AI Vendor Contract Clauses
Tags: Frameworks
TL;DR —
- Nail down Input Rights, Training Data warranties, Output Rights, Retention/Deletion, and Consents.
- Push back on liability caps, no-consequential-damages, and one-sided indemnities—especially for market-facing outputs.
Why it matters for HK marketers: The fine print determines who owns outputs, who bears IP risk, and whether your data can train someone else’s model.
Clauses to scrutinize
- Input Rights: Limit use of your prompts/inputs to providing the service; prohibit training beyond your enterprise model; restrict retention to what’s necessary.
- Training Data: Vendor warrants lawful sourcing, license compliance, and privacy protections; no use beyond stated purpose.
- Retention & Deletion: Seek deletion on termination; note technical limits if inputs trained the model.
- Output Rights: You should own or have exclusive rights to outputs created with your data/direction; bar vendor reuse.
- Consents: Allocate who secures notices, lawful bases, and ongoing consent when personal/third-party data is used.
Risk allocation
- Liability caps: Focus on cap exceptions (gross negligence, willful misconduct, confidentiality breaches, indemnities) and fit to your risk exposure.
- No consequential/indirect damages: Try to carve back for lost profits, brand harm, business disruption where relevant.
- Indemnities: Seek vendor indemnity for third-party IP claims; vendors often resist broad output indemnities—negotiate scope.
Scraping & third-party terms
- Warranties that tools won’t rely on data scraped in violation of site terms or robots.txt; accurate user-agent identification; no bypass of protections.
So what for marketers
- Standardize an AI ToS checklist and make enterprise non-training commitments and output ownership non-negotiables for tools used in Hong Kong.
← Back to Knowledge Base