anaboo.ai
A business owner reading small-print terms of service on a laptop screen with an AI chat interface visible in the background, representing AI vendor contract liability
← All posts

What your AI vendor contract actually says about liability

3 October 2026Brett Alegre-Wood6 min read
AI vendor contract liabilityAI indemnification clauseAI output liabilityAI terms of service riskAI governance SMEAI legal risk
Listen to this article0:00 / 4:35
Two AI hosts discuss this article. Generated from the text.Download

TL;DR

Most AI vendor contracts contain an indemnification clause that places full liability for AI-generated outputs onto the customer, not the vendor. The clause is rarely flagged during onboarding. If your business publishes, acts on, or sends AI-generated content without accountable human review, you own the legal consequences. The vendor does not.

The clause nobody reads at sign-up

When you sign up to an AI platform, you move fast. There is a product to test, a problem to solve, a team waiting. The terms of service get a scroll and a click.

That scroll just transferred legal responsibility for every piece of content the AI generates to you.

The indemnification clause in most AI vendor agreements says, in plain terms: the vendor provides the tool, you are responsible for the output. Whatever the AI writes, calculates, recommends, or decides, if it causes harm, infringes a copyright, makes a false claim, or misleads someone, the liability sits with your business.

This is not unusual in software contracts. But it carries unusual weight with AI, because AI outputs can be wrong in ways that look completely right.

What "you own the output" actually means

A standard software tool does predictable things. A spreadsheet does not invent numbers. A calendar does not book appointments with people who do not exist.

An AI that drafts contracts, writes marketing copy, answers customer queries, or generates compliance summaries can produce confident, polished, entirely wrong output. And that output goes out under your name, on your letterhead, from your domain.

If a customer receives incorrect advice from your AI chatbot and makes a financial decision based on it, the claim comes to you, not to the AI vendor.

If your AI drafts a proposal with an incorrect specification and you send it to a client, that is your proposal. If your AI generates a compliance summary that misses a material obligation, that is your compliance failure. If your AI writes marketing copy that makes a product claim you cannot substantiate, that is your consumer law problem.

The vendor's position is consistent: they gave you a tool. You used it. You signed the terms.

Where small businesses are most exposed

Large enterprises tend to have in-house legal review of AI vendor agreements before they sign. SMEs almost never do.

The exposure concentrates in a few common areas:

  • Customer-facing AI outputs. Chatbots, automated email replies, AI-generated quotes. If the output is wrong and the customer relies on it, the claim comes to you.
  • AI-assisted professional documents. Contracts, compliance reports, financial summaries, HR documentation. Wrong content in a professional document carries more weight than a badly worded internal note.
  • Marketing and advertising copy. AI that invents a product feature, exaggerates a capability, or makes a claim that cannot be substantiated is creating a consumer law problem, not a technology problem.
  • Decisions made using AI recommendations. If you can show that a business decision was made on the basis of AI output, and the output was wrong, the decision is still yours. The AI's confidence is not a defence.

None of these are edge cases. They are the normal use patterns for AI in an SME.

Does a human reviewer protect you?

Many businesses assume that having a person review AI output before it is sent solves the liability question. It helps, but it does not fully close the gap.

The reason is practical. When AI is generating high volumes of output, the review process tends to become cursory. A person scanning fifty AI-written emails for tone is not catching a factual error buried in paragraph three. A manager approving thirty AI-generated quotes is not verifying every line item independently.

The vendor knows this. Their contract does not require you to have a perfect review process. It requires you to accept that the output is yours.

That said, a documented review process does matter for your own risk position. If something goes wrong, the difference between "we had a process and it failed" and "we sent AI output directly without any review" can be significant in how a dispute resolves and what your insurer says.

Start here

See where AI fits in your business. Free.

A 45-minute audit. We map the highest-value automations and what they're worth in time and money. No pitch, no pressure.

What the contract usually will not tell you

Beyond the indemnification clause, there are other provisions worth understanding before you use an AI vendor for anything consequential.

Data ownership and confidentiality. When you feed your business data, customer records, or proprietary processes into an AI tool, the terms around who owns that data and how it can be used vary significantly between vendors. Some allow your inputs to be used for model training. Some do not. Most do not volunteer this information clearly in the onboarding flow.

Accuracy disclaimers. Nearly every AI vendor includes a disclaimer that their tool does not guarantee accuracy and should not be relied on for professional, legal, or financial advice. That disclaimer exists for a reason. It shifts the risk of relying on inaccurate output to you, the person doing the relying.

Termination and portability. If a vendor changes their pricing, discontinues a product tier, or shuts down an API, your workflows that depend on it stop working. The contract rarely provides remedy for that disruption to your business.

Can you negotiate better terms?

For most SMEs using off-the-shelf AI tools, the honest answer is no. Enterprise-tier contracts sometimes allow negotiation on liability caps and data handling. Consumer and SME tiers almost never do.

What you can do is choose where to concentrate AI use based on the risk profile of the output.

Low-stakes tasks, drafting internal notes, generating first-pass ideas, summarising long documents for your own review, carry limited liability regardless of accuracy. If the AI gets something wrong in a draft you then edit and correct, the harm is minimal.

High-stakes tasks, anything that gets sent to a client, filed with a regulator, included in a contract, or used to make a financial decision, need human review with actual accountability attached to it.

That is not a technology decision. It is a governance decision. And it is one most businesses are not making explicitly.

What governance looks like without a legal team

Most SMEs that use AI well do not have a dedicated legal or compliance function. They have a handful of people who understand the business and care about doing it right.

Practical governance for AI vendor liability does not require a policy document the length of a law firm memo. It requires a clear answer to three questions for every AI use case:

  1. Who reviews this output before it is used or sent?
  2. What are they specifically checking for?
  3. If this output is wrong and causes a problem, who in the business is accountable?

If you cannot answer those three questions for a given AI workflow, that workflow carries unmanaged risk. The terms you already signed have made sure of that.

This accountability layer is what AIOS builds into how AI is deployed across a business. Every workflow has an owner. Every output has a review step where it matters. The AI augments the person responsible for the decision. It does not replace the judgement call, and it does not absorb the liability.

What to do this week

  1. Read the indemnification clause in the terms of service for every AI tool your business currently uses. It will sit under a heading like "Indemnification", "Limitation of Liability", or "Your Responsibilities". Read it once. You will not forget it.
  2. List your customer-facing AI outputs. Any AI-generated content that reaches a customer, whether a chatbot response, an email, a quote, or a report, needs a documented review step with a named person responsible for it.
  3. Check the data use terms. Find the clause that describes how your inputs are handled. If your tool uses customer data for model training by default, decide whether that is acceptable and whether your customers are aware of it.
  4. Set a risk threshold. Agree internally on which categories of AI output require mandatory human review before use, and which can proceed without it. Write it down, even if it is one short paragraph. That record matters.
  5. Add it to your risk register. AI vendor liability is a live business risk. If you have a risk register, it belongs there with an owner and a review date. If you do not have one, this is a reasonable prompt to start.

Where to from here

Book a free AI audit and we'll show you what's worth augmenting first in your business, and what isn't.

Live with passion & AI,

Brett

Speaking

Running an event? Put practical AI on your stage.

Keynotes and workshops that send business owners home with a plan they can use Monday morning. No hype.

Frequently asked questions

What is an AI indemnification clause?

+

An indemnification clause in an AI vendor contract means you agree to hold the vendor harmless for any harm caused by the tool's outputs. In practice, if the AI generates wrong, misleading, or legally problematic content and your business uses it, the liability sits with you, not the vendor.

Are AI vendors ever responsible for incorrect outputs?

+

Most AI vendors include explicit accuracy disclaimers stating their tools do not guarantee correct outputs and should not be relied on for professional, legal, or financial decisions. These disclaimers shift reliance risk to the customer. In standard SME agreements, vendor liability for output errors is either capped at a minimal amount or excluded entirely.

Does reviewing AI output before sending it protect my business?

+

It helps, but it does not fully close the gap. The vendor's contract does not require a perfect review process. What matters is whether you can show you had a documented, accountable review step, not just that someone glanced at the output before it went out.

Which types of AI output carry the most legal risk for a small business?

+

Customer-facing outputs carry the most risk: chatbot responses, automated quotes, AI-drafted contracts, compliance documents, and marketing claims. Any output that a third party might rely on or act on creates exposure if the content is wrong.

Can I negotiate AI vendor terms as a small business?

+

For off-the-shelf SME and consumer-tier AI tools, meaningful negotiation is rarely possible. Enterprise contracts sometimes allow it. The more practical approach is to treat the standard terms as fixed and design your internal governance to manage the risk they create.

What is the minimum governance an SME needs to manage AI output liability?

+

For each AI workflow, you need a clear answer to three questions: who reviews this output before it is used, what are they specifically checking for, and who is accountable if it is wrong. That does not require a lengthy policy document. It requires a brief, honest conversation and a written record.

Does this apply to all AI tools or just the big platforms?

+

It applies to any AI tool where you agree to terms of service, which covers almost every platform, large or small. The specific wording varies, but the standard position across the industry is that the vendor provides the capability and the customer is responsible for how outputs are used.

Brett Alegre-Wood, founder of Anaboo
About the author
Brett Alegre-Wood

Brett is a four-time founder (Darra Tyres, Gladfish, EzyTrac, Anaboo) and the operator behind AIOS, Anaboo's AI Operating System. He writes from inside the build, installing AI in his own businesses first and reporting back what actually moves the numbers. Based between Singapore, the UK and Australia.

WE USE AI: All images are made with programmatic AI (a prompt is used rather than real photos) so when you meet Brett and the team they may look slightly different from these images. This is done to show you what's possible.

Want Anaboo AIOS in your business?

Free 60-minute audit. We'll show you what's worth automating first.