Guides

    Who indemnifies what in an AI contract

    Indemnity splits two ways: you cover tool terms-of-service breaches, the client covers distribution and labelling. A two-way split to drop into an agreement.

    Versely Team9 min read

    Indemnity is where AI production contracts stall longest, usually because both sides argue it as a single blob of risk to be pushed onto the other party. It is not a blob. It splits along a clean line, and once you draw the line the negotiation gets short.

    The split that practitioner drafting converges on: the agency indemnifies for using AI tools in breach of those tools' terms of service, and the client indemnifies for distributing without required AI disclosure labels, stripping provenance metadata, or using deliverables for undisclosed purposes. Two lists, two owners.

    The organising principle is control. Each party indemnifies the risks only it can see and prevent. You know which model produced which frame and under which licence. The client knows which markets the asset ships to, which platform it uploads through, and whether their media team re-encodes it on the way. Neither can inspect the other's half, which is why the indemnity follows the visibility.

    Not legal advice. The drafting below is a starting point for counsel.

    Your side: everything upstream of delivery

    The supplier half is about production inputs. It is broader than most people's first draft, and worth enumerating because vague indemnities get read expansively later.

    Tool terms of service, on the tier you actually hold. Commercial-use rights are frequently tier-dependent, and using output commercially from a plan that does not permit it is a breach you caused and nobody else could have seen. This is the core of the supplier obligation and it is fair.

    Model licences for anything open-weight. These vary sharply and several of them restrict commercial deployment, territory, or downstream distribution in ways that a casual read misses. If your pipeline includes self-hosted weights, what you can actually ship depends on the specific licence, and the client has no way to audit it.

    Third-party inputs you introduced. Stock footage, fonts, reference images, music, brand assets you sourced rather than received. Same logic: your sourcing decision, your exposure.

    Likeness and voice consent for anyone you cast or cloned. Written, scoped to the actual uses, retained with the asset.

    Non-infringement, to your knowledge. Note the qualifier. A knowledge-qualified non-infringement indemnity is defensible. An absolute one on generative output is a promise about somebody else's training corpus, which you cannot inspect.

    What should not be on your side, and what clients will try to put there: the copyright status of AI-generated material as a matter of law. If your agreement already carves the originality warranty out because you cannot assign rights that may not exist, an indemnity covering the same thing quietly puts it back. Keep the two clauses consistent or the carve-out is decorative.

    Their side: everything downstream of delivery

    The client half is about publication, and it has become considerably more concrete since Article 50 of the EU AI Act became binding on 2 August 2026. The deployer duty in that regime falls on whoever publishes realistic synthetic content, and the test turns on whether the content would falsely appear authentic to its audience rather than on whether anyone intended to deceive. That is a duty you cannot discharge for them, because you do not control the upload.

    Four items belong to the client:

    Labelling and disclosure at the point of publication. Platform-level AI labels, ad-network disclosures, endorsement and partnership labels where they stack. Whether an AI content label is required is a function of the destination and the audience, and a single asset going to five destinations can need five different treatments. That is a cross-platform labelling problem sitting inside the client's publishing workflow, not yours.

    Provenance metadata preservation. More on this below, because it is the item most often missed.

    Use beyond the disclosed purpose. The brief said organic social; the asset ends up on out-of-home in a market with different rules. Distribution scope is the client's decision and the associated compliance risk should follow it.

    Claims and substantiation in the approved script. If the client supplied or signed off the product claims, the claims are theirs. This one predates AI entirely and gets forgotten because everyone is busy arguing about models.

    Risk Who controls it Who indemnifies
    Tool used outside its commercial-use terms Agency Agency
    Open-weight model licence breach Agency Agency
    Uncleared likeness, voice, font, stock Agency Agency
    Missing platform AI label at upload Client Client
    Provenance metadata stripped in re-encode Client Client
    Asset used in an undisclosed market or channel Client Client
    Unsubstantiated product claim in approved copy Client Client

    The metadata half, and how to make it enforceable

    Provenance stopped being a niche concern. C2PA passed 6,000 members and affiliates as of January 2026; Adobe ships Content Credentials by default in GenStudio for Performance Marketing; Microsoft began adding C2PA metadata to Microsoft 365 content in February 2026; and OpenAI shipped layered C2PA and SynthID provenance in May 2026. Platforms read it: TikTok has been labelling uploads that carry Content Credentials rather than relying solely on creator self-declaration.

    The practical consequence for a contract is this. If you deliver a file with credentials intact and the client's media team runs it through a compression step that strips them, the client has created their own compliance problem, and possibly an inconsistency between a stripped file and a platform expecting a signal. That is why the indemnity assigns it to them. But the assignment only holds if you can show the credentials were present at handoff.

    So the clause needs a matching handoff spec, or it is unenforceable in practice:

    1. Deliver with credentials intact and say so in the delivery note. One line: "Delivered file carries Content Credentials. Re-encoding may remove them."
    2. Keep a verification record. Check the delivered master and log the result with the date. This is the evidence that makes the indemnity operable, and it takes under a minute.
    3. Deliver the project, not only the flat export. An EDL-based editor keeps the edit as a re-renderable decision list, so if a credential-preserving re-export is needed later you are not rebuilding the edit from scratch.
    4. Name the destinations in the SOW. The labelling obligation is destination-specific, so an indemnity referencing "required disclosures" needs a list of where the asset is actually going.
    5. Flag what your pipeline does not carry. Some steps drop metadata, and some marks survive re-encoding while others do not. Being specific about what actually survives a real pipeline is worth more than a blanket promise.

    Worth diarising: provider-side marking obligations may run on a separate clock, under a grandfathering rule still contingent on the AI Omnibus proposal being adopted. Tool behaviour on metadata can change mid-project, which is another reason to verify at handoff rather than assume.

    Drafting the two-way split

    Keep it symmetrical in structure so it reads as an allocation rather than a defensive manoeuvre.

    Agency Indemnity. Agency shall indemnify Client against third-party claims arising from (a) Agency's use of any AI tool in breach of that tool's terms of service or applicable model licence; (b) third-party materials introduced by Agency without the necessary licence or consent, including stock media, fonts, likeness and voice; and (c) any breach by Agency of the confidentiality or Client Materials provisions of this Agreement.

    Client Indemnity. Client shall indemnify Agency against third-party claims arising from (a) Client's publication or distribution of Deliverables without any AI disclosure, label or provenance marking required by applicable law or platform policy; (b) Client's removal, alteration or degradation of provenance metadata present in Deliverables as delivered; (c) use of Deliverables outside the channels, markets and purposes stated in the applicable Statement of Work; and (d) claims or representations supplied or approved by Client.

    Procedure. The indemnified party shall give prompt written notice, permit the indemnifying party to control the defence with counsel of its choosing, and provide reasonable cooperation at the indemnifying party's expense. Neither party shall settle a claim in a manner imposing obligations on the other without prior written consent, not unreasonably withheld.

    The procedure paragraph is not filler. Prompt notice, control of defence and a no-unilateral-settlement rule are what stop an indemnity from becoming an open cheque signed by someone else. Suppliers routinely negotiate the substance hard and then accept a procedure clause that lets the client settle at any number and invoice it.

    One interaction to settle deliberately: whether indemnities sit inside or outside the liability cap. Clients typically want them outside. The workable middle is a sub-cap your professional indemnity cover can actually meet, applied both ways. Settle it in the same conversation as the cap, because deciding separately is how the two clauses end up contradicting each other.

    FAQ

    Should the indemnity be mutual even if the client insists theirs is one-way?

    Ask for it every time. The client half of this split is not a favour, it is an allocation of risks they alone create, and framing it that way usually works better than reciprocity arguments. If they refuse outright, the fallback is to move the same items into their warranties and obligations instead. Less powerful, but it still establishes who owns the duty when something goes wrong.

    What if the client's platform strips metadata automatically?

    Then the risk is real and needs discussing rather than drafting around. Some publishing pipelines and ad platforms re-encode on ingest as a matter of course. Verify behaviour on a test asset before the campaign, document what happens, and decide together whether an on-screen disclosure is needed because the machine-readable one will not survive. An indemnity for a stripped credential is cold comfort next to a label that was never going to make it.

    Does this replace the disclosure clause?

    No, and the two do different jobs. The disclosure clause establishes what you told the client about how the work was made. The indemnity allocates the consequences of what happens after delivery. A contract with an indemnity but no disclosure clause has assigned risk without establishing the facts the assignment depends on.