AI contract clauses: residency, training and IP you must negotiate.
Three clauses decide whether an enterprise AI deployment is safe to sign — data residency, training rights, and output indemnity. A fourth, audit rights, is now decisive under the EU AI Act. This note compares OpenAI, Anthropic, Microsoft, Google, AWS Bedrock and IBM Watsonx on all of them, and gives the exact contract language to demand.
The default AI contract leaks training data, hands the vendor unlimited rights to your prompts, and exposes you to copyright damages the vendor will not cover. Only two of six major vendors offer residency, training opt-out and indemnity in standard paper — and indemnity caps span from fees paid to uncapped. The fix is six negotiated paragraphs.
01 Key findings
Three clauses shift material risk; a fourth is rising fast. Master agreements run 40–80 pages, but only data residency, training opt-out and copyright indemnity move the risk profile. Audit rights are now decisive under the EU AI Act and US state-level AI laws.
The residency line is softer than it reads. Most vendors offer EU residency for inference but not for underlying training infrastructure, and standard clauses quietly exclude logs, abuse-monitoring data and human-reviewed safety samples from the named region.
Training opt-out has converged — on paper. OpenAI Enterprise, Anthropic, Azure OpenAI, Google Vertex AI and AWS Bedrock all now state in the master agreement that they do not train on customer content. Regulated buyers should push past that to audit rights plus liquidated damages.
Indemnity is where vendors diverge most. Microsoft and IBM offer uncapped cover for their own models; OpenAI, Anthropic, Google and AWS cap at or near fees paid. Every programme carries safety-system carve-outs enforced at vendor discretion.
Audit rights are no longer optional. Under DORA and the EU AI Act, financial-services and high-risk deployments need a direct audit right — vendor self-attestation will not satisfy the regulator.
02 The clauses that matter
Most AI vendor master agreements run 40 to 80 pages. Only three clauses materially shift risk: data residency, training opt-out, and copyright indemnity. A fourth, audit rights, is rising under the EU AI Act and US state-level AI laws. The table sets the weak default language against the position to negotiate to.
| Clause | Default vendor language | Negotiated buyer language |
|---|---|---|
| Data residency | Vendor-elected region, no contractual lock | Named region; written notice required before any cross-border processing |
| Training on customer data | Permitted for service improvement | Prohibited; no opt-out form required; audit right attached |
| Output IP ownership | Customer owns outputs; vendor disclaims warranties | Customer owns outputs; vendor warrants no third-party rights |
| Copyright indemnity | Excluded or capped at fees paid | Uncapped or 3x annual fees, with named carve-outs |
| Audit rights | Vendor self-attestation only | Third-party SOC 2, ISO 42001, and direct audit for regulated workloads |
03 Data residency
Residency is the first question general counsel asks, and the easiest clause for a vendor to soften without changing the technical architecture. The contractual goal is to name the processing region in the order form and require written notice plus consent before any cross-border move. Most providers offer EU residency for inference but not for underlying model-training infrastructure.
| Vendor | EU inference | EU training | US inference | India / Canada / Australia |
|---|---|---|---|---|
| OpenAI (ChatGPT Enterprise) | Yes (Ireland, Germany) | No (US only) | Yes | Australia yes; Canada partial |
| Anthropic (Claude Enterprise) | Yes (Frankfurt, Dublin) | No (US only) | Yes | Via AWS Bedrock regions |
| Microsoft Azure OpenAI | Yes (Sweden, Switzerland, France) | No (fine-tuning yes, base training no) | Yes | 14 regions globally |
| Google Vertex AI / Gemini | Yes (Belgium, Netherlands, Finland) | No (US, Singapore) | Yes | Multi-region |
| AWS Bedrock | Yes (Frankfurt, Ireland, Paris) | N/A (inference-only) | Yes | Multi-region |
| IBM Watsonx | Yes (Frankfurt, London) | Yes (selective) | Yes | Multi-region |
The EU AI Act sits above GDPR. Providers of general-purpose AI models placed on the EU market must comply with transparency, copyright and risk obligations from 2 August 2025, with high-risk system obligations from 2 August 2026. Reference Article 53 obligations in the contract so the vendor commits to the disclosures you will be asked for under your own AI Act compliance programme.
Vendor standard contracts say “data processed in customer-selected region” but exclude logs, abuse-monitoring data and human-reviewed safety samples from that scope. Push for “all customer content, including telemetry, prompt logs, completion logs and human-reviewed safety samples, processed and stored in the named region” with no carve-outs.
04 Training rights
Enterprise contracts now fall into four bands on training rights. Anything below Position 3 is unsuitable for enterprise data; regulated workloads should reach Position 4.
Trains by default, dashboard opt-out
The consumer OpenAI posture and the Google Workspace AI feature default. Unsuitable for any enterprise deployment.
Trains by default, opt-out on request
The legacy Microsoft and Google enterprise position. Contractual opt-out exists but must be requested and evidenced.
No training, written in the MSA
No opt-out form needed. The OpenAI Enterprise, ChatGPT Team, Claude Enterprise, Azure OpenAI and Vertex AI position today.
No training, audit right + damages
Customer can verify, and any training breach triggers liquidated damages. Negotiate this for financial services, healthcare and EU public sector.
| Vendor | Standard position | Contract language to look for |
|---|---|---|
| OpenAI Enterprise | Position 3 | “OpenAI does not train its models on Customer Content” |
| Anthropic Claude Enterprise | Position 3 | “Anthropic does not train our models on Customer Inputs or Outputs” |
| Microsoft Azure OpenAI | Position 3 | “Your prompts and completions are NOT used to improve the OpenAI models” |
| Google Vertex AI | Position 3 | “Google does not use Customer Data to train, fine-tune, or improve any Generative AI Models” |
| AWS Bedrock | Position 3 | “AWS does not use Customer Content to train or improve the AWS Generative AI Services” |
| IBM Watsonx | Position 3 (negotiable to 4) | “IBM will not use Client Content to train its Foundation Models” |
A dashboard toggle is not a contract. Consumer and team tiers often default to training with an opt-out buried in settings that any admin can reverse. Insist the no-training commitment sits in the master agreement itself, covers both inputs and outputs, and — for regulated data — carries an audit right so you can verify it rather than trust it.
05 Output IP & indemnity
Output ownership is now uniform: the customer owns the outputs. The contested clause is what happens when an output infringes third-party copyright. The six vendors take materially different positions on scope, cap and carve-outs.
| Vendor | Indemnity scope | Cap | Carve-outs |
|---|---|---|---|
| Microsoft Copilot Copyright Commitment | Copyright claims for Microsoft Copilot outputs | Uncapped for Copilot, subject to volume license terms | Customer must use content filters; misuse forfeits cover |
| OpenAI Copyright Shield | Copyright claims for ChatGPT Enterprise and API outputs | Fees paid in prior 12 months as a floor; negotiable above | No bypassing safety systems; Enterprise and Team only |
| Anthropic indemnity | Third-party IP claims from Claude outputs | Up to prior-12-month fees; negotiable to 3x for enterprise | Misuse, off-policy content, bypassed safety controls |
| Google Vertex AI Output Indemnification | Third-party IP for output from approved Google models | Per master agreement cap, often 2x fees | Customer prompt that is itself infringing |
| AWS Bedrock IP indemnification | Copyright claims for Amazon Titan and select partner models | Subject to AWS Enterprise Agreement cap | Customer-provided fine-tuning data |
| IBM Watsonx | IBM IP indemnity for IBM-developed Granite models | Uncapped for Granite; capped for routed third-party models | Customer fine-tuning with non-IBM data |
For workloads where outputs are published externally, set the indemnity floor at 12 months of fees minimum. Where outputs feed customer-facing products, push for 3x annual fees uncapped on direct damages. Reject any “customer indemnifies vendor for use” clause that flips the indemnity direction.
“Indemnity does not apply where Customer disables, modifies, or routes around safety systems.” Reasonable in principle, but enforcement is by vendor discretion. Negotiate a 30-day cure period, written notice, and the right to dispute the determination before indemnity is forfeited — and confirm output ownership carries a warranty of no third-party rights, not a bare disclaimer.
06 Audit rights & compliance
Audit rights were optional through 2024. From 2026, regulated industries need them. EU AI Act Article 50 transparency obligations and Article 26 deployer obligations require customers to evidence that their AI vendor complies with documented practices. Standard vendor contracts give no audit right; negotiated contracts grant a SOC 2 Type II inspection right, ISO 42001 certification disclosure, or a direct audit right for regulated workloads at the customer’s expense with reasonable notice.
For financial-services workloads under DORA (Digital Operational Resilience Act, effective 17 January 2025), the audit clause is non-negotiable. DORA Article 30 requires financial entities to hold audit and inspection rights over ICT third-party providers supporting critical functions. AI vendors classified as critical ICT providers must accept the direct audit right or be replaced.
Ask for all three, in order of strength: ISO 42001 disclosure (baseline), SOC 2 Type II inspection (standard for regulated data), and a direct audit right (mandatory under DORA for critical functions). If a vendor will not move past self-attestation, treat it as a red flag on any workload carrying customer or employee data.
07 Negotiation checklist
Apply this to every AI vendor contract before signature. Aim for green on all five rows for any workload above $250,000 in annual fees, or any workload involving customer or employee data.
| Row | Green | Amber | Red |
|---|---|---|---|
| Data residency | Named region, no carve-outs, written notice required | Named region with logs carve-out | Vendor-elected, no contract lock |
| Training opt-out | “Vendor does not train on Customer Content” in MSA | Opt-out by dashboard toggle | Vendor trains by default |
| Output IP | Customer owns; vendor warrants no third-party rights | Customer owns, no warranty | Customer indemnifies vendor for outputs |
| Copyright indemnity | Uncapped or 3x fees, named carve-outs only | Capped at 12 months of fees | Excluded; customer bears risk |
| Audit rights | Direct audit + SOC 2 + ISO 42001 disclosure | SOC 2 Type II only | Vendor self-attestation only |
This is the same workbook our advisors use during enterprise AI procurement reviews. To pair these clauses with vendor capability scoring, see our enterprise AI vendor selection framework and AI RFP template. For pricing benchmarks across the same vendors, see our enterprise LLM cost comparison and ChatGPT Enterprise pricing pillar. For vendor-specific context, see our Microsoft and Google Cloud vendor hubs.
08 Our recommendation
Financial services, healthcare and EU public sector should demand named-region residency with no carve-outs, no-training with an audit right and liquidated damages, and a DORA-grade direct audit clause. Nothing below green is signable.
Where outputs are published or feed customer-facing products, the copyright indemnity is the decisive term. Push for 3x annual fees uncapped on direct damages and strip discretionary safety-system forfeiture down to a noticed, curable event.
For internal-only use, most Position 3 vendors already give residency and no-training in standard paper. Confirm the training language sits in the MSA, secure SOC 2, and reserve indemnity effort for higher-risk workloads.
Lock the AI contract before you sign
Independent reviews lift 9 of 14 standard clauses in a typical 30-day negotiation across residency, training, IP, indemnity and audit.
The Licensing Edge
Weekly vendor and AI-contract intelligence for enterprise IT leaders. 3,000+ subscribers.