What It Does
An AI liability clause decides who carries the risk of a machine's work product. For in-house counsel, it usually arrives as vendor paper that assigns the entire risk to you: the vendor disclaims the warranties on output, requires you to verify all of it, and caps its exposure at a few months of fees. The reasoning behind that posture is sound as far as it goes, because the vendor cannot control what you type into the prompt. The reasoning stops short of the parts of an output that trace to the model, the training data, and the vendor's own guardrails.
A practical test: read the clause and ask whether a claim caused entirely by the vendor's training data would still land on you. If it would, the clause has no causation line in it.
Defines what counts as AI, what counts as an input, and what counts as an output
Sets whether the vendor may use your data or confidential information to train or improve its models
Assigns ownership of the output and of any synthetic data derived from your material
Allocates third-party infringement, privacy, and discrimination claims arising from the output
Fixes whether AI claims sit inside the general liability cap or in a separate one
Dedicated AI and AI-output sections have become far more common in enterprise services agreements drafted since 2024.
When You'll See It
AI liability language appears wherever a vendor touches your data or produces work product: SaaS agreements, master services agreements, consulting and outsourcing statements of work, data and content licenses, and cloud infrastructure agreements. In older contracts it hides inside the warranty disclaimer and the limitation of liability. In contracts drafted since 2024 it stands on its own, as a numbered AI article or as an AI addendum that controls over the rest of the agreement where the two conflict.
Two neighboring provisions get confused with it.
General limitation of liability: caps the money available for every claim in the agreement, while the AI clause decides whether an output claim qualifies at all before any cap applies.
Anti-AI clause: prohibits the vendor from using AI on your engagement at all, which some regulated buyers adopt as their entire position on output liability. The clause matters most where output leaves your building, in marketing copy, code shipped to production, customer-facing decisions, and anything a regulator will read back to you.
Examples
Talcott Resolution Life, Inc. / Cognizant Worldwide Limited
Master Agreement for Outsourced Services
Prior-approval gate, customer owns the output
One-Sided
2026
"Unless otherwise agreed to in writing by the Parties, all outputs (including content, predictions, recommendations, decisions, and results) generated by AI in response to processing Talcott Data or Talcott IP as input shall be deemed Talcott Data and/or Talcott IP, as applicable, and may not be used or disclosed by Service Provider for any purpose other than as necessary to perform the Services."
AgEYE Technologies, Inc. / YouneeqAI Technical Services, Inc.
Software License Agreement
Licensor IP indemnity with modification and combination carve-outs
Mutual
2026
"AGEYE shall indemnify, defend, and hold harmless YQAI and its officers, directors, and employees from and against any third-party claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising out of a claim that the unmodified AGEYE IP, as provided by AGEYE and used within the Scope of Use and in accordance with this Agreement, infringes or misappropriates any United States intellectual property right of such third party. AGEYE shall have no indemnification obligation to the extent the claim arises from... combinations of the Licensed Software with products, services, data, or systems not provided or approved by AGEYE..."
Rumble Inc. / Tether Investments, S.A. de C.V.
Form of Tether Customer Agreement
Output risk split by the source of the training input
Mutual
2025
"Parent shall indemnify, defend and hold harmless Customer against any and all... Losses... incurred by any Customer, relating to or resulting from any third-party claim arising from... (c) Customer's use of Rumble Content... in the training, development or deployment of the AI Models in accordance with this Agreement infringes, violates or misappropriates a third party's intellectual property or proprietary rights... Customer shall indemnify, defend and hold harmless Parent against any and all Losses... arising from... (ZZ) Customer's use of Third Party Technology in the training, development or deployment of the AI Models which infringes, violates or misappropriates a third party's intellectual property or proprietary rights..."
AIcreatesAI Inc. / Raphael Pharmaceutical Inc.
Enterprise AI Transformation and Growth Partnership
Fault follows the materials each party supplied
Mutual
2026
"Each party will defend and indemnify the other against third-party claims arising from its gross negligence, willful misconduct, material violation of law, or infringement caused by materials it supplied. Raphael will also be responsible for claims arising from product safety, product labeling, approved medical or scientific claims, clinical operations, securities disclosures, regulated activities, or Raphael-supplied data and materials, except to the extent caused by AIcreatesAI's gross negligence or willful misconduct."
Vetted Consultant LLC / Range Impact, Inc.
Master Services Agreement
No supplier liability for reliance on AI output
One-Sided
2026
"Client is solely responsible for reviewing, validating, and verifying all AI-generated content, recommendations, flags, and outputs before relying on them for any business, operational, regulatory, legal, or compliance decision. Consultant shall have no liability for any decision made or action taken by Client (or any third party) in reliance on AI output."
SAI AU No.2 Pty Ltd / SpocHub Solutions Private Limited and ESDS Cloud FZ-LLC
Master Services Agreement
Full disclaimer of output accuracy and hallucination risk
One-Sided
2026
"The Customer acknowledges that the Service Provider does not review, validate, monitor or control any datasets, models, training data, prompts, configurations, code, inputs or outputs used in or generated through the Services. Without limiting the foregoing, the Service Provider does not warrant or represent: (a) the accuracy, completeness, reliability, legality, safety or suitability of any AI Outputs... (d) that AI Outputs will be free from errors, hallucinations, bias, harmful content or inaccuracies..."
Negotiate
You want the vendor to carry the parts of the output it controls
Define AI, AI input, and AI output in the contract, because an indemnity that never names the output will be read to cover the software alone.
Require the vendor to indemnify you for third-party intellectual property, privacy, and publicity claims arising from the output, to the extent the claim is not caused by the data or prompts you supplied.
Prohibit training on your data and confidential information without written approval, and pull any synthetic data derived from your material into your ownership.
Put intellectual property and data claims outside the general cap or under a separate multiple, since a cap set at three months of fees will not fund a copyright defense.
Require notice of material model or provider changes and a right to re-test for accuracy and bias, so the system you approved stays the system in production.
You want the risk to follow the input you cannot see
Tie every output warranty to inputs you approved, and exclude outputs generated from customer data, prompts, or fine-tuning you did not review.
Make documented human review a condition of the output indemnity, so a claim traced to unreviewed output falls outside it.
Carve out modifications, combinations with third-party technology, and use outside the documented scope, which is where output claims tend to originate.
Keep the AI cap tied to fees paid in a defined recent period, and resist a super-cap that prices model risk against the customer's revenue.
Reserve the right to change models and upstream providers, since your own supplier terms will change without your consent.
The vendor cannot see your prompt and you cannot see the training data, so the version that gets signed is usually the one that splits the output by cause, tracing each claim back to the side that created it.
Red Flags
An indemnity written against the "Services" or the "Software" that never mentions output, which leaves the claim you are most likely to face outside the promise.
A flat statement that the customer is solely responsible for all outputs, so the consequences of training data you never saw land on you.
An AI indemnity capped at fees paid, which prices a copyright or right-of-publicity defense below the cost of answering the complaint.
Permission to use your data "to improve the Services," left undefined. That is a training license written in operations language.
A right to change models or upstream providers with no notice and no re-testing, which lets the vendor swap out the system you diligenced after signature.
FAQs
This content is for informational purposes only and does not constitute legal advice.



