In brief

Developing and growing a successful technology company increasingly depends on one critical thing, data. Whether you are developing AI-enabled products, training models, or using third-party AI services, early decisions about data and data governance can have lasting legal and commercial consequences on the success of your company.

Many founders focus on product development first and governance later. This is why often avoidable issues emerge when signing up customers, fundraising or on regulatory review.

Below are five areas that any founder using AI, analytics or large databases should consider from the outset.

Key takeaways

  • Have a clear position on how customer data is used and tell your customers of that position
  • Decide your model training position early
  • Create a data register
  • Review customer contracts carefully
  • Implement governance policies earlier than you think you need them

In more detail

1. Have a clear position on how customer data is used

If you are using customer data to help build your platform or model, you need to have clear terms in place allowing that use. Many founders assume that having terms and conditions in place giving broad rights of use will be sufficient. This is not necessarily the case. Customer trust is important, and customers are increasingly aware that their data has value, and expect transparency about how their data is used, who has access to it, and whether third-party providers are involved in processing it.

If you intend to use customer data to improve your products, develop new capabilities, evaluate models or support AI training activities, you should be clear about that and capture it clearly in your customer contracts.

A clear and defensible position on customer data use not only reduces legal risk, but also strengthens customer trust. Customer trust is key. 

2. Decide your model training position early

A key governance decision is what data you will use to train or improve AI models.

Founders should develop a clear position early and consistently apply it across product design, customer contracts and operational practices. This requires an understanding of what rights attach to datasets that are purchased, licensed from data providers, sourced from customers or obtained through other channels. Holding a dataset does not necessarily mean it is available for AI training purposes or to build your model.

These questions apply to all datasets but are especially important for datasets that contain any personal information of individuals.

Founders should keep front of mind:

  • What rights were granted when the data was acquired?
  • Do the licence terms allow model training or derivative use?
  • Are additional permissions or consents needed to use this data?
  • Are there restrictions on commercialisation or downstream use?

3. Create a data register

Data provenance is rapidly becoming a critical AI governance issue.

To support your model training position, maintain a register of datasets used. This register should include where data originated, how it was acquired, what rights apply to it and how it is being used.

A simple data provenance register can become increasingly helpful during customer due diligence, investment rounds and regulatory reviews.

The register should be clear where scraped data is used in the business. Founders should exercise caution where scraped data is involved. While web-scraped content may appear readily accessible and easy to obtain, the legal position is often more complicated. Usage rights to that data may be governed by copyright law, contractual terms of use and privacy laws. Founders need to be alive to how scraped data is being used across the company, especially where it may be mixed with other datasets to create critical platforms or products for the business.

At a minimum, founders should be aware of:

  • Which datasets have been scraped
  • Where those datasets originated
  • What terms applied when the data was collected
  • What copyright or intellectual property risks may arise

The ability to explain the source of training data places an organisation in a stronger position to demonstrate AI governance (for transparency and maturity).

4. Review customer contracts (especially standard terms contracts) carefully

Founders should also especially be on the look out for standard customer terms. These boilerplate terms often aren’t built specifically for AI-enabled products or SaaS projects, and can therefore fall short of offering you the protections required down the line.

One area that deserves particular attention is intellectual property ownership. Standard contractual terms may contain broad intellectual property provisions which inadvertently assign ownership of deliverables, improvements or enhancements to the customer.

If you are signing up a customer whose data you want to include in your model, it is essential to check the intellectual property provisions that might be included in the standard agreement that they provide to you. If it contains provisions that assign ownership of IP generated during the term of the Agreement to the customer, this undermines your ownership of the model. 

Key questions to ask may be:

  • Who owns the platform and the underlying technology?
  • Who owns the deliverables, improvements or enhancements made during the course of the project?
  • Are there any particular restrictions on future development or commercialisation using datasets, insights or outputs from this project?

5. Implement governance policies earlier than you think you need them

Many founders view governance as something that can be addressed after a business reaches scale. Instead, in practice, lightweight governance adopted early often enables faster and safer growth for the company.

Governance policies establish the principles that guide how data, AI systems and technology are developed and used across the organisation. They create consistency in decision-making and reduce the risk that different teams take conflicting approaches to data use, model development or customer commitments.

Importantly, governance should not be viewed as a constraint on innovation. Well-designed policies create guardrails that help teams move faster while remaining aligned with the company’s objectives and risk appetite.

Even relatively simple policies can provide significant benefits if they address matters such as:

  • Approved uses of data
  • AI model development and deployment standards
  • Customer data handling requirements
  • Security and access controls
  • Escalation and incident management processes
  • Third-party AI procurement and governance requirements

As companies grow, governance frameworks provide founders with confidence that teams can continue to innovate without requiring constant oversight. They also help demonstrate maturity to customers, regulators, investors and future acquirers. 

Related content

Explore More Insight