Every AI vendor contract I have reviewed in the last year has similar architecture, and once you see it you cannot unsee it. The vendor is selling you a tool whose behavior it cannot fully specify, that it reserves the right to change at any time, that it does not warrant to be accurate, and for which it accepts capped liability. The contract exists to move the uncertainty of the technology from the company that built it to the company that is using it.

That's not a criticism. It's a description of the product. The vendor isn't selling you certainty. It's selling you capability and allocating to you the risk that comes with it.

This is the article I would have wanted every client to read before they clicked “I agree.” It's not a general treatment of vendor contracts — that's a longer conversation about commercial agreements broadly. This is specifically about what changes when the thing being licensed is a model rather than a program, and what to negotiate before you sign.

The central idea: in an AI purchase, the contract is not paperwork attached to the product. The contract is the product, because it's the only thing that determines what you actually bought.

Why the AI Vendor Contract Is Different

Conventional software does what it was written to do. When it doesn't, that's a bug, the vendor can reproduce it, and a warranty that the software will perform substantially in accordance with documentation means something. The entire apparatus of software licensing — acceptance testing, warranty periods, service credits — rests on the premise that the product's correct behavior can be described in advance.

A model doesn't have a specification in that sense. It has a distribution of behaviors. The same prompt can produce different outputs on different days. The model can be updated, retrained, or replaced under the same product name without the vendor changing a line of the contract. Its outputs can be legally consequential — a hiring recommendation, a credit decision, a medical suggestion — in ways that a spreadsheet's outputs typically are not.

Almost every AI-specific clause in a vendor contract exists to allocate that uncertainty, and most of them, in the default version, allocate it to you. Six clauses matter most.

Clause 1: Data Training Rights

The default in most business-tier and consumer-tier AI contracts permits the vendor to use your inputs (and often outputs) to train or improve the model. In consumer tiers, this is essentially universal. In business tiers, it varies — some vendors default to no training use; others allow it unless you opt out; a few condition their advertised feature set on training rights.

The negotiable position for anything above trivial-use tiers:

Getting this in writing is often free with enterprise or business-plus tiers and difficult on standard business tiers. The largest foundation model providers have moved toward no-training as a default for business relationships. Mid-tier vendors selling AI features on top of those models are less consistent.

Clause 2: Retention

How long does the vendor keep your inputs and outputs, and under what circumstances? This matters for two reasons.

First, retained records are discoverable. If your business faces litigation, the AI vendor's records of your uploads are subject to subpoena on the same terms as any other third-party record custodian. What you uploaded to think through a business problem three years ago can become evidence in a lawsuit today.

Second, longer retention exposes you to breach risk. Every day the vendor holds your data is a day it can be accessed inappropriately, exposed in a breach, or accessed by the vendor's employees.

Negotiable positions:

The retention question is worth asking directly. Vendors often have flexible retention options they don't feature in marketing.

Clause 3: Indemnification — Which Way It Runs

Indemnification is the promise that one party will defend and pay for claims brought against the other. In AI contracts, indemnification direction matters a lot.

The default in most standard vendor contracts: the customer indemnifies the vendor. Meaning if the AI produces output that leads to a third-party claim — copyright infringement, defamation, discriminatory decision — the customer defends and pays.

What you want: a vendor IP indemnity covering claims that the vendor's model or its outputs infringe third-party intellectual property, plus reasonable conditions (customer used the tool as intended, didn't modify outputs, followed the usage policy).

Several major AI providers now offer “shield” or “indemnity program” coverage for enterprise customers. The terms of these programs vary significantly. Read the actual language, not the marketing summary — the coverage typically has conditions (must have paid tier, must have followed usage policy, must not have modified outputs in specified ways) that determine whether the coverage actually applies when you need it.

Clause 4: The Liability Cap

Every AI vendor contract caps the vendor's total liability. Typical caps:

The problem: the losses from a serious AI-caused business incident — a bad decision on a large loan, a compliance failure, a discovery request that reveals problematic model outputs — can vastly exceed 1x annual fees. If you paid $50,000 for the AI service last year and the incident causes $2 million in losses, the cap leaves you holding $1.95 million of it.

Negotiable positions:

Clause 5: Model Change and Deprecation

The model you evaluated is not the model you'll be using in a year. Providers retire models on schedules measured in months, replace them under the same product name, and update them continuously. A change that improves average performance can degrade performance on your specific task, and you won't know unless you're testing — because nothing in the interface will tell you.

Most contracts address this with a sentence permitting the vendor to modify the service at any time. What you want:

If you can't get the clause, get the practice. Keep a fixed set of test prompts with known-good outputs and run them on a schedule. It's the only way to know the tool changed before your customers do — and it's the evidence, in a negligence case, that you were watching.

Clause 6: Rights to Decision Data

If your AI tool makes or influences decisions about people — hiring, lending, insurance, benefits — you need contractual rights to the data that would let you test outcomes and respond to a regulator, plaintiff, or subpoena. Specifically:

Colorado's AI framework, effective January 2027, makes this a compliance requirement rather than a preference: the deployer's duties depend on documentation that only the developer holds, and the statute obligates developers to supply it. Other states are likely to follow the structure.

A vendor that can't provide the third of these — the documentation necessary for you to give a legally adequate explanation of an adverse decision — is selling you a tool you can't lawfully use for consequential decisions in a growing number of jurisdictions. Better to learn that before signing.

The Pass-Through Problem

The AI feature in your software is very often a call to someone else's model, and your data goes where the call goes. The subprocessor list in the data processing agreement (DPA) is where this surfaces, if it surfaces at all.

Questions worth asking:

A vendor operating under a consumer or unpaid tier of its own model provider has no more protection than an employee with a personal account — and neither do you. The vendor's indemnity is only as strong as its own upstream contract.

The Realistic Frame for Small Businesses

Below enterprise scale, you're generally not negotiating the terms with the major AI providers. You're accepting the terms they offer for your tier. That's fine — but understand what you accepted.

Practical realistic steps for small business:

  1. Read the DPA and privacy terms of any AI tool used for business purposes. Know which tier you're on and what that tier permits.
  2. Move sensitive uses to business or enterprise tiers. The cost differential is usually modest; the terms differential is significant.
  3. On tools where you can negotiate — mid-tier vendors, AI-native startups — push on training rights, retention, and vendor IP indemnity. These are often the most winnable asks.
  4. For any tool making or influencing consequential decisions, insist on decision data rights before signing. Colorado's framework makes this a compliance requirement in growing jurisdictions.
  5. Maintain your own test set. Keep a fixed set of prompts with known-good outputs. Run them monthly. When the model changes — and it will — you'll know before your customers do.

The AI vendor contract is the product. Buying without reading it is buying a product you haven't specified.

Frequently Asked Questions

What's the single most important clause to negotiate in an AI vendor contract?

For most businesses, data training rights — whether the vendor may use your inputs and outputs to train the model or its successors. Getting a “no training use” commitment applies retroactively and prospectively, applies to subprocessors, and shifts the entire risk posture of using the tool. Second priority: vendor IP indemnity with reasonable conditions. Third: notice of model changes with a termination right.

Do AI vendors actually indemnify customers for IP claims?

The major foundation model providers have moved toward offering IP indemnity programs for paid enterprise customers, typically covering claims that the vendor's outputs infringe third-party intellectual property. Coverage terms vary significantly — most include conditions like “must have paid tier,” “must have followed the usage policy,” and “must not have modified outputs.” Read the actual policy language, not the marketing summary. Mid-tier AI vendors typically offer weaker or no such indemnity.

What happens if the AI vendor updates the model and my results change?

Under most default vendor contracts, nothing you can enforce. The vendor reserved the right to modify the service at any time. Your recourse if the update degrades your use case is limited to termination (often only at the end of a term). What you want in the contract: notice of a stated period before material changes, continued availability of the prior model during the notice period, and a termination right without penalty if the change materially degrades your documented use.

Are AI vendor liability caps enforceable?

Generally yes, with narrow exceptions. Liability caps in commercial software contracts are broadly enforceable in most U.S. jurisdictions, subject to standard doctrines like unconscionability (rarely successful against sophisticated business parties) and public policy exceptions for specific claim types. In some jurisdictions, gross negligence and willful misconduct cannot be capped. IP indemnity and data breach liability are sometimes carved out from the general cap.

What's a data processing agreement (DPA), and do I need one?

A DPA is a contract addendum that governs how the vendor processes personal data on your behalf — required under GDPR, useful under U.S. state privacy laws like CCPA, and generally good practice for any AI vendor handling data about individuals. If your AI vendor doesn't offer a DPA, that's a warning sign. If they offer one but the subprocessor list is opaque or the retention terms unfavorable, negotiate.

This article draws from the forthcoming Silverton Publishing book AI in Business and Law: A Practical Guide to Using Artificial Intelligence Without Getting Sued. AI vendor terms change frequently; for ongoing updates on vendor terms, indemnity programs, and regulatory developments after this article's publication, see the AI Legal Tracker.

This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.