Legal and procurement team reviewing an AI vendor contract on a large screen
GenAI Vendors

GenAI contracting red lines. The 2026 white paper.

GenAI contracts are written for the vendor. This white paper sets the buyer side red lines on IP indemnity, training data, model swap rights, and EU AI Act allocation for 2026.

Contact Us GenAI Advisory
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

GenAI contracts are drafted to protect the vendor, so the buyer side job is to hold four red lines: intellectual property indemnity, training data exclusion, model swap rights, and clear EU AI Act allocation.

Key takeaways

  • Demand intellectual property indemnity for model output with no gutting carve out.
  • Bar training on your inputs and outputs in writing, with deletion terms.
  • Secure model swap, version pinning, and deprecation notice rights.
  • Allocate EU AI Act obligations explicitly between provider and deployer.
  • Resist token liability caps for IP and confidentiality breaches.
  • Prefer shorter terms because the GenAI market moves fast.

What intellectual property indemnity should a GenAI contract include?

A GenAI contract should give you vendor indemnity for third party intellectual property claims from model output, without a cap carve out that hollows it out. The major vendors publish copyright commitments, but scope and conditions vary, so the indemnity is a negotiation, not a given.

Compare the published positions, such as the OpenAI business terms and the Anthropic commercial terms, against your risk before signing.

Scope and conditions that gut indemnity

Read the conditions, because indemnity often depends on using vendor guardrails and unmodified output. A commitment that evaporates the moment you fine tune or filter is not real protection.

  • Carve outs: watch for exclusions that remove the core claim.
  • Caps: a low cap turns indemnity into a gesture.
  • Conditions: guardrail and output requirements must be workable.

How should training data and your inputs be handled?

Enterprise GenAI contracts should bar training on your inputs and outputs entirely, stated explicitly with deletion and retention terms. The red line is a contractual guarantee that your data never trains shared or foundation models.

Vendors document enterprise data handling, for example the OpenAI enterprise privacy page, but the binding statement must live in your contract, not a marketing page.

GenAI contract red lines and the vendor default

Red lineVendor defaultBuyer positionWhy it matters
IP indemnityCapped or carved outUncapped for IP claimsOutput may infringe
Training dataSometimes permittedNever on your dataConfidentiality and IP
Model swapNo noticeNotice and version pinSilent change breaks apps
AI Act dutyUnallocatedExplicitly assignedCompliance liability

Why do model swap and deprecation rights matter?

Model swap and deprecation rights matter because the vendor can retire or alter the model your application depends on. Without notice periods and version pinning, a silent model change can break outputs and compliance overnight.

Version pinning and transition windows

Negotiate a guaranteed deprecation notice and a transition window so you can test a new model before it becomes mandatory. This single clause turns a forced change into a managed migration.

What does the EU AI Act add to GenAI contracts?

The EU AI Act assigns obligations by risk tier across providers and deployers, so your contract must say who carries which duty. The EU AI Act text sets out documentation and transparency obligations that need explicit allocation.

Allocating provider and deployer duties

Name who owns each duty in the contract so neither side assumes the other handles it. Unallocated AI Act obligations are a liability gap that surfaces only after something goes wrong.

  • Risk tier: confirm how your use case is classified.
  • Provider duties: documentation and transparency from the vendor.
  • Deployer duties: your obligations as the operator.

Where the common advice on GenAI contracting is wrong

The common advice is to sign the vendor paper quickly so you do not miss the productivity wave. We disagree. Across the GenAI contracts we reviewed in 2024 and 2025, the rushed deals accepted capped indemnity, ambiguous training rights, and no model swap protection, and those gaps became real problems within a year as models were deprecated and outputs were challenged. Speed is not the same as advantage. The buyer side move is to hold the four red lines, accept a shorter term to preserve optionality in a fast market, and keep a credible alternative model in view, so the next renewal is a negotiation rather than a captive renewal of a weak contract.

A contracts lawyer marking red lines on a printed GenAI master agreement
The four red lines are not boilerplate, they are where a fast moving model market and slow moving liability law collide in your agreement.
4
Red lines that decide the deal
0
Training on your data, by contract
25+
GenAI contracts reviewed, 2024 to 2025

Source: Redress Compliance advisory engagement file, 2024 to 2025.

The model you buy today may be deprecated next year. The contract you sign today will still bind you. Negotiate the one that lasts.

What should a buyer do next

  1. Demand uncapped intellectual property indemnity for model output and review the carve outs.
  2. Insert an explicit ban on training with your inputs and outputs, with deletion terms.
  3. Negotiate model deprecation notice, version pinning, and a transition window.
  4. Allocate EU AI Act provider and deployer duties in the contract.
  5. Raise or carve out liability caps for IP and confidentiality breaches.
  6. Prefer a shorter term and keep a credible alternative vendor in view.

Frequently asked questions

What intellectual property indemnity should a GenAI contract include?

A GenAI contract should include vendor indemnity for third party intellectual property claims arising from model output, with no cap carve out that guts it. The major vendors now offer copyright commitments, but the scope, conditions, and caps vary, so the indemnity is a red line to negotiate, not accept as printed.

Can a GenAI vendor train on our prompts and data?

By default some consumer tiers can, but enterprise agreements should bar training on your inputs and outputs entirely. The red line is an explicit contractual statement that your data is never used to train shared or foundation models, backed by deletion and retention terms you can verify.

Why do model swap and deprecation rights matter?

Model swap and deprecation rights matter because the vendor can retire or change the underlying model your application depends on. Without notice periods and version pinning, a silent model change can break outputs and compliance, so the contract should guarantee deprecation notice and a transition window.

What does the EU AI Act mean for GenAI contracts?

The EU AI Act assigns obligations by risk tier and applies to providers and deployers, so your contract must allocate who carries which compliance duty. The red line is clear contractual allocation of AI Act obligations, documentation, and transparency duties between you and the vendor.

Should GenAI contracts cap the vendor liability for AI errors?

Vendors push low liability caps for AI errors, but for high stakes use the cap should reflect the real exposure, not a token multiple of fees. Negotiate a carve out or raised cap for intellectual property and confidentiality breaches, which are the failures that actually hurt.

How do you keep leverage across a GenAI renewal?

Keep leverage by avoiding deep proprietary lock in, holding model swap rights, and keeping a credible alternative vendor in view. The GenAI market moves fast, so a one year term with renewal rights usually beats a long commitment to a single model family.

GenAI Red Lines

The full GenAI Red Lines framework from the GenAI Advisory.

the indemnity red line, the training data red line, the model swap right, and the regulatory allocation across the GenAI estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

No spam. We will only email you about this download. Privacy.
Benchmark your GenAI contract exposure with the software spend health check in under five minutes.
Open the Tool →
4
Red lines that decide the deal
0
Training on your data, by contract
25+
GenAI contracts reviewed, 2024 to 2025

The model is a commodity. The contract is not. The four red lines decide whether the deal protects you or the vendor.

Morten Andersen
Co Founder. Ex IBM, ex Oracle.
Deep Library

More on this topic.

GenAI Advisory →
GenAI renewal strategy on a screen
GenAI
GenAI contract renewal strategy
How to hold leverage at renewal.
8 min read
GenAI lock in assessment chart
GenAI
GenAI vendor lock in assessment
Measure your switching cost.
7 min read
GenAI knowledge hub index page
GenAI
GenAI Knowledge Hub
Every GenAI contracting guide.
6 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of your GenAI contracts.

Quarterly buyer side notes on GenAI contracting, indemnity, and vendor lock in. No vendor spin.