What company data can't be licensed to AI labs?
A company can't license what it does not own or control. That often rules out client deliverables, records covered by an NDA and content you license from someone else. Personal data, health records and export-controlled technical data are restricted by law. Removing names helps with some of this. It does not fix a contract that says no.
Disclosure. Pinprick offers a data licensing service that represents the firm selling, so we have a commercial interest in this topic. We are not a law firm and nothing here is legal advice. Use your own counsel before you sign anything. Sources are linked below.
What should stay out?
| Type of record | Why it is a problem | Starting position |
|---|---|---|
| Client deliverables and client files | Your client agreement likely limits use and disclosure. | Out, unless the contract or the client clearly allows it. |
| Anything under an NDA | The NDA's terms govern it. Removing names does not automatically change that. | Often out. The NDA's terms decide. |
| Licensed third-party content | Analyst reports, licensed training content, vendor runbooks. The license rarely covers passing it on. | Out. |
| Personal data about customers | Privacy laws such as the CCPA and GDPR. | Out, or removed under an agreed standard. |
| Employee records | Privacy law, and your staff's trust. | HR, payroll and discipline out. Work messages only with care. |
| Health information | HIPAA sets a specific de-identification standard. | Out, unless that standard is met and counsel agrees. |
| Export-controlled technical data | ITAR defines technical data for defense articles. | Out until export counsel says otherwise. |
This is general information, not legal advice. Your contracts and your counsel decide what applies to you.
Why is client work usually off limits?
Because the contract usually says so. Master service agreements and NDAs typically restrict how you use and disclose a client's confidential information, as an October 2026 analysis by Rajesh Beri points out. For an engineering firm, that can cover drawings, calculations and reports. For a freight forwarder, shipment details and rates. For an insurance administrator, claim files.
The same analysis notes that de-identification may not cure a confidentiality clause. If the contract says the material is confidential, taking the client's name off it does not change the contract.
Troveo, a data licensing marketplace, lists third-party confidential material and data under contractual restriction among the categories it excludes or handles under explicit safeguards.
What about content you licensed from someone else?
Beri's analysis notes that knowledge bases routinely contain material the company does not own: analyst reports, licensed training content, vendor runbooks and software documentation. It says those licenses rarely allow redistribution. They need to come out.
What does privacy law restrict?
California. The CCPA applies to for-profit businesses that do business in California and meet any of three tests, including gross annual revenue of over $25 million, per the Attorney General's page, or buying, selling or sharing the personal information of 100,000 or more California residents or households. It gives people the right to opt out of the sale or sharing of their personal information. The exemptions for employment-related and business-to-business personal information expired on December 31, 2022.
Europe. Where the GDPR applies, Article 5(1)(b) says personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Beri's analysis argues that commercial AI training is a new purpose for a sales contact collected in order to sell.
Health. Under the HIPAA rule, health information counts as de-identified only by one of two routes: a qualified expert determines the risk of identification is very small, or 18 listed types of identifier are removed and the holder has no actual knowledge the rest could identify someone. Insurance and benefits administrators that handle health information should ask counsel whether this rule applies to them.
What about export-controlled work?
If your firm does defense-related work, some of your files may be technical data under ITAR. The definition covers information needed to design, develop or operate defense articles, such as blueprints, drawings and instructions. Treat any project like that as out of scope until your export counsel tells you otherwise.
Does removing names solve it?
For contract limits, not automatically. For privacy, only partly. A 2019 study in Nature Communications estimated that 99.98% of Americans could be correctly re-identified in any dataset using 15 demographic attributes.
The Spirit Airlines case shows how this plays out. Customer profiles were excluded from the proposed sale. Unions representing flight attendants still objected that personal information about former employees might not be properly redacted or anonymized, and the pilots' union argued some safety records should stay confidential even after de-identification, Fortune reported.
What is left?
Records of your own way of working are what buyers ask for. micro1's program page asks for standard operating procedures, knowledge bases, internal documents, project histories and quality checks. Your contracts and your counsel decide which of those you can include.
Sometimes little is left. If nearly everything you hold is client work under tight contracts, the honest answer is that this is not for your firm.
How do you sort it?
List your systems. For each one, mark who the content belongs to and which contracts touch it. Have your counsel read the list before any buyer sees a file. Be wary of any process that starts by asking for everything.
Next, read the terms that matter and how the process works. Sorting what is yours is also the second step of Pinprick's data licensing service.
Common questions
Can we license work we did for clients?
Often not without the client's consent. Client agreements and NDAs commonly restrict how you use and disclose the client's confidential information. Check each agreement with your own counsel before any of it is in scope.
Does removing names make client or personal data safe to license?
Not by itself. A confidentiality clause can still apply after names are removed, and research shows people can often be re-identified from other details. Treat de-identification as a safeguard on data you may license, not as a way to license data you may not.
Can we license our employees' emails and messages?
It carries real risk. For businesses the CCPA applies to, the exemptions for employment-related and business-to-business personal information expired on December 31, 2022. In the proposed Spirit Airlines sale, unions representing flight attendants objected that personal information about former employees might not be properly redacted or anonymized. Ask your counsel, and think about how your staff would react.
What do buyers ask for that is not client work?
micro1's program page asks for standard operating procedures, knowledge bases, internal documents, project histories and quality checks. Whether yours can be included depends on your contracts and on taking out client and personal details. That is a question for your own counsel.
What if nearly everything we hold is client work?
Then this may not be for you, and it is better to know early. Records you cannot license add nothing to a deal. A short rights review will tell you whether what is left is worth anyone's time.
Sources checked October 10, 2026
- The Daily Brief (Rajesh Beri), October 10, 2026: micro1 program terms and rights risks
- Troveo, August 20, 2026: Can a company license its data for AI?
- California Attorney General: CCPA overview and FAQ
- GDPR Article 5(1)(b): purpose limitation
- 45 CFR 164.514: HIPAA de-identification standard
- 22 CFR 120.33: ITAR definition of technical data
- Rocher, Hendrickx and de Montjoye, Nature Communications, July 23, 2019: re-identification in incomplete datasets
- Fortune, September 14, 2026: micro1's late bid for Spirit Airlines' data
- micro1: Enterprise Data Partnerships program page