Docusign just admitted that they use customer data to train AI
DocuSign’s updated AI FAQ reveals that it may use customer documents to train its proprietary AI models, raising concerns about privacy, consent, and the feasibility of truly anonymizing sensitive contract data. Commenters question whether “contractual consent” buried in terms of service can be considered genuine opt-in, especially when services like DocuSign are effectively mandatory for many jobs and business relationships. Others note this reflects a broader trend of SaaS platforms mining user data for AI, while DocuSign later clarified that only customers in specific AI programs who give explicit consent have their de-identified data used for training.
Source and link handling
- Some object to using a screenshot tweet instead of the original DocuSign FAQ, noting the article is public.
- Others argue screenshots avoid later edits by DocuSign; counterpoint is that archive links (Wayback, archive.is) are better than random screenshots.
- Another reason given: Twitter downranks posts with links, so people lead with images.
What DocuSign says it does
- FAQ text (quoted in the thread) says data may be used to train DocuSign’s in-house AI “if you have given contractual consent,” with anonymization/de-identification.
- A later DocuSign response (linked) claims they only train on data from customers who explicitly consent as part of specific AI products/betas, and only after de-identification.
- Some note the headline overstates things: for OpenAI/Microsoft chat features, they use paid APIs that purportedly don’t retain data.
Consent, “contractual consent,” and legality
- Debate over whether “contractual consent” is genuine opt‑in or just a buried clause in terms.
- Several argue that under GDPR, consent cannot be bundled into a contract like this and must be informed, retractable, and uncoerced.
- Others note DocuSign’s privacy policy basis “Consent (where required)” implies use without consent where law allows.
Privacy, anonymization, and AI training risks
- Many emphasize that reliably anonymizing arbitrary customer documents, especially free text with PII, is effectively impossible.
- Concerns include models regurgitating confidential clauses, settlement terms, passwords, or personal details.
- Some highlight non-material harms: violation of expectations of confidentiality and ownership of data, especially for a service marketed on security/compliance.
- A minority argue anonymization plus removal of form fields might be enough, and actual leakage risk may be small, but this is contested.
Use cases and motives for AI in e‑signing
- Proposed legitimate uses: contract generation, extension, validation, loophole detection, fraud/abuse detection (fake or reused IDs, AI-generated documents).
- Others suspect “AI” is mainly investor hype and monetization of contract data; “data is the new money.”
User power, regulation, and alternatives
- Some suggest regulation (e.g., a “Don’t train AI on my personal information” control like other privacy links or headers).
- There’s pessimism that most SaaS will mine data regardless, so people should encrypt or self-host where possible.
- One self-hosted alternative (Docuseal) is mentioned.
- Concern that individuals often cannot meaningfully refuse: employers, banks, and others choose DocuSign, and using it can be tied to jobs or financial services.
Overall sentiment
- Predominantly skeptical and critical of DocuSign’s approach, especially around consent and anonymization.
- Some see practical benefits and accept AI use with strict consent and safeguards, but trust in implementation and enforcement is low.