The AI Indemnity Arms Race Is Distracting Us From The Bigger Story AI vendors and enterprise customers are negotiating AI risk directly into commercial contracts rather than waiting for insurance products or legislation, according to an Above the Law analysis of the trend. The piece argues that indemnification announcements dominate headlines while the more consequential shift is occurring in the hundreds of pages of commercial terms covering data use restrictions, model training limits, output ownership, confidentiality, transparency commitments, acceptable use provisions, audit rights, governance obligations, human oversight, and liability clauses. The author contends these provisions are quietly becoming a primary way AI risk is governed before lawmakers or insurers settle on a common approach. Every few weeks another AI company announces expanded indemnification. One vendor broadens its copyright protections, another updates its enterprise terms, and a third promises to stand behind customers facing intellectual property claims. The headlines practically write themselves, and for a day or two everyone debates which company now offers the strongest protections. But I think those headlines are causing us to miss the far more interesting story. From ‘Associate’ To ‘Doppelganger’: The Evolution Of The Legal AI Persona https://abovethelaw.com/2026/09/from-associate-to-doppelganger-the-evolution-of-the-legal-ai-persona/ Confronting Biglaw’s ‘snake eating its own tail’ problem. In my experience, indemnification has become the easiest part of the AI contract conversation. The real shift is happening elsewhere, in the hundreds of pages of commercial terms that determine how AI can actually be deployed inside an organization. Those provisions are quietly becoming one of the primary ways AI risk is governed, long before lawmakers or insurers have settled on a common approach. Contracts Are Filling The Governance Gap For years, we assumed that emerging technology risks would eventually migrate into insurance products. Cyber risk followed that path. Privacy risk developed its own insurance market. It was reasonable to assume artificial intelligence would do the same. Instead, AI is taking a different route. Willkie Elevates Legal Work with Lexis+ with Protégé https://abovethelaw.com/2026/09/willkie-elevates-legal-work-with-lexis-with-protege/ Willkie AI and Innovation leader Todd Friedlich spoke to LexisNexis about firm’s thoughtful approach to legal AI Rather than waiting for insurance products to mature or regulators to answer every difficult question, vendors and enterprise customers are negotiating those risks directly into commercial agreements. Every contract becomes an opportunity to define responsibilities, allocate liability, and establish operational guardrails that didn’t exist a few years ago. That shift matters because contracts evolve much faster than legislation. Legislatures debate. Agencies issue guidance. Courts eventually interpret the rules. Commercial lawyers, meanwhile, negotiate practical solutions every day because business cannot simply wait for the law to catch up. The Questions Have Changed A few years ago, software agreements rarely asked whether customer data could be used to improve future AI models. They did not spend pages addressing ownership of AI-generated content or explaining how prompts and outputs should be treated for confidentiality purposes. Human oversight requirements, acceptable AI uses, transparency commitments, and model disclosures were simply not part of the conversation. Today, those issues routinely find their way into enterprise agreements. Just as important, companies are negotiating who bears responsibility when an AI system hallucinates, produces biased results, infringes someone else’s intellectual property, or creates regulatory exposure. Those discussions extend well beyond indemnification. They touch governance, operational processes, internal controls, and risk management in ways that traditional software contracts rarely did. What strikes me is that these are no longer product questions. They are contract questions, and that changes the role of legal departments in a meaningful way. A Pattern Is Starting To Emerge One of the most interesting developments is that AI agreements are beginning to look more alike. The wording varies from vendor to vendor, and no two templates are identical. Even so, the same themes continue to appear across negotiations. Data use restrictions, limitations on model training, ownership of outputs, confidentiality protections, transparency commitments, acceptable use provisions, audit rights, governance obligations, human oversight, and carefully negotiated liability clauses are becoming familiar territory. That doesn’t mean the market has reached consensus. Far from it. Companies continue to negotiate these provisions aggressively because the business implications are significant. What it does suggest is that the market is slowly building its own framework for responsible AI adoption. It is happening organically, through thousands of negotiations taking place between vendors and customers every day. Nobody announced a standard, yet one is beginning to emerge. Why This Matters For Legal Departments I think this evolution changes how lawyers should think about AI contracts. Reviewing an AI agreement is no longer an exercise in checking boilerplate or negotiating liability caps. Lawyers are increasingly evaluating governance frameworks that affect how an organization can use AI after the contract is signed. The legal review has become intertwined with operational reality. That also means legal teams cannot evaluate these agreements in isolation. Product teams, security professionals, privacy counsel, procurement, compliance, and business stakeholders all have legitimate interests in provisions that once might have seemed like standard legal language. A sentence about model training or data retention can have significant operational consequences months after implementation. I’ve also noticed that these negotiations increasingly determine whether a transaction moves forward at all. Procurement teams are asking harder questions. Security reviews have become more sophisticated. Vendors are using contractual commitments as competitive differentiators because customers want assurances that extend well beyond marketing claims. In many organizations, the contract itself has become the operating manual for responsible AI adoption. The Bigger Story The conversation around AI often focuses on regulation. Every new legislative proposal generates headlines about what governments might require in the future. Those discussions are important, and eventually many of them will reshape the legal landscape. But something equally important is happening right now. Commercial contracts are already defining practical rules for AI deployment. They determine what data can be used, how models may evolve, who bears responsibility when something goes wrong, and what safeguards must exist before technology reaches employees or customers. Those negotiated provisions often become the rules businesses actually follow, regardless of whether a regulator has spoken on the issue. That is why I think the recent wave of AI indemnification announcements deserves less attention than it receives. Indemnities matter, but they represent only one clause in a much larger governance framework. Focusing exclusively on copyright protection is a little like evaluating a house based solely on the front door. You miss everything that makes the structure work. Contracts have always been about allocating commercial risk. What’s changing is that they are also becoming one of the primary mechanisms for governing artificial intelligence itself. The next chapter of AI governance may not be written first by legislators, regulators, or insurers. It may be written by commercial lawyers sitting across negotiating tables, one redline at a time. I suspect that years from now, we’ll look back and realize that many of the practical rules governing enterprise AI didn’t begin in a statute or a courtroom. They began in a contract. Olga V. Mack is the CEO of TermScout, where she builds legal systems that make contracts faster to understand, easier to operate, and more trustworthy in real business conditions. Her work focuses on how legal rules allocate power, manage risk, and shape decisions under uncertainty. A serial CEO and former General Counsel, Olga previously led a legal technology company through acquisition by LexisNexis. She teaches at Berkeley Law and is a Fellow at CodeX, the Stanford Center for Legal Informatics. She has authored several books on legal innovation and technology, delivered six TEDx talks, and her insights regularly appear in Forbes, Bloomberg Law, VentureBeat, TechCrunch, and Above the Law. Her work treats law as essential infrastructure, designed for how organizations actually operate.