A policy page can change with a web edit and an order form term cannot, and treating the two as equivalent is the most common GenAI procurement error we see
The defaults are stronger than most procurement teams assume. The gap is everything the defaults do not cover, and all of it is set by contract.
Prepared by Redress Compliance · August 19, 2026 · GenAI vendor contracts reviewed. 25 to 35 files, 2024 to 2025.
Executive summary
Roughly 1 in 4 enterprise buyers had no executed Data Processing Addendum, despite processing personal data through the API, across roughly 25 to 35 GenAI vendor contracts reviewed between 2024 and 2025.
Training defaults were misread. Teams assumed API traffic trains models by default, then paid for assurances already given in writing.
Retention windows went unmanaged in 60 to 70 percent of agreements, which kept the standard abuse monitoring retention where zero data retention was available.
OpenAI paper was the most frequently signed without a single privacy redline of any vendor in the file.
What happens to enterprise data by default?
Models are not trained on enterprise or API data by default, and that commitment sits in the published privacy commitments. The default position is stronger than most procurement teams assume.
The gap is everything the defaults do not cover. Retention windows, subprocessor changes, breach notice timing and audit rights are set by the contract documents, not by the marketing page.
The three documents that actually govern
- Business terms. The business terms govern API and enterprise use. Read data ownership and indemnity first.
- The addendum. The DPA carries the processor commitments. It must be executed, not just referenced.
- Trust portal. Audit reports and subprocessor lists live on the trust portal. Pull them before signature, not after.
The business terms set ownership and liability, the addendum sets processor obligations, and the portal evidences the controls. A privacy review reading only one of the three is incomplete.
| Channel | Trains on your data | Default retention | Zero retention available |
|---|---|---|---|
| Consumer tiers | Yes unless opted out | Provider discretion | No |
| Team | No | Workspace controlled | No |
| Enterprise | No | Admin controlled | No |
| API standard | No | 30 days abuse monitoring | By approval |
| API with zero retention | No | None at rest | Yes |
Which nine clauses should the agreement carry?
Nine separate a defensible agreement from a signed marketing page, and each one has a concrete buyer position.
Clauses one to five, data handling
- Training exclusion in the order form. Restate the no training default as a contract term so it survives policy edits.
- Retention window. Name the abuse monitoring window and require written notice if it changes.
- Zero data retention. If your workload qualifies, get approval in writing and reference it in the agreement.
- Subprocessor notice. 30 days advance notice of new subprocessors, with a right to object.
- Breach notice. 72 hours, rather than the vaguer commercially reasonable standard.
Clauses six to nine, control and exit
- Audit rights. Annual report delivery plus a written security questionnaire right.
- Data residency. If you need regional processing, name the region. Silence means provider discretion.
- Deletion on exit. Certified deletion within 30 days of termination, including backups on a defined cycle.
- Indemnity scope. Confirm the output indemnity covers your usage tier and is not voided by your own fine tuning data.
- Every privacy clause checked against the vendor's own published commitments
- Retention, subprocessor and deletion language flagged with replacement text
- The gap between policy page and order form made explicit before signature
How do you negotiate these without stalling the deal?
Anchor every ask to something the vendor has already published, because the fastest redlines are the ones conceded elsewhere.
The privacy page, the addendum and the trust portal give you the anchor for seven of the nine clauses.
Sequence matters. Send the addendum and the security questionnaire in week one, in parallel with commercial terms. Teams that treat privacy as a closing formality lose two to four weeks at signature.
What the account team will push back on
- Zero retention eligibility. Granted by use case review rather than by negotiating pressure, so submit the use case early.
- Custom breach windows. Smaller deals get the standard terms, and below roughly 250 thousand dollars a year expect limited movement.
- Audit beyond the standard report. On site audits are reserved for the largest commitments, so the report plus questionnaire route is the realistic position.
The OpenAI negotiation guide
The nine clause checklist, the published anchors behind each one, and the sequence that keeps privacy off the critical path.
Get the guide →What 25 to 35 GenAI contract reviews showed
Across the GenAI vendor contracts reviewed between 2024 and 2025, OpenAI paper was the most frequently signed without a single privacy redline.
The three patterns that recurred
- Training defaults misread: teams assumed API traffic trains models by default, then paid for assurances already given in writing.
- Retention windows unmanaged: 60 to 70 percent of agreements kept the standard abuse monitoring retention where zero data retention was available for their use case.
- Addendum never executed: roughly 1 in 4 enterprise buyers had none signed despite processing personal data through the API.
The first and third point in opposite directions. One is paying for protection you already have, the other is operating without protection you assumed you had.
Research briefingReading the frontier vendor agreementsWhere the published commitments, the processing addendum and the order form meet, and which of the three actually binds.
Where the common advice on these terms is wrong
The standard advisory line is that the terms are non negotiable below seven figures, so buyers should sign the standard paper and move on. We disagree.
In roughly 12 of the 30 reviews run in 2024 to 2025, named retention, subprocessor notice and deletion clauses were accepted at mid six figure spend, because the asks restated published commitments as contract terms rather than inventing new obligations.
Convert policy into contract. That is the whole move, and it is cheaper than any assurance you could buy instead.
Most privacy clauses are conceded fastest when the redline quotes the published commitment it restates.
Despite processing personal data through the API.
Keeping the standard window where zero retention was available.
At mid six figure spend, by restating published commitments.
The equivalent work on the neighbouring vendor sits in negotiating with Anthropic and with our GenAI licensing practice. The signature stage itself is walked through in episode three of the negotiation series.
Your first five moves
- Execute the processing addendum before anything else, because 1 in 4 buyers were operating without one.
- Restate the no training default as an order form term, so it survives a policy page edit.
- Check whether your use case qualifies for zero data retention and submit that review early, since it is granted on use case rather than pressure.
- Name the retention window, the subprocessor notice period, the breach notice hours and the deletion timeline as contract terms.
- Send the addendum and security questionnaire in week one alongside commercial terms, rather than treating privacy as a closing formality.
Frequently asked questions
Does enterprise data train the models by default?
No. Enterprise, team and API data are excluded by default, and that commitment is published. The default is stronger than most teams assume.
So what is actually at risk?
Everything the defaults do not cover: retention length, subprocessor changes, breach notice timing, residency and exit deletion. All are contract variables.
How many buyers lacked a processing addendum?
Roughly 1 in 4 enterprise buyers had none executed, despite processing personal data through the API.
Which documents actually govern?
Three: the business terms for ownership and liability, the addendum for processor obligations, and the trust portal for control evidence.
What is the most common wasted spend?
Paying for assurances already given in writing, because the team misread the training defaults before reading the published commitments.
How often is retention left unmanaged?
In 60 to 70 percent of agreements, which kept the standard abuse monitoring window where zero data retention was available for the use case.
Are these terms negotiable below seven figures?
Yes. In roughly 12 of 30 reviews, named retention, subprocessor and deletion clauses were accepted at mid six figure spend.
Why do those asks get accepted?
Because they restate published commitments as contract terms rather than inventing new obligations. The vendor has already conceded the substance.
What will the account team resist?
Zero retention eligibility outside a use case review, custom breach windows on smaller deals, and audit rights beyond the standard report.
Why does a policy page not suffice?
Because it can change with a web edit and an order form term cannot. Treating the two as equivalent is the most common GenAI procurement error.