Tech Blog, Insights/9 Oct 2026
Borenius Tech Blog: Contracting for AI
Part 2 of 2 – Intellectual property, liability and exit
This second part of our blog series on AI contracts examines three areas that require particular care: intellectual property, liability and risk allocation, and termination and exit.
The familiar framework of IT contracts still applies to AI contracts: ownership, warranties, liability and termination all must be addressed in the same way they would in any technology agreement.
Foundation models, training data, fine-tuned models, inputs and outputs all need to be considered separately from an intellectual property (IP) perspective. The performance of an AI system is harder to measure because outputs are probabilistic. Exit arrangements also tend to be more complex than in a standard software agreement.

Intellectual property
Two IP issues tend to dominate the discussion. First, it is still unclear whether AI-generated content can be protected by intellectual property rights, and the answer varies between jurisdictions. Second, most foundation models are trained on third-party material, so their outputs carry an inherent risk of infringing third-party rights.
- Buyer side: The contract should clearly address who owns the outputs, or at least confirm the buyer’s right to use them. For customisations or fine-tuning of the AI system, an exclusive licence is often more realistic than ownership, because the supplier will likely keep the IP rights in the underlying system. If the solution uses prompts or prompt libraries developed during the engagement, the contract should also cover the buyer’s rights to use them.
- Supplier side: The supplier should keep the IP in the system itself, including pre-existing components and any improvements it develops independently. Any indemnity should be limited to matters the supplier can actually oversee, not framed as a broad warranty. The supplier should also check whether its commitments to the buyer go further than what the upstream model provider offers.
Suppliers should normally indemnify the buyer against third-party IP claims. The buyer should check whether the IP indemnity covers the AI model, its training data and its outputs, rather than assume that protection for one covers all three. In the AI context, suppliers may only be willing to indemnify against risks the supplier can reasonably control. In practice, AI indemnities are now often limited to the agreed use case and operating parameters. This is because AI outputs are probabilistic, and a supplier is unlikely to be reasonably capable to stand behind everything a model produces, especially if it is used outside its intended scope.
Liability and risk allocation
Warranties, liability provisions and indemnities should work together so the contract clearly allocates risk between the parties. In traditional IT contracts, the main operational risks, such as service and system outages, are usually relatively easy to predict. In AI contracts, risk is harder to allocate because the risks may not be clear from the start: outputs are probabilistic, and errors can be hard to detect.
- Buyer side: A broadly drafted disclaimer about input quality can excuse almost any poor output. Likewise, a promise that the system will perform “substantially as described” can leave a lot of room for disagreement. AI can produce plausible but erroneous outputs, and suppliers typically place the responsibility to verify them on the buyer. The buyer should push for accuracy warranties, acceptance testing, or a liability regime that reflects who is best placed to prevent or catch the error.
- Supplier side: Warranties should reflect what the system is designed to do. It is better to define that performance carefully than to overpromise and rely on the liability cap to cover the consequences. The supplier’s exposure should also reflect what it genuinely controls. Where the system is built on a third-party foundation model, the supplier may have limited control over the model’s original training data and its limitations.
One option worth considering is a separate liability limit for losses arising from AI outputs, with a clear explanation of how it interacts with the general liability cap.

Termination and exit
Exit planning raises many of the same questions as in traditional IT contracts. For customised AI solutions, it must also cover what happens to fine-tuning data and customer-specific models when the relationship ends.
- Buyer side: Return and deletion obligations should cover all relevant data, including inputs, outputs and any fine-tuning datasets, in order to avoid any unintentional vendor lock-in. The contract should specify the format for returning data, and state whether the buyer can keep or continue using any customer-specific model after termination. As in traditional IT contracts, the supplier should provide transition assistance and continued access to the service on agreed terms. The buyer must have enough time to switch to an alternative solution with minimal disruption.
- Supplier side: The scope, duration and cost of transition assistance and continued service access should be agreed in advance. Before agreeing to return or delete data and customer-specific model elements, the supplier should check what the system’s architecture actually allows. Where customer data has been used for training or fine-tuning, the parties should agree what can be deleted and flag any technical limitations.
It should be noted that regulatory obligations, such as the switching and portability rights introduced by the EU Data Act, may still apply after termination regardless of what the contract says.
Final thoughts
IP, liability and exit clauses work best when negotiated together, as each one affects the others.
For an off-the-shelf product on standard terms, the suppliers are hesitant to even negotiate the terms. If negotiation is possible, it should be focused on the provisions that carry the greatest practical risk. A customised, high-value deployment calls for a broader review of the whole contract by both parties.
If you missed the first post in this series, it covers definitions, data rights and ownership, and AI Act compliance, and can be found here.
If you have questions about these matters or need assistance negotiating or reviewing an AI contract, please do not hesitate to contact us.
Categories
Additional information

