Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The agreement states that Modal will not use Customer Data to train AI models or ingest Customer Data into large language models without the Customer's prior written consent, and that Input and Output from AI Tools are classified as Customer Data.
This analysis describes what Modal's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are classified as Customer Data, this prohibition extends to materials submitted to and generated by Modal's AI Tools.
Under this clause, Customer Data including AI tool inputs and outputs will not be used to train AI models or fed into large language models without Customer's prior written consent. The agreement classifies both Input submitted to AI Tools and Output generated by AI Tools as Customer Data, bringing both categories within this protection.
Cross-platform context
See how other platforms handle AI Model Training Prohibition Without Consent and similar clauses.
Compare across platforms →Monitoring
Modal has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Modal will not, except with Customer's prior written consent: (i) train any AI model using Customer Data, or (ii) export Customer Data into, or cause Customer Data to be ingested by, large language models.Excerpt from Modal's Terms of Service
(1) REGULATORY LANDSCAPE: This provision engages GDPR Article 5 (purpose limitation) and Article 22 (automated decision-making), as well as equivalent provisions under UK GDPR and US state privacy laws including CPRA. The EU AI Act's requirements around training data and transparency for general-purpose AI models may also be relevant depending on the nature of the AI Tools involved. Enforcement authorities include EU supervisory authorities, the UK ICO, and US state attorneys general. (2) GOVERNANCE EXPOSURE: Medium. The prohibition is clear as a contractual default, but the written consent mechanism means that Customers who grant consent without adequate internal review could inadvertently authorize AI training on sensitive business data. The definition of Customer Data as including AI Tool Input and Output means that query-level data, which may contain personally identifiable or commercially sensitive information, is covered. (3) JURISDICTION FLAGS: EU and UK Customers processing personal data through AI Tools should evaluate whether the purpose limitation under GDPR Article 5(1)(b) would independently restrict AI training use cases beyond this contractual provision. California Customers should assess whether CPRA's restrictions on use of personal information for secondary purposes add requirements beyond the contractual consent mechanism. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should confirm that no Service Orders or supplemental agreements inadvertently include consent to AI training as a standard term. Data processing agreements with downstream customers should be reviewed to confirm that the Customer's own obligations to data subjects are compatible with the consent-based carveout Modal reserves. (5) COMPLIANCE CONSIDERATIONS: Data protection officers should assess whether the written consent mechanism aligns with their organization's data governance policies, particularly for Customers processing special categories of personal data or regulated data types through AI Tools. Internal policies governing employee or end-user submissions to AI Tools should be reviewed in light of the classification of Input as Customer Data.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a contractual prohibition on AI model training using Customer Data as a default, requiring affirmative written consent before any such use. Because Input and Output are classified as Customer Data, this prohibition extends to materials submitted to and generated by Modal's AI Tools.
Under this clause, Customer Data including AI tool inputs and outputs will not be used to train AI models or fed into large language models without Customer's prior written consent. The agreement classifies both Input submitted to AI Tools and Output generated by AI Tools as Customer Data, bringing both categories within this protection.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Modal.