Blog

AI terms as a risk surface: why liability caps and training defaults differ per provider tier

OpenAI, Google and Microsoft cap liability and handle training and indemnity differently per tier. Here is how to vet AI provider terms as an operational risk.

· By

Top-down view of a desk with two printed contracts side by side, each highlighted on different clauses, reading glasses, a closed laptop and a notepad with a handwritten comparison.
Liability caps, training defaults and indemnity differ per provider and per tier, so lay the terms side by side clause by clause.Image: IamVera.ai — original editorial illustration

With AI providers, check not only model quality but also the contract structure: liability caps, indemnity exceptions, training defaults and opt-out settings differ sharply per tier and per product tier. Treat these provider terms as an operational risk that you vet per individual workflow, manage with data routing and record with documented choices.

The occasion is OpenAI's current help page on data use, in which the company describes that users can choose, via the Data Controls setting or the privacy portal, not to have new conversations used for training. At the same time, the Terms of Use and the Services Agreement continue to impose strict liability limits. That interplay makes clear that the risk lies not only in the model, but above all in the provider terms and settings hidden behind the interface.

In our assessment, this is the core that most organisations overlook: ease of access says little about the legal and data-governance defaults that come to apply to you as soon as you enter sensitive content.

Which liability limits are in the Terms of Use of OpenAI and Google?

OpenAI states in its Terms of Use that aggregate liability is capped at the greater of the amount paid over the preceding twelve months or 100 dollars, and that indirect, incidental, special, consequential and punitive damages are excluded. Under these standard terms, the potential recoverable damages for the customer are therefore very limited.

Google formulates similar limitations. In its Terms of Service, Google limits its liability, excludes indirect and consequential damages, and the user may be required to indemnify Google against third-party proceedings arising from unlawful use. Separate service-specific terms additionally limit liability for pre-GA offerings and limit or exclude liability for customer models and individual offerings.

The pattern is therefore not a peculiarity of a single provider. Anyone comparing AI providers would do well to lay the liability clauses side by side instead of dismissing them as standard fine print.

How do consumer and enterprise terms differ on training, retention and indemnity?

The OpenAI Services Agreement shows that business terms materially differ from consumer terms. Liability under that agreement is generally capped at the total fees paid in the preceding twelve months. More importantly, the indemnification obligations are excepted from it, and the service-specific indemnity is not subject to the liability cap.

This means the risk allocation between tiers is not symmetrical. You see that same pattern of differing business terms across enterprise procurement channels of providers such as Microsoft, which resells OpenAI models through its Azure OpenAI offering under its own enterprise contract: it is the chosen provider tier and the associated agreement, not the brand of the model, that determines which defaults apply. An overview of the axes on which consumer and business terms diverge:

  • Training: whether entered content is used by default for model training, and whether that differs per product tier.
  • Retention: how long data is retained and under what conditions it is deleted.
  • Human review: whether people can view content, for example for quality or abuse control.
  • Liability cap: the upper limit on recoverable damages, worked out differently per tier.
  • Indemnity: indemnification obligations that may be excepted from the cap and thus form a non-obvious risk.

On its help page, OpenAI moreover distinguishes ChatGPT and Codex tasks from consumer use. In our assessment, that distinction is one reason to check per provider and product tier rather than per brand.

What do the opt-out settings for model training mean in practice for sensitive work?

According to OpenAI's help page on data use, users can opt out of model training via Data Controls or the privacy portal, after which new conversations are, according to OpenAI, no longer used to train the models. OpenAI's privacy policy, updated in September 2026, describes the broader data practices and refers to the contact for the data protection officer.

The practical tension is that training exclusion depends on a setting and on the product tier, not on the interface itself. Anyone processing sensitive work must therefore:

  1. Establish which provider tier is actually being used and which defaults come with it.
  2. Check whether opt-out for training is enabled and record that.
  3. Verify whether retention and any human review are compatible with the confidentiality of the task.
  4. Document the choices made as part of GDPR accountability.

This splitting of privacy information across multiple pages and settings is, in our assessment, itself a risk: the standard configuration is not always the safest, and the evidence of a deliberate choice rests with the user.

How do I vet AI terms as an operational risk per workflow?

The sources say nothing about how organisations should set up data routing and workflow controls. That is the open question the contract material leaves unaddressed. Our editorial analysis: treat the provider terms as a risk surface that you assess per workflow, not as a one-off procurement check. Concretely, that means a review along the following points:

Anyone who anchors these controls in the broader governance approach, as described in the topic hub on AI governance and control measures, shifts attention from model quality alone to the contractual and data-governance defaults that determine the real risk. The liability caps of OpenAI and Google and the tier-dependent training rules are the concrete evidence for that.

Sources and references

  1. Terms of UseOpenAI · 2026-01-01
  2. OpenAI Services AgreementOpenAI · 2025-12-01
  3. How your data is used to improve model performanceOpenAI · 2026-09-21
  4. Privacy policy - OpenAIOpenAI · 2026-09-10
  5. Terms of ServiceGoogle · 2026-09-19

Sources: The article relies on the primary terms and help pages of OpenAI and on the Terms of Service of Google.

← All articles in this topic ← All articles