top of page

SaaS and AI Vendor Contracts: Indemnities, Data, IP, and Audit Rights for Pennsylvania and New York Companies

Writer: Todd B. Nurick
Todd B. Nurick
4 hours ago
9 min read

AI vendor contracts involving SaaS, data rights, intellectual property, indemnities, and audit rights
AI vendor contracts involving SaaS, data rights, intellectual property, indemnities, and audit rights

Most companies still sign AI tools under a familiar SaaS template. That is a problem. Traditional software contracts were built around uptime, support, and stored data. Generative AI and model-backed SaaS products raise different questions: who owns the output, whether your prompts and documents can be used to train someone else's model, what happens when the system produces fabricated citations or biased screening results, and how far your indemnities and liability caps stretch when the risk sits with the model provider, a foundation-model subprocessor, and your business at the same time.


For Pennsylvania and New York companies, the contract is often the first and last practical control. Regulation is moving, but it is uneven. New York City already regulates certain automated employment decision tools. Federal privacy and healthcare rules still govern sensitive data. European and other state AI frameworks continue to evolve. Waiting for a perfect statute to arrive is not a procurement strategy.


This article focuses on four negotiation priorities that repeatedly decide who bears the downside: indemnities, data rights, intellectual property in prompts and outputs, and audit rights. It is written for owners, executives, and counsel who are buying SaaS and AI tools, not selling them.


Start With the Use Case, Not the Logo


Before you redline the order form, classify the deal.


A low-risk embed of AI inside a tool you already use, with no regulated data and no consequential decisions about people, may need only confirmation that the existing data processing terms cover the feature and that customer content is not used for model training in the enterprise configuration.


A standalone drafting, research, summarization, or analytics tool that will see confidential business information usually deserves a full review of training restrictions, output ownership, AI-specific liability carve-outs, termination and exit rights, and an AI-aware data processing agreement.


Any tool that scores applicants, sets prices for individuals, underwrites insurance, makes credit or housing decisions, takes autonomous actions, fine-tunes on your data, or processes protected health information belongs in a higher-risk category. In that category, standard vendor paper is rarely enough. Require bias testing where decisions about people are involved, audit and assessment rights that actually work, and indemnities that match the risk. If protected health information is in scope, a separate business associate agreement is required under the HIPAA Rules when the vendor is a business associate. A sentence in the MSA is not a substitute for the BAA itself.


Pennsylvania and New York businesses that sell into broader markets should also ask whether the vendor's stack, marketing claims, and documentation support compliance with rules that may apply to you as a deployer, not only to the vendor as a provider. That includes New York City's Local Law 144 for certain automated employment decision tools used to screen candidates or employees in the City, and, for companies with EU exposure, the European Union's Artificial Intelligence Act, Regulation (EU) 2024/1689.


Indemnities: Close the Liability Gap the Template Leaves Open


Vendor paper often squeezes AI-specific risk onto the customer. The vendor and its upstream model providers control the architecture, training choices, subprocessors, and guardrails far more than the customer does. The customer receives the output and lives with the consequences when that output is wrong, discriminatory, or infringing.


Three indemnity issues deserve priority attention.


IP and output risk. Many forms indemnify only for infringement claims about the software as delivered, not for claims arising from generated content. If you will publish, ship, or rely on model output, press for output-level intellectual property protection, or at least a clear explanation of why the vendor will not provide it. Microsoft's published Customer Copyright Commitment for certain commercial Copilot and related services is a useful commercial benchmark: Microsoft has publicly committed to defend customers against certain covered third-party intellectual-property claims involving output, subject to product-specific terms and required safeguards. Use that benchmark as leverage, not as a substitute for reading the actual indemnity in your deal.


Discrimination and automated decisions. If the tool will screen applicants, rank employees, or otherwise contribute to decisions about people, do not accept a clean vendor disclaimer of downstream employment or civil-rights risk. In Mobley v. Workday, Inc., No. 3:23-cv-00770-RFL (N.D. Cal.), the court denied in part a motion to dismiss and allowed disparate-impact claims to proceed against an AI hiring-platform vendor on an agency theory, concluding that the complaint plausibly alleged Workday's tools participated in traditional hiring functions rather than merely implementing employer criteria in a rote way. See the July 12, 2024 order. The same court later granted preliminary ADEA collective certification on May 16, 2025. The litigation remained active in 2026, with later orders addressing amended claims and the scope of the case. See, for example, the July 1, 2026 order. None of those rulings is a final judgment that Workday's tools discriminated against anyone. They do show why counsel should treat AI screening tools as employment-risk products, not as ordinary SaaS utilities, and should negotiate bias testing, disclosure of material limitations, and meaningful indemnity or risk-sharing language.


Regulatory and confidentiality failures. Push for indemnity covering the vendor's breach of data-protection obligations, unauthorized training or retention of customer content, and the vendor's failure to comply with AI or privacy laws applicable to the services as provided. Watch for carve-outs that swallow the promise, including broad "customer instructions," "customer data," or "third-party model" exclusions that leave you holding risk the vendor or its upstream providers control.


Indemnity language is only as good as the liability cap sitting next to it. If AI-specific failures are capped at fees paid, ask for a separate super-cap, or an uncapped basket where commercially supportable, for confidentiality breaches, unauthorized training, IP infringement in outputs, and discrimination claims tied to the model's design or performance.


Data Rights: Training, Retention, Subprocessors, and Exit


In a conventional SaaS deal, "customer data" usually means records in a database you can export and delete. In an AI deal, data can be transformed into embeddings, fine-tuning datasets, logs, and evaluation sets in ways that are harder to unwind.


Negotiate with precision.


Define customer data to include prompts, uploaded documents, outputs, embeddings, and fine-tuning corpora attributable to your business. A promise not to use data for "training" does not by itself define what the vendor may do with it for inference, evaluation, logging, product improvement, or sharing with foundation-model providers. State the permitted processing purposes expressly.


Prohibit training and fine-tuning on your content unless you expressly approve it in writing for a defined purpose. If you permit anonymized or aggregated data to be used for product improvement, define de-identification tightly, prohibit re-identification, restrict the permitted uses, and state expressly whether that license survives termination.


Require a current subprocessor list, advance notice of material changes, and flow-down of the same confidentiality, security, and training restrictions to foundation-model and cloud providers. Many AI products are assemblies. Your contract should reach the parts of the assembly that actually touch your data.


Address retention, deletion, and exit up front. You need portable export in a usable format, certified deletion on request or termination, and survival of confidentiality and data obligations after the subscription ends. For New York companies, the SHIELD Act requires reasonable administrative, technical, and physical safeguards for private information and expressly includes selecting service providers capable of maintaining appropriate safeguards and requiring those safeguards by contract. Pennsylvania's Breach of Personal Information Notification Act remains a core breach-notification framework for businesses that maintain computerized personal information of Pennsylvania residents. Your vendor schedule should make it possible for you to investigate and notify on the timelines those regimes require.


Intellectual Property: Prompts, Outputs, and Fine-Tuned Weights


Do not assume you own what the model returns.


Negotiate express ownership to the extent rights exist, or at minimum a broad, perpetual, irrevocable license in outputs generated for you from your prompts and data. Confirm that the vendor does not claim ownership of your prompts, documents, or confidential inputs. Contractual allocation and copyrightability are different questions: the U.S. Copyright Office has explained that generative-AI output is copyrightable only where sufficient human authorship exists. If the engagement includes fine-tuning, address who owns or controls the fine-tuned weights or adapters, whether they reflect customer-specific information, and what happens to them on termination.


Separate the vendor's underlying model and platform IP from your business content. The vendor can keep the model. You should preserve the rights necessary to use the business value created from your information.


For professional use, treat verification as part of the operating model, not as an afterthought. Federal Rule of Civil Procedure 11 requires an attorney or party presenting a filing to certify that the representations are based on an inquiry reasonable under the circumstances. An AI-generated citation that does not exist is still your problem if you sign the paper. Contractual performance warranties and human review workflows belong together.


Audit Rights That Work in Practice


An audit clause that only allows review of "policies" after thirty days' notice will not help when a regulator asks how the model was tested, what data it saw, or why a screening tool produced a disparate result.


Effective AI audit language usually includes:


periodic and for-cause assessment rights covering security, privacy, bias and fairness testing where relevant, performance, and regulatory compliance;

access to model documentation, evaluation summaries, and existing third-party certifications, not only marketing one-pagers;

the right to use independent assessors bound by confidentiality;

remediation deadlines and escalation rights if material findings are not fixed; and

no extra fees for ordinary cooperation.


If Local Law 144 or similar automated-decision rules are in play, make sure the contract requires the vendor to support the bias audits, summaries, and notices you need to publish or provide. The City's DCWP page on automated employment decision tools is a practical starting point for New York City employers and employment agencies.


Model Change, Performance, and the Limits of "As Is"


AI systems change. Vendors retrain models, swap foundation-model providers, alter guardrails, and update acceptable-use policies. An "as is" disclaimer plus a unilateral change right leaves you buying a moving target.


Ask for notice before material model changes, a right to test before forced migration, rollback or termination rights if performance or risk profile changes materially, and measurable service commitments where the use case supports them. Uptime alone is not enough for a tool whose value depends on output quality. Where the vendor will not warrant accuracy, at least preserve your termination rights, require transparency about known limitations, and keep human review mandates in your internal policy.


What General Counsel Should Do Before the Next AI Order Form


Inventory AI and AI-enabled SaaS already in use, including features turned on inside existing platforms.

Classify each tool by data sensitivity and by whether it contributes to decisions about people.

Require Legal, Security, and the business owner to review yellow- and red-risk deals before anyone pastes confidential information into the product.

Insist on written answers to four questions: Does the vendor train on our data? Who owns or controls the outputs? Which subprocessors touch our content? What indemnity and audit rights survive the marketing deck?

Align the contract with your internal generative-AI use rules so employees are not asked to follow a policy the vendor agreement makes impossible.

Build verification and escalation into the workflow. The contract allocates risk. It does not replace professional judgment.


If your company is negotiating contracts and commercial agreements for SaaS, AI, or technology vendors, or needs ongoing Fractional General Counsel support for technology and risk issues, the Law Office of Todd B. Nurick can help evaluate the paper against the actual use case before the tool is live.


About Todd B. Nurick


Todd B. Nurick is a Pennsylvania and New York business attorney and Fractional and Outside General Counsel. He advises companies on contracts, transactions, employment, corporate governance, investigations, compliance, technology, and related business risk. Legal services are provided through the Law Office of Todd B. Nurick, a fictitious name of Nurick Law Group LLC. Learn more at ToddNurickLaw.com and ToddNurick.com.


Sources














This article is for general informational purposes only and does not constitute legal advice or create an attorney-client relationship. SaaS and AI vendor contracting, data protection, intellectual property, indemnification, audit rights, employment-related automated decision tools, and related compliance obligations are highly fact-specific and depend on the product, use case, jurisdiction, and applicable law. Businesses should obtain legal advice concerning their particular circumstances.

bottom of page