AI labs are paying for real business records.See what yours could be worth →

Checklist

Approached by an AI data buyer? Questions to ask before you say yes

Key takeaways

  • Before you share anything, including samples, find out who the buyer is, who they work for and where your records will end up.
  • Pin down exactly what they want: which systems and date ranges, raw or prepared records, and for what purposes.
  • Ask how records will be de-identified, who controls that process and what will be excluded entirely.
  • Get retention, deletion, exclusivity, payment timing and liability in writing, and have counsel review the agreement before you sign.

If an AI data buyer has contacted you, slow down before you share anything. Ask who they are and who they work for, exactly which records they want and why, how people in your records will be protected, how long they’ll keep the data, and what you’ll be paid and when. Then get the answers in writing.

Operating companies are now getting these calls regularly, according to lawyers at Frankfurt Kurnit Klein & Selz, who note that most companies can’t license everything a buyer requests and that the work involved is usually more than the offer suggests. The questions below will help you tell a good opportunity from a rushed one.

Before anything else: don’t share data yet

Don’t send exports, samples or logins on a first call. A sample is itself a disclosure, and it may include confidential client information or personal details you haven’t reviewed. Describe your systems and history instead. That’s enough for any serious buyer to say whether there’s a fit.

Who is the buyer, and who do they work for?

Start with the basics. Many approaches come from intermediaries rather than the company that will actually use the data.

  • What is your company’s legal name, and where is it based?
  • Are you buying for your own use, or on behalf of AI labs or other clients?
  • Who will be the end user of my records? Can that be named in the contract?
  • If someone referred you to me, who pays them, and how?
  • What’s your track record? Can you share references from businesses like mine?

What exactly do they want?

Vague requests produce vague contracts. Ask for specifics.

  • Which systems, record types and date ranges do you want?
  • Roughly how much data are you expecting, and in what format?
  • Do you want raw records, or records we prepare and de-identify first?
  • Is this a one-time license or a recurring feed?
  • What will make the data more or less valuable to you?

What will they use the records for?

Permitted use is the heart of the license.

  • Will the records be used to train AI models, to test (evaluate) them, or both?
  • Will they be used to build simulated work environments for AI agents?
  • Could the resulting models compete with my business or my clients?
  • Will you combine my records with other companies’ data?
  • Will my records, or anything derived from them, be resold or sublicensed?

How will the records be accessed and transferred?

How data moves is a security question as much as a logistics one.

  • Do you need access to our systems, or will we deliver an export?
  • Who on your side will see raw records, and where will they be stored?
  • How will data be encrypted in transit and at rest?
  • What are you prepared to commit to in writing about security incidents?

The Frankfurt Kurnit lawyers advise limiting who can see raw data before it’s de-identified and avoiding giving buyer tools direct access to company systems.

How will people and sensitive information be protected?

Ask about the method, not just the promise. “We anonymize everything” isn’t an answer.

  • Who performs de-identification, and can we approve the protocol?
  • Will names be replaced with consistent stand-ins across all sources, or simply removed?
  • How are identifiers like tax IDs, account numbers, addresses and passwords handled?
  • Which categories will be excluded entirely, such as legal correspondence, HR and payroll matters, health information and personal tax records?
  • What review passes happen before data leaves our control? Can we see a de-identified sample first?
  • Will you commit in writing not to re-identify anyone?

There’s real value at stake in these answers. In the Spirit Airlines bankruptcy auction, one bidder offered more if it could obtain the raw data first and anonymize it itself, Business Insider reported. Raw access can raise the price, and it also moves control of privacy to the buyer. For what good de-identification looks like, see how business records are de-identified.

How long will they keep the records, and what happens after?

Retention terms decide how long your risk lasts.

  • How long will you keep the raw records and any prepared datasets?
  • Will you delete or return them at the end of the term, and certify that you have?
  • What about backups and copies held by your contractors?
  • What happens to models already trained on the records if the license ends?

Be realistic about that last question. Once data is used to train a model, it can’t practically be pulled back out, as the Frankfurt Kurnit post notes. That’s why exclusions and use limits matter more than deletion promises.

Is the license exclusive?

  • Do you want exclusivity? For which records, and for how long?
  • What would a non-exclusive license be worth to you instead?
  • Are you asking for a no-shop period while we negotiate?

Exclusivity has value, so if a buyer wants it, it should be priced in. Be careful with no-shop clauses in early letters of intent, since they can stop you from comparing offers.

What will they pay, and when?

  • What is the total price, and how was it calculated?
  • Is payment up front, on delivery, in installments or tied to milestones?
  • Are there conditions that could reduce or delay payment, such as quality reviews?
  • For a recurring feed, how is each period priced?
  • Who pays for preparation and de-identification?

A single offer tells you what one buyer will pay. Our guide to what business data is worth covers the reported price points and what moves them.

Who carries the risk if something goes wrong?

Read the warranty and indemnity sections closely. Buyers often ask sellers to promise they have the right to license everything delivered.

  • What representations and warranties do you expect from me?
  • Will you indemnify us if your use of the data causes a claim?
  • Is liability capped, and at what amount, for each side?
  • What happens if a client or employee objects after delivery?

Our guide to AI data license agreement terms explains these clauses in plain English.

What happens if the buyer is acquired or shuts down?

Data outlives companies. The Spirit Airlines case itself began with a company in bankruptcy.

  • If your company is acquired, does the license transfer to the new owner?
  • If you shut down or go bankrupt, must the records be deleted rather than sold?
  • Can you assign or sublicense the agreement without our consent?

Red flags to watch for

Proceed carefully if a buyer:

  • Pushes for samples, exports or system access before any agreement.
  • Won’t say who the end user of the data will be.
  • Describes de-identification only in general terms.
  • Wants exclusivity or a no-shop period without paying for it.
  • Asks you to warrant that you have rights to everything, with no limits.
  • Sets a short deadline that leaves no time for counsel to review.

How to compare offers

Put every offer side by side on the same terms: price, payment timing, permitted uses, exclusivity, retention, de-identification control, warranties and liability. A higher price with broad rights and unlimited liability can be worth less than a lower one with tight limits.

If you’d rather not run that process yourself, a seller-side representative can do it for you. Our comparison of marketplaces, buyer programs and representation explains the trade-offs, and our pillar guide covers how to license your business data from start to finish.

Cascade represents established businesses in exactly these conversations. We compare offers, negotiate price and terms, and keep you to the decisions that matter. Rights and privacy are reviewed before any records are shared, and we’re paid a success fee only. If a buyer has already reached out, tell us about it before you reply.

This checklist is general information, not legal advice. Review any agreement with your own counsel.

Frequently asked questions

Should I send a sample of my data to a buyer who asks for one?

Not before you've reviewed rights and privacy. A sample is itself a disclosure. If a buyer needs to see examples, share a de-identified sample under a confidentiality agreement, after you've decided what is in scope and what stays out.

Is it a red flag if a buyer wants my raw data?

Not automatically, but it changes who controls privacy. Some buyers pay more for raw records they de-identify themselves. If you agree to that, the contract should specify the de-identification protocol, who can see raw records, how they're secured and when they're deleted.

Can I talk to more than one buyer?

Usually, yes, as long as you haven't signed an exclusivity or no-shop clause. Comparing offers is the only way to know whether a price is fair, so read any letter of intent carefully before you sign it.

The person who contacted me isn't the buyer. Does that matter?

It can. Many approaches come from intermediaries or referral partners. Ask who they work for, how they're paid and who the end user of your records will be, since that's who you're really granting rights to.

This guide is part of our series on how to license your business data to AI labs.

Related guides

Start here

Let’s talk about what you’ve built.

A conversation is all it takes to start. No files or login details needed.

Request a free consultation Get your estimate first
  • You pay nothing unless a license is signed
  • You approve every term