← Insights
Governance & shadow AI

Why "your data never trains a public model" is a promise you should demand in writing.

TanX Labs6 min readUpdated 2026

Every AI vendor says some version of "we do not train on your data." Said in a sales call, that sentence is worth nothing. Written into a contract, with a defined technical mechanism behind it, it is worth everything. The gap between the two is where the risk lives.

What "zero retention" actually has to mean

A genuine zero retention guarantee is a specific, checkable claim: your inputs are not stored beyond the request, not used in any training run, present or future, and not accessible to the vendor's own staff for review. 2026 governance guidance is explicit that enterprises should evaluate whether frontier model vendors offer real zero retention modes, content filtering, and redact on ingest, not just a line in the terms of service.

The question to actually ask

"Can you point to the specific clause in our contract, not your public terms of service, that guarantees zero retention and zero training, and what technical control enforces it?"

If a vendor cannot answer that in writing, in a contract you have both signed, the marketing language means nothing. Public terms of service can change unilaterally. A negotiated contract clause cannot.

Why this matters more as adoption grows

The volume of sensitive data reaching AI tools has grown sharply: one industry estimate puts the year over year increase in data shared with AI tools at close to 500%. As that volume grows, a vague promise stops being a minor gap and starts being the largest unmanaged risk on the books.

Where TanX Labs draws this line

Every AI provider we route through is chosen partly on this basis. Your data stays yours, never used to train anyone else's model, and that is a commitment we put in writing, not a slide in a deck.