Disclosure, up front
We are a vendor. Several of the questions below are ones a client should ask us, and we have written them as we would want to be asked rather than as we would find easiest to answer. Not legal advice — this is a checklist for reading a contract, not a substitute for someone qualified reading it, and section 06 says when that is warranted.
Nobody reads AI terms of service. They are long, they are written by the vendor's lawyers, and the sign-up button is right there.
You do not need to read all of it. Six clauses account for nearly everything that goes wrong, and each can be checked in a couple of minutes. Two of them are the reason a business ends up unable to leave a tool it no longer wants.
This is the list we run before recommending anything, and the one we would expect a careful client to run on us.
The six, in order of how often they bite
- Training on your inputs — does your data improve their model?
- Retention and deletion — how long is it kept, and can you actually get it removed?
- Sub-processors — who else touches the data, and are you told when that changes?
- Output rights — what they grant, and what they cannot grant.
- Indemnity — who pays if the output infringes someone's rights.
- Exit — can you export, and what happens on the way out.
01Training on your inputs
The single most consequential setting, and the one most likely to differ between the free tier your staff signed up for and the business tier you thought you were on.
What to establish: is your input used to train or improve their models, is that on by default, and is it a contractual commitment or a toggle they can change? A setting in a preferences page is weaker than a term in an agreement, because the setting can move in an update and the term cannot.
This is also where consumer and business tiers most often diverge, which is the practical argument for providing sanctioned accounts rather than leaving people on personal ones.
02Retention and deletion
Two different questions that get one answer in most terms.
- Retention: how long do they hold conversations, uploads and logs by default? "As long as necessary" is not an answer, it is a placeholder.
- Deletion: if you delete something, is it gone from backups and derived data, or only hidden from your view? And how long does that take?
This matters most if you hold personal data about other people, because a customer's deletion request becomes your problem, and you can only honour it to the extent your vendor lets you. Establish this before you put personal data in, not when someone asks for it back.
03Sub-processors, and the notice you probably do not get
Your AI vendor is unlikely to be running the model. There is usually a model provider, a cloud host, and often analytics or support tooling underneath. Each is another party with access.
What matters is less the list than whether you are told when it changes. Good terms publish a sub-processor list and commit to notice before adding one. Ordinary terms reserve the right to change it at will, which means the answer you got today has no shelf life.
The one-line test for a whole contract
Search the document for "we may modify" and read every hit. Terms that can be changed unilaterally with notice-by-posting are not commitments; they are current intentions. That is normal and often unavoidable, but it tells you which parts of your diligence expire, and it is a two-minute check on any agreement.
04Output rights and indemnity
Most major tools now assign you whatever rights they have in the output. Read that literally: whatever rights they have. As covered in the ownership article, a vendor cannot grant you a copyright that does not exist, so this clause settles your right to use the output and not your ability to stop others using it.
Indemnity is the more practical question, and the one that has moved fastest. Some vendors now indemnify business customers against third-party IP claims arising from output. That is a genuine commercial commitment, and where it exists it is usually conditional — on being on a paid tier, on not disabling safety filters, on not having supplied the infringing material yourself.
If you publish generated material at any scale, find out whether you have this and what voids it. If you do not, the exposure is yours, which may be perfectly acceptable — but it should be a decision rather than a discovery.
05Exit, which is where people actually get stuck
| Check | Good | Get it in writing |
|---|---|---|
| Export | Self-service export of your data and configuration in a usable format | Export on request, or PDF-only, or "contact support" |
| What you built | Prompts, workflows and custom instructions are exportable | Anything describing your configuration as theirs |
| Access after cancellation | A defined grace period to retrieve data | Access ends immediately at term end |
| Deletion on exit | Confirmed deletion within a stated period, on request | Silence — the default is usually indefinite retention |
| Price changes | Notice period, and the ability to leave without penalty | Auto-renewal with mid-term repricing |
Our checklist, from reviewing tools before recommending them. The right-hand column is not a reason to walk away — plenty of good products have ordinary terms — it is a list of things worth knowing before you build a process around the tool rather than after.
The row that catches people is the second one. Businesses invest months refining prompts, workflows and instructions, then discover that the accumulated configuration cannot leave with them. That is not usually malice; it is that nobody built an export. But it is a real switching cost, and it is invisible at sign-up.
06When this needs a lawyer rather than a checklist
- You are putting other people's confidential information in. Client files, patient records, anything held under a confidentiality obligation you did not write.
- You are signing a negotiated agreement rather than clicking through standard terms. If there is a signature block, get it read.
- A customer contract requires you to flow terms down to your own suppliers. Common in enterprise and public sector work, and easy to breach unknowingly.
- The tool makes or materially assists decisions about people — hiring, credit, access. That is a different risk category, covered here.
07The honest summary
Six clauses cover nearly all of it. Does your input train their model, how long is it kept and can you truly delete it, who else touches it and are you told when that changes, what output rights are actually granted, is there an indemnity and what voids it, and can you leave with what you built.
Two of those decide whether adopting the tool is reversible: deletion and export. Check them before you build a process around the product, because that is the point at which the answer stops being academic.
And search for "we may modify" while you are in there. It tells you which of today's answers have a shelf life.
08Common questions
What should I check first in AI terms of service?
Whether your inputs are used to train or improve the vendor's models, whether that is on by default, and whether it is a contractual commitment or a preferences toggle. A setting can change in an update; a term cannot. This is also the clause that most often differs between the free tier a staff member signed up for and the business tier you assumed you were on, which is the practical argument for providing sanctioned accounts.
What is the difference between retention and deletion?
Retention is how long the vendor holds conversations, uploads and logs by default — and as long as necessary is a placeholder, not an answer. Deletion is whether removing something actually removes it from backups and derived data or merely hides it from your view, and how long that takes. Both matter most if you hold personal data about other people, because a customer's deletion request becomes your problem and you can only honour it as far as your vendor allows.
Why do sub-processors matter?
Because your AI vendor is probably not running the model. There is usually a model provider, a cloud host and often analytics or support tooling underneath, each with access. What matters more than the current list is whether you are notified when it changes. Good terms publish a sub-processor list and commit to notice before adding one; ordinary terms reserve the right to change it at will, which means today's answer has no shelf life.
Does my AI vendor give me ownership of the output?
Most major tools assign you whatever rights they have in the output, and that phrase should be read literally. A vendor cannot grant a copyright that does not exist, so the clause settles your right to use the output rather than your ability to stop others using it. Under US law, purely AI-generated material is not registrable because copyright requires human authorship, and no contract term changes that.
What is an AI indemnity and do I need one?
Some vendors now indemnify business customers against third-party intellectual property claims arising from generated output. Where it exists it is normally conditional — on being on a paid tier, on not disabling safety filters, on not having supplied the infringing material yourself. If you publish generated material at any scale, find out whether you have one and what voids it. If you do not, the exposure is yours, which may be acceptable as a decision but not as a discovery.
What exit terms should I look for?
Self-service export of your data and configuration in a usable format; the ability to take prompts, workflows and custom instructions with you; a defined grace period to retrieve data after cancellation; confirmed deletion within a stated period on request, since the default is often indefinite retention; and notice of price changes with the ability to leave without penalty. Export and deletion are the two that determine whether adopting the tool is reversible.
What gets small businesses stuck with an AI tool?
The configuration, more often than the data. Businesses spend months refining prompts, workflows and custom instructions, then find that accumulated work cannot be exported. It is rarely malice — usually nobody built an export — but it is a genuine switching cost that is invisible at sign-up and very visible once you want to move. Check it before you build a process around the product.
Is there a quick way to sanity-check any contract?
Search the document for the phrase we may modify and read every hit. Terms that can be changed unilaterally with notice-by-posting are current intentions rather than commitments. That is normal and often unavoidable in software, but it tells you which parts of your diligence expire and which you can rely on, and it takes about two minutes.
Send us the terms before you sign
Send a link to the terms of any AI tool you are considering, or already use, and tell us what kind of data you intend to put in it. We will run the six checks and tell you which answers are solid, which are toggles rather than commitments, and whether you could actually leave with what you build. Free, and the answer is often that the tool is fine.
Ask for a contract checkThis article is a reading checklist drawn from our own vendor reviews, not a survey of any particular provider's terms — terms differ by vendor, by plan tier and by date, and several of the areas described here (indemnity provisions in particular) have changed materially during 2026. Verify against the actual agreement in front of you rather than relying on this description of the category. The point about output rights follows the US Copyright Office position discussed in the ownership article. This is not legal advice, and the situations in section 06 warrant a qualified lawyer reading the document. Related: Your Staff Are Already Using AI You Didn't Approve and Your Software Bill Stopped Being Predictable.
Hero image from Unsplash, used under the Unsplash License.