Articulate's AI training promise now covers only generative models

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
Articulate 360's new Terms of Service, Privacy Notice, and subprocessor list are dated September 10, 2026.
The old terms barred training "any AI or machine learning models" on your content, and the new ones bar training "generative AI models" unless you authorize it.
Articulate can now create and own "Derived Structural Data," which is the pattern of your courses with the text, media, and names removed.
Articulate's own summary of the update lists "We don't train AI models on your content" among the commitments that "remain unchanged."
Custom avatars bring facial images and facial geometry into the Privacy Notice, with you as the party responsible for consent.
Several edits favor customers, including 30 days' notice of material changes and AI output indemnity for customers of every size.
What to do: If you build courses in Articulate 360, read sections 5.4 and 5.5 of the new terms yourself, and get written consent from anyone whose face or voice you turn into an avatar.
The change
Articulate makes Articulate 360, a set of tools that companies use to build workplace training. On September 10, 2026, it replaced the Terms of Service that had been in effect since January 15, 2026, and updated its Privacy Notice, Data Processing Agreement, and subprocessor list on the same day.
Articulate handled the update more openly than many vendors do. It published a summary of the changes and kept the previous version available as a PDF. That makes a line-by-line comparison possible, and the comparison shows that the clause many customers look at first, the one on AI training, did not stay the same.
What changed
AI training. The old clause said: "Articulate will not use Customer Content, including Input or Output, to train any AI or machine learning models." The new one covers "any generative AI models" and adds "unless Customer expressly authorizes such use."
Derived data. A new section lets Articulate create "De-Identified Data and Derived Structural Data" from customer content, usage data, and personal data, and says Articulate owns what it creates.
Avatars and biometric data. The Privacy Notice has a new section on Custom Photorealistic Avatars, and the subprocessor list now says which provider powers them.
Credits. Some features can now be paid for with credits, which "expire at the end of the Subscription Term."
Time to bring a claim. A new clause says claims for damages, other than non-payment, "must be commenced in an action within 12 months of when the claim accrues."
Work email accounts. If an account is created with an email address owned by an organization, that organization "may be able to claim, administer, access, restrict, transfer, or delete the account and associated Customer Content."
Edits in the customer's favor. Articulate now gives 30 days' notice of material changes, promises not to degrade purchased services during the term, extends its AI output indemnity to all customers, commits to report security incidents within 72 hours where feasible, and raises the liability cap for privacy and confidentiality claims to three times the general cap.
From "any AI or machine learning models" to "generative AI models"
The new clause, section 5.5, reads: "Articulate will not, and does not permit others to use Customer Content to train, re-train, fine-tune, or otherwise adjust the weights or parameters of any generative AI models unless Customer expressly authorizes such use." Set against the old sentence, three things moved.
The promise used to cover any AI or machine learning model. It now names generative AI models, and the clause does not mention other kinds.
The promise used to have no exception. It now has one, and it depends on the customer's express authorization.
A new sentence allows Articulate to use customer content to "provide, configure, evaluate, improve, or operate customer-specific features, prompts, workflows, retrieval layers, models, or intelligence features for Customer's benefit."
The new wording is also tighter in places. It covers fine-tuning and adjusting model weights, it extends to third parties through the words "does not permit others," and the terms add that Articulate "will not use Customer Content to generate materials for, or respond to the requests of, any other customer." So this is not a vendor opening the door to training on your courses. It is a broad promise replaced by a narrower and more detailed one, as happened when Apple's promise not to train AI on your data gained an exception and when Snyk added an AI training exception.
The data Articulate now owns
Section 5.4 introduces two categories that the January terms did not have. De-Identified Data is data derived from customer content, usage data, or personal data that can no longer reasonably be used to identify a person, a customer, or the substance of a customer's proprietary content. Derived Structural Data is defined as "the structural, logical, and technical patterns of Customer Content including, course flow, branching logic, interaction types," with all text, media, names, and other identifying content removed.
In plain terms, that second category is the shape of a course without its words: how it is ordered, where it branches, and which kinds of interactions it uses. Articulate may keep and use both categories to "operate, maintain, protect, analyze, develop, test, benchmark, tune, and improve the Services and the models, prompts, retrieval layers, classifiers, systems, and features that support them." On ownership the section is direct: "Articulate owns the De-Identified Data and Derived Structural Data that it creates."
The section comes with limits. It says it does not permit training generative AI models on customer content. Articulate will not try to re-identify the data except to test its own process, will not disclose it outside its service providers except in aggregated form, and must stop using it if it turns out to identify a customer or allow a course to be reconstructed. The definition also excludes customer-specific methodologies and confidential business practices.
What Articulate's summary says
Articulate calls its summary "an informal, high-level summary," and it is accurate on most points. It does mention the new framework for de-identified and structural data. On three points the comparison shows more than the summary does.
The summary lists "We don't train AI models on your content" under commitments that "remain unchanged," while the clause itself went from all AI and machine learning models to generative AI models with an authorization exception.
The summary says Articulate may create and use the derived data. It does not say that Articulate owns it.
The 12-month limit on bringing claims and the rule on accounts created with an organization's email address are not mentioned.
The summary page has its own history. Its January section now reads "We don't train foundation models on your content without your permission," although the January terms covered "any AI or machine learning models." Venpo's record of the page shows that this line was edited in late August 2026, before the new terms took effect, and that it used to read "We don't train AI models on your data." A summary tells you what a vendor chose to highlight, which is the point we made when X's new terms dropped a promise its summary did not mention.
Avatars bring biometric data into the Privacy Notice
The old Privacy Notice named biometric data in a list of sensitive data that Articulate does not knowingly collect. The new one has a section for a feature that lets customers create an AI avatar of a real person. It lists "Facial images and photographs you upload" and "Biometric Data including facial geometry extracted from your submissions," and it refers to the Illinois and Texas biometric privacy laws.
Two sentences set the roles. "Articulate is a Processor of the Biometric Data collected through the Custom Photorealistic Avatar feature, and the Customer is the Controller." And: "Articulate does not process your biometric data to uniquely identify you." The Terms of Service add that the customer is responsible for notices and consents for individuals whose "likeness, voice, biometric information, or content" goes through the services. The subprocessor list changed with it: the entry for Features & Labels (FAL) now reads "Powers AI features, including image generation and Custom Photorealistic Avatars." Changes like that one are the reason to monitor AI subprocessors along with the terms.
What did not change
You still own your content, and the terms still say Articulate does not claim ownership of it.
Articulate still deletes customer content on request or "six (6) months after expiration or termination of the Subscription Term," whichever comes first.
New York law and the courts of New York County still govern disputes.
Articulate still has to give 45 days' written notice before changing fees for a renewal term.
Why this matters
Training courses are not generic content. They hold a company's internal processes, product knowledge, compliance procedures, and sometimes the faces and voices of its own people. For many teams the AI training clause is the one line they check before approving a tool like this, and some will have recorded it in a vendor review as a flat ban on AI training.
That record is now out of date in a specific way. The promise still exists, but it is narrower, it has an exception, and it sits next to a new right for Articulate to own data derived from how courses are built. None of it is hidden, and much of the update favors customers. It still takes reading the clause, not the summary, to see it, which is what vendor contract monitoring is for.
Potential impact
If you use Articulate 360, the update raises five practical questions:
Does your vendor record describe Articulate's AI commitment in the new wording, or in the old one?
Do your courses contain structure you consider your own, such as assessment logic or branching scenarios?
Has anyone's face or voice been used for an avatar, and do you have their consent on file?
Will you have unused credits when your subscription term ends?
Which accounts were created with work email addresses, and who should control them when someone leaves?
How Venpo detected it
Venpo monitors Articulate's legal documents as part of continuous vendor risk monitoring. It recorded the new Terms of Service, Privacy Notice, and subprocessor list when they replaced the earlier versions, and marked what was added and removed. Every quote in this article was checked against both versions, the live pages, and Articulate's own archived PDF. The redlines are on the Terms of Service change page and the Privacy Notice change page, and every monitored Articulate document is listed on the Articulate vendor profile.
Business outcome
Teams that track Articulate saw the old and new training clauses side by side, together with the new ownership clause that the summary does not spell out. That is enough to update a vendor record, brief the people who build courses, and decide whether avatars need a consent step. A team that read only the summary came away with "We don't train AI models on your content" and no reason to look further.
Key takeaway
Articulate's promise not to train AI on customer content went from every AI and machine learning model to generative AI models, gained an exception for customer authorization, and now sits beside a clause that lets Articulate own de-identified and structural data derived from courses. Articulate's summary calls the commitment unchanged, so the reliable way to see the difference is to monitor vendor terms of service and compare the text.
The change
Articulate makes Articulate 360, a set of tools that companies use to build workplace training. On September 10, 2026, it replaced the Terms of Service that had been in effect since January 15, 2026, and updated its Privacy Notice, Data Processing Agreement, and subprocessor list on the same day.
Articulate handled the update more openly than many vendors do. It published a summary of the changes and kept the previous version available as a PDF. That makes a line-by-line comparison possible, and the comparison shows that the clause many customers look at first, the one on AI training, did not stay the same.
What changed
AI training. The old clause said: "Articulate will not use Customer Content, including Input or Output, to train any AI or machine learning models." The new one covers "any generative AI models" and adds "unless Customer expressly authorizes such use."
Derived data. A new section lets Articulate create "De-Identified Data and Derived Structural Data" from customer content, usage data, and personal data, and says Articulate owns what it creates.
Avatars and biometric data. The Privacy Notice has a new section on Custom Photorealistic Avatars, and the subprocessor list now says which provider powers them.
Credits. Some features can now be paid for with credits, which "expire at the end of the Subscription Term."
Time to bring a claim. A new clause says claims for damages, other than non-payment, "must be commenced in an action within 12 months of when the claim accrues."
Work email accounts. If an account is created with an email address owned by an organization, that organization "may be able to claim, administer, access, restrict, transfer, or delete the account and associated Customer Content."
Edits in the customer's favor. Articulate now gives 30 days' notice of material changes, promises not to degrade purchased services during the term, extends its AI output indemnity to all customers, commits to report security incidents within 72 hours where feasible, and raises the liability cap for privacy and confidentiality claims to three times the general cap.
From "any AI or machine learning models" to "generative AI models"
The new clause, section 5.5, reads: "Articulate will not, and does not permit others to use Customer Content to train, re-train, fine-tune, or otherwise adjust the weights or parameters of any generative AI models unless Customer expressly authorizes such use." Set against the old sentence, three things moved.
The promise used to cover any AI or machine learning model. It now names generative AI models, and the clause does not mention other kinds.
The promise used to have no exception. It now has one, and it depends on the customer's express authorization.
A new sentence allows Articulate to use customer content to "provide, configure, evaluate, improve, or operate customer-specific features, prompts, workflows, retrieval layers, models, or intelligence features for Customer's benefit."
The new wording is also tighter in places. It covers fine-tuning and adjusting model weights, it extends to third parties through the words "does not permit others," and the terms add that Articulate "will not use Customer Content to generate materials for, or respond to the requests of, any other customer." So this is not a vendor opening the door to training on your courses. It is a broad promise replaced by a narrower and more detailed one, as happened when Apple's promise not to train AI on your data gained an exception and when Snyk added an AI training exception.
The data Articulate now owns
Section 5.4 introduces two categories that the January terms did not have. De-Identified Data is data derived from customer content, usage data, or personal data that can no longer reasonably be used to identify a person, a customer, or the substance of a customer's proprietary content. Derived Structural Data is defined as "the structural, logical, and technical patterns of Customer Content including, course flow, branching logic, interaction types," with all text, media, names, and other identifying content removed.
In plain terms, that second category is the shape of a course without its words: how it is ordered, where it branches, and which kinds of interactions it uses. Articulate may keep and use both categories to "operate, maintain, protect, analyze, develop, test, benchmark, tune, and improve the Services and the models, prompts, retrieval layers, classifiers, systems, and features that support them." On ownership the section is direct: "Articulate owns the De-Identified Data and Derived Structural Data that it creates."
The section comes with limits. It says it does not permit training generative AI models on customer content. Articulate will not try to re-identify the data except to test its own process, will not disclose it outside its service providers except in aggregated form, and must stop using it if it turns out to identify a customer or allow a course to be reconstructed. The definition also excludes customer-specific methodologies and confidential business practices.
What Articulate's summary says
Articulate calls its summary "an informal, high-level summary," and it is accurate on most points. It does mention the new framework for de-identified and structural data. On three points the comparison shows more than the summary does.
The summary lists "We don't train AI models on your content" under commitments that "remain unchanged," while the clause itself went from all AI and machine learning models to generative AI models with an authorization exception.
The summary says Articulate may create and use the derived data. It does not say that Articulate owns it.
The 12-month limit on bringing claims and the rule on accounts created with an organization's email address are not mentioned.
The summary page has its own history. Its January section now reads "We don't train foundation models on your content without your permission," although the January terms covered "any AI or machine learning models." Venpo's record of the page shows that this line was edited in late August 2026, before the new terms took effect, and that it used to read "We don't train AI models on your data." A summary tells you what a vendor chose to highlight, which is the point we made when X's new terms dropped a promise its summary did not mention.
Avatars bring biometric data into the Privacy Notice
The old Privacy Notice named biometric data in a list of sensitive data that Articulate does not knowingly collect. The new one has a section for a feature that lets customers create an AI avatar of a real person. It lists "Facial images and photographs you upload" and "Biometric Data including facial geometry extracted from your submissions," and it refers to the Illinois and Texas biometric privacy laws.
Two sentences set the roles. "Articulate is a Processor of the Biometric Data collected through the Custom Photorealistic Avatar feature, and the Customer is the Controller." And: "Articulate does not process your biometric data to uniquely identify you." The Terms of Service add that the customer is responsible for notices and consents for individuals whose "likeness, voice, biometric information, or content" goes through the services. The subprocessor list changed with it: the entry for Features & Labels (FAL) now reads "Powers AI features, including image generation and Custom Photorealistic Avatars." Changes like that one are the reason to monitor AI subprocessors along with the terms.
What did not change
You still own your content, and the terms still say Articulate does not claim ownership of it.
Articulate still deletes customer content on request or "six (6) months after expiration or termination of the Subscription Term," whichever comes first.
New York law and the courts of New York County still govern disputes.
Articulate still has to give 45 days' written notice before changing fees for a renewal term.
Why this matters
Training courses are not generic content. They hold a company's internal processes, product knowledge, compliance procedures, and sometimes the faces and voices of its own people. For many teams the AI training clause is the one line they check before approving a tool like this, and some will have recorded it in a vendor review as a flat ban on AI training.
That record is now out of date in a specific way. The promise still exists, but it is narrower, it has an exception, and it sits next to a new right for Articulate to own data derived from how courses are built. None of it is hidden, and much of the update favors customers. It still takes reading the clause, not the summary, to see it, which is what vendor contract monitoring is for.
Potential impact
If you use Articulate 360, the update raises five practical questions:
Does your vendor record describe Articulate's AI commitment in the new wording, or in the old one?
Do your courses contain structure you consider your own, such as assessment logic or branching scenarios?
Has anyone's face or voice been used for an avatar, and do you have their consent on file?
Will you have unused credits when your subscription term ends?
Which accounts were created with work email addresses, and who should control them when someone leaves?
How Venpo detected it
Venpo monitors Articulate's legal documents as part of continuous vendor risk monitoring. It recorded the new Terms of Service, Privacy Notice, and subprocessor list when they replaced the earlier versions, and marked what was added and removed. Every quote in this article was checked against both versions, the live pages, and Articulate's own archived PDF. The redlines are on the Terms of Service change page and the Privacy Notice change page, and every monitored Articulate document is listed on the Articulate vendor profile.
Business outcome
Teams that track Articulate saw the old and new training clauses side by side, together with the new ownership clause that the summary does not spell out. That is enough to update a vendor record, brief the people who build courses, and decide whether avatars need a consent step. A team that read only the summary came away with "We don't train AI models on your content" and no reason to look further.
Key takeaway
Articulate's promise not to train AI on customer content went from every AI and machine learning model to generative AI models, gained an exception for customer authorization, and now sits beside a clause that lets Articulate own de-identified and structural data derived from courses. Articulate's summary calls the commitment unchanged, so the reliable way to see the difference is to monitor vendor terms of service and compare the text.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
