SaaS Contracts: The 2026 Guide for Every GTM Motion
SaaS contracts depend on your GTM motion. This 2026 guide covers every required agreement, AI training clauses, and the December 2026 EU liability deadline.
Generate a master services agreement (msa) in 60 seconds
Describe what you need in plain English. A panel of AI agents (Researcher, Drafter, Critic, Validator, Adversary) writes a review-ready draft you can edit, sign, and send.
What Contracts Does a SaaS Company Actually Need?
A SaaS company needs contracts matched to its go-to-market motion. A PLG business starts with Terms of Service, a Privacy Policy, and a DPA. A sales-led company also needs an MSA, Order Form, and SLA. In 2026, every AI-enabled product needs an explicit training-data clause—absent in 92% of AI contracts per Stanford Law CodeX and TermScout.
Key takeaways
- Your GTM motion—PLG, sales-led, or hybrid—determines your contract stack before any generic checklist does.
- GDPR Article 28 and more than 20 US state privacy laws require a written Data Processing Agreement the moment your platform processes personal data on a customer's behalf.
- Stanford Law CodeX and TermScout found that roughly 92% of AI contracts claim data-usage rights beyond what is strictly necessary to deliver the service.
- Common Paper's 2026 SaaS Contract Benchmark Report shows explicit AI training prohibitions appeared in 14% of cloud service agreements—up from under 1% in 2024. Vendors granting training rights stayed flat at 3%.
- EU Directive 2024/2853 takes effect December 9, 2026, classifying SaaS and AI systems as "products" subject to strict product liability. Article 14 prohibits contractual exclusion of this liability against end users—every EU-facing MSA needs a mandatory law carve-out now.
- Enterprise procurement adds up to 20 weeks of delay between verbal commitment and signed contract: security review (2–6 weeks) + legal redlines (2–8 weeks) + procurement approval (2–6 weeks). A complete contract stack compresses each phase.
Why Your Go-To-Market Motion Decides Your Contract Stack
Every SaaS contract guide publishes the same list: MSA, SLA, DPA, NDA, BAA, ToS, SOW. The list is accurate. The problem is that it treats all SaaS companies as identical.
A PLG company with a $49/month plan does not need an MSA on day one. Adding one creates friction in a self-serve funnel that depends on frictionless sign-up. A sales-led company closing $100,000 enterprise contracts cannot survive with clickwrap Terms of Service that cap liability at one month of fees—enterprise procurement teams will catch that in the first round of legal review.
The GTM motion determines three things simultaneously: who signs (one individual vs. a procurement committee), how they sign (clickwrap vs. negotiated), and which clauses the other party's legal team will demand before they touch a pen to paper.
| GTM Motion | Typical ACV | Required at Launch | Required at Enterprise Scale |
|---|---|---|---|
| PLG / Self-Serve | Under $10K | Terms of Service, Privacy Policy, DPA (if EU or US regulated data) | MSA template, NDA, SLA tiers, BAA (healthcare), AI training clause |
| Hybrid (PLG + Sales) | $5K–$50K | ToS, Privacy Policy, DPA, NDA, Order Form | MSA, custom SLA, reseller agreement, SOW |
| Sales-Led / Enterprise | Over $25K | MSA, Order Form, SLA, DPA, NDA | BAA (healthcare), channel partner agreement, SOW, source code escrow |
Most B2B SaaS companies in 2026 operate a hybrid model—PLG for acquisition, a sales overlay for enterprise expansion. Any PLG company with enterprise ambitions should prepare an MSA template, a GDPR-compliant DPA, a custom SLA tier, and an explicit AI training prohibition before the first enterprise inbound arrives. The contracts every startup needs guide maps each document to growth stage.
The Core SaaS Contract Stack
Terms of Service and the SaaS Subscription Agreement
Terms of Service govern how any user may interact with your platform: acceptable use, IP ownership, liability limits, and account termination rules. For PLG companies, the ToS is typically the only contract a user signs—delivered as a clickwrap agreement at account creation.
Once you move into B2B sales, a SaaS subscription agreement replaces or supplements the ToS. This negotiated contract adds pricing, billing cycles, renewal terms, and customer-specific obligations that a public ToS cannot address. Enterprise procurement teams will not accept a clickwrap ToS as a substitute for a negotiated MSA on any deal above roughly $25,000 per year.
Master Service Agreement and Order Form
A Master Service Agreement is the foundational B2B contract. It defines IP ownership (your platform, their data), warranty disclaimers, the limitation of liability cap, indemnification obligations, and governing law. Individual Order Forms attach to the MSA to specify pricing, user seats, subscription term, and any custom deliverables for each purchase.
The MSA–Order Form structure lets you negotiate legal terms once and close subsequent deals faster. See MSA vs. SOW for guidance on when each document is the right tool. To generate an MSA that covers these provisions, Pactlio's AI agents draft, critique, and validate the document before it reaches your lawyer.
Service Level Agreement
Every commercial SaaS SLA should specify: the uptime percentage (99.9% is standard; 99.95%–99.99% for mission-critical workloads), how downtime is measured (monthly vs. annual measurement produces materially different results), the window for claiming service credits, and the credit amount per breach tier. An SLA that names a percentage but specifies no remedy is a performance target, not an enforceable contract clause.
Data Processing Agreement
A DPA is not optional once your platform processes personal data on a customer's behalf. GDPR Article 28(3) mandates eight specific obligations in every processor contract. US state law adds further requirements. To draft a Data Processing Agreement meeting GDPR and US state standards, Pactlio generates a full DPA with a sub-processor annex and breach notification timeline. For a clause-by-clause breakdown, the DPA and GDPR compliance guide covers every mandatory provision.
The 2026 SaaS Contract Clause Audit
This table maps the eight clauses that carry the most financial and legal risk in 2026, the legacy language that creates that risk, the defensible current standard, and current market benchmarks.
| Clause | Legacy Language (Risk) | 2026 Defensible Standard | 2026 Market Data |
|---|---|---|---|
| AI Training Rights | "Vendor may use service data to improve, develop, and enhance the product" | Training off by default; opt-in required; covers de-identified data; no retention for model training | Prohibition in 14% of CSAs (up from <1% in 2024); 92% of AI contracts claim rights beyond service necessity |
| Liability Cap | 1 month of fees paid | 12 months of fees paid; carve-outs for breach, IP, gross negligence; mandatory PLD carve-out for EU | 96% of contracts cap at 1x annual fees; 0.5x cap declined from 7% to 2.5% |
| Supercap (Increased Claims) | No tier above general cap | 2x annual fees for data breach and IP infringement; unlimited for fraud and willful misconduct | 2x supercap grew from 0.3% to 2.7% of all CSAs; 5x supercap fell from 2.5% to 1.7% |
| Auto Fee Increase | Annual price increases at vendor's discretion | CPI cap or 3–5% ceiling; 60+ days advance notice | Auto fee increase clauses fell from 23% to 13% of CSAs |
| Auto-Renewal Notice | 30-day opt-out window | 60–90 day mutual opt-out; click-to-cancel in same medium | 87% of CSAs include auto-renewal; notice window is primary negotiation point |
| Sub-Processor Disclosure | No list; vendor discretion | Named sub-processor list; 30-day advance notice; right to object | Required under GDPR Article 28; absence voids GDPR processor compliance |
| Data Return on Termination | No provision | Standard format export (CSV/JSON); 30–90 day window; written deletion attestation | GDPR Article 28(3)(g) mandatory; absence is a standard enterprise redline |
| Insurance | Not specified | Cyber liability ($2M+ limits); tech E&O; annual certificate; customer named as additional insured | Cyber insurance in CSAs: 9% (2024) → 12% (2026); E&O flat at ~7% |
The AI Training Data Clause: The #1 Enterprise Redline in 2026
Standard SaaS master agreements have for two decades included vendor rights to use "service data" to "improve, develop, and enhance the product." Drafted when "improve the product" meant fixing bugs and adding features, that same wording in 2026 covers training a foundation model on customer inputs—on a literal reading, under contract terms customers signed years ago.
Stanford Law CodeX, in partnership with TermScout, systematically reviewed the terms of service and master agreements of commercial AI products. As reported by PYMNTS in June 2026, the analysis found that roughly 92% of AI contracts claim data-usage rights beyond what is strictly necessary to deliver the service, compared with a 63% market average for SaaS contracts more broadly. Most enterprise buyers and in-house counsel are still catching up with the exposure.
Common Paper's 2026 benchmark confirms the directional shift. AI training prohibitions appeared in under 1% of cloud service agreements in 2024, 11% in 2025, and 14% in 2026. AI-specific edits of any kind now appear in 20% of SaaS contracts, up from under 4% in 2024. Vendors granting training rights stayed flat at 3%—the market is moving decisively toward prohibition.
WCR Legal identifies this as the highest-frequency redline from enterprise clients in 2025–2026. Clients with GDPR obligations, trade secrets, or confidential operational data will not execute an MSA that does not explicitly prohibit use of their data for model training.
The defensible contract standard for AI-enabled SaaS in 2026 has five components:
- Training off by default. The contract prohibits use of customer data for training, fine-tuning, reinforcement learning, or benchmarking any AI model without prior written consent from a named customer signatory.
- Opt-in only, not opt-out. Any change to the training default requires affirmative written authorization—not a console toggle the vendor can unilaterally flip.
- No de-identification carve-out. The prohibition covers data even after anonymization or aggregation, unless the vendor can demonstrate that re-identification is technically impossible.
- Zero-retention fallback. When a vendor will not commit to full opt-in, the negotiated fallback is zero-retention processing: the vendor processes customer data to generate output and does not retain it for any model training purpose.
- Sub-processor disclosure. Most SaaS startups are not running their own models—prompts flow to OpenAI, Anthropic, or Google, making those providers sub-processors. GDPR Article 28 requires those providers to be identified and authorized in a current sub-processor annex.
One provision that no 2024-era MSA template contains: a model update clause. As AI-enabled SaaS platforms retrain or swap underlying foundation models, customers face material accuracy and compliance risk from changes they did not consent to. The current negotiation standard is 30–60 days' advance notice before any material model change, with the customer receiving a right to test the replacement model against its own data before the swap is forced into production.
For a full treatment of EU AI Act contract obligations by risk tier, the EU AI Act contracts guide covers provider and deployer obligations in detail.
The EU Product Liability Directive: The December 9, 2026 Deadline SaaS Companies Cannot Miss
This is the section most SaaS contract guides have not yet addressed.
EU Directive 2024/2853 on liability for defective products takes effect December 9, 2026—the date by which all EU member states must transpose the revised Product Liability Directive into national law. The Directive explicitly classifies software, including standalone applications, AI systems, and SaaS delivered via cloud, as a "product" for the purpose of strict product liability (Article 4(1); Recital 12–13). Products placed on the market before December 9, 2026, remain subject to the prior 1985 regime.
Three implications for SaaS contract drafting are non-negotiable:
1. Limitation of liability clauses cannot exclude PLD liability against end users. Article 14 of the Directive prohibits contractual exclusion or limitation of liability toward an injured person. A general liability cap in a vendor MSA cannot waive a third-party user's PLD claim for covered harm. The cap governs B2B economic loss allocations between the contracting parties—it does not protect against consumer-facing PLD liability. Any MSA covering EU-facing SaaS must include a mandatory law carve-out: "Nothing in this Agreement limits liability that cannot be excluded under applicable mandatory law, including Directive (EU) 2024/2853." Enterprise EU clients are already requiring this language; if you omit it, they will add it in redlines.
2. Each substantial software update is a new product placement. Reed Smith and Outlex both identify this as a live exposure for SaaS companies running continuous deployment. Any update that is substantial enough to alter the product's safety profile constitutes a new product placement under the Directive, starting a fresh liability period. Teams running CI/CD pipelines should log each material release with a record of the safety assessment conducted before deployment.
3. The new categories of covered damage are directly relevant to SaaS. The revised Directive adds data destruction or corruption and medically recognized psychological harm to the categories of compensable damage, alongside physical injury and property damage. A SaaS platform that loses or corrupts a customer's personal data can now face PLD claims in addition to GDPR enforcement. WCR Legal's 2026 MSA analysis notes that EU AI Act non-compliance creates a presumption of defectiveness under the PLD—compounding exposure for vendors who have not updated their compliance posture.
The practical contract fix: add an AI-specific liability clause that addresses output-generated claims separately from general service claims, maintains the 12-month fee reference for B2B economic loss, and includes an explicit carve-out confirming that nothing limits liability under Directive (EU) 2024/2853 or other applicable mandatory law.
A Worked Example: The Enterprise Contract Gap Costs 20 Weeks and Real Deals
A project management SaaS company launches on a PLG model with polished Terms of Service and Privacy Policy. Three years in: $4 million ARR, 1,200 self-serve customers, first Fortune 500 inbound.
Procurement sends a vendor questionnaire. Here is what happens, mapped against published 2026 benchmarks:
| Week | Request | Company Status | Deal Risk |
|---|---|---|---|
| 1 | MSA requested | No MSA exists; ToS doubles as the B2B agreement | High: procurement stalls pending a legal document |
| 2 | GDPR-compliant DPA with sub-processor list | Privacy Policy has one paragraph on data processing | High: EU legal review blocked |
| 3 | Custom SLA at 99.95% uptime | ToS promises "commercially reasonable efforts" | High: SRE team scrambles |
| 4 | AI training prohibition confirmed | ToS is silent; "service improvement" clause covers training | Critical: legal hold on deal |
| 5–14 | MSA redline cycles (3–5 rounds) | Each redline round: 3–10 business days (HyperStart 2026) | Deal slippage confirmed |
Per Prospeo's 2026 enterprise benchmarks, security review adds 2–6 weeks, legal redlines add 2–8 weeks, and procurement approval adds another 2–6 weeks. Worst case: 20 weeks between verbal commitment and signed contract. The Optifai Pipeline Study (2026, N=939) found that the Negotiation → Close stage accounts for 35–40% of total enterprise deal cycle time, and legal redlines are the #1 cause of delayed closes.
A competitor with a prepared enterprise contract stack—MSA, DPA with sub-processor annex, explicit AI training prohibition, custom SLA tier—moves through each phase with an existing document rather than drafting under deal pressure. That structural advantage closes deals weeks faster. A pre-built enterprise contract package is a revenue-cycle asset, not a compliance checkbox.
Data Privacy Compliance: The DPA Requirement
GDPR Article 28(3) requires that processing by a processor be governed by a written contract specifying eight mandatory obligations: process only on documented controller instructions; ensure staff confidentiality; implement Article 32 security measures; comply with sub-processor authorization requirements; assist with data subject rights; assist with breach notification; delete or return all data on termination; and make information available for audits. Violations can trigger GDPR Article 83 fines of up to €10 million or 2% of global annual revenue, whichever is higher.
More than 20 US states now have comprehensive privacy laws with processor agreement requirements, including the Texas Data Privacy and Security Act (effective July 1, 2024) and Virginia's Consumer Data Protection Act. A GDPR-only DPA will not satisfy all US state requirements. The state privacy laws 2026 guide maps current processor obligations by jurisdiction.
When reviewing contracts your enterprise customers send, the how to review a contract guide and the red flags in contracts guide cover the buyer-side perspective in detail.
Auto-Renewal Compliance in 2026
California AB 2863 (effective July 1, 2025) amends Cal. Bus. & Prof. Code § 17600 et seq. to require: express affirmative consent to auto-renewal terms at sign-up; annual renewal reminders regardless of billing frequency; advance notice of fee changes at least seven days before the change takes effect; click-to-cancel using the same medium the customer used to subscribe; and consent records retained for three years or one year after contract termination, whichever is longer. Free trials that convert to paid subscriptions are explicitly covered.
The FTC's Negative Option Rule was vacated by the Eighth Circuit in Custom Communications, Inc. v. Federal Trade Commission (July 8, 2025) on procedural grounds. The FTC filed an Advance Notice of Proposed Rulemaking with OIRA on January 30, 2026, initiating a new rulemaking process. California's AB 2863 requirements are now treated as the de facto national standard by many compliance teams while the federal framework is unsettled. Massachusetts 940 C.M.R. 35.00 (effective September 2, 2025) and New York Gen. Bus. Law § 527 add parallel state-level requirements.
The auto-renewal clause guide walks through what compliant renewal language looks like in practice.
Jurisdiction Notes
| Jurisdiction | Key Law | Key Provision | SaaS Impact |
|---|---|---|---|
| European Union | GDPR Article 28 | Written DPA mandatory | Sub-processor authorization required; deletion on termination |
| European Union | EU AI Act Article 50 (eff. Aug 2, 2026) | Chatbot disclosure; AI content labeling | Applies to all AI-enabled SaaS with EU users now |
| European Union | Directive (EU) 2024/2853 (eff. Dec 9, 2026) | SaaS = "product"; strict liability; Article 14 non-waivable | Mandatory PLD carve-out required in every EU-facing MSA |
| European Union | EU AI Act Annex III (eff. Dec 2, 2027) | High-risk AI system obligations | Conformity assessments, technical files, CE marking |
| California, USA | Cal. Bus. & Prof. Code § 17600; AB 2863 | Automatic Renewal Law | Click-to-cancel, annual reminders, 3-year consent records |
| Massachusetts, USA | 940 C.M.R. 35.00 (eff. Sept 2, 2025) | Auto-Renewal Regulation | Cancellation as easy as enrollment; same medium required |
| New York, USA | N.Y. Gen. Bus. Law § 527 | Auto-Renewal Law | Clear pre-purchase disclosure; easy online cancellation |
| United Kingdom | UK GDPR Article 28 (retained) | IDTA or EU SCCs + UK Addendum | Required for data transfers post-Brexit |
| Healthcare (US) | HIPAA 45 C.F.R. Parts 160 & 164 | Business Associate Agreement | Required before processing any Protected Health Information |
Healthcare SaaS requires a Business Associate Agreement under 45 C.F.R. § 164.308(b) before your platform handles any PHI. A standard SaaS subscription agreement does not substitute for a BAA. The healthcare contracts and HIPAA guide covers BAA requirements and the required administrative, physical, and technical safeguard provisions.
Common Mistakes to Avoid
- Using PLG clickwrap terms for enterprise deals. Clickwrap ToS with liability caps tied to monthly fees will fail enterprise legal review. Prepare an MSA template before your first inbound enterprise prospect arrives—not after procurement requests one under deal pressure.
- Treating the Privacy Policy as the DPA. A public-facing Privacy Policy describes data practices to end users. A DPA is a binding contract with your business customer specifying processor obligations under GDPR Article 28. They serve different legal functions and cannot substitute for each other.
- Leaving AI training rights ambiguous. Broad "service improvement" language in your current MSA almost certainly covers model training on a literal reading. Stanford CodeX and TermScout found this exposure in 92% of AI contracts reviewed. Add an explicit prohibition before legal review surfaces it in a live deal.
- No mandatory PLD carve-out in EU-facing MSAs. Article 14 of Directive 2024/2853, effective December 9, 2026, makes limitation of liability unenforceable against end users for covered harm. Enterprise EU clients are already requiring this language in redlines—omit it and they add it.
- Setting the liability cap at one month of fees. On any contract above roughly $10,000 per year, this cap is commercially unreasonable. The 2026 market standard is 1x annual fees paid, with carve-outs for data breaches, IP indemnification, gross negligence, and a mandatory law carve-out for PLD.
- Missing auto-renewal compliance on free-to-paid conversions. California AB 2863 covers free trials that convert to paid subscriptions as of July 1, 2025. Many PLG companies with California subscribers are non-compliant today.
- No data return clause in the termination section. Without explicit language on data portability, export format, and post-termination retention window, customers have no contractual right to their data after cancellation—a GDPR Article 28(3)(g) requirement and a standard enterprise redline.
- Omitting a model update clause. A vendor that swaps from one foundation model to another mid-contract without notice can create accuracy regressions and compliance gaps. Require 30–60 days' advance notice of material model changes, with customer testing rights before the swap takes effect.
You can generate a privacy policy or create terms of service with Pactlio's AI contract generator as a starting point before attorney review. Understanding what makes a contract legally binding is useful grounding before any negotiation.
Sources
- GDPR Article 28 – Processor: https://gdpr-info.eu/art-28-gdpr/
- GDPR Article 83 – General Conditions for Imposing Administrative Fines: https://gdpr-info.eu/art-83-gdpr/
- Common Paper – 2026 SaaS Contract Benchmark Report: https://commonpaper.com/resources/2026-saas-contract-benchmark-report/
- PYMNTS – Enterprise SaaS Contracts Are Secret AI Training Licenses (June 24, 2026): https://www.pymnts.com/news/artificial-intelligence/2026/enterprise-saas-contracts-are-secret-ai-training-licenses/
- Gibson Dunn – EU Product Liability Directive: Responding to Software, AI and Complex Supply Chains: https://www.gibsondunn.com/eu-product-liability-directive-responding-to-software-ai-and-complex-supply-chains/
- Reed Smith – The New EU Product Liability Directive: Implications for Software, Digital Products, and Cybersecurity: https://www.reedsmith.com/articles/eu-product-liability-directive-software-digital-products-cybersecurity/
- Goodwin – EU Updates its Product Liability Regime: Important Considerations for Providers of AI Systems and Software: https://www.goodwinlaw.com/en/insights/publications/2025/02/alerts-practices-aiml-eu-updates-its-product-liability-regime
- California AB 2863 – Automatic Renewal and Continuous Service Offers: https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2863
- Cal. Bus. & Prof. Code § 17600 et seq. – California Automatic Renewal Law: https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=BPC§ionNum=17600
- Eighth Circuit – Custom Communications, Inc. v. FTC (July 8, 2025): https://www.lw.com/en/insights/eighth-circuit-vacates-ftc-click-to-cancel-rule-days-before-compliance-deadline
- Gibson Dunn – FTC Restarts Negative Option Rulemaking (January 2026 ANPRM): https://www.gibsondunn.com/ftc-restarts-negative-option-rulemaking-after-eighth-circuit-vacatur-enforcement-under-rosca-continues/
- New York General Business Law § 527: https://www.nysenate.gov/legislation/laws/GBS/527
- HIPAA Business Associate Agreement requirements (45 C.F.R. § 164.308): https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html
- EU AI Act – Official Text (Regulation 2024/1689): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- EU AI Act Digital Omnibus – Formal Entry into Force (July 27, 2026): https://knowledge.dlapiper.com/dlapiperknowledge/globalemploymentlatestdevelopments/2026/The-Digital-AI-Omnibus-Proposed-deferral-of-high-risk-AI-obligations-under-the-AI-Act
- WCR Legal – What AI Clauses Does Your MSA Need in 2026: https://wcr.legal/ai-msa-clauses-2026/
- GC AI – A SaaS Agreement Has up to 50 Clauses. Six Carry the Risk: https://gc.ai/blog/saas-agreement
- Prospeo – Enterprise SaaS Sales 2026 Benchmarks and Field Guide: https://prospeo.io/s/enterprise-sales-saas
- Optifai – B2B Sales Cycle Length Benchmarks, 939 Companies: https://optif.ai/learn/questions/sales-cycle-length-benchmark/
- Massachusetts 940 C.M.R. 35.00 – Automatic Renewal Regulation: https://www.mass.gov/regulations/940-CMR-3500-automatic-renewals
This article is general information, not legal advice. Laws vary by jurisdiction. Pactlio generates professional drafts for review — have a licensed attorney review anything important.
Frequently Asked Questions
What contracts does a SaaS company need?▾
A SaaS company needs, at minimum, Terms of Service, a Privacy Policy, and a Data Processing Agreement once it handles personal data on behalf of customers. Sales-led companies also need an MSA, Order Form, SLA, and NDA. The exact stack depends on go-to-market model, customer type, and annual contract value—a PLG company and an enterprise SaaS company have fundamentally different requirements.
When does a SaaS company need a Data Processing Agreement?▾
A DPA is required as soon as your platform processes personal data on behalf of a customer. GDPR Article 28 mandates a written DPA for any processor handling EU residents' data. The CCPA as amended by the CPRA and 20+ US state privacy laws impose similar requirements on SaaS service providers, making a DPA necessary for virtually any B2B SaaS company.
What uptime guarantee is standard in a SaaS SLA?▾
Commercial SaaS SLAs typically promise 99.9% uptime, allowing roughly 8.7 hours of downtime per year. Mission-critical platforms in payments, healthcare, or infrastructure often commit to 99.95% or 99.99%. The SLA must define downtime precisely, specify how it is calculated (monthly vs. annually matters), and tie service credits or termination rights to each breach tier.
Can a SaaS vendor use customer data to train its AI models?▾
Only if the contract permits it. Stanford Law CodeX and TermScout found that roughly 92% of AI contracts claim data-usage rights beyond what is strictly necessary to deliver the service. Common Paper's 2026 benchmark shows explicit AI training prohibitions in 14% of CSAs—up from under 1% in 2024. Enterprise buyers now require opt-in consent and prohibitions covering de-identified data.
What does the EU Product Liability Directive mean for SaaS companies?▾
Directive (EU) 2024/2853 takes effect December 9, 2026, and explicitly classifies SaaS as a 'product.' Providers face strict liability for harm caused by defective software, including data corruption and medically recognized psychological harm. Article 14 prohibits contractual exclusion of this liability against end users. Each substantial software update can constitute a new product placement under the Directive.
Does California's auto-renewal law apply to B2B SaaS companies?▾
California AB 2863 (effective July 1, 2025) amends Cal. Bus. & Prof. Code § 17600 et seq. and primarily targets consumer subscriptions. It can reach B2B SaaS when employees subscribe online directly. The law requires click-to-cancel, annual renewal reminders, and three years of consent records. All SaaS companies with California subscribers should audit their renewal flows for compliance.
What is the difference between Terms of Service and a SaaS subscription agreement?▾
Terms of Service are a public clickwrap contract covering acceptable use, IP ownership, and liability limits for all users. A SaaS subscription agreement is a negotiated B2B contract adding pricing, SLA commitments, data handling obligations, and customer-specific terms. Enterprise procurement teams will not accept a clickwrap ToS as a substitute for a negotiated MSA on any deal above roughly $25,000 per year.
What happens to customer data when a SaaS subscription ends?▾
The subscription agreement should specify data portability rights, export formats, and a post-termination retention window—typically 30 to 90 days. GDPR Article 28(3)(g) requires processors to delete or return all personal data after services end. For AI-enabled SaaS, the contract must separately require deletion of model weights, embeddings, or derived artifacts trained on customer data.