top of page

AI Liability Allocation in Enterprise Software Agreements: Warranties, Indemnities, and Termination Under Indian Law

Aug 26
7 min read

Introduction : AI is now increasingly becoming part of the core of enterprise software products, from generative AI agents integrated into productivity tools to automatic credit scoring within lending platforms. Unlike a traditional software bug, an AI model could act exactly as intended and still produce a wrong, biased or infringing output because it is a probabilistic technology and not a deterministic one. This presents liability issues that standard software licence templates are not designed to address. This article explores the scope, nature and operation of warranties for accuracy, explainability, security and regulatory compliance in enterprise AI agreements, the nature of indemnities for infringement, privacy breaches and harmful outputs, audit rights, the model change clause and the assistance that may be provided if the contract is terminated.  The analysis is based on Indian contract, data protection and consumer law as well as the risk tiered regime of the European Union, and is rounded off by a negotiation checklist.


Legal Provisions


The Indian Contract Act, 1872 provides the default law of indemnity in India, which can be found in sections 124 and 125 of the Act, which can be paraphrased as: a contract of indemnity shall guarantee the indemnifier against the loss of the indemnifier caused by the conduct of the indemnifier or a third party and the indemnifier shall be entitled to recover the costs and damages if the loss has been reasonably incurred. There is no specific allocation of risk in the Act for failure of the model, meaning that it is almost entirely a matter of negotiation between the parties.


Chapter VI of the Consumer Protection Act 2019, which is applicable to a product, introduces a statutory product liability action against a manufacturer, product seller and/or product service provider if harm is caused due to a defective product or deficient service, including harm caused by inadequate instructions or warnings; relevant to an AI system that cannot explain the basis for a consequential decision.


The Digital Personal Data Protection Act, 2023, on the data side, allows a data fiduciary to rely on a data processor only when a contract is in place, imposes reasonable security measures and requires notification in the event of a breach. In other words, Section 8(1) imposes a compliance obligation on the data fiduciary regardless of any specific contractual arrangement, and therefore does not enable an enterprise customer to shift the responsibility of compliance to the AI vendor, but instead only to the economic cost via indemnity.


It is not mandatory, but it is guiding as Reserve Bank of India's FREE-AI Committee Report (13 August 2025) outlines seven guiding principles and twenty-six recommendations for regulated financial entities such as a board approved AI policy and a communication to the market of a ‘tolerant supervisory’ approach to early AI errors where there are sufficient safeguards. 


The EU AI Act (Regulation 2024/1689) has established prohibitions on systems that create unacceptable risks and obligations on general-purpose AI model providers beginning in February 2025 and obligations on high-risk systems that take effect in August 2025, which was delayed to December 2027 by the Digital Omnibus on AI (Regulation 2024/1695) from 27th July 2026.


Legal Analysis


The key challenge when creating an accuracy warranty is that the typical use of an AI system contains some margin of error which no vendor can reasonably warrant away. The vendor will typically provide "commercially reasonable efforts" or a performance metric that is defined in terms of a "benchmark data set" and will transfer any residual risk to the customer unless it negotiates a specific, measurable threshold under the terms of a service credit or termination clause.


Explainability is in a related void. While there is no overall Indian legislation requiring an AI system to defend a particular output, there are expectations in the sector that this will become a requirement, as seen in frameworks like FREE-AI. A customer that installs a black-box algorithm in a framework of a regulated decision process (such as granting or refusing credit or employment) may not be able to meet the requirement of a regulator or an affected individual that the customer provide a reason for the decision, and would not have a contractual basis to require the vendor to provide a reason later.


The security warranties are linked to the statutory liability distribution in the Digital Personal Data Protection Act. In other words, even if an enterprise customer is relying on an AI vendor acting as a processor, and the AI vendor was responsible for the breach, the AI customer remains liable under Section 8(1). Then, it simply is not a drafting nicety but the customer's only realistic course of action for any vendor's violation of a security warranty with a high value indemnity.


Indemnities for infringement, privacy violations, and harmful outputs raise distinct issues a single boilerplate clause tends to blur together. Infringement exposure arises both from training data and from a specific output a user generates, and these two sources of liability can attract different legal treatment even within the same dispute, meaning indemnity language addressing only training-data provenance may leave a customer unprotected against a claim based on a specific harmful output.


Case Laws


Getty Images (US) Inc. & Ors v. Stability AI Ltd., [2025] EWHC 2863 (Ch), decided by the UK High Court on 4 November 2025, is the most instructive available authority, even as a foreign judgment with only persuasive value in India. The court rejected Getty's secondary copyright infringement claim, holding that ‘Stability AI's model’ did not constitute an infringing copy of the underlying training images, but upheld a trade mark infringement claim where the model generated outputs reproducing Getty's watermark, holding ‘Stability’ responsible as the party controlling the training data rather than the end user who supplied the prompt. The case shows that training-level and output-level infringement claims can succeed or fail independently, so an indemnity addressing only one leaves a real gap.


On the domestic law of indemnity, Gajanan Moreshwar Parelkar v. Moreshwar Madan Mantri, AIR 1942 Bom 302, remains the leading authority on an indemnity-holder's rights under Sections 124 and 125, establishing that an indemnity-holder need not wait until actual loss is suffered before calling on the indemnifier, provided the liability is certain and absolute. The case predates AI by decades and involves no AI-specific finding, but its reasoning on when an indemnity becomes enforceable remains the backbone against which any AI vendor indemnity clause is interpreted in an Indian court.


Practical Implications


Sector Impact


Regulated sectors are moving fastest on these clauses. Financial service providers whose models operate under the RBI’s FREE-AI expectations, as well as healthcare and hiring platforms, are most vulnerable to the repercussions of an AI's making a consequential decision, and therefore most likely to be able to engage in negotiating specific warranty and indemnity terms with the vendor instead of taking the vendor's standard terms. It is also possible that vendors provide a new AI capability as part of a regular update of an enterprise agreement without either party renegotiating the liability cap and scope of indemnity for the pre-AI product.


Deal Structuring and Bargaining Power


The negotiating strength is closely related to the size of the deal. Large enterprise customers are more likely to be able to negotiate an IP infringement, privacy violation and harmful-output indemnity from the vendor's general liability cap, and smaller customers are more likely to have liability capped at fees paid under a limited period of time, an amount bearing no relationship to the potential downstream cost of a regulatory penalty or third-party claim.


Audit Rights & Model Changes


Customers are more and more asking for audit access to the results of the bias testing and for security practices, and they wish to receive advance warning if a vendor has introduced new code or in any other way made a material change to the underlying system which might result in a working system acting differently without any code change for the customer. Vendors are generally reluctant to provide training data or model weights, usually on trade-secret grounds, and audit-scope disputes are often settled via third-party certification or a brief compliance report, not by providing access to the data or weights.


Termination Assistance


Termination clauses need to address who owns any model weights fine-tuned on the customer's data, a defined transition period to support migration to an alternate vendor, and certified deletion of customer data consistent with the erasure obligations in Section 8(7) of the Digital Personal Data Protection Act.


Negotiation Checklist


  • Define the accuracy metric, benchmark dataset, and measurement method rather than an undefined commercially-reasonable-efforts standard.

  • Require an explainability commitment suited to the decision context, particularly for credit, hiring, or insurance use cases.

  • Tie security warranties to verifiable safeguards and confirm a high-value indemnity for a vendor-caused data breach.

  • Separate the infringement indemnity into training-data provenance and output-level infringement.

  • Address privacy-violation indemnities specifically, including memorised or leaked personal data appearing in outputs.

  • Cover harmful, defamatory, or discriminatory outputs as a distinct indemnity head.

  • Negotiate audit rights over bias testing and compliance documentation, even where model-weight access is refused.

  • Require advance notice and a right to object before a material model change or retraining.

  • Secure carve-outs from the general liability cap for the AI-specific indemnity heads above.

  • Set out termination assistance, including data deletion certification, transition support, and ownership of fine-tuned outputs.


Conclusion


Currently, Indian law is not directly addressing AI liability, having a general contract law, consumer protection or data protection approach and the contract remains the main tool for distributing liability between an enterprise customer and the AI vendor. The EU has a more formalized system, but even its strictest requirements for high-risk systems have been postponed until December 2027, and that's just the latest example of the general inconsistency of AI liability laws. Until Indian regulators adopt an approach like the RBI's FREE-AI approach that extends beyond the financial sector, enterprise customers and counsel should consider accuracy, explainability, security, infringement, privacy and harmful outputs separately as the best protection they have to offer.


Author: Abhinav Verma in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at  Khurana & Khurana, Advocates and IP Attorney.


References (Endnotes)


  1. Indian Contract Act, No. 9 of 1872, §§ 124–125 (India).

  2. Consumer Protection Act, No. 35 of 2019, ch. VI, §§ 82–87 (India).

  3. Digital Personal Data Protection Act, No. 22 of 2023, § 8 (India).

  4. Reserve Bank of India, Report of the Committee on Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) (Aug. 13, 2025).

  5. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence, 2024 O.J. (L 1689).

  6. Digital Omnibus on Artificial Intelligence (EU), provisional agreement announced May 7, 2026, entered into force July 27, 2026.

  7. Getty Images (US) Inc. & Ors v. Stability AI Ltd., [2025] EWHC 2863 (Ch) (Eng.).

  8. Gajanan Moreshwar Parelkar v. Moreshwar Madan Mantri, AIR 1942 Bom 302 (India).


Comments


bottom of page