AI Contract: The Seven Clauses to Read Before You Sign With an AI Vendor
The phrase means two different things, and search results are dominated by one of them. Most pages using it are selling software that reads or drafts contracts. That is a real category and worth knowing about, but it is not what somebody typing the phrase with an agreement open in another tab is trying to work out. The other meaning is the contract you sign with an AI vendor, and it is where the interesting problems live.
This post covers the second meaning. It is general information about US commercial contracting rather than legal advice, terms in this market change quickly enough that the version in front of you is the one that counts, and for anything significant a lawyer is the right person to ask. If you came looking for tools rather than terms, the guide to choosing AI contract review software covers that side.
What is an AI contract?
Used precisely, it is an agreement governing the supply and use of an artificial intelligence product: a model, an API, an assistant or a feature built on one. Structurally it is an ordinary software agreement, with a handful of terms that exist because the product generates output rather than merely storing or moving data. Seven are worth reading first.
- Output ownership. Whether the vendor assigns the output to you or simply promises not to claim it, and what either is worth.
- Input and training rights. Whether the vendor can train on what you put in.
- Confidentiality of prompts. Whether what you type is named as confidential information, which depends heavily on your tier.
- Accuracy and warranty. Disclaimed in essentially every agreement in the category, and rarely negotiable.
- IP indemnity. Whether the vendor defends you if an output infringes, which varies more than any other term here.
- Permitted and prohibited use. What you are allowed to do with it, usually in a policy the vendor can change.
- Model change and deprecation. Whether the thing you built on can be altered or retired.
Seven clauses to read first, and what to check in each. Several differ between the consumer and business tiers of the same product.
None of these is unreasonable on its own. What is worth seeing as a set is the direction they all point: the vendor's exposure is defined and capped, and the residual risk of using generated output in your business sits with you.
1. Who owns what the model produces
Two drafting patterns are common. Some vendors assign the output to the customer, in language close to: as between the parties, and to the extent permitted by law, you own the output. Others make no assignment at all and instead state that they do not assert ownership rights in the generated output. Both do real work. Neither lets the vendor claim your output, both clear the way for commercial use, and both give you something to point at.
What neither can do is manufacture a copyright. In the assigning version, the qualifier is doing that work, and it is the part people skip.
What the contract gives you, against what copyright gives you. Both are worth having. Quotes from the Copyright Office report and the opinion.
On the narrow question, the US position is settled. The Copyright Office concluded in January 2025 that copyright does not extend to purely AI-generated material, or to material where there is insufficient human control over the expressive elements, and that on current technology prompts alone do not provide sufficient control. Two months later the D.C. Circuit held that the Copyright Act requires all eligible work to be authored in the first instance by a human being, in a case about a work its applicant said had been generated autonomously with a machine named as the sole author. The Supreme Court declined to review that in March 2026, which is not a ruling on the merits.
What is not settled is the question most people actually have, which is how much human contribution is enough. The D.C. Circuit expressly did not reach it, the Copyright Office tied its conclusion on prompts to current technology, and the boundary is in active litigation. The report is agency guidance too, which courts may find persuasive but are not bound by.
None of this is an argument against using the tools. The Copyright Office is explicit that your own contribution is protectable: work of yours perceptible in the output, the creative selection, coordination or arrangement of AI-generated material, and creative modifications of it. AI-assisted work with real human input can be registered, though the application has to disclose and disclaim the AI-generated portions.
It is worth being clear about what the clause does give you, because the point here is a gap rather than a worthless term. You can use, sell and build on the output. Outputs you keep confidential can be protected as trade secrets, which for most commercial content is the protection that does the work. And the clause gives you exclusivity against the vendor even where copyright gives you none.
What to look for: which of the two patterns you have, whether the grant is unconditional or lapses with your account, whether the vendor keeps a license back over what you generate, and whether your business depends on stopping other people copying the output. If it does, that gap matters more than anything else in the agreement.
2. What the vendor can do with what you put in
Training rights are the clause most likely to differ between the free tier, the paid consumer tier and the business tier of the same product, and the difference is rarely obvious from the marketing. Some agreements train on inputs by default with an opt-out buried in settings. Some exclude business customers entirely. Some distinguish between training the model and using content to operate the service, which are not the same thing.
The distinction worth holding onto is where the promise lives. A commitment in the contract binds the vendor. A toggle in a settings page is a product feature, and product features change.
What to look for: whether training on your content is opt-in or opt-out, whether your tier is covered by the promise you read, whether human reviewers may see your inputs, and what happens to submitted content on termination.
3. Whether what you type is confidential
This is the clause where the gap between tiers is widest, and where assumptions do the most damage. Business and enterprise agreements from major providers commonly name customer inputs and outputs as confidential information, with an express obligation attached. Consumer click-through terms for the same product frequently have no confidentiality article at all.
People routinely paste client material, contract drafts and internal figures into a consumer account on the assumption that the protections they read about apply to them. Often they were reading the business terms.
What to look for: whether your agreement contains a confidentiality article, whether it covers the content you submit rather than only the commercial relationship, whether human reviewers may see inputs, and whether any of that changes on the tier you are actually paying for.
4. The accuracy disclaimer, which is in nearly all of them
Essentially every agreement in this category disclaims accuracy. The service is provided as is, output may be wrong, and you are responsible for reviewing it before you rely on it. That is not a red flag and it is rarely negotiable at ordinary contract sizes. It is a commercial choice rather than a technical impossibility: vendors do make other output-related commitments, including defending certain infringement claims, they simply do not warrant that generated text is correct.
What is worth attention is the pairing. The disclaimer often sits a few pages away from marketing describing the product as accurate, reliable or expert. Where a specific capability was promised in the sales process and matters to your decision, the place to resolve it is the contract, since a merger clause will otherwise make it much harder to rely on what was said outside the document.
What to look for: whether any warranty survives at all, whether service levels are commitments or targets, and whether the specific thing you were sold on appears anywhere in the document.
5. Whether the vendor stands behind you if an output infringes
This clause varies more than anything else in an AI agreement, and the variation is easy to miss because the marketing sounds similar across vendors. Some do commit to defending third party intellectual property claims arising from output, subject to conditions such as leaving the safety and citation features enabled, not deliberately seeking infringing material, and stopping use once a rightsholder complains. At least one major provider's published business terms take the opposite approach and carve customer content, defined to include both input and output, out of the indemnity altogether.
So the question is not whether your vendor has an indemnity. Most have one covering the service. The question is whether it reaches output, which is the part that generates the claim.
What to look for: whether output is covered or only the service, what conditions attach and whether you are meeting them, whether it exists on your tier, and whether it is capped separately from everything else in the agreement.
6. What you are allowed to use it for
Nearly every AI agreement incorporates an acceptable use policy by reference, and those policies commonly restrict use in decisions with legal or similarly significant effects without human review. Employment, credit, housing, insurance and healthcare turn up repeatedly.
This is worth reading before the deployment rather than after, because two failure modes are common. The first is discovering that the intended use is on the wrong side of the policy. The second is the policy being a document the vendor can revise unilaterally, so a use permitted today is not necessarily permitted next year.
There is a third consideration the contract will not raise. Several states have begun imposing obligations directly on the business deploying an automated system in consequential decisions, separately from whatever the vendor's policy allows. Vendor permission and legal permission are different questions, and only one of them is in the document.
What to look for: whether the policy is attached or merely linked, whether you get notice of changes to it, and whether the thing you actually intend to do is described in it.
7. What happens when the model changes
Change and discontinuation clauses are standard in software contracts and long predate AI. What is different here is the consequence: a workflow tuned to one model's behavior can stop producing the same results when that model is retired, in a way that swapping a version of ordinary software does not usually cause.
For casual use this does not matter. For anything you have built a process around, it is one of the more consequential terms in the agreement, and it rarely gets negotiated because it does not look like a risk clause.
The picture has improved. Some API providers now publish deprecation notice commitments running to months, which is a genuine constraint. Consumer terms for the same companies frequently still reserve the right to change or discontinue the service without notice, so which document governs you matters.
What to look for: whether a published notice period applies to the models you use, whether pinned or dated versions are available, and how long a deprecated version stays accessible.
The six questions worth answering before you sign
Most AI agreements are click-through terms you cannot change. Reading them is still worth the twenty minutes, because the point is to know what you have rather than to negotiate it.
- Can they train on what I put in, and does that answer change on my tier?
- Do I own the output, and does anything I care about depend on copyright in it?
- Is there an IP indemnity, and what conditions attach to it?
- Is my intended use permitted under the acceptable use policy?
- What happens to my data on termination?
- Can the model I am building on be changed or retired, and with what notice?
Anything the agreement is silent on is worth noticing. Silence does not automatically favor the vendor, since ambiguity in a form contract is often construed against the party that drafted it, but it does mean nobody has promised you anything on that point.
Where RateMyContract fits in
AI vendor terms are long, they are updated often, and they are usually presented at the moment somebody wants to start using the tool rather than at a moment convenient for reading. RateMyContract exists to remove the first barrier: upload the agreement and it works through the document in plain English and highlights clauses that look unusual or one sided, so you have a view on which paragraphs deserve your attention. It is an AI tool reading an AI contract, so the point made in section four applies to it as well: it is a starting point for your own reading rather than a substitute for it.
What it does not do is give legal advice, assess whether a clause would hold up, or tell you whether to sign. It reads. For a purchase that matters, a lawyer is the right next step, and arriving at that conversation already knowing what the document says makes it a much shorter one.
When to talk to a lawyer
Most people accept AI terms without advice. Whether that is the right call depends on what you are doing with the tool rather than on the size of the bill. Review most obviously earns its cost where you are deploying the tool in a regulated area such as hiring, lending, housing or health; where confidential client or patient information will pass through it; where output feeds a product you intend to sell or license; where the contract is negotiable, which usually means an enterprise agreement; and where an existing obligation to your own customers may conflict with what the vendor's terms permit.
The short version
An AI contract is an ordinary software agreement with a set of terms that exist because the product generates output. Seven are worth reading first: output ownership, training rights, prompt confidentiality, the accuracy disclaimer, IP indemnity, permitted use, and model deprecation. The one that most often misleads people is the first. Being given the output is not the same as owning a copyright in it, because in the United States purely AI-generated material is not copyrightable and no contract can change that. The clause is still worth having, since it lets you use and sell the output and can support trade secret protection. What copyright still reaches is the part a person contributed.
If a set of AI terms is in front of you now, RateMyContract will read them back in plain English. For the underlying rules on what makes any agreement binding, what is a contract covers the four elements, and the contract checklist works through a document point by point.
Frequently asked questions about AI contracts
What is an AI contract?
The phrase is used two ways. It can mean software that reads, drafts or manages contracts using AI, and it can mean the agreement you sign with an AI vendor to use their product. This post covers the second. Structurally it is a software contract with additional terms covering output ownership, training rights, confidentiality of what you submit, accuracy, indemnity, permitted use and model changes.
Do I own the content that AI generates for me?
Under most vendor contracts, yes, as between you and the vendor. Under US copyright law that is a separate question. The Copyright Office concluded in 2025 that copyright does not extend to purely AI-generated material, and that prompting alone does not make you an author. Your own creative contributions to the result remain protectable, and the contract clause is still worth having for commercial use and trade secret protection.
Can an AI company train on my data?
It depends on the agreement and often on your tier. Some train on inputs by default with an opt-out in settings, some exclude business and enterprise customers, and some distinguish training the model from processing content to run the service. The reliable version of the promise is the one written into the contract rather than a toggle in a settings page.
Are AI vendor contracts negotiable?
Click-through terms for individual and small business plans generally are not. Enterprise agreements usually are, and the clauses most often moved are training rights, confidentiality of inputs, the indemnity, data retention and notice before a model is deprecated. Whether you have leverage tends to track how much you are spending.
What is an AI indemnity clause?
A promise by the vendor to defend you against certain third party claims, most often that an output infringed somebody's intellectual property. Some major providers offer one, typically conditioned on leaving safety features enabled and not deliberately seeking infringing output. Others expressly exclude customer content, meaning both input and output, from their indemnity. Reading which you have is the whole exercise.
Is AI contract review software the same thing?
No, though the phrase gets used for both. That is software applying AI to contracts you already have, whether reviewing, drafting or managing them. An AI contract in the sense used here is the agreement governing your use of an AI product. The two topics share a name and almost nothing else.