You have almost certainly clicked a button that said something like Got it. It sat under a short paragraph about improvements to a product you use every day, and it stood between you and whatever you were trying to finish, so you clicked it without reading the paragraph. (How few people read these things turns out to be measurable; the number comes later.)
You probably have no idea what you agreed to. The trouble is less your carelessness than a mechanism, one that has been quietly turning ordinary software agreements into artificial-intelligence agreements, often without anyone signing anything new.
What changed in August
On August 17, 2026, Atlassian — the company behind Jira and Confluence, which between them hold the project plans and internal documentation of a very large slice of the working world — began using customers' metadata and in-app data to improve its apps and AI features. The plan was public months ahead, and Atlassian's own FAQ says the change is reflected in our customer terms, with an updated customer agreement, AI terms, data processing addendum and privacy policy all taking effect that day.
The Register put it more bluntly in April: unless a customer pays for the most expensive license or the law forbids it, Atlassian will collect their data to train its AI models. And for customers whose highest active plan is Free, Standard or Premium, Atlassian's head of product communications, Arseny Tseytlin, told the outlet, metadata contribution is always on, and they are not able to opt out.
Not opt out by emailing support. Not opt out in the admin console. Not able to.
How did a change that large reach customers without a signature? Through a clause in the agreement itself. Atlassian's customer agreement lets it modify this Agreement (which includes the Policies, Product-Specific Terms and DPA) from time to time, by posting the modified portion(s) on its website, using commercially reasonable efforts to post each change thirty days before it takes effect. Customers can subscribe to email notice of those updates. By default, the contract changes by being posted.
To be fair to Atlassian, that is the careful version. Paying customers ordinarily get new terms at renewal, and when Atlassian brings a change in mid-term — to comply with the law, or to reflect new product features — a customer who objects may terminate the rest of the term for a refund, provided it says so within thirty days. That exit is the whole remedy. You can leave; you cannot say no and stay. Free accounts get less: their changes take effect during the term, per Atlassian's notice.
Careless versions are common enough that a law firm advising buyers warns such changes often arrive without a contract amendment, without updated data processing terms, and without formal notice that the nature of the platform has materially changed.
The mechanism is older than AI. The Electronic Frontier Foundation's 2005 guide to dangerous license terms reproduced a clause under which a customer's continued use of a service will be deemed to constitute your acceptance of whatever terms the company has since added. Two decades later, the same move decides whether a machine learns from your customer records.
What, then, should the contract say? Fifteen things, sorted not by importance but by who already owes you what.
Tier one: five the law already writes down
Europe's AI Act contains a joke that is easy to miss and hard to unsee. For the systems it classes as high-risk, it puts duties on the buyer — the "deployer," in the jargon — whose subject matter sits inside the vendor's building. Other duties below fall on the vendor, and they only help you if your contract makes them usable.
Start with logs. For high-risk systems, the Act requires the deployer to keep the logs the system generates — to the extent such logs are under their control, and for at least six months. Those rules take effect on December 2, 2027 (more on that date in a moment). Now reread the scoping clause. In a hosted product — almost everything you buy — the logs sit on someone else's servers under someone else's retention policy. The narrow reading is that your duty then shrinks to nothing. The better reading, I think, is that the law has just told you where control has to come from: your contract.
1. Log access, export, and retention. Ask for it in writing, and ask for it to survive termination.
2. The documentation pack. For the same high-risk systems, the Act directs deployers, where applicable, to use the information the provider must supply when they carry out a data-protection impact assessment. You cannot use what you were never sent. Make the provider's full documentation — not just the instructions for use — a contract deliverable, updated whenever the system changes.
3. Subprocessor and sub-model disclosure. If you handle Europeans' personal data, you may already hold a version of this right: where a processor has general permission to add subprocessors, European law requires it to tell you about each new one, giving the controller the opportunity to object to such changes. The AI wrinkle is that when your vendor swaps the foundation model under its product, it may be adding a new subprocessor — possibly in a new country, mid-contract. So the right may already be in your paper. The question is whether the notice reaches a person or a changelog.
4. Material-change notification. Colorado rewrote its AI law this year. The replacement, which takes effect January 1, 2027, regulates automated decision-making technology used in what it calls consequential decisions, and it obliges developers of those systems to give deployers notice of any material updates or modifications. It gives you no private right of action; enforcement belongs to the state attorney general alone. A statutory duty you cannot enforce yourself is a reason to copy it into your contract.
5. The rebranding clause. Put your own name or trademark on a vendor's high-risk AI system and the Act treats you as its provider, with every obligation that implies — without prejudice to contractual arrangements stipulating that the obligations are otherwise allocated. That carve-out appears only in the rebranding provision; the neighboring provision on making a substantial modification carries no such language. So ask for two things: a clause allocating the provider's obligations if you rebrand, and a warranty that the way you plan to use and configure the system will not amount to a substantial modification. Here the statute itself invites the negotiation.
When do these apply? The Digital Omnibus entered into force on July 27, 2026 — six days before the high-risk rules had been due to apply — and the Commission now says those rules for high-risk AI systems will apply starting December 2, 2027 (later still, August 2, 2028, for AI embedded in products). Items one, two and five fall under those rules. Treat the delay as lead time rather than relief: a three-year agreement signed this week is still running on that date, and unless someone thought to write it in, it has no mechanism for pulling the documentation forward when the duty lands.
Tier two: five somebody has already conceded in writing
For most of these, a major vendor has already published the clause — which turns please into your competitor already does this.
6. No training on your data — in the contract, not on a settings page. Both big model makers publish reassuring pages, and both lean on the same two words. OpenAI's reads: We do not train our models on your data by default. Anthropic's reads: By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models. A default is a setting, and settings change with product updates. The firmer promise sits in each company's contract. OpenAI's business terms state that OpenAI will not use Customer Content to develop or improve the Services unless the customer explicitly agrees, and Anthropic's commercial terms say it may not train models on Customer Content. Even contracts move — OpenAI may update its agreement on reasonable notice, including by posting the update on its website, and Anthropic's updates take effect thirty days after they are posted — but a contract changes through a process with a notice and a date. So when a vendor reassures you, ask which document the reassurance lives in. Buyers are starting to insist on the contract version: Common Paper, which makes free standard agreements that companies use and then edit, reports that across the deals built on its templates, Prohibiting AI Training language went from showing up in under 1% of all CSAs in 2024 to 11% in 2025 and 14% in 2026.
7. An anti-degradation lock. The most useful single sentence I found in any vendor's terms sits in OpenAI's business terms. They fold in the indemnities from OpenAI's separately published service terms as they stood on the agreement's effective date, and promise that OpenAI may not materially reduce the customer's protections under those indemnities without the customer's written agreement. The lock is narrow: it covers those particular indemnities, not the whole agreement, which OpenAI can otherwise update on notice. It is still the right shape of promise. Ask every vendor to match it.
8. The indemnity has to sit outside the liability cap. An indemnity is theater if the cap swallows it. Michael Volkov, writing about AI vendor contracts on September 17, warns that such a promise can be effectively meaningless if the same contract caps the vendor's total liability at a figure like a year's fees. Several vendors have already carved it out. AWS says its defense and payment obligations under this Section 50.10 will not be subject to any damages cap under the Agreement, for the generally available AI services it lists; Anthropic's commercial terms say their liability limits do not apply to either party's indemnification obligations; and OpenAI's business terms put the indemnities from its service terms outside the cap as well.
9. Deprecation notice and version pinning. The published floors are shorter than you might guess. Unless safety or compliance concerns require a faster timeline, OpenAI promises at least six months' notice for generally available models, while preview models may be retired with much shorter notice, such as 2 weeks. Anthropic publishes at least 60 days' notice before model retirement for publicly released models. Meanwhile the control you want already exists, as a product setting rather than a contract right: Microsoft's platform offers a NoAutoUpgrade option and states flatly that Retirement dates aren't extendable. Ask your vendor to expose pinning, to stop changing behavior under a stable model name without telling you, and to give you a window to re-test. Behavior does move. Researchers who compared the March and June 2023 versions of two widely used models found that the performance and behavior of both GPT-3.5 and GPT-4 can vary greatly over time, on the very same questions.
10. An exit clause that names what was built. When the contract promises to return "customer data," ask in writing whether that includes the embeddings, retrieval indexes, fine-tuned models and agent memory built from your material. Get your source material back in a form you can reuse, too, since some of those derived pieces may only work inside the system that made them.
Tier three: where the exposure hides
Where are you most exposed? Start with the software you have not bought yet.
11. Your pilot may be on the tier with no indemnity. Four of the AI indemnities checked for this piece are written, in different ways, for paying customers or finished products. Google's covers only services not provided to Customer free of charge. AWS's covers "generally available features" of the AI services it lists. Anthropic's covers the customer's "paid use." And OpenAI's service terms exclude beta services from any indemnification obligations. Now consider where proofs of concept live. The least protected software in your organization may be the software you are still deciding about.
12. The homework hidden inside your indemnity. Microsoft's copyright commitment for customers building on its Azure AI services comes with required mitigations, among them that the customer must have run its own evaluations for infringing output — and the report of results and mitigations must be retained by the customer and provided to Microsoft in the event of a claim. AWS's indemnity likewise applies only if you "retain and provide sufficient records" to show you qualified. The protection you think you bought has a homework requirement, and the fix sits outside the contract: decide who in your organization keeps that file (it takes one email).
13. Notice before new AI features arrive. The federal government's own acquisition memo tells agencies to consider requiring vendors to provide a notification to relevant agency stakeholders prior to the integration of new AI enhancements. Your own vendor reviews may not catch these changes. Evan Rowse, a governance specialist at Vanta, makes the point in a guide that Vanta — which calls itself an "agentic trust platform" — produced and Stacker syndicated in September (weigh it accordingly): Traditional TPRM wasn't built for vendors that can materially change their risk profile without triggering a contract clause. Third-party risk management, in other words, assumes the vendor you assessed is the vendor you have.
14. Litigation-hold notice, and knowing which tier you are on. In 2025, the court hearing The New York Times's copyright case against OpenAI ordered the company to preserve and segregate all output log data that would otherwise be deleted on a going forward basis. A deletion policy, overridden by a lawsuit its business customers were not party to. Who was spared? Trade reporting on the order records that ChatGPT Enterprise, ChatGPT Edu, and business customers with Zero Data Retention contracts remain excluded from the preservation requirements. The contract tier decided it, not the privacy policy. The court ended the order going forward that fall, though logs already preserved stayed preserved, and I would not treat a carve-out from one order as permanent immunity. Where the policy page and the contract disagree, the contract is what you have.
15. A kill switch with somewhere to land. A right to switch off an AI feature is worth little if switching it off breaks the product. Published model clauses cover part of this, though they point it at you: an optional clause in Bonterms' AI Standard Clauses bars the customer from using AI features for decisions with legal or similarly significant effects on people unless it does so with adequate human review and in compliance with Laws. The vendor's half is the one to ask for by name: an obligation to keep serving you a working non-AI fallback while the switch is off.
So that settles it — read your contracts. Right?
No — and the objection deserves a serious hearing, because for many readers it is simply correct.
You have no leverage. If you run a twenty-person nonprofit, you are not redlining your cloud provider's paper. Your proposed amendment is unlikely to reach anyone with authority to accept it, and the honest answer to "how do I negotiate this" is often: you don't.
It gets worse. One legislature has already said that some risk cannot be moved by contract at all. Colorado's new statute renders void any contract clause purporting to indemnify a party for its own discriminatory use of the technology in a consequential decision. You can push a great deal of risk around with paper — not that. And enforcement of Colorado's law is currently suspended while a constitutional challenge proceeds, which tells you how unsettled all of this remains.
Two things survive the objection.
The first is that you are in better company than you think. When the Electronic Privacy Information Center went looking in 2023, it counted 621 state contracts with vendors providing AI tools. It also found procurement officials in at least forty-two states signing on to cooperative purchasing agreements — deals negotiated once, by a lead state, and then used by others to bring AI products into state agencies without competitive bids, transparency, or individualized contract negotiations. State governments with procurement staff and lawyers of their own are using AI terms they never individually negotiated, much as you are.
The second is that negotiate was never the only move. Choosing is a move. Knowing which tier you are on is a move. Items eleven and fourteen need no counterparty's consent at all.
Meanwhile, a European town council has better paper than an American hospital
What does a buyer get when a government decides to help?
If you are a public buyer in the European Union, you can download a full set of model contractual clauses for procuring AI — twenty-one articles and eight annexes, designed to be attached to your main contract, free, in twenty-four languages. Remember the logging problem from tier one, the duty whose subject matter lives in the vendor's building? The accompanying commentary contemplates letting the buying organization itself access the logs in real time, if necessary. That is the problem solved, in writing, for nothing. The high-risk version also gives the buyer an audit right to check the supplier's compliance.
Two caveats. Using them is voluntary — as a privacy lawyer writing for the International Association of Privacy Professionals points out, organizations are not legally required to use the MCC-AI — and the commentary, which labels itself a "Dynamic Working Document," predates the deadlines Europe moved in July.
What does the American commercial buyer have? The closest equivalent is that federal acquisition memo from item thirteen, and it is genuinely good. It requires contract terms that reduce the risk of switching vendors becoming cost-prohibitive, and — the line most worth stealing — it says contracts "must not prohibit agencies from internally disclosing how the vendor conducts testing or the results of testing." In plain terms, the vendor cannot stop you from sharing its test results inside your own organization.
It binds federal agencies. Not you.
To be fair — and this is my argument, reasoned from the record rather than found in it — America is not quite empty-handed. Published commercial clauses like Bonterms' exist. What is missing is an institution standing behind them, the thing that turns a template into a norm a vendor expects to be asked for.
Now imagine the version where you are not the one clicking
Push this forward a few years — no further than the term of a long software agreement.
The software stops waiting for you to click. It transacts. The plumbing already exists: in 2025, Google announced a payments protocol for autonomous agents built on tamper-proof, cryptographically-signed digital contracts that stand in for a human pressing buy. You sign a mandate up front, setting price limits, timing and other conditions, and your agent does the rest.
Now put that inside the paperwork you already have. Clifford Chance, a global law firm, warned this February that many of these systems are still deployed under legacy technology contracts written for passive, predictable software firmly under human control. An indemnity drafted for a tool that answers questions was not drafted for one that renews a subscription, accepts updated terms on your behalf (at 3 a.m., naturally), and thereby consents to model training on your customer database.
So why not let an AI read the contracts for you? Better still, let it negotiate and draft them. Will Rinehart, a senior fellow at the American Enterprise Institute, argues that telling your agent to do exactly that would be a textbook UPL violation: unauthorized practice of law, because a machine would be drafting legal documents and acting on your behalf without a license. Sit with the shape of that. The people least able to afford counsel may also be the people least permitted to automate their way around not having any.
Where the think tanks agree
Groups that want very different remedies turn out to agree on the facts.
The Information Technology and Innovation Foundation, an innovation-policy think tank writing about Canadian government cloud policy, puts the case for portability plainly: Exit options matter because providers change terms, products are discontinued, and systems become harder to untangle the longer they run. Its premise is this piece's premise: providers change terms. Its remedies run through purchasing power — making safeguards "standard, non-negotiable conditions of service" — with legal tools such as a blocking statute behind them.
The EFF, a digital-rights group, has long argued that terms of service let companies dictate their legal relationship with users through private contracts rather than rely on the law as written, on terms users never get a chance to negotiate. And a 2024 comment to federal budget officials from the Electronic Privacy Information Center, the Brennan Center for Justice and other civil-society groups made the operational version of the same point: few vendors provide the information agencies need to conduct meaningful AI testing.
Same fact, different remedies: exit on one side, consent on the other. That is much harder to dismiss as partisan than either argument alone.
Beneath both sits a piece of research that should retire a comfortable assumption. The informed minority hypothesis holds that a few careful readers discipline sellers on everyone else's behalf. Researchers tested it by tracking real browsing behavior and found that only one or two of every 1,000 retail software shoppers access the license agreement, and that most of those who do read only a small part of it. The study watched consumer software shoppers, and businesses may behave differently; among those shoppers, though, the careful minority the theory needs barely exists.
Nor does the usual fix rescue it. Omri Ben-Shahar and Carl E. Schneider, law professors whose book examines the failure of mandated disclosure, concluded that disclosure does not work; it cannot be fixed. That is an uncomfortable finding for a piece that keeps telling you to read things, and I would rather hand it to you than hide it. The answer, then, is fewer and better-chosen defaults rather than more reading.
What does this mean for you?
Concretely, this week:
Find out which tier you are on. Not which product — which tier. Free, trial, preview and beta offerings often carry no indemnity and weaker notice promises. If something has quietly become essential, move it to a paid tier or stop relying on it.
Name the owner of the evidence file. If your indemnity requires you to have tested and kept the report, someone has to own that. Decide who.
Search your agreements for improvement and development. Contract language permitting vendors to use customer data for "improvement" and "development" of services has been a routine negotiating point in software deals, and those are the clauses to read closely for permission to train.
Ask one question before every renewal: has any AI functionality been added to this product since we signed, and does any of our data reach a model we have not been told about? Get the answer in writing. A written answer is something you can rely on; a sales call is not.
Ask for three things even when you have no leverage. Notice before new AI features. No training on your data, in the contract rather than on a settings page. Your logs on request, surviving termination. The worst outcome is that someone says no, and a no tells you something about the vendor.
Check where the notices go. Subprocessor notices, terms updates and deprecation notices go wherever your account's contact address points. Make sure that is a person who will act on them — and if your vendor offers email notice of contract updates, subscribe to it.
If you are the one who clicks the button — and in a small organization you are — make it a rule that no one accepts updated terms on a product holding customer data without a second person seeing them. It costs nothing and turns a reflex into a decision.
The lesson, as I see it
The contract is the last place these decisions are visible before they become invisible.
Public debate pours enormous energy into whether AI should be regulated and very little into the small private acts of lawmaking that happen in admin consoles and renewal emails, each one perfectly legal and many of them unread. Two scholars writing about public procurement described decisions made with no public participation, no reasoned deliberation, and no factual record. They meant government purchasing. I think the description fits your renewal notice just as well.
The button you clicked was probably harmless; most are. The trouble is the layer of consequential decisions now resting on that gesture — a few seconds, no record, no sign that anyone weighed it.
You will not read them all; if those software shoppers are any guide, almost no one does. So my vote is narrower and more achievable: pick the three or four agreements that hold something you would be sorry to lose, and treat them as documents rather than obstacles. You will not win every clause. The alternative is learning what you agreed to after it has already taken effect.
One product update and an unopened notice are all it takes to turn a filing cabinet into a training set. The HAIA Foundation would rather that were a decision someone made on purpose — so forward this to whoever renews your software, and subscribe before the next terms update lands.





