be quietly pasting client material into public tools anyway, which is exactly what the contracts are trying to prevent.

Why the answer is usually "it depends on the wording"

Contract clauses about data vary a great deal. Some forbid any sub-processor without consent. Some require data to stay within a region. Some prohibit use of data to train AI models, which is a narrower thing. Some were written before anyone was thinking about AI and are ambiguous. The first mistake is treating all of them as a flat ban.

The second mistake is assuming AI means sending data to a US consumer service. There are several ways to run capable models, and they differ in where data goes, who can see it, and what terms apply. Matching the architecture to the contract is a design task, not a yes or no.

What the stalemate costs

If nothing changesThe effect
AI ideas shelvedRepetitive work on client files stays manual
Staff use AI anywayThe breach the contract prevents happens informally
Competitors move aheadClients start asking why you are slower
No documented positionYou cannot answer a client who asks how you use AI

The informal use is the real exposure. A ban with no approved alternative tends to produce exactly the behaviour it is meant to stop.

How we design AI that keeps client data where it belongs

  1. We read the relevant clauses with you, and your legal adviser where needed, and write down in plain terms what each type of client data is and is not allowed to do.
  2. We map the data flow for each proposed AI use: what leaves which system, where it is processed, whether anything is stored, and who could access it.
  3. We choose a hosting option to fit. That might be an open-weight model such as Llama or Mistral running in your own Azure or AWS account or on your own server, or a managed service such as Azure OpenAI or Amazon Bedrock in a chosen region under business terms, where the contract allows it.
  4. We keep retrieval, indexing and logs inside your environment, so the document store and the history of questions and answers never sit with a third party.
  5. We add redaction or pseudonymisation where it helps, so names and identifiers can be replaced before text is processed and restored afterwards.
  6. We produce a short written description of the setup that you can share with clients who ask, based on what was actually built.

Self-hosted models are generally less capable than the largest hosted ones, so we test the actual task on your data before committing. For many internal jobs, such as summarising, classifying and searching, a well-chosen smaller model is enough.

What you end up with

AI working on client material in a way you can explain in one paragraph: where the data goes, where it does not, and what model is used. Staff have an approved route, so the informal workarounds lose their reason to exist.

When a client sends an AI questionnaire, you can answer it from a real description of your setup rather than a hopeful one.

Where a contract is stricter than the rest, that client's data can be handled differently, for example processed only by the self-hosted model, while other work uses a more capable hosted one. The routing is set by the data, not left to each member of staff to remember.

Is this your situation?

  • Client agreements restrict sharing data with third parties or outside a region.
  • AI projects stop as soon as client data is mentioned.
  • Clients have started asking how you use AI on their information.
  • You suspect staff are using public AI tools on client material regardless.
  • You need AI on private data without sending it outside your environment.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Is a self-hosted model as good as ChatGPT?

For general reasoning the largest hosted models are usually stronger. For focused tasks on your own documents, a well-chosen open-weight model is often good enough, and we test it on your data before you decide.

Can you tell us whether our contracts allow this?

We can help you read them in technical terms and map the data flow. The legal interpretation should come from your own adviser, and we work alongside them.

Does running a model ourselves need special hardware?

Smaller models run on standard cloud GPU instances or a single capable server. Larger ones need more. We size it to the task.

What drives the cost?

Mainly the hosting choice and the volume of work. Self-hosting shifts cost from per-request fees to the servers that run the model.

What do you need from us?

The relevant contract clauses, a description of the AI tasks you have in mind, and access to a sample of the data in a safe environment.

Keep reading

More on Problems We Solve

Start here

Tell us what is blocking AI in your business

Describe the documents, systems and constraints you are working with, and what you want AI to do. We will give you a straight view of what is realistic, and if a smaller change would fix it, we will tell you.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →