- What an AI service agreement actually does
- Scope of permitted use
- Data use and training rights
- Privacy obligations and personal information
- Output ownership
- Accuracy, hallucinations, and liability for false outputs
- Limitation of liability and indemnity
- Termination and transition
- Situational clauses worth including
- How Artificer Legal approaches AI service agreements
- The clause that decides whether the agreement works
A vendor sends you a link. "Click to accept our terms." You're about to connect an AI tool to your customer database, your email system, or your internal files. The agreement is thirty pages long and the vendor tells you it is non-negotiable. You click through anyway.
That moment carries real legal weight. AI service agreements — the contracts that govern your use of tools like large language model platforms, automated decision-making systems, and AI-powered customer service software — determine who owns what comes out, who is liable when something goes wrong, and what happens to the data you feed in. Most providers offer standard terms for free or lower-tier accounts that you cannot change. Even where negotiation is possible (usually at the enterprise level), you need to know which clauses matter and why before you sit down at the table.
What an AI service agreement actually does
An AI service agreement is a commercial contract between you and an AI provider. It governs access to the platform, the data you can input, the outputs you can use, and the respective rights and obligations of each party. It sits alongside — and sometimes conflicts with — your own customer agreements, privacy policy, and internal data-handling procedures.
Unlike a straightforward software licence, an AI service agreement has to grapple with a set of legally novel questions: who owns a piece of text or code that a model generated? What happens if the model produces false information that you then pass on to a client? And what privacy obligations do you inherit simply by inputting a customer's name and email?
The clauses below are ordered by the sequence in which they tend to appear in a standard agreement — and by commercial weight.
Scope of permitted use
Every AI service agreement defines what you can and cannot do with the platform. Common restrictions include:
- prohibitions on using outputs to build a competing product;
- bans on certain categories of input (personal health data, financial data, classified material);
- limits on the volume of API calls or prompts in lower tiers; and
- restrictions on commercial use entirely — some free-tier agreements prohibit you from using AI-generated outputs in products or services you sell.
The drafting trap: Scope clauses are typically written broadly in the provider's favour and narrowly when it comes to your permitted uses. Check whether your actual use case — including the type of data you plan to input and the commercial context in which you will use the output — is squarely within the permitted scope. If it is not, using the platform anyway exposes you to contract breach.
The variant providers push: Free accounts often include a licence back to the provider to use your inputs and outputs to improve their models. Paid enterprise accounts usually offer an opt-out. If model training on your data is a concern — particularly where your inputs contain confidential business information or personal data about your clients — this is a clause worth negotiating or choosing a tier that already excludes it.
Data use and training rights
Closely related to scope, but worth treating separately because the legal consequences are different. This clause governs what the provider can do with the data you send to the platform.
Key questions to ask of this clause:
- Does the provider claim a licence to use your inputs for training or fine-tuning its models?
- Does that licence extend to personal information about your customers or staff?
- Is there an opt-out, and if so, what is the process and what is the effective date?
- Where is the data processed and stored?
The last question matters because most major AI providers process data through servers located overseas — in the United States or across global data centre networks. When personal information is involved, that triggers your obligations under Australian Privacy Principle 8 (APP 8) in the Privacy Act 1988 (Cth). APP 8 requires you to take reasonable steps to ensure that an overseas recipient handles personal information in accordance with the Australian Privacy Principles. Under s 16C of the Privacy Act 1988 (Cth), you remain accountable for any privacy breach that occurs overseas. Entering into a contract with the provider that requires APP-compliant handling is one recognised way of meeting your APP 8 obligation, but only if you actually review those contractual terms — not just click through them.
The trap: Businesses routinely overlook this clause and later discover that customer data has been processed in a jurisdiction with weaker privacy protections than Australia's, with no contractual backstop.
Privacy obligations and personal information
If any personal information passes through the platform — names, contact details, purchasing history, or anything that identifies or could reasonably identify a living individual — the Privacy Act 1988 (Cth) applies to you, regardless of what the vendor's agreement says.
Australian Privacy Principle 6 (APP 6) prohibits you from using personal information for a purpose other than the primary purpose for which you collected it, unless:
- the individual has consented; or
- the individual would reasonably expect the secondary use, and that secondary purpose is related to the primary purpose (or, for sensitive information, directly related to it).
In practice: if you collected a customer's email address to send order confirmations, you cannot feed that email into an AI system to train a general-purpose marketing model without fresh consent or a solid reasonable-expectation argument. The OAIC's guidance on using commercially available AI products is explicit that businesses should not input personal information into public AI tools due to the associated privacy risks.
Sensitive information — which includes health information, racial or ethnic origin, political opinion, religious beliefs, and sexual orientation, among other categories defined in s 6(1) of the Privacy Act 1988 (Cth) — attracts an even stricter standard. Secondary use of sensitive information must be directly related (not merely related) to the primary purpose, which is a harder threshold to satisfy.
The AI service agreement itself will not resolve these obligations for you. What it can do — if drafted well — is confirm the provider's own privacy commitments, which you can then rely on when assessing your APP 8 obligations.
Output ownership
Who owns the text, code, image, or analysis the AI generates in response to your prompt? This clause varies significantly across providers and tiers, and the answer has two parts: what the contract says, and what Australian law says.
What the contract says: Many enterprise agreements assign output ownership to you. Free-tier agreements often retain a broad licence for the provider or say nothing at all, leaving ownership uncertain. Some agreements distinguish between outputs generated by your prompts (which you may own) and the model itself (which the provider owns absolutely).
What Australian law says: Even if the agreement grants you full ownership of outputs, the Copyright Act 1968 (Cth) requires human authorship for copyright to subsist in a work. Where AI generates content with minimal human creative input, Australian copyright law is unlikely to protect that output. The practical consequence: a competitor could copy purely AI-generated text from your website without infringing your copyright, because you may not have any copyright to infringe.
There is a secondary risk here too. If the AI reproduces material from its training data — text, code, or images in which a third party holds copyright — distributing that output could constitute copyright infringement on your part. The agreement will often include a warranty from the provider about this, but those warranties are usually heavily qualified.
What to check:
- Does the agreement confirm you own outputs for your commercial use case?
- Does it include a warranty (even a limited one) that outputs do not infringe third-party IP?
- Does it include an indemnity from the provider if outputs do infringe? (Enterprise agreements sometimes do; free tiers almost never do.)
Accuracy, hallucinations, and liability for false outputs
AI systems can generate false information that reads as credible — a legal citation that does not exist, a product specification that is wrong, a financial figure that is invented. If you publish or pass on that information to a client, the legal risk is yours.
Under s 18 of the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)), a business must not engage in conduct that is misleading or deceptive. Intent is irrelevant — what matters is the impression created on the audience. Republishing an AI hallucination as fact can expose you to ACL liability.
AI service agreements typically disclaim all warranties about accuracy. The provider will not be liable if the model produces wrong answers. That risk sits with you.
What this means for your operations:
- Never publish AI-generated content to customers without human review;
- Keep records showing that outputs were checked before use;
- Your own contracts with clients should not promise AI-generated output as verified professional advice; and
- Internal AI policies should require a sign-off step before AI outputs are used externally.
Limitation of liability and indemnity
This is the highest-stakes clause in most AI service agreements and the one that is most often accepted without scrutiny. Providers cap their liability — often at the amount you paid them in the preceding twelve months, or a fixed dollar amount that may be trivially small relative to the harm their platform could cause.
Common drafting features to watch:
- Total liability caps — a ceiling on what the provider will ever pay you, regardless of the nature of the breach.
- Consequential loss exclusions — the provider excludes lost profits, reputational damage, and other indirect losses. These can be the most significant losses your business suffers if an AI tool fails or exposes personal data.
- Mutual vs one-way indemnities — providers often include indemnities running in their favour (you indemnify them if you misuse the platform) without a reciprocal indemnity running in yours.
- Carve-outs — some providers carve out IP infringement indemnities or data breach indemnities from the general cap. These are worth identifying.
The negotiating priority at enterprise level: Push for a meaningful liability cap (a multiple of annual fees, not a nominal figure), a consequential loss exclusion carve-out for data breaches and privacy incidents, and a provider-side indemnity for third-party IP infringement claims arising from outputs.
Termination and transition
What happens to your data when the contract ends? A well-drafted termination clause addresses:
- whether the provider deletes your data, and within what timeframe;
- whether you can export your data (and in what format) before termination;
- what happens to any fine-tuned models built on your data; and
- the survival of confidentiality and data-handling obligations after termination.
Providers often delete data promptly after termination — which can be a problem if you need records for your own compliance purposes. Make sure you export anything you need before the termination date.
Situational clauses worth including
Not every AI service agreement will need these, but they are worth considering depending on your use case:
- Audit rights — if you are a regulated entity (financial services, healthcare), the right to audit the provider's data-handling practices may be required by your own regulators or contractual counterparties.
- Sub-processor notification — AI providers frequently use third-party infrastructure. A clause requiring notice before new sub-processors are added gives you a chance to reassess your APP 8 position.
- Service level commitments — if your operations depend on the AI tool's availability, a service level agreement with meaningful remedies (not just credits) is worth requesting at enterprise level.
- Change in terms notice — some providers reserve the right to change terms unilaterally. A clause requiring advance notice and giving you a termination right without penalty if you do not accept the change protects you from being locked into terms you did not agree to.
- Regulatory compliance assistance — if a regulator (OAIC, ACCC) investigates your use of the AI tool, a clause requiring the provider to cooperate with your response can be invaluable.
How Artificer Legal approaches AI service agreements
The clauses that matter most in an AI service agreement are not the ones at the front — they are buried in the liability, data use, and termination provisions at the back. That is where providers protect themselves most aggressively and where most businesses accept unfavourable terms by default.
When reviewing an AI service agreement, our practitioners focus first on the data use and training rights clause (because it often creates privacy obligations the business has not anticipated), then on the liability cap and consequential loss exclusion (because these determine your practical remedy if something goes wrong), and finally on the output ownership and IP indemnity provisions (because these determine whether you can safely use the tool commercially).
For businesses on free-tier agreements with no room to negotiate, the review exercise is still worthwhile: it tells you the risks you are accepting and lets you put internal controls in place — human review of outputs, restrictions on what data you input, and documented AI policies — that reduce exposure within the constraints of the agreement.
If you are at the enterprise procurement stage, earlier engagement is better. The leverage you have before you sign is far greater than after. We can advise on the specific clauses to push back on, the market-standard positions for your industry, and the internal documentation you should have in place before you go live.
The clause that decides whether the agreement works
If there is one clause that most often makes the difference between an AI service agreement that works for a business and one that causes it harm, it is the data use and training clause — not the liability cap, which gets more attention. Businesses that do not read this clause carefully can find themselves in a position where personal information they collected for one purpose is being processed by a foreign provider to train a general AI model, with no opt-out and no contractual protection. That is a potential breach of the Privacy Act 1988 (Cth) that originated at the moment of sign-up.
AI service agreements are novel commercial instruments sitting on top of a privacy framework that was written before generative AI existed. The obligations are real, even where the agreement makes no mention of them. Understanding what the agreement says — and what Australian law adds to it regardless of what the agreement says — is the starting point for using these tools safely.