An April 2026 client alert on negotiating AI provisions in commercial and technology contracts concluded that a generic AI disclaimer no longer satisfies an enterprise buyer, and that model update, output accuracy, and data use terms now belong inside the signed customer agreement rather than a linked policy page. The finding matters because most SaaS master agreements were built for a passive tool a human reviewed before acting on it, not for an agentic feature that executes a workflow on its own. Two regulatory deadlines compress the timeline further: the European Union’s Product Liability Directive treats a software update or a machine learning change as a product defect subject to strict manufacturer liability once member states transpose it by December 9, 2026, and Colorado’s amended Artificial Intelligence Act imposes high risk system disclosure duties starting January 1, 2027. Founders who embedded an AI feature into an existing SaaS product over the past two years now have a narrow window to move these terms out of a policy document and into the contract itself.
Most SaaS agreements signed before 2024 addressed artificial intelligence, if at all, through a single clause acknowledging that the platform may incorporate AI features, paired with a disclaimer of any warranty as to accuracy. That approach tracked how AI was actually used at the time: a suggestion engine, a drafting aid, a classifier a person reviewed before the business acted on the result. The agreement priced risk accordingly, capping vendor liability and pushing responsibility for output review onto the customer.
Why did the generic AI disclaimer stop working
The generic AI disclaimer stopped working once AI features began making decisions rather than suggesting them, a shift that removed the human review step the original risk allocation depended on. Practitioners advising both buyers and vendors on these agreements now describe sophisticated enterprise customers pushing for defined service descriptions, performance based warranties, oversight and audit rights, and liability tied to outcomes rather than uptime alone. A defined service description has to state what the AI is actually doing, the workflows it executes, the decisions it makes, the systems it touches, and the guardrails that apply, because a vague description leaves both sides guessing about who owns the outcome once the feature acts on the customer’s behalf.
What should a model update clause say
A model update clause should require the vendor to give advance notice before any material change to the underlying model, define materiality by reference to a measurable accuracy or output shift, and give the customer a window to test the replacement before the change becomes mandatory. In current negotiations a thirty to sixty day notice period is common, paired with a right to run the replacement model against the customer’s own test set in a staging environment before the swap is forced into production. A service credit or termination right should attach if the replacement underperforms the prior benchmark for two consecutive measurement periods, so the customer is not locked into a downgraded product for the balance of the term.
What does an enforceable AI accuracy warranty look like
An enforceable AI accuracy warranty replaces the blanket disclaimer of any warranty as to accuracy with a narrow, benchmark tied express warranty, because a tribunal has already refused to let a vendor hide behind a separate policy page when its own AI feature misled a customer. In Moffatt v. Air Canada, 2024 BCCRT 149, decided February 14, 2024, the British Columbia Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation after its customer service chatbot gave a passenger incorrect information about retroactive bereavement fares. Air Canada argued that a separate webpage stated the correct policy and should control. The tribunal rejected that argument, holding that the airline owed the customer a duty of care and that the chatbot could not be treated as a separate entity from the company itself.
The practical response is a narrow express warranty stated in the agreement: a defined accuracy rate against an agreed test set, tested on a stated cadence, with hallucination or output drift named explicitly as a residual risk allocated through the liability cap rather than disclaimed away entirely. A remediation obligation, retrain, reconfigure, or credit, should attach when the benchmark is missed for two consecutive testing periods.
How should a SaaS contract handle AI training data
A SaaS contract should define Training Data as a term separate from Customer Data and require the customer’s affirmative opt in consent before either is used to train or fine tune the vendor’s model or any third party foundation model. An opt in requirement, rather than an opt out buried in a settings page, shifts the default toward the customer, which is the posture enterprise procurement teams are now requesting as standard. The agreement should also require notice when the vendor introduces a new foundation model as a subprocessor and should specify a data return or deletion timeline at termination.
This provision intersects directly with the European Union’s Artificial Intelligence Act. Chapter V requires providers of general purpose AI models to give downstream integrators information about the model’s capabilities and limitations sufficient to let those integrators meet their own obligations, enforceable with fines up to fifteen million euros or three percent of global turnover starting August 2, 2026. A SaaS vendor receiving that disclosure from its own foundation model supplier should be passing an equivalent disclosure to its customers through the contract, not through a public model card the customer’s legal team never sees.
Who absorbs the cost of the new AI liability exposure
Indemnification language written for ordinary software bugs does not reach the risk profile of an AI feature. Current practice favors keeping indemnification pointed at intellectual property claims, while routing accuracy risk through the express warranty and the liability cap rather than through an open ended indemnity for any claim arising from the AI service. Under the incoming EU product liability system, a vendor that pushes a model update or a retraining pass could itself be deemed the manufacturer of a new defect, since the directive extends manufacturer status to any party that substantially modifies a product after it reaches the market. The customer agreement should state explicitly which party bears the cost of that expanded exposure, and the Federal Trade Commission’s July 2026 policy statement applying Section 5 to AI systems that steer outputs toward an undisclosed objective adds a second reason neither side should leave that allocation to a generic clause never written with AI in mind.
Read my full analysis here: https://theinnovationattorney.com/blog/
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit theinnovationattorney.substack.com/subscribe