The real risk sat in clauses buyers rarely read, because most legal teams review the agreement as a software subscription when it behaves like a developer platform contract
Six categories of risk, and the commercial one gets all the attention. Deprecation, indemnity and portability decide more of the outcome than the rate card does.
Prepared by Redress Compliance · August 19, 2026 · OpenAI enterprise agreements. 15 to 25 agreements reviewed, 2024 to 2025.
Executive summary
Model deprecation windows of 6 to 12 months forced unplanned migration on 30 to 50 percent of reviewed estates. That is an engineering programme arriving on somebody else's calendar.
Usage commitments were set above realistic consumption, stranding 15 to 30 percent of prepaid credit. Token spend forecasting carries 30 to 60 percent variance, so plan for the range rather than the point estimate.
Data and intellectual property indemnity language varied widely, leaving gaps on 1 in 3 agreements. The protection is narrower than the marketing around it suggests.
Exit clauses have to protect portability explicitly: conversation history, fine tuned models, embeddings and custom assistants. None of that transfers by default.
Why does the review need to change shape?
Because the agreement is closer to a developer platform contract than to a software subscription, and a legal team reading it as the latter checks the wrong things carefully. The published terms sit in the business terms.
Six categories of buyer side risk run through it: token spend forecasting, model deprecation, data governance, indemnification, commercial protection and exit. Only the first is normally modelled.
The commercial category gets all the attention
It is the one that looks like a normal procurement question. The other five are where the reviewed agreements actually carried their exposure, and none of them appear on a rate card.
What does model deprecation actually cost?
An unplanned engineering programme. Windows of 6 to 12 months forced migration on 30 to 50 percent of reviewed estates, and windows of 6 to 18 months are common across the market.
| Risk category | What it looks like in the paper | What it costs when unread |
|---|---|---|
| Token spend forecasting | A committed consumption figure | 15 to 30 percent of prepaid credit stranded |
| Model deprecation | A notice period, often short | Unplanned migration on 30 to 50 percent of estates |
| Data governance | Tier dependent training and retention terms | Carve outs nobody confirmed at signature |
| Indemnification | Narrow scope with exclusions | A gap on 1 in 3 agreements reviewed |
| Exit and portability | Silence on most artifacts | History, tuned models and embeddings that do not travel |
Deprecation is a discrete, schedulable risk rather than a background one. It belongs in the agreement as a notice period you can plan against, not as a policy the vendor revises.
The OpenAI enterprise contract levers
The clause level positions that decide an AI agreement, and the language that fixes them.
Get the brief →What 15 to 25 OpenAI agreements showed
Across roughly 15 to 25 OpenAI enterprise agreements reviewed between 2024 and 2025, the real risk sat in clauses buyers rarely read. Three patterns recur.
- Model deprecation windows of 6 to 12 months forced unplanned migration on 30 to 50 percent of reviewed estates.
- Usage commitments were set above realistic consumption, stranding 15 to 30 percent of prepaid credit.
- Data and intellectual property indemnity language varied widely, leaving gaps on 1 in 3 agreements.
Token spend forecasting carries 30 to 60 percent variance. A commitment sized to the point estimate is a commitment sized to the least likely outcome.
- Every risky clause flagged with the verbatim quote and page anchor
- Entitlements, caps and protections verified across your whole contract portfolio
- Paste ready replacement language and an evidence trail for the response
What do the data and indemnity clauses actually say?
It varies by tier, which is the part that catches people. The enterprise tier carries no training on customer data by default, and the carve outs still need confirming rather than assuming, against the published policy index.
Indemnification scope is narrower than the surrounding marketing implies. The copyright protection covers specific products and carries exclusions, and the reviewed agreements left a gap in 1 of every 3.
Exit is the category nobody drafts
Conversation history, fine tuned models, embeddings and custom assistants are all artifacts you built and none of them transfer by default. Portability has to be written in, product by product.
Watch the briefing · 3:50Signing the Enterprise AgreementWhat the agreement has to cover: the commitment shape, data terms, deprecation and capacity.
How should the commitment be sized?
Against a range rather than a forecast. Token spend forecasting carries 30 to 60 percent variance, which makes any single number the wrong one to commit against.
A range, not a forecast
Commitments set above realistic consumption stranded 15 to 30 percent of prepaid credit in the reviewed agreements. That credit does not carry forward and it does not come back.
The commercial half of this, and how the commitment interacts with the rate card, sits in the procurement playbook and the negotiation brief.
The cross vendor position sits in the vendor comparison, the Claude enterprise guide and the Anthropic negotiation guide.
What the reviews measured, 2024 to 2025
Two cuts of the engagement file, neither of them commercial.
By deprecation windows of 6 to 12 months, arriving on the vendor's schedule rather than the estate's.
Where data and intellectual property indemnity language left the buyer exposed on a category it assumed was covered.
Neither shows up in a price comparison. Both decide more of the total cost of the relationship than the rate card does.
Your first five moves
- Review the agreement as a developer platform contract, not a subscription, because a team checking the wrong things carefully still misses all six risk categories.
- Negotiate the deprecation notice period explicitly, since windows of 6 to 12 months forced unplanned migration on 30 to 50 percent of reviewed estates.
- Size the commitment against a range rather than a point estimate, because forecasting carries 30 to 60 percent variance and stranded credit does not return.
- Confirm the training and retention carve outs in the contract, rather than relying on a tier default that a product update can revise.
- Write portability in product by product: history, tuned models, embeddings and custom assistants. The GenAI practice runs the clause review alongside the commercial one, and the platform contract brief carries the language.
Frequently asked questions
Why does this contract need a different review?
Because it behaves like a developer platform contract rather than a software subscription. A legal team reading it as the latter checks the wrong things carefully.
What are the six risk categories?
Token spend forecasting, model deprecation, data governance, indemnification, commercial protection and exit. Only the first is normally modelled at all.
How short are deprecation windows?
Between 6 and 12 months in the reviewed agreements, and 6 to 18 months is common across the market. They forced unplanned migration on 30 to 50 percent of those estates.
How much prepaid credit gets stranded?
Between 15 and 30 percent, where the commitment was set above realistic consumption. It does not carry forward and it does not come back.
Why size against a range?
Because token spend forecasting carries 30 to 60 percent variance. Committing against a point estimate is committing against the least likely single outcome.
Does the enterprise tier train on customer data?
It carries no training by default, and the carve outs still need confirming in the contract rather than assumed from the tier.
How wide is the indemnity?
Narrower than the surrounding marketing implies. The copyright protection covers specific products with exclusions, and 1 in 3 reviewed agreements left a gap.
What has to be protected on exit?
Conversation history, fine tuned models, embeddings and custom assistants. These are artifacts you built and none of them transfer by default.
How long does a clause review take?
About three weeks, which is enough to reframe most enterprise agreements of this type before signature rather than after.
Which category costs the most when unread?
Deprecation, because it converts into an engineering programme on somebody else's calendar. It is also the easiest of the six to fix with a drafted notice period.