Authors
Introduction
The predominant way that rights to collect, use, and share data are allocated to create business certainty is through licensing. A license is a right or a permission for a person or company to use another party’s intellectual property, often in exchange for a fee. The benefit of the licensing model is that it offers tremendous flexibility to slice, dice, allocate, monetize, expand, and limit collection, use, and disclosure in an area where traditional intellectual property rights – such as patent, copyright, trademark, and trade secret law – may be less clear, or where there may be differing opinions or points of view. Licensing can help address these issues among and between businesses and even consumers. In particular, licensing as a tool has broadly enabled many of the data-focused innovations of the Internet age. Licensing also helps address privacy and data protection issues in many legal systems; for example, in the United States, not only do privacy policies often address these issues, but terms of use or terms of service frequently include license grants that also address such issues.
Since this guide was first published, regulatory developments have added new dimensions to AI licensing. The EU AI Act imposes obligations on providers and deployers of AI systems, and in the United States, the Copyright Office maintains that using copyrighted works to train generative AI can constitute infringement, reinforcing the importance of licensing as a mechanism for securing data rights and complying with obligations.
In addition, licensing can be used to help address issues of confidentiality, usage considerations or limitations and, increasingly, learning and other issues that often may be experiential and machine-aided in connection with the collection, use, and disclosure of data. For example, secondary usage or derivative usage of data, which may not be subject to copyright or trade secret protection, is increasingly addressed by contract. Similarly, residuals, which refer to information in nontangible form that may be remembered by persons with access to confidential information, are something increasingly important for parties to consider when exchanging confidential information with other parties. Not only can the information generated by a business relationship be valuable, but who has a right to secrecy with respect to it and whether and how the counterparty can use it has become so important that the entire enterprise value of certain businesses has been written off when rights in underlying data were questioned, and, more recently, acquisition transactions have had their purchase price adjusted or deals have failed to close because of uncertainty about data rights. These risks have been magnified by the wave of copyright litigation targeting AI training practices.
With this in mind, it is helpful to understand common contractual provisions used in licensing relating to the collection, use, and disclosure of data.
Key provisions
Representation, warranties, and covenants
In contracts, representations are legally binding assurances that certain facts are true, while warranties provide that, if a stated fact is not true, the recipient of the product or service covered by the assertion of fact will be protected from loss. In contrast, a covenant states that something will or cannot be done and affirmatively obligates a party. Breach of a covenant could result in money damages or an obligation for specific performance. When negotiating a contract for AI products or services, the representations, warranties, and covenants should be specific to AI to address the risks associated with the use of such technology. Examples of such representations, warranties, and covenants include:
- Sufficient rights to use the technology. Many customers may require warranties that state that the vendor has sufficient rights and/or licenses to provide the technology. These come in the form of affirming original creation and/or appropriate licenses, as well as an express representation and warranty of non-infringement. This representation and warranty allow the customer to assert an “innocent infringer” defense to certain intellectual property (IP) claims as well as requiring the vendor to stand behind its IP. However, as a vendor, it may be challenging to provide such representation and warranty since it is difficult to find and assess potential threats, and a vendor may never be sure that it is free from threats of IP infringement. This is especially difficult given the rapidly evolving legal landscape of AI and the concept of copyright protection.
- Consent from individuals. As discussed throughout this guide, data protection laws worldwide may rely on obtaining a user’s consent before processing or using that user’s data. Vendors want to ensure that customers have obtained consent from such individuals to provide personal data or personal information to the vendor in the input data, as well as that the customer is not prohibited from using the data beyond the stated purpose for which consent was given.
- Performance of the AI model. Performance of the AI model is important to ensure that it is working in accordance with any specifications and documentation provided by the vendor. Additionally, a customer may request a warranty and a covenant that certain performance obligations are to be met, including results to be achieved, accuracy, and operability in the customer’s environment. These warranties and covenants may be valuable to a customer to ensure the AI model works as intended and for the customer’s purposes. In turn, a vendor may precisely define and limit the expected performance since AI model development is complex and iterative. A vendor may want to allocate the risk to the customer in determining whether the AI model is suitable for a customer’s business.
- Security-related. There are many issues with regard to cybersecurity vulnerabilities in AI. Customers may request appropriate representations and warranties ensuring adequate proactive and responsive cybersecurity policies and procedures.
- Physical equipment with embedded API. When a vendor sells physical equipment that includes AI, customers should ensure that the representations and warranties in the contract also cover injuries, damages, and even death that could be caused by the customer’s and its users’ use of the AI-enabled machines and devices.
Miscellaneous. Customers should consider how they will use AI in their business. If they intend to incorporate AI into mission-critical functions, such as automating production lines, then the representations and warranties relating to the AI system may address the potential business impact of a total system failure and extended downtime. In situations where the AI includes a facial recognition tool, the risk may be allocated to the developers to ensure that the model is built so that outputs are not deceptive and are free from bias and discrimination.
Indemnification
Indemnification clauses allocate liability to the party with greater culpability for the event that results in liability. Customers paying for the use of generative AI tools may consider obtaining indemnification from the vendor for IP infringement. The parties should carefully consider how to allocate liability for the AI’s functionality because it may be difficult to determine whether the vendor or the customer caused the event giving rise to liability. For example, if the output data infringes on a third party’s IP rights, it may be difficult to determine whether the input data provided the infringing content or materially contributed to or caused the infringement. Other indemnities that a customer may request a vendor to provide include property damage or personal injury if the AI model is used in a high-risk environment such as a manufacturing plant, or data breaches if the AI model ingests personal data. A customer might review its use of the AI model and the type of data it is providing the vendor to ensure it is protecting itself from potential third-party risks. However, a vendor will want to ensure that its indemnities are limited to third-party claims that may occur and for which it would be responsible. It may not be reasonable to provide indemnities for matters outside of its control or within the control of the customer.
The market for AI-related indemnification continues to evolve. Major generative AI providers now offer IP indemnification covering outputs generated by their enterprise AI products, provided customers use built-in guardrails and content filters. These vendor indemnification programs have become an important baseline in AI licensing negotiations, though their scope varies and they are typically subject to conditions, including that the customer did not intentionally create infringing output. Customers should carefully review the scope, conditions, and limitations of any vendor-provided indemnification and negotiate for broader coverage where warranted.
Limitation of liability
A limitation of liability clause limits the amount of damages that a party can recover from another party for breaches or performance failures. Limitation of liability clauses typically limit the liability to one of the following amounts: (1) the compensation and fees paid under the contract; (2) an agreed-upon amount of money; (3) available insurance coverage; or (4) a combination of two or more of the above. When the parties are negotiating a liability cap in an agreement, they should look closely at the specific risks and apply individual limitations accordingly. For example, if there is a supply line that is operated by AI-enabled robots and those robots fail, a customer’s business could be severely impacted if it is unable to operate as usual. In these situations, a customer would want to seek damages sufficient to cover their losses and any consequences of being unable to run their business. Many liability caps also involve a waiver of consequential damages that prevents parties from recovering special, indirect, and consequential damages, and customers may want to consider exceptions to such a waiver. For instance, if an AI data analytics system inadvertently discloses personal information of downstream users, the customer may face third-party claims from those users and sustain serious reputational damage. The negotiations over liability limitations therefore deserve careful attention. With increasing regulatory requirements, parties should also consider whether regulatory fines and penalties should be carved out from standard liability caps and consequential damages waivers, as the financial exposure from regulatory non-compliance may substantially exceed typical contractual liability limits.
Insurance
Insurance requirements may be critical in an AI-related commercial contract as they decrease the risk associated with the AI system and shift the consequences of that risk to another party. There are several types of insurance coverages that a party can obtain, and a party should review each policy type to ensure that it covers the variety of damages that may occur. If an AI system fails or causes damage, the parties may determine which coverage, if any, applies in any given situation, and, if not, whether coverage can be expanded or added, or whether coverage is available at all. One type of insurance many parties request in commercial agreements when data, personal information, or other systems are involved is cybersecurity insurance. Cybersecurity insurance, however, may not cover all AI failures. Cybersecurity insurance typically covers model-stealing attacks and data leakage, not bodily harm, brand damage, or damage to physical property. If this is important to a party, it should ensure that it requires the vendor to obtain the appropriate insurance policy. As the AI regulatory landscape continues to mature, parties should also consider whether insurance policies adequately address AI-specific risks, including regulatory fines, IP infringement claims arising from AI-generated outputs, and algorithmic bias claims. The insurance market for AI-related risks is still developing, and parties may need to negotiate bespoke coverage or higher policy limits to address the unique risk profile of AI systems.