Skip to content
AI & legal work

AI copyright indemnity: the conditions that decide whether the vendor pays

Three of the largest model vendors publish a promise to defend paying customers against copyright claims arising from what their models produce. The promises are real and, for the two that quantify it, they sit outside the liability cap. They are also conditional, and the conditions are not the ones people expect: not fair-use arguments or the provenance of training data, but a metaprompt, two optional filters left switched on, a retained test report, and an output you did not touch afterwards.

9 min readPublished How we write these

The short version

  • Every vendor copyright promise is conditional. Microsoft's Customer Copyright Commitment applies only if the customer has not disabled the safety systems and has implemented every mitigation on Microsoft's published list.
  • On Azure OpenAI those mitigations include an anti-infringement metaprompt, protected-material detection in filter mode, Prompt Shield for jailbreak attacks in filter mode, and a retained testing report producible on a claim.
  • Four exclusions recur across Microsoft, OpenAI and Anthropic: output you modified or combined, use you knew or should have known infringes, inputs you had no rights to, and trademark use in trade.
  • The promise runs from the vendor to its customer. If your client sues you over a deliverable, that claim is decided by your own contract — and a deliverable is usually a modified, combined output.

The question worth asking about an AI vendor's copyright indemnity is not whether it exists. It exists at all three of the vendors below, and at two of them it sits outside the liability cap, which makes it one of the few genuinely unlimited obligations in the contract. The question is what you have to have been doing at the moment the output was generated, because that is what these clauses turn on.

What the three vendors actually promise

The shapes differ more than the marketing suggests. Microsoft does not write a standalone insurance policy at all: the Customer Copyright Commitment works by extending the intellectual-property defence obligation that already exists in your volume licensing agreement, and by switching off the reverse obligation you owe Microsoft. OpenAI and Anthropic write the promise directly into the terms you accept.

VendorWhat the promise coversAgainst the liability cap
MicrosoftMicrosoft's duty to defend under your volume licensing agreement is extended to claims based on your "use or distribution of Output Content" of a Covered Product, and your own duty to defend Microsoft is switched off — but only "if all the following additional conditions are met".Whatever the underlying volume licensing agreement provides. There is no commitment standing on its own without one.
OpenAIFor API customers and for ChatGPT Enterprise, Edu, Healthcare and Business, the indemnity "include[s] any third party claim that Customer's use or distribution of Output infringes a third party's intellectual property right".Services Agreement 13.1 states the Service-Specific Terms Indemnity "is not subject to any liability cap", and that OpenAI may not materially reduce it without written agreement.
AnthropicA claim that "Customer's paid use of the Services ... or Outputs generated through such authorized use violates any third-party intellectual property right" (Commercial Terms K.1). Note the words "paid use".Section L.3.b: the limits on liability "do not apply to either party's obligations under Section K (Indemnification)".
Three drafting styles, one structure: a defence duty triggered by an allegation, then a list of ways out of it. On the general mechanics of defend-versus-indemnify, see indemnification clauses explained.

Microsoft's commitment is forfeited by a configuration setting

The Microsoft Product Terms attach five conditions to the commitment, and they are cumulative — the text says the defence applies "if all the following additional conditions are met". The first and the fifth are the unusual ones, because they are about how you configured the product rather than about what you did with the output.

The five conditions on the Customer Copyright Commitment

Customer Copyright Commitment, Microsoft Product Terms

All five must hold. Conditions two to four appear in some form at every vendor; the first and fifth are Microsoft's own, and are the ones a deployment can fail without anybody noticing.

That fifth condition is a live document rather than a fixed list. Microsoft publishes the required mitigations separately, each row with its own effective date, and gives customers six months from publication to implement a new one before coverage depends on it. New services, features and models can arrive with requirements effective immediately. The page also states the practical consequence plainly: a customer tendering a claim "will be required to demonstrate compliance with all relevant requirements".

The filters the commitment requires are optional features

This is the part that turns a contractual footnote into a real exposure. Azure's protected-material and jailbreak classifiers are not part of the default safety baseline; Microsoft's own content-filtering documentation describes them as "other optional classification models" whose use "is optional". The commitment requires several of them to be on, and to be on in a specific mode.

What Azure OpenAI coverage requires you to have configured

  • A metaprompt in your offering directing the model to prevent copyright infringement in its output — Microsoft points at its "Protected Material – Text" sample system message.
  • For open text generation: the protected material text model on in filter mode. Annotate-only runs the classifier and returns annotations without blocking anything, and does not satisfy the requirement.
  • For code generation: the protected material code model on in annotate or filter mode — and if you choose annotate, you must comply with any licence cited for the output.
  • For both: Prompt Shield for jailbreak attacks configured on in filter mode.
  • A retained report of guided red teaming or systematic measurement designed to detect output of third-party content, with any significant ongoing reproduction addressed, producible to Microsoft when a claim is tendered.

None of this applies uniformly across the Microsoft estate. The required-mitigations page limits itself to Azure OpenAI and other covered products with configurable metaprompts or safety systems; products whose safety systems are fixed carry no equivalent homework, and as of 3 April 2026 GitHub offerings have no additional required mitigations at all. Which product you bought decides how much of the compliance burden is yours.

Fix the contract you can actually change

You cannot negotiate a hyperscaler's published terms. You can decide what you warrant to your own clients about the work you deliver, and where the risk sits when a deliverable is challenged.

Open

The exclusions repeat across vendors, and that is where claims land

Read the three documents side by side and the same four carve-outs appear at all of them. That convergence is informative: it is the industry describing, in unison, the fact patterns it will not stand behind.

Shared exclusions, and what each vendor adds

Microsoft adds

  • Any mitigation on the published list not implemented
  • No retained testing and evaluation report
  • Output flagged after the fact by the async filter

All three exclude

  • Output you modified, or combined with other material
  • Use you knew or should have known infringes
  • Inputs you had no rights to supply
  • Trademark claims from use of output in trade

OpenAI and Anthropic add

  • A patented invention practised in an output (Anthropic K.3(e))
  • Beta, preview and early-access services (OpenAI)
  • Output from a third-party offering (OpenAI)
The middle column is where most real claims sit. Anthropic reaches disabled safety features only through its general carve-out for breach of the agreement and wilful misconduct, rather than naming filters — Microsoft and OpenAI name them.

Two of the shared exclusions are far broader in practice than they look on the page. "Modified, transformed, or used in combination with products or services not provided by" the vendor, in OpenAI's wording, describes nearly every professional use: nobody ships raw model output. Anthropic's K.3(a) and K.3(b) say the same thing in two clauses. The exclusion is not a trap so much as an honest statement of what a defence obligation can cover — the vendor can stand behind what its model produced, not behind what you built out of it.

The "knew or should have known" exclusion does the other half of the work. It is the clause that answers the prompt engineered toward a named artist, character or article. A prompt naming the work you want to look like is evidence you should have known, and it is preserved in your logs.

The indemnity does not follow the output to your client

This is the gap the vendor comparison pieces rarely reach, and it is the one that matters to anyone delivering work for money. The promise runs to the customer. Anthropic's extends to "Customer and its personnel, successors, and assigns"; Microsoft's operates inside the customer's own volume licensing agreement. Your client is none of those things.

Two claims, and only one of them is the vendor's problem

A third party alleges your AI-assisted deliverable infringes

The claim against you

It runs on your client contract — your IP warranty, your originality representation, your indemnity. Nothing in the vendor's terms gives your client a right against the vendor, and nothing in them changes what you promised.

Your claim back to the vendor

A separate tender, on which you must show the filters were on, the mitigations were in place, and the output was used as generated. A finished deliverable is usually a modification or a combination.

The first branch is settled entirely by your own contract. The second is where the conditions above are tested — after the fact, with your deployment configuration and your logs as the evidence.

The practical drafting consequence: do not price the vendor's promise into what you are willing to warrant downstream. If you give a client an unqualified warranty that the deliverable is original and non-infringing, backed by an uncapped indemnity, you have taken on a risk that the vendor has already excluded on at least two grounds. That is the connection point with AI clauses in client contracts — the clause that allocates AI risk on your side of the chain is the only one you control. A SaaS agreement you sign as a customer and a service agreement you sign as a supplier are two different positions in the same chain, and the second is where the exposure sits.

Owning the output and being defended over it are different promises

All three vendors also assign the output. Anthropic "assigns to Customer its right, title and interest (if any) in and to Outputs"; OpenAI's Services Agreement 4.1 says the customer "owns all Output" and assigns OpenAI's interest "if any"; Microsoft states that output content is customer data and that "Microsoft does not own Customer's Output Content".

Note the two words both drafters chose: "if any". An assignment transfers what the assignor has, which where the output is purely machine-generated may be nothing at all — the subject of who owns AI-generated content. Ownership language tells you the vendor will not claim your file. It is silent on whether anyone else can, and that second question is the one the indemnity is about. Reading the assignment clause as reassurance about infringement risk is the most common misreading of these documents.

What to check before you rely on any of this

  • Your tier. Anthropic's commitment covers "paid use" under the commercial terms; OpenAI's runs to API and named business tiers, and expressly not to beta services. Consumer and free accounts are a different document.
  • Your configuration, in writing. For Azure, screenshot or export the content-filter configuration attached to the deployment, with dates. Coverage is proved by what was running when the output was generated, not by what is running when the claim arrives.
  • Your evaluation report. Microsoft requires one to be retained and produced. A deployment that has never been red-teamed for third-party content reproduction fails a condition it has probably never read.
  • Your logs. The "should have known" exclusion is decided on prompts. Retaining them cuts both ways, and a policy that never mentions them is not a neutral choice.
  • Your own contract. The IP assignment and warranty language you give clients should not assume a defence you may not be able to tender.

The most useful thing about these documents is not the promise at the top. It is the list underneath it, which is the clearest published account anywhere of the fact patterns the model vendors believe are risky: outputs generated with the protected-material classifier off, prompts steered at a specific work, inputs the customer had no right to, and marks used in trade. That list is a better guide to where infringement exposure actually lives than the indemnity is a shield against it — and unlike the indemnity, it costs nothing to act on.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Does OpenAI indemnify customers for copyright claims about output?

Yes, for API customers and for ChatGPT Enterprise, Edu, Healthcare and Business. The Service Terms extend OpenAI's indemnity to claims that a customer's use or distribution of output infringes a third party's intellectual property right, and the Services Agreement states that indemnity is not subject to any liability cap. Six exclusions apply, including output that was modified or combined, and beta services.

Do I lose Microsoft's Customer Copyright Commitment if I turn a filter off?

Yes. The Product Terms condition the commitment on the customer not having disabled, evaded, disrupted or interfered with the content filters, metaprompt restrictions or other safety systems while producing the output. For Azure OpenAI there is a further condition: every mitigation on Microsoft's published required-mitigations page must have been implemented in the offering that generated the output.

Does the vendor's indemnity protect my client if I hand them AI-assisted work?

No. The obligation runs from the vendor to its customer — Anthropic's extends to the customer and its personnel, successors and assigns, and Microsoft's operates inside the customer's own licensing agreement. A client's claim against you is decided by your contract with them. You would have to tender separately to the vendor, and a finished deliverable is usually a modified or combined output.

Are these AI indemnities capped at the fees I have paid?

At two of the three, no. Anthropic's terms state that the limits on liability do not apply to either party's indemnification obligations, and OpenAI's Services Agreement says the service-specific indemnity is not subject to any liability cap. Microsoft's commitment operates through the volume licensing agreement it sits under, so the position depends on that agreement.

What exclusions appear in every vendor's AI copyright indemnity?

Four recur at Microsoft, OpenAI and Anthropic: output the customer modified or combined with other material, use the customer knew or should have known infringes, inputs the customer had no rights to supply, and trademark claims arising from use of the output in trade. Anthropic separately excludes practising a patented invention contained in an output.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week