All insights
EN · AI Strategy & Transformation

AI services contracts: how to negotiate liability, warranties, and indemnities

Allocate AI risk by control, evidence, and remedy—without demanding blanket unlimited liability or leaving critical failures uncovered.

Eight AI risk pathways pass through balanced contractual controls before converging on a governed system.
The AI Contract Risk Allocation Proof-8 connects each risk to control, evidence, remedy, cap, insurance, and exit. · Generated with OpenAI

Do not begin with a generic liability cap. Start with failure scenarios, identify who controls each cause, define preventive evidence, and attach an enforceable remedy. Liability, warranty, indemnity, insurance, service credits, cure, and exit perform different jobs in an AI services contract. The commercial architecture should connect them without double recovery or leaving a material risk ownerless.

Allocate each risk to the party best able to prevent, detect, and mitigate it. The provider may control code, configuration, security practices, and subcontractors; the buyer controls supplied data, human decisions, intended use, and changes to its environment. Foundation-model dependencies, regulatory change, and emergent behavior may require shared controls. Moving every risk to the provider usually increases price, reduces bidder diversity, or creates an obligation no firm can actually perform.

The AI Contract Risk Allocation Proof-8

Score each class from zero to four: zero is ignored; one is boilerplate; two names responsibility but lacks evidence or remedy; three documents control, evidence, response, and cap; four has been scenario-tested operationally. Require at least 24 of 32, no zero, and passage of the mandatory gates. Counsel validates enforceability; the matrix ensures business, engineering, risk, and procurement are negotiating the same system.

  • Outcome and use — purpose, users, prohibited decisions, human oversight, and plausible losses.
  • Data and privacy — source, instructions, roles, use, retention, incident response, deletion, and third parties.
  • Security — access, secure development, vulnerabilities, notification, containment, and recovery.
  • Intellectual property — inputs, components, outputs, third-party claims, defense, and replacement.
  • Models and supplier chain — terms, change, availability, regions, versions, and subcontractors.
  • AI quality and safety — evaluations, known limitations, review, drift, and correction.
  • Operations and continuity — SLAs, repeat failures, support, fallback, transition, and safe shutdown.
  • Regulation and change — each party's duties, cooperation, audit, changes in law, and replanning.

Use a remedy ladder instead of one catch-all clause

For every risk, walk through seven layers: verifiable prevention; a specific warranty; a cure period; service credits or holdback where appropriate; indemnity for defined categories of third-party claims; direct damages under the applicable cap; and termination or assisted exit when failure threatens the operation. Insurance may fund certain losses, but it does not replace an obligation, control, or remedy.

FAR warranty guidance offers a useful drafting discipline: state exactly what is warranted, the obligations following breach, available remedies, duration, and notice process. For AI, reject absolutes such as perfect accuracy, zero hallucinations, or automatic compliance with every law. Use testable commitments tied to the SOW, acceptance criteria, use policy, evaluation set, and operating controls.

Eight questions for the risk-allocation matrix

  • What concrete event triggers the obligation?
  • Who controls the cause, and who controls the final decision?
  • What evidence proves prevention and performance?
  • What comes first: cure, replace, rerun, refund, or suspend?
  • Which direct losses are plausible, and how will they be measured?
  • Is there a third-party claim that needs a specific indemnity?
  • Is insurance available, and does it actually cover the event?
  • Which access, cooperation, and documentation survive termination?

Separate the general cap, supercaps, and carve-outs

A general cap can address ordinary contractual breach. Categories with materially different exposure—privacy, confidentiality, security, or intellectual property—may justify separate supercaps. Uncapped liability should be exceptional and tied to losses that cannot lawfully be limited or intentionally excluded conduct. Do not copy market multiples without modeling impact, likelihood, insurance, and the provider's financial capacity.

The UK Government's 2026 risk-allocation guidance calls for an explainable relationship between each limit and assessed risk and warns that excessive transfer can become a risk premium or an onerous contract. It also distinguishes data-protection exposure from general losses. For each scenario, record the owner, control, impact range, cap, insurance evidence, exclusions, and residual risk retained by the buyer.

Make warranties survive acceptance

Acceptance proves that a deliverable passed the agreed tests at a point in time; it should not erase latent defects or continuing duties. Define duration, defect reporting, severity, response time, correction cost, and retesting. Tie warranties to controllable specifications: conformance to documentation, professional performance, stated authorization and licenses, no prohibited training on buyer data, access controls, and delivery of agreed artifacts.

Reserve indemnities for defined claims

An indemnity should not mean 'anything that goes wrong.' Define the event, eligible claimant, notice, control of defense, cooperation, settlement consent, exclusions for buyer materials or instructions, and interaction with the applicable cap. An IP claim, a subcontractor-caused breach, and unauthorized data use may warrant different treatment from a first-party performance defect.

Inspect insurance beyond the certificate

Request coverage aligned to the actual exposure, such as technology errors and omissions/professional liability, cyber, and commercial general liability where relevant. Check the named insured, territory, per-claim and aggregate limits, retention, material exclusions, claims-made versus occurrence basis, retroactive date, subcontractor treatment, and cancellation notice. A certificate without exclusions can create false confidence; lack of third-party insurance does not automatically disqualify a provider if proportionate self-insurance is demonstrable.

Run three contract scenarios before signature

  • Bad decision: the system recommends an action that creates loss. Test whether the provider missed an agreed evaluation or guardrail and whether the buyer bypassed required human review.
  • Data incident: separate incorrect buyer-provided data, provider access failure, and a foundation-model vendor event. Walk through notice, containment, investigation, cooperation, and cost.
  • Model outage or change: simulate unavailability, price increase, term changes, or version retirement. Verify fallback, substitution, acceptance of changed behavior, and exit rights.

U.S. enforceability, statutory exposure, privacy obligations, and the treatment of consequential damages, caps, indemnities, and insurance vary by state, sector, and facts. The EU clauses and government procurement sources are useful design references, not plug-and-play U.S. language. Have qualified counsel adapt the final agreement.

Connect risk to the SOW, security, rights, and acceptance

Use https://makinai.co/insights/en/what-to-include-ai-services-contract-sow for the agreement structure, https://makinai.co/insights/en/security-due-diligence-ai-services-company for control evidence, https://makinai.co/insights/en/who-owns-code-data-prompts-ai-services-engagement for assets and licenses, and https://makinai.co/insights/en/ai-project-acceptance-criteria-payment-milestones to connect evidence to payment.

When to involve MAKINAI

MAKINAI can turn scope, architecture, dependencies, and failure modes into a negotiable risk matrix before signature, connecting technical evidence, acceptance, operations, and exit. Explore https://makinai.co/services/en/ai-strategy-transformation-consulting. Qualified counsel should review final drafting and liability decisions in the applicable jurisdictions.

Sources and references

  1. GOV.UK — Risk Allocation and Pricing Approaches · UK Government Commercial Function

    Guides buyers to allocate each risk to the party best able to control it, using a risk matrix, proportionate caps, insurance and performance mechanisms.

    2026-09-04
  2. EU AI Model Contractual Clauses · European Commission Public Buyers Community

    Provides model clauses and commentary that buyers can adapt for high-risk and non-high-risk AI systems.

    2026-09-04
  3. FAR Subpart 46.7 — Warranties · Acquisition.gov

    Explains the purpose and design of warranties, including scope, obligations, remedies, duration, notice and enforceability.

    2026-09-04
  4. NIST AI 600-1 — Generative AI Profile · NIST

    Applies the AI RMF to generative-AI risks and emphasizes governance, measurement, documentation, incidents and third parties.

    2026-09-04
  5. NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management · NIST

    Supports lifecycle management of cybersecurity risks introduced by suppliers, products, services and dependencies.

    2026-09-04
Making connections

Continue exploring

AI Strategy & Transformation

How to define AI provider governance and performance management before hiring

Read insight
AI Strategy & Transformation

How to evaluate an AI consulting ROI business case before hiring

Read insight
AI Strategy & Transformation

Boutique AI firm, global consultancy, or systems integrator: how to choose

Read insight
Related capability

AI strategy & transformation

An AI transformation consultancy should answer four questions before recommending technology: where business value exists, which capabilities and data are required, how risk will be controlled, and who will operate the change. MAKINAI connects those answers in an executable plan with priorities, owners, metrics and scale decisions.

Explore this capability