SaaS MSA for AI Startups: Key Contract Terms
Review an AI startup's SaaS MSA for customer data, training rights, output ownership, indemnity, liability limits and exit terms before signing.
What it is
A SaaS master services agreement sets the relationship between a software provider and its customer. For an AI product, it should work with the order form, data processing addendum and actual model-provider terms to address inputs, outputs, training, permitted uses and responsibility when something goes wrong.
The points below are negotiation questions, not a universal market standard or a ready-to-sign contract. Terms depend on the product, customer, data, bargaining position and applicable law.
Parties
-
VendorContracting party. Provides the AI or SaaS service.
-
CustomerContracting party. Uses the service on the agreed terms.
-
Model providers and hostingDependencies in the stack, not automatically parties to this agreement. Their own terms may control training, retention and permitted uses.
-
End usersOther participants who access the service through the customer. Whether they sign anything depends on the deal structure.
Clause by clause
12 clauses · what it does, what to negotiate, what to flag.
Scope and order forms
Identifies the service actually being bought and where deal terms live.
Describe the service, environments, users and affiliates, and state which document controls if the MSA, order form and policies conflict.
A scope that does not match the product demonstrated, or an order form that silently changes MSA terms without saying so.
Customer data
Defines what the customer's data covers.
Say whether inputs, prompts, outputs, uploaded files, configuration and telemetry are treated as customer data, and how each may be used.
Categories left undefined, so prompts or outputs fall outside the protections the customer thinks it has.
Output rights
Allocates whatever rights exist in what the system generates.
Allocate use rights between the parties and state any restrictions. No contract can create copyright in material that is not copyrightable.
A promise that every generated output carries exclusive copyright without assessing human authorship and third-party rights.
Training and improvement
Decides whether customer material can improve the service or a model.
State whether training is off by default or opt-in, how de-identification or aggregation works, and whether model-provider terms are flowed down.
Broad service-improvement language that leaves training permissions unclear or inconsistent with the provider terms behind the product.
IP indemnity
Allocates third-party intellectual property claims.
Identify what is covered, what is excluded, who controls defense and settlement, and how the indemnity interacts with the liability cap.
An indemnity whose exclusions remove the risks that actually apply to the product in use.
Output errors and reliance
Addresses inaccurate, incomplete or unsuitable output.
Describe review and verification obligations, human oversight where relevant, documentation commitments and the remedy for defects.
A guarantee of accurate output, or reliance obligations that do not match how the customer plans to use the product.
Permitted and prohibited uses
Sets the boundaries of the customer's use.
List prohibited uses specifically, connect them to enforcement steps, and confirm the customer's real use case is permitted.
Open-ended restrictions decided at the vendor's discretion, or restrictions that conflict with the customer's disclosed use.
Model providers and other vendors
Handles the rest of the stack behind the service.
Identify material providers, change-notice rights and flow-down obligations. A model provider is not automatically a party to this agreement.
MSA promises that cannot be met because the underlying provider terms say something different.
Privacy and security
Covers personal data and security commitments.
Attach a data processing addendum where applicable, define roles, set incident-notice timing against the law that applies, and describe security controls and audits. There is no universal 72-hour notice rule between commercial parties.
Obligations the security program cannot perform, or missing terms required for the actual processing roles and applicable law.
Liability
Allocates financial exposure.
Negotiate the cap, any separate caps, exclusions and carve-outs against the deal's actual risk. There is no universal twelve-month-fee cap or standard uncapped carve-out.
A cap or exclusion set by template that leaves the priced risk with the party least able to control it.
Renewal and termination
Sets how the relationship continues or ends.
Define the term, renewal mechanics, notice periods, cure rights, suspension rights and the fee consequences of ending early.
Renewal or notice mechanics nobody has calendared, or termination rights that are unusable in practice.
Data return and deletion
Covers what happens to the data at exit.
Define export formats, the export window, deletion timing, backup handling and any retention required by law.
Best-efforts deletion language with no timeline, or export rights that expire before a migration can finish.
How to negotiate it
The order to work through these clauses for max leverage.
-
1Map the actual service and data
Write down what the product does, who uses it, what data goes in, what comes out and which of it is sensitive or regulated.
-
2Read the complete contract stack
Review the MSA, order form, DPA, published policies and the underlying model-provider terms together, and specify which document controls on conflict.
-
3Resolve data and output permissions
Settle how inputs, prompts and outputs may be used, whether any training is permitted and what rights each side has in the output.
-
4Price the risk allocation
Look at indemnities, caps, exclusions, remedies, fees, insurance and what happens if the service fails, and treat them as one commercial package.
-
5Confirm delivery and exit
Check security, support, incident handling, renewal, export and deletion with the team that will actually perform them.
-
6Record decisions before signing
Close open issues in the document, confirm signatories and confirm which version is the approved one.
Red flag checklist
- •The written scope does not match the service and data you actually reviewed.
- •Documents in the stack conflict and no order of precedence is stated.
- •Data, training and output permissions are left unclear.
- •Indemnities, caps and exclusions do not match where the risk sits.
- •Security, incident and support commitments were never checked with the performing team.
- •Open issues are left to a side email instead of the signed version.
Frequently asked
Does an AI startup need a different MSA?+
It needs an MSA that fits its service. AI features often require express treatment of prompts, outputs, training, model providers and reliance on results. The rest of the contract still needs to match the business.
Who owns AI outputs?+
A contract can allocate the parties' rights, but it cannot create copyright where the law provides none. The U.S. Copyright Office distinguishes human-authored expression from material generated entirely by AI. Review the human contribution, third-party rights and provider terms.
Can a vendor train on customer prompts?+
The answer depends on the contract, applicable law and actual service settings. Address training and improvement explicitly, including the role of model providers; do not infer a permission or prohibition from a generic confidentiality clause.
What liability cap should a SaaS MSA use?+
There is no single cap that fits every deal. Evaluate fees, likely loss, insurance, available remedies and the duties each party controls, then specify any higher caps or exclusions clearly.
Related deep-dives
Sources
Updated September 16, 2026. General information about contract terms—not legal advice on your specific deal.