「学習をオフにしているから大丈夫」。AIを使うフリーランスからよく聞く言葉で、私自身も独立した当初はそう考えていた。調べていくと、この認識は半分だけ正しい。学習に使われるかどうかと、データが相手のサーバーに渡るかどうかは、別の問題だからだ。
フリーランスコンサルタントとして業務委託契約を結びながらAIを使い倒してきた立場から、確認してきたことを整理する。なお本稿は法的助言ではなく、契約と利用規約の確認を促すための整理である点を先に断っておく。
事実の整理──「学習」と「保存」は別の話
主要サービスの公式ポリシーを確認すると、構造はどのサービスもおおむね共通している。
個人向けプランは、学習利用が初期設定で有効になっているものが多い。 ChatGPTのFree/Plusでは会話が既定でモデル学習に使われ、オフにするには設定からオプトアウトする必要がある。Claudeも2025年8月の規約改定でFree/Pro/Maxの会話を学習に使うかの選択制になったが、報道では設定画面のトグルの初期値はオンとされており、使われたくなければ自分でオフにする必要がある。GeminiやCopilotの個人向け版にも同種の仕組みがある。
そして重要なのは、学習をオフにしてもデータの送信と保存は残ることだ。 ChatGPTでは学習をオフにしても、新規チャットは不正利用監視のため最大30日間サーバーに保持される。Claudeは学習を許可した場合、対象チャットが非識別化のうえ最大5年間保持される(オフなら削除後30日以内にバックエンドから消去)。さらに2025年には、米国の訴訟に伴う裁判所命令でOpenAIが削除済みチャットを含むデータを一時的に無期限保持する義務を負った実例もある(同年9月に終了)。設定でどう選ぼうと、入力した瞬間にデータが第三者のサーバーに渡るという事実は変わらない。
法人向けプランとAPIは扱いが根本的に違う。 ChatGPTのTeam/EnterpriseやAPI、Claudeの商用プラン(Team/Enterprise/API)では、入出力は既定で学習に使われない。API利用では審査制のゼロデータ保持(ZDR)契約も用意されている。「どのサービスか」だけでなく「どのプラン・どの契約形態か」でデータの行き先が変わる。
契約書の論点──入力自体が「開示」になりうる
ここからが本題で、業務委託契約との関係だ。
法律事務所の解説(STORIA法律事務所)では、秘密保持条項がある場合、生成AIサービスへの秘密情報の入力(送信)行為自体が、契約上の「第三者への開示」に該当しうると整理されている。学習に使われるかどうか以前に、送信そのものが論点になるということだ。加えて、入力情報がAI事業者の学習に利用される場合は秘密情報の目的外利用に該当しうること、顧客の個人情報の入力は個人情報保護法上の第三者提供の論点になりうることも指摘されている。
契約書によっては、データの国外持ち出しや特定サーバー以外への保管を制限する条項が入っていることもある。主要な生成AIサービスの多くは海外にサーバーを置くため、こうした条項がある契約でのAI利用は確認なしには進められない。
公的な整理も進んでいる。経済産業省は2025年2月に「AIの利用・開発に関する契約チェックリスト」を公表し、AIサービス事業者による学習利用を「学習に利用されない/汎用的な学習に利用される/サービス提供に必要な範囲でのみ利用される」の3パターンに分けて契約時の確認を促している。IPAやJDLAのガイドラインでも、他社から秘密保持義務を課されて開示された情報や自組織の機密情報を入力に使わないことが注意事項として挙げられている。
受託者側のチェックリスト
以上を踏まえて、私が案件開始時に確認している項目を挙げる。
- 契約書にAI利用に関する条項があるか。 利用可・不可・事前承認制のどれかが書かれていれば、それに従う。書かれていなければ次へ
- 扱う情報のうち、何が契約上の秘密情報に当たるか。 公開情報の調査・一般論の壁打ちと、クライアント固有情報の処理を区別する
- 使うサービスのプランとデータの扱い。 個人向けプランの既定設定のままクライアント情報を扱わない。商用プラン・API・ZDRの利用を検討する
- 秘密情報を扱う必要がある場合は、事前に書面で確認を取る。 使うサービス名・プラン・用途を具体的に示して承諾を得る
- 入力の工夫で回避できないか。 固有名詞の置き換え、数値の抽象化、構造だけの相談に落とせないかを先に考える
3分で終わる確認だが、これを飛ばして事故が起きた場合に失うものは大きい。
発注側への提言──契約書に書いてほしいこと
逆の立場から言うと、企業がフリーランスや外部ベンダーに業務を委託する際、AI利用について契約書が沈黙しているのが一番危うい。受託者ごとに判断がバラつき、良かれと思って個人向けプランに秘密情報を入力する人が出る。
実務解説では、受託者が生成AIを利用する場合の事前通知・承諾条項や、秘密情報をAIサービスへの入力に使う場合の書面承諾条項の条文例が紹介されている。最低限、①AI利用の可否と条件(許容するサービス・プラン)、②入力してよいデータの区分、③学習利用されない設定・契約形態の義務付け、の3点を契約書に明記しておけば、受託者側も迷わない。
規約は頻繁に変わる。Claudeの2025年8月の規約改定のように、前提が1回の更新で変わることは今後も起きる。確認した日付とともに記録を残し、案件の開始時に見直す。地味だが、この習慣がフリーランスの信用を守ると考えている。
出典
- OpenAI「Data Controls FAQ」「Enterprise privacy at OpenAI」「Data controls in the OpenAI platform」 — https://help.openai.com/en/articles/7730893-data-controls-faq / https://openai.com/enterprise-privacy/ / https://developers.openai.com/api/docs/guides/your-data
- OpenAI「How we're responding to The New York Times' data demands」2025年 — https://openai.com/index/response-to-nyt-data-demands/
- Anthropic「Updates to Consumer Terms and Privacy Policy」2025年 — https://www.anthropic.com/news/updates-to-our-consumer-terms
- Anthropic Privacy Center「Is my data used for model training?」「How long do you store my data?」 — https://privacy.claude.com/en/articles/10023580 / https://privacy.claude.com/en/articles/10023548
- Anthropic「API and data retention」 — https://platform.claude.com/docs/en/manage-claude/api-and-data-retention
- Google「Gemini Apps プライバシーに関するヘルプ」 — https://support.google.com/gemini/answer/13594961
- Microsoft「Privacy FAQ for Microsoft Copilot」 — https://support.microsoft.com/en-us/topic/privacy-faq-for-microsoft-copilot-27b3a435-8dc9-4b55-9a4b-58eeb9647a7f
- STORIA法律事務所「生成AIと秘密情報の入力」 — https://storialaw.jp/blog/13047
- 経済産業省「AIの利用・開発に関する契約チェックリスト」2025年2月 — https://www.meti.go.jp/press/2024/02/20250218003/20250218003.html
- IPA「テキスト生成AIの導入・運用ガイドライン」2024年 — https://www.ipa.go.jp/jinzai/ics/core_human_resource/final_project/2024/generative-ai-guideline.html
- JDLA「生成AIの利用ガイドライン」第1.1版 2023年 — https://www.jdla.org/news/202310060002/
※各サービスの規約・ポリシーは頻繁に改定されます。本稿の記載は執筆時点の公式情報の確認に基づきますが、利用判断の際は必ず最新の公式ページを確認してください。
"I turned off training, so it's fine." I hear this constantly from freelancers who use AI, and I believed it myself when I first went independent. Look closer and the belief is only half right — whether your data trains a model and whether your data reaches someone else's server are two different questions.
What follows is how I now handle this as an independent consultant working under NDAs, based on what I have verified in official policies. This is not legal advice; it is an argument for reading your contract and your AI vendor's terms before you paste.
The facts: training and storage are separate issues
Check the official policies of the major services and a common structure emerges.
Consumer plans often have training enabled by default. ChatGPT Free/Plus conversations are used for model training unless you opt out in settings. Claude moved to a choice-based model for Free/Pro/Max accounts in an August 2025 terms update — though press coverage notes the settings toggle defaults to on, so staying out still requires action. Consumer versions of Gemini and Copilot have similar mechanisms.
More importantly, opting out of training does not stop transmission and storage. ChatGPT retains new chats for up to 30 days for abuse monitoring even with training off. Claude retains training-eligible chats for up to five years when training is enabled (with training off, deleted chats leave the backend within 30 days). In 2025, a US court order in litigation forced OpenAI to preserve even deleted consumer chats indefinitely for a period (the obligation ended that September). Whatever you choose in settings, the moment you press enter, the data is on a third party's server.
Business plans and APIs are structurally different. ChatGPT Team/Enterprise and the API, and Claude's commercial plans (Team/Enterprise/API), do not use inputs and outputs for training by default, and approval-based zero data retention (ZDR) arrangements exist for API use. Where your data goes depends not just on which service, but on which plan and contract form.
The contract issue: input itself can constitute "disclosure"
Now the part that matters for anyone working under a services agreement.
Japanese legal commentary (Storia Law) frames it this way: where a confidentiality clause exists, the act of entering confidential information into a generative AI service — the transmission itself — can constitute "disclosure to a third party" under the contract, regardless of whether the data is used for training. Separately, if the input is used for the vendor's model training, that can amount to use beyond the contractual purpose; and entering client personal data raises third-party-provision issues under data protection law.
Some contracts also restrict storing data outside the country or outside designated servers. Most major AI services run on servers overseas, so under such clauses AI use is simply not something to proceed with unchecked.
Public-sector guidance is catching up. Japan's METI published a contract checklist for AI use in February 2025, sorting vendor training practices into three patterns (not used for training / used for general training / used only as needed to provide the service) and urging parties to verify which applies. IPA and JDLA guidelines likewise flag information received under NDA and internal confidential information as data that should not be entered.
A checklist for the contractor side
What I check at the start of every engagement:
- Does the contract say anything about AI use? If it specifies allowed / prohibited / prior-approval, follow it. If silent, continue
- Which information in scope counts as confidential under the contract? Separate public-information research and generic sparring from processing client-specific data
- Which service, which plan, what data handling? Never process client information on a consumer plan's default settings; consider commercial plans, API, or ZDR
- If confidential data must be involved, get written confirmation first. Name the service, plan and use, and get sign-off
- Can the input be de-identified instead? Swap proper nouns, abstract the numbers, reduce the question to structure
The check takes three minutes. Skipping it and having an incident costs a freelancer the one thing that is hard to rebuild: trust.
A note to the buying side
From the other direction: when a company hires freelancers or vendors, the most dangerous contract is the one that says nothing about AI. Each contractor then improvises, and someone will paste confidential material into a consumer plan with the best of intentions.
Practitioner commentary offers model clauses — prior notice and approval for generative AI use, written consent before confidential information touches an AI service. At minimum, put three things in the contract: whether and under what conditions AI may be used (which services and plans), what classes of data may be entered, and a requirement for non-training configurations or contract forms. Your contractors will thank you for the clarity.
Terms change often — Claude's August 2025 consumer terms update is a case in point. Record what you verified and when, and re-check at the start of each engagement. It is unglamorous work, and it is exactly the kind of habit that keeps an independent consultant's reputation intact.
Sources
Same as the Japanese edition above (OpenAI data controls and enterprise privacy documentation; OpenAI statement on the NYT litigation data demands, 2025; Anthropic consumer terms update, 2025; Anthropic Privacy Center and API data retention documentation; Google Gemini Apps privacy help; Microsoft Copilot privacy FAQ; Storia Law commentary on generative AI and confidential information; METI contract checklist for AI use and development, Feb 2025; IPA text-generation AI guideline, 2024; JDLA generative AI usage guideline v1.1, 2023). Policies change frequently — verify against the current official pages before relying on them.
KATAは、戦略コンサルタントがAIを実務に入れる過程を記録している個人サイトです。