Contents
Key takeawaysThe five data termsWhy retention comes firstEnterprise tiers and trainingOutput ownership and indemnityGovernance before priceWhat we have seenContract wording to ask forChecking your contractsWhat to do nextFAQAn enterprise AI contract has to settle training use, residency, retention, output ownership and IP indemnity. The five are usually negotiated as a checklist, yet retention decides whether the other four still mean anything.
- Five terms, one dependency. Training use, residency, output ownership and indemnity all hold only for as long as the vendor keeps your data, so fix a deletion window first.
- Defaults favor the vendor. In our reviews, default or standard tiers permitted input reuse for training in 50 to 70 percent of first drafts.
- Silence is the usual gap. Residency, retention and output ownership were absent until the buyer raised them, and absence is harder to spot than hostile wording.
- The tier carries the protection. Enterprise and API tiers usually exclude your data from training, but only for the SKU you buy and only if the clause is in the signed agreement.
- Indemnity has conditions. Read the cap, the exclusions and any required mitigations, because a claim can fail on a filter your developers switched off.
- Governance before price. Terms raised after the discount is agreed are settled with little room to push, so close all five before the rate discussion opens.
What should an enterprise AI contract say about your data?
It should settle five terms in writing: whether the vendor may train on your inputs, where your data is stored, how long it is kept, who owns the output, and who pays when that output infringes someone else's IP. Standard order forms settle the first one at best and say nothing on the rest.
Silence on any of these terms is not neutral. The vendor's own practice fills the gap, and that practice can change without your signature.
| Term | Risk when the contract is silent | What to get in writing |
|---|---|---|
| Training use | Inputs reused to improve the model | An explicit no training clause bound in the agreement |
| Residency | The vendor chooses the region | Named regions written into the order |
| Retention | Open ended storage of prompts and outputs | A fixed deletion window |
| Output ownership | Ambiguous, resting on unsettled law | Customer ownership stated explicitly |
| Indemnity | Silent, with the customer carrying the output risk | Vendor indemnity on third party IP claims, with the cap read |
Put the gaps together and a standard order form amounts to a set of consumer defaults printed on enterprise paper. Our AI procurement framework places these terms inside the wider category review, and the AI data security guide covers the security questionnaire that runs alongside them.
Signing the Enterprise Agreement
Why is retention the clause that makes the others enforceable?
Retention decides how long every other promise has to hold. A no training commitment only governs data the vendor still has, so an open ended hold means it must survive every future change of policy, ownership and jurisdiction. A fixed deletion window gives the other four terms an end date.
How retention protects the no training promise
Deleted data cannot be trained on, sold with the company or produced under a subpoena. Held data can be, whatever today's policy says. In 2025, a US court in The New York Times copyright case ordered OpenAI to preserve consumer ChatGPT and standard API content indefinitely, including chats users had deleted.
ChatGPT Enterprise, ChatGPT Edu and Zero Data Retention API customers were outside the order, and OpenAI says the obligation ended on September 26, 2025. Customers on a standard 30 day deletion promise learned that a court could extend it.
How retention bounds residency
A named region without a deletion window fixes where the data lives and places no limit on how long it lives there. Read the edges of the residency offer too. OpenAI sets residency when a workspace is provisioned, and its documentation says workspace metadata, billing data and some integration data may sit outside the chosen region.
Retention on your own side of the contract
Amazon Bedrock keeps model invocation logging off by default. Once your team turns it on, prompts and responses land in your own CloudWatch Logs group or S3 bucket. Neither expires them unless someone sets a retention period on the log group or a lifecycle rule on the bucket, so put both in your own retention schedule.
Worked example: what an open ended window holds
Say 2,000 staff each send 25 prompts per working day, or 50,000 prompts a day, and a month has 20 working days.
| Retention term | Calculation | Prompts held at any time |
|---|---|---|
| 30 day deletion window | 50,000 a day x 20 working days | About 1,000,000, always the latest month |
| Open ended, after year 1 | 50,000 x 240 working days | 12,000,000 |
| Open ended, after year 3 | 50,000 x 240 x 3 | 36,000,000, including prompts from staff who have left |
The no training clause reads the same in both cases. What changes is how much of your history is exposed to the next policy change, acquisition or legal demand.
Enterprise AI Procurement Strategy Brief
Governance clauses, category review and commitment sizing for your next AI agreement in one guide.
Get the white paper →Does buying an enterprise tier stop the vendor training on your data?
Usually yes, and only for the tier you actually bought. Enterprise and API tiers at the major vendors generally exclude customer data from training, but the protection belongs to the tier you select and the clause you bind.
Anthropic's consumer terms change shows how far apart tiers can sit at one vendor. Starting August 28, 2025, Anthropic asked Claude Free, Pro and Max users to choose whether their chats could train its models, with 5 year retention for those who agreed. Claude for Work, Government, Education, the API, Amazon Bedrock and Google Cloud's Vertex AI were excluded.
Find the clause, and ignore the product page
A no training statement on a help article, trust center or blog post is not a contractual commitment, and the two are routinely conflated during evaluation. Ask the account team to show you the sentence in the agreement you will sign, then read it for exceptions.
OpenAI's published Services Agreement says it will not use customer content to improve its services unless the customer explicitly agrees. Its enterprise privacy page adds that data shared through opt in feedback mechanisms may be used for training, so settle whether user ratings are in scope.
Bind it in the master agreement
A no training term in a referenced policy carries the same amendment risk as any document the vendor can revise alone. Put it in the master agreement, and where the contract links to a policy by URL, fix the version that applies for your term.
For platform specifics, see our Azure OpenAI negotiation guide, the guide to AI data terms in Microsoft contracts and, for AWS, the Amazon Bedrock pricing guide.
Who owns AI output, and what does an IP indemnity cover?
Most enterprise terms assign output to the customer, and you should still get that stated explicitly. The clause settles rights between you and the vendor. Whether the output has copyright protection against anyone else is unsettled law.
OpenAI's Services Agreement says the customer owns all output and assigns it whatever rights OpenAI has, if any. In January 2025 the US Copyright Office concluded that prompts alone do not give a person enough control over the result to be its author, so generated copy may not be registrable.
Why ownership is the weakest term on its own
Owning a result matters less when the inputs that produced it remain retained and reusable under an open ended window. Your prompts, documents and strategy notes are still on someone else's servers. Fix retention and ownership becomes worth more.
Read the indemnity cap and its conditions
Several vendors now indemnify business customers against third party IP claims on output. An indemnity with a low cap or a long list of exclusions reads as protection and works as a disclosure.
| Vendor | What is covered | Conditions to check |
|---|---|---|
| Microsoft | Customer Copyright Commitment in the Product Terms, for claims on output content | For Azure OpenAI and configurable services, every required mitigation must be in place, including a metaprompt, content filters and a testing report |
| Google Cloud | One indemnity for training data, one for generated output from listed services | Output cover applies only to listed products, and only if you did not try to create infringing content |
| OpenAI | Services Agreement IP indemnity, extended to output by Copyright Shield on eligible business products | Excludes combination with other products, modification and your own content; general liability cap is 12 months of fees, with indemnity carved out in the published version |
Get the indemnity into the signed agreement, confirm it covers your tier and models, and check whether it sits outside the liability cap. Where it depends on mitigations, name an owner to keep the evidence.
Why should the governance terms close before price?
Close them first because in an AI agreement the governance terms define what you are buying. In a seat based deal, legal and commercial tracks run in parallel because terms and price are largely independent. Here, conceding price first gives away the bargaining power you need to change what you are buying.
Our AI procurement work finds that data terms settled after price are settled with little room to push. The discount has already been conceded, and reopening the paper costs goodwill the buyer no longer has.
A discount agreed against unresolved governance terms is paid for twice: once in the concession you traded for it, and again in the term you accept to avoid reopening the deal.
The standard order form is not safe to sign as it stands
The common advice holds that the major AI vendors are enterprise safe by default, so the standard order form is fine to sign. Our review file contradicts that. The protections exist and are usually available, and they are not applied unless the buyer selects the tier and binds the clause.
Treat the order form as an opening position. Close training use, residency, retention, output ownership and indemnity, in that order of dependency, and only then discuss the rate. Assurances outside the contract are marketing.
What have we seen in enterprise AI contract reviews in 2024 and 2025?
Across roughly 20 to 30 enterprise AI contract reviews we supported between 2024 and 2025, default terms favored the vendor on training and intellectual property in most first drafts. Three patterns recurred.
- Training allowed by default. Default or standard tiers allowed prompts and outputs to be reused for model training in 50 to 70 percent of first drafts.
- Residency left to the vendor. Data residency was unspecified or vendor chosen unless the buyer raised it.
- Ownership and indemnity missing. Output ownership and indemnity were silent until the buyer negotiated them in.
Three of the five terms, residency, retention and output ownership, were simply absent rather than drafted against the customer. The commercial logic is plain, since a term the customer never asks for is a term the vendor never has to give.
Absence makes the review harder. Hostile language stands out on a first read. A missing term does not, because a silent contract reads as clean. The review has to look for what is absent as deliberately as for what is adverse.
What contract wording should you ask for?
Ask for these clauses in the master agreement or in an order form rider that overrides the vendor's standard documents.
- Deletion window. Deletion of prompts, outputs and files within a fixed number of days, and of all customer content at termination, backups included. This clause bounds everything else.
- Legal demand notice. Prompt notice of any subpoena or preservation order covering your data, where the law allows, so your counsel can respond first.
- No training, fully scoped. No use of customer content, feedback or fine tuning data to train models, extending to affiliates, subprocessors and models released after signature.
- Named regions. Storage and processing regions listed in the order, covering backups, support access and subprocessors, with any exceptions listed.
- Frozen policies. Linked policies fixed at the version current on signature, with changes that reduce protection needing your written consent.
- Output ownership. An assignment of whatever rights the vendor has in output, and a statement that it claims none.
- IP indemnity. Cover for third party IP claims on output for your tier, outside the general liability cap, with required mitigations listed.
Add an exit right if the vendor changes these terms at renewal. Our guide to the GenAI termination for convenience clause covers the wording, and the AI contract red lines guide covers the commercial terms beside it.
What the account team will say, and what to say back
- "Enterprise customers are never used for training. It is on our trust page." Then writing it into the agreement costs you nothing.
- "Your admins control retention in the console." The console controls what our admins delete. The contract has to cover your copies, including logs, backups, abuse monitoring stores and legal holds.
- "Our data processing addendum is standard for every customer." We will sign it, with a rider that takes precedence on training, retention and residency.
- "You already have IP indemnity in our terms." Show us the cap, the exclusions and the required mitigations, and confirm it covers the tier on this order.
How do you check what your current AI contracts say?
Start from the signed paper and the admin settings, and set the vendor's summary aside. Score each contract against a recognized control set such as ISO/IEC 42001 or the NIST AI RMF, plus the EU AI Act risk tier for regulated use cases, so the review is repeatable.
- Inventory tools and tiers. Include personal accounts used for work and AI features switched on inside existing SaaS products.
- Pull the documents. Collect the order form, master agreement, data processing addendum and every policy referenced by URL.
- Record the settings. Note the ChatGPT Enterprise retention setting, whether Zero Data Retention or Azure modified abuse monitoring has been approved, and where Bedrock invocation logs go.
- Confirm the regions. Check which region each workspace or resource was created in.
Our AI procurement checklist turns this into a signing list, and the clause guides for OpenAI and Anthropic point to the sections to read.
Common mistakes and what they cost
- Buying the right tier for half the users. Staff outside the enterprise workspace keep using personal accounts, whose terms may allow training and longer retention.
- Relying on the admin retention setting. It governs workspace chat history. Vendor logs, backups and legal holds need contract terms.
- Losing the indemnity to a switched off filter. Cover that depends on content filters or testing reports fails if the build team disabled them.
What to do next
- This month. List every AI tool in use and the tier each one is bought on, since the protections belong to the tier you buy, whatever the size of your company.
- Before any renewal or new order. Fix retention first with a defined deletion window, because an open ended hold leaves the no training promise exposed to every future policy, ownership and jurisdiction change.
- During contract review. Locate the training use clause, confirm it applies to your tier, and bind it in the master agreement.
- In the same review. Name the required data regions and state customer ownership of outputs, because silence on either resolves in the vendor's favor.
- Before signature. Require an IP indemnity, read its cap and conditions, and name an owner for any mitigations it depends on.
- Only then. Open the commercial conversation, and hold signature until all five terms are agreed. The GenAI practice runs the review with you.
Frequently asked questions
Can AI vendors train on enterprise data?
Only where the contract allows it. In half to two thirds of the first drafts we reviewed, default or standard tiers did allow it. Enterprise tiers usually switch training off, but that protection comes from the tier you choose and the clause you sign. Check the agreement itself, and treat the vendor's marketing page as a description that can change.
Why is retention the most important clause in an AI contract?
It sets the time limit on every other promise. A vendor can only misuse, disclose or be forced to hand over data it still holds, whether through a policy change, a sale of the company or legal process. With a short deletion window, a later change in any of those circumstances reaches little or none of your history.
What does silence mean in an AI contract?
Silence hands the decision to the vendor's current practice. Where the contract names no region, the vendor picks it. Where it names no deletion window, storage is open ended. Where it says nothing on ownership, rights in machine generated work rest on unsettled law. Review for missing terms with the same care you give adverse ones.
Is a no training promise on a vendor blog or help page binding?
No. Only the contract binds, and a help article or trust page can be edited without notice. Ask for the commitment in the master agreement or an order form rider, confirm it covers your tier, and where the agreement links to a policy, fix the version that applies for your term.
Who owns the output an AI model produces?
Most enterprise terms assign output to the customer, so ask for that assignment in writing. Copyright in machine generated work is still unsettled, which means the clause mainly settles rights between you and the vendor. Ownership is also the weakest of the five terms if the inputs behind the output stay on the vendor's servers.
Should we require an IP indemnity from an AI vendor?
Yes. Microsoft, Google Cloud and OpenAI all publish indemnities for third party IP claims on output for business customers. Each carries conditions, from required content filters to exclusions for modified output. Get the indemnity into the signed agreement, confirm whether it sits outside the liability cap, and name someone to keep the evidence it depends on.
When should AI governance terms be negotiated?
Before the commercial conversation opens. In an AI agreement these terms define the product you are buying. A buyer who agrees the rate first usually finds the account team reluctant to reopen the paper, and ends up trading governance points away to protect the discount already won.
How should an AI vendor contract review be structured?
Around a recognized control set, so the result is repeatable and does not depend on who runs it, paired with the applicable regulatory risk tier for regulated use cases. Add one discipline most reviews lack, a check for terms that are missing, because absence was the dominant pattern in the contracts we reviewed.