Commercial AI Service Terms

Commercial AI Service Terms

For Informational Purposes Only

Enterprise-grade terms for companies procuring or providing AI services — covering data rights, training restrictions, model transparency, output IP, high-impact use controls, and agentic-action governance.

Download Template (.docx)

What This Document Does

This agreement governs the commercial relationship between an AI service provider and its business customers. It covers what happens to the data customers send in (Input), who owns what comes out (Output), whether the provider can use customer data to train its models, how model changes are handled, what controls apply to high-risk decisions, and how the entire model supply chain — including third-party foundation models and subprocessors — is documented and governed.

The template is built around four schedules that serve as the operational backbone: a model and subprocessor matrix documenting every AI system in the chain, service levels and fee mechanics, acceptable-use and high-impact-use controls, and data protection and security terms. These schedules turn abstract promises into auditable commitments tied to specific products and data flows.

Why Startups Need This

AI is no longer a research experiment — it is embedded in production workflows, customer-facing products, and business-critical decisions. But the legal infrastructure for AI procurement has not kept up. Most companies are still using generic SaaS terms to govern AI relationships, which leaves critical questions unaddressed: Can the provider train on my data? What happens when the underlying model changes? Who is liable when output is wrong? Can I use AI output in regulated decisions?

For AI providers, clear terms build enterprise trust and reduce sales-cycle friction. For customers, they protect data, preserve operational control, and establish the accountability structure that investors, regulators, and enterprise buyers increasingly expect. This template works from both sides of the table.

Key Provisions Explained

Training Election with Anti-Circumvention

The agreement presents three training options: no training (provider cannot use customer data to train shared models), express opt-in (training only with recorded customer consent specifying categories and purpose), or order-specific terms. Critically, Section 5.5 prohibits the provider from reclassifying input, output, or customer data as “usage data,” “feedback,” “safety data,” or “deidentified data” to circumvent the training restriction — closing a loophole present in many commercial AI terms.

Output IP Assignment with Honest Limitations

The provider assigns its rights in output to the customer — but the assignment is qualified honestly. It acknowledges that rights in AI output may be uncertain under current law, that similar output may be generated for other customers, and that third-party rights may exist. The agreement includes an optional output IP defense election for providers willing to indemnify against copyright claims arising from qualifying output, with clear exclusions for customer-caused issues.

High-Impact Use Controls

Using AI output as the basis for decisions affecting legal rights, employment, credit, housing, insurance, or healthcare requires more than a contractual checkbox. The agreement requires a use-case impact assessment, qualified human review with override authority, affected-person notice, and a named accountable individual within the customer’s organization. High-impact use is prohibited unless the specific use case is approved in the order and these controls are implemented.

Model Supply Chain Transparency

Schedule 1 requires the provider to document every material model in the service — name, version, provider, hosting location, data categories transmitted, retention period, human-access controls, and purpose. This transparency is essential because many AI services are built on third-party foundation models, and the customer needs to know the full processing chain to comply with data-protection obligations, assess risk, and respond to incidents.

Model Change Controls

Silent model changes — where the provider swaps the underlying model without notice — can break validated workflows and introduce regression. The agreement requires 30 days’ advance notice of material model changes, updated documentation, a reasonable test window, and the customer’s right to request version maintenance or terminate if the change materially degrades performance. This gives customers the stability they need for production deployments.

Bilateral Indemnification for AI-Specific Risks

The provider indemnifies for IP claims against the unmodified service (and optionally, qualifying output). The customer indemnifies for claims arising from its input, prohibited uses, products built on output, and decisions based on output — including high-impact decisions. This allocation reflects the practical reality: the provider controls the model, the customer controls how output is used.

Emerging Provisions (2025–2026)

Agentic AI Governance

As AI systems move from generating text to taking actions — calling APIs, executing code, interacting with external systems — new contractual controls are needed. The agreement includes an optional agentic-actions module that requires explicit authorization in the order, with Schedule 3 specifying permitted action types, scope and transaction limits, human-confirmation requirements, credential management, logging, rollback procedures, and kill-switch controls. Agentic actions are prohibited by default.

Training Data Provenance and Anti-Circumvention

The question of whether AI providers train on customer data remains the single most contested issue in enterprise AI procurement. This template goes beyond a simple “no training” toggle by including anti-circumvention language that prevents reclassification of customer data under different labels, requires objective deidentification standards, and bans reconstruction. The training election is designed to be technically testable — tied to specific API settings, provider-chain flowdowns, and audit evidence.

Training Restriction Violation Carve-Out

The limitation-of-liability section specifically carves out violations of the training restrictions from the general cap. This is a deliberate choice — if a provider’s core promise is “we will not train on your data” and it breaches that promise, limiting damages to 12 months of fees may not provide adequate deterrent or compensation. The carve-out signals that training commitments are not just aspirational.

No-Override Protection for Negotiated Terms

Many AI providers maintain online terms of service, acceptable-use policies, and privacy policies that can change at any time. The agreement includes explicit protections: no unilateral change to an online policy may override negotiated terms in an Order, and the order-of-precedence clause places the DPA, negotiated Order terms, and these Terms above online policies. Material changes to legal obligations or data practices require advance notice and, where required, affirmative assent.

How to Use This Template

Start with the Order Summary, selecting the training policy, output IP defense level, high-impact use approach, and agentic-action policy. If you are the customer, the training election and model-change provisions are typically the highest-priority negotiation items. If you are the provider, focus on ensuring the high-impact use controls and indemnity exclusions align with your product’s actual capabilities and limitations.

Complete the four schedules with specifics for your deployment. Schedule 1 (Model/Subprocessor Matrix) should be populated before signing — the customer needs to know the full processing chain. Schedule 3 (Acceptable Use and High-Impact Controls) should reflect the actual use cases the customer plans to deploy, not generic categories. Have both business and legal stakeholders review the agreement, as AI terms sit at the intersection of commercial, technical, and regulatory concerns.

This template is provided by Montague Law for informational and educational purposes. It does not constitute legal advice and does not create an attorney-client relationship. Commercial AI agreements involve complex intellectual property, data protection, liability, and emerging regulatory considerations that vary by jurisdiction and use case. Consult qualified legal counsel before using this template. Montague Law is a Florida-based law firm focused on corporate, M&A, venture capital, and technology transactions.