AI Usage Clause Explained: The 2026 Contract Risk Guide
An AI usage clause controls who can use AI tools, who owns the outputs, and who pays when things go wrong. Here's what every contract needs in 2026.
Generate a master services agreement (msa) in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Is an AI Usage Clause?
An AI usage clause is a contract provision that defines which AI tools a party may use, how data flowing through those tools is handled, who owns the resulting outputs, and who bears liability when an AI system produces something wrong, biased, or legally risky. Any contract where a vendor, employee, or contractor could touch your data or create deliverables now needs one.
Key takeaways
- An AI usage clause is not a single paragraph — it is a coordinated system of provisions that must be consistent across your MSA, DPA, SOW, and any employment or freelancer agreements.
- The costliest drafting mistake is placing a training data opt-out in the main agreement while a companion DPA contains permissive carve-out language that legally overrides it.
- California AI Transparency Act (SB 942, Cal. Bus. & Prof. Code §§ 22757–22757.6), operative August 2, 2026, requires GenAI providers who license their systems to third parties to include a contractual disclosure-maintenance obligation — making AI clauses a supply-chain legal requirement, not just a best practice.
- EU AI Act Article 26 (Regulation 2024/1689), with full applicability from August 2, 2026, imposes deployer obligations — including human oversight and worker notification — that must be reflected in vendor contracts.
- A training opt-out negotiated today can legally disappear at contract renewal if the vendor reserves the right to update terms on 30 days' notice and no written-consent requirement is in place.
Why One AI Clause in the Wrong Document Is Not Enough
Most guides on AI usage clauses treat them as a single add-on paragraph. That framing creates a dangerous blind spot.
Commercial contracts rarely live in one document. A typical vendor relationship spans a master services agreement (MSA), one or more statements of work (SOW), and a data processing addendum (DPA). AI vendors frequently structure their agreements so that data usage restrictions appear in the main service agreement while the actual terms governing data processing appear in a separate DPA. When those two documents conflict, the DPA typically governs for data-processing matters.
Here is what that failure looks like in practice. A procurement team reads the MSA, finds the clause: "Provider will not use Customer Data to train or fine-tune any AI model." They flag it as protected and move on. Nobody reads Exhibit C — the DPA — which states: "Provider may use aggregated and anonymized data to improve its services." The two documents conflict. The DPA governs data processing. The training restriction the team negotiated is a dead letter.
This is not hypothetical. During AI vendor renewals, procurement teams often focus on pricing, seats, and deadlines — comparing contracts from memory instead of against the previous version. AI-specific data usage clauses are easy to miss and can have significant legal consequences. A training data opt-out you negotiated today can be removed at the next renewal cycle without renegotiation, provided the vendor gives adequate notice — typically 30 days under most SaaS terms.
The fix is covered in the mistake-and-fix pair below. The principle: AI clause provisions must be drafted, reviewed, and cross-referenced across every document in the contract stack.
The Five Elements Every AI Usage Clause Must Cover
A complete AI usage clause addresses five things precisely:
1. Permitted tools and scope Name the permitted AI systems or categories — for example, "enterprise-tier tools with zero prompt retention" — and explicitly prohibit public, free-tier, or consumer AI products that store or log user inputs. Language like "commercially reasonable AI practices" gives the other party near-unlimited discretion.
2. Training data prohibition Specify that Customer Data — including prompts, outputs, and usage logs — may not be used to train, fine-tune, or otherwise improve any AI model, whether proprietary to the vendor or provided by a third-party model provider. Make this restriction survive contract termination and require your prior written consent to modify it.
3. IP ownership of outputs The U.S. Copyright Office's current position is that copyright does not vest in works generated purely by AI without meaningful human authorship. Without explicit assignment language, output ownership is legally contested. The clause must state that all outputs, including AI-assisted drafts, are assigned to the customer upon delivery, with the vendor warranting non-infringement to the extent it controlled the AI tool's inputs.
4. Disclosure and human review Require the vendor to disclose when a deliverable was materially AI-generated and to apply human review before delivery. This maps to EU AI Act Article 50 transparency obligations (effective August 2, 2026) and to California SB 942's latent-disclosure requirements under Cal. Bus. & Prof. Code § 22757.2.
5. Liability and indemnification Allocate who pays if an AI output infringes third-party IP, produces biased results, or violates a consumer protection statute. Many vendor limitation-of-liability clauses cap exposure at subscription fees paid — a figure that may be tens of thousands of dollars against potential EU AI Act Article 99 fines of up to €35 million or 7% of global annual turnover.
Which Document Needs Which AI Clause Element?
Not every provision belongs everywhere. This table shows where each element must appear and where it is commonly missed.
| AI Clause Element | MSA | SOW | DPA | Employment Agreement | Freelancer Contract |
|---|---|---|---|---|---|
| Permitted AI tools list | ✓ | ✓ | — | ✓ | ✓ |
| Training data prohibition | ✓ | — | ✓ (must match) | — | ✓ |
| IP ownership of outputs | ✓ | ✓ | — | ✓ | ✓ |
| Disclosure / human review | ✓ | ✓ | — | ✓ | ✓ |
| Audit rights for AI use | ✓ | — | ✓ | — | — |
| Survival on termination | ✓ | ✓ | ✓ | ✓ | ✓ |
The DPA column is the most commonly missed. If your DPA is silent on training restrictions while the MSA prohibits them, the conflict-resolution provision in your DPA will often override your MSA intent. Check it now. For help structuring the data-processing layer correctly, our guide to GDPR-compliant data processing addendums covers what GDPR Article 28 requires from processor contracts and how AI subprocessors must be disclosed.
How to Draft an AI Usage Clause: Step by Step
-
Map your AI surface area. List every place AI enters the contract relationship: vendor tools processing your data, employees using generative AI on deliverables, subcontractors generating content with AI. This inventory determines where the clause must appear.
-
Classify the risk level. Low-risk use — AI-assisted spell-check on non-sensitive documents — needs lighter controls than high-risk use such as AI-generated employment decisions, legal analysis, or processing of biometric data. EU AI Act Annex III classifies AI systems used in recruitment, performance evaluation, worker monitoring, education, credit scoring, and biometric identification as high-risk.
-
Draft the permitted use definition. Be specific. "Approved AI Systems" should reference an exhibit or appendix listing permitted tools by name or category, so the list can be updated without amending the entire agreement.
-
Insert the training data prohibition with explicit scope. Use precise language: "Provider will not use Customer Data, including any inputs, prompts, queries, or outputs generated in connection with the Services, to train, fine-tune, or otherwise improve any AI model or system, whether proprietary to Provider or provided by a third party, without Customer's prior written consent. This restriction survives termination of this Agreement." Then verify the DPA does not contain a carve-out that defeats it.
-
Add the IP assignment. State that all deliverables — AI-assisted or fully AI-generated — are the work product of Provider and are assigned to Customer upon delivery, free of any retained Provider IP interest.
-
Include a disclosure and human review requirement. For services agreements, a single sentence prevents the most common disputes about AI-generated work: "Provider will notify Customer in writing before using AI to generate any material portion of a Deliverable and will apply human review before delivery."
-
Cross-reference and reconcile every document. Read the DPA, any subprocessor list, and any linked policy schedule. Add explicit governing-order language to the AI clause: "To the extent this Section conflicts with any DPA, policy schedule, or order form, the terms most protective of Customer Data control."
-
Schedule a review cadence. EU AI Act obligations, state AI statutes, and vendor terms are all moving. Build a biannual review trigger into the contract or your internal calendar so the clause stays current with laws like Colorado SB 24-205 and the EU AI Act's rolling implementation timeline.
If you want an MSA with AI usage terms built in, Pactlio's MSA template includes a modular AI clause covering training restrictions, output ownership, and cross-document consistency. For independent contractor relationships, the contractor agreement template includes corresponding AI and IP provisions.
Jurisdiction-Specific Rules That Shape Your AI Clause
Your AI usage clause must account for the specific regulatory obligations that apply to your business and your counterparty's jurisdiction.
| Law / Regulation | Jurisdiction | Key Contract Obligation | Effective / In Force |
|---|---|---|---|
| EU AI Act, Art. 26 (Reg. 2024/1689) | EU / EEA | Deployers of high-risk AI must inform affected workers and ensure human oversight; vendor contracts must operationalize these duties | Aug. 2, 2026 (Annex III systems; Omnibus defers some obligations to Dec. 2, 2027) |
| EU AI Act, Art. 50 (Reg. 2024/1689) | EU / EEA | Providers and deployers must disclose when users interact with AI (chatbots, deepfakes); contracts must support this disclosure chain | Aug. 2, 2026 |
| California AI Transparency Act, SB 942 (Cal. Bus. & Prof. Code §§ 22757–22757.6) | California | Covered GenAI providers must contractually require licensees to maintain latent-disclosure capability; 96-hour license revocation for non-compliance | Aug. 2, 2026 |
| Colorado AI Act, SB 24-205 | Colorado | Developers and deployers of high-risk AI must disclose use to affected consumers in consequential decisions, including employment | June 30, 2026 (delayed from Feb. 1, 2026) |
| Illinois AI Video Interview Act (820 ILCS 42) | Illinois | Employers using AI to analyze video interviews must notify candidates and obtain consent; vendor contracts must enable compliance | In force |
| GDPR, Art. 28 | EU / EEA | Processor agreements must cover AI subprocessors; training on personal data requires a legal basis under GDPR Art. 6 | In force |
| GSA Draft Clause GSAR 552.239-7001 | U.S. Federal contractors | Contractors must disclose AI systems used in performance within 30 days of award; American AI system and anti-bias certification requirements | Proposed Mar. 6, 2026 — not yet final |
For a deep look at EU AI Act implications for commercial agreements, our EU AI Act contracts guide covers provider versus deployer obligations and how they translate into contract language. For California-specific requirements, the California AI Transparency Act guide details SB 942 and the AB 853 amendments that pushed the operative date and added hosting-platform obligations.
The Classic "Document Split" Mistake — and the Fix
This is the most common, most expensive AI contracting error. It has a clear pattern and a clear solution.
The mistake:
A company negotiates a strong training restriction into the body of its SaaS MSA:
"Provider shall not use Customer Data to train, fine-tune, or improve any AI model without Customer's prior written consent."
Procurement signs off. Nobody reads Exhibit C — the DPA — which states:
"Provider may use aggregated and anonymized usage data to improve its services."
When the DPA governs data processing conflicts (as it typically does), the "aggregated and anonymized" carve-out effectively licenses the vendor to de-identify the customer's data and train on it. The MSA restriction becomes unenforceable for the very category of processing it was meant to prohibit. The contract renews. The new terms take effect. The customer never knows.
The fix:
Add one sentence to the MSA AI clause:
"For the avoidance of doubt, the prohibition in this Section applies to de-identified, anonymized, and aggregated derivatives of Customer Data, and shall govern over any conflicting provision in any DPA, order form, or policy schedule attached to this Agreement."
Then amend or delete the "aggregated and anonymized" carve-out in the DPA. Execute both documents at the same time, or attach a DPA amendment as an exhibit to the MSA at signing.
The same document-split risk exists in independent contractor agreements when a confidentiality clause and an AI restriction appear in the body of the agreement while a separate IP assignment schedule contains broader rights. All documents in the contract stack must be read together and reconciled before execution.
How California SB 942 Makes AI Clauses a Supply-Chain Legal Requirement
California's AI Transparency Act (Cal. Bus. & Prof. Code §§ 22757–22757.6), operative August 2, 2026, does something no prior U.S. law had done: it makes a contract clause mandatory by statute for a specific category of AI transaction.
If a covered GenAI provider — one with over one million monthly users in California — licenses its system to a third party, it must contractually require that licensee to maintain the system's latent-disclosure capability. If the provider learns that a licensee has stripped or disabled that capability, the provider must revoke the license within 96 hours. The licensee must then cease using the system immediately.
For businesses that license generative AI tools to build products or services, this creates two obligations: first, your vendor must include that requirement in the license you sign; second, you must not modify the tool in a way that strips provenance metadata, or you risk a four-day notice of termination.
The penalty structure compounds quickly: the California Attorney General can bring a civil action for $5,000 per daily violation. For a downstream licensee that continues using a revoked system for even a week, that is $35,000 in potential civil exposure — plus attorney's fees and costs.
Practical takeaway for procurement and legal teams: read the license agreement from any major GenAI platform before signing. Check whether it includes the SB 942 disclosure-maintenance obligation. If it does not, and you are a licensee building on that platform for California users, ask for it. If you are the covered provider, confirm your license template already includes the clause and that you have technical monitoring in place to detect downstream stripping of provenance data.
The broader IP ownership questions that arise from AI-generated outputs are covered in our guide to IP clauses in contracts.
Common Mistakes to Avoid
- Restricting AI in the MSA but ignoring the DPA. A conflicting DPA carve-out for "aggregated and anonymized" data can make the MSA restriction unenforceable for data-processing purposes. Read both documents side by side.
- Using vague scope language. "Commercially reasonable AI practices" or "appropriate AI tools" give the other party near-unlimited discretion. Specify permitted tools or tool categories in an exhibit.
- Forgetting subcontractors and subprocessors. AI vendors routinely relay your data to third-party model providers via API. Require disclosure of any subprocessor that touches your data through AI and extend all restrictions downstream by contract.
- Omitting survival-on-termination language. A restriction that expires with the contract leaves your data exposed to post-termination training. State expressly that the training prohibition survives.
- Not requiring written consent for term changes. Many SaaS agreements let vendors update AI terms unilaterally on 30 days' notice. Require a longer notice period and your written consent for any change affecting AI data rights.
- Treating the AI clause as a one-time exercise. EU AI Act obligations, state AI statutes, and vendor terms are all evolving on overlapping timelines. Build a biannual review into the contract or your internal compliance process.
Sources
- EU AI Act (Regulation 2024/1689): https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
- EU AI Act Digital Omnibus — entered into force July 27, 2026: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- High-level summary of the EU AI Act: https://artificialintelligenceact.eu/high-level-summary/
- California AI Transparency Act (SB 942), Cal. Bus. & Prof. Code §§ 22757–22757.6: https://leginfo.legislature.ca.gov/faces/billNavClient.xhtml?bill_id=202320240SB942
- Kolmogorov Law — California AI Transparency Act operative guide: https://www.kolmogorovlaw.com/california-ai-transparency-act-sb-942
- Jones Day — California Enacts AI Transparency Law: https://www.jonesas.com/en/insights/2024/10/california-enacts-ai-transparency-law-requiring-disclosures-for-ai-content
- GSA Draft AI Procurement Clause (GSAR 552.239-7001), March 6, 2026: https://governmentcontracts.foxrothschild.com/2026/03/articles/general-federal-government-contracts-news-updates/what-gsas-new-draft-ai-procurement-clause-could-mean-for-your-gsa-schedule-contract/
- Bonterms AI Standard Clauses, Version 1.0: https://bonterms.com/forms/ai-standard-clauses-version-1-0
- Taft Law — The Expanding Prevalence of AI Clauses in Contracts: https://www.taftlaw.com/news-events/law-bulletins/the-expanding-prevalence-of-ai-clauses-in-contracts/
- CloudEagle.ai — AI Contract Clauses and the Document Split Risk: https://www.cloudeagle.ai/blogs/ai-contract-clauses
- ThoughtRiver — AI Clauses in Commercial Contracts: https://www.thoughtriver.com/resources/ai-clauses-in-commercial-contracts-a-practical-guide-part-1
- EBG Law — Workplace AI Regulation in 2026: https://www.ebglaw.com/insights/publications/workplace-ai-regulation-in-2026-how-employers-can-navigate-the-changing-legal-landscape
- Illinois AI Video Interview Act (820 ILCS 42): https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=4015&ChapterID=68
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What is an AI usage clause in a contract?▾
An AI usage clause is a contract provision that defines which AI tools a party may use, how data flowing through those tools is handled, who owns the outputs, and who bears liability when AI-generated content is wrong, biased, or legally risky. It belongs in any contract where AI could touch deliverables or confidential data.
Does an AI usage clause need to be in a separate addendum?▾
Not necessarily. The clause can sit inside a master agreement, statement of work, or data processing addendum. What matters is consistency: if your MSA restricts AI training but your DPA permits de-identified data use for model improvement, the DPA language typically governs — and your MSA restriction evaporates.
Who owns content generated by AI under a contract?▾
Ownership depends on what the contract says. Without explicit language, U.S. copyright law generally does not protect purely AI-generated works. Most commercial agreements assign output rights to the customer. A well-drafted AI clause should state that all outputs, including AI-assisted ones, are assigned to the client upon delivery.
Can a vendor silently change its AI data training policy at renewal?▾
Yes, unless the contract prohibits it. Many AI vendor agreements allow term changes with 30 days' notice. A training opt-out negotiated today can disappear at the next renewal if the vendor updates its terms. Demand a clause that survives termination and requires your written consent to change.
Does the EU AI Act require AI usage clauses in contracts?▾
Not in those exact words, but EU AI Act Article 26 (Regulation 2024/1689) requires deployers of high-risk AI systems to inform affected workers and implement human oversight. That obligation translates directly into vendor contract terms, particularly for employment, credit, and biometric AI systems.
What happens if a contractor uses AI without permission?▾
Without an AI clause, the client may have limited recourse even if confidential data was uploaded to a public AI tool. With a clear clause, unauthorized AI use is a material breach, triggering termination rights, indemnification obligations, and potentially liquidated damages for the affected party.
Do employment contracts need AI usage clauses?▾
Yes, especially for employers subject to Illinois's AI Video Interview Act (820 ILCS 42), Colorado SB 24-205, or EU AI Act Article 26. Any employer using AI for performance evaluation or any employee using AI tools on company data needs written rules covering permitted tools, data handling, and human review.
What's the difference between an AI usage clause and a data processing addendum?▾
A data processing addendum governs how personal data is processed, as required by GDPR Article 28 or CCPA. An AI usage clause governs how AI tools are used, who owns outputs, and who bears liability for AI errors. For AI vendors handling personal data, you need both — and they must not contradict each other.