Summary. The working documents of an AI licensing practice, annotated.


Template 1 — Data provenance manifest

The foundation. Cannot be reconstructed after the fact.

Field Entry
Source ID
Source name and location
Collection method Crawl / API / purchase / license / contribution / internal
Collection date range
Archived copy of governing terms File reference + capture date
Machine-readable restrictions observed Robots directives, reservations
License or agreement asserted by source Reference
Consideration paid
Volume (records / tokens / bytes)
Personal information present? Categories
Lawful basis for personal information
Third-party confidential information?
Identifiable persons (voice, likeness)?
CMI preserved? Bears on 17 U.S.C. § 1202
Filtering and exclusions applied
Deduplication method
License tier assigned Free / permissive / restricted / excluded
Retention and deletion policy
Owner
Last verified

Two rules. Archive the terms as of the collection date — sites change and reconstruction is an evidentiary problem. Tag license tier at ingestion, because a corpus that mixes tiers is usable only at its most restrictive level and cannot be remediated if components cannot be separated.


Template 2 — Model and corpus inventory

Field Entry
Model name and version
Base model and its license
License type Proprietary / open weight with restrictions / permissive
Field-of-use restrictions
Scale threshold Trigger and current position
Output-training restriction
Attribution / notice obligations
Flow-down obligations to customers
Fine-tuning permitted? Ownership of result?
Corpora used (with versions)
Deployed versions in production
Indemnity received Scope, conditions, cap
Does current deployment satisfy indemnity conditions? Y/N + which fail
Indemnity granted downstream Scope, cap
Retained risk Gap between the two rows above
Provider rights over our inputs
Next review

The two bolded rows are the point of the document. Most organizations cannot answer either.


Template 3 — Procurement intake form

AI PROCUREMENT INTAKE                    REQUESTER: ____  DATE: ____

1. WHAT IS BEING ACQUIRED?
   [ ] Data corpus   [ ] Model weights   [ ] Hosted model service
   [ ] Fine-tuning service   [ ] Application built on a model

2. WHAT WILL WE DO WITH IT?
   [ ] Train from scratch  [ ] Fine-tune  [ ] Inference only
   [ ] Retrieval at query time            [ ] Evaluation only
   [ ] Embed in a distributed product     [ ] Distribute the model

3. WHAT DATA WILL WE SEND IT?
   [ ] None  [ ] Internal non-sensitive  [ ] Customer data
   [ ] Personal information  [ ] Regulated (health/financial/biometric)
   [ ] Third-party confidential information

4. WHO SEES THE OUTPUTS?
   [ ] Internal  [ ] Customers  [ ] Public
   Do outputs enter a record of legal or regulatory significance?  Y/N

5. IF THE VENDOR DISAPPEARED NEXT TUESDAY
   Migration effort: ______   Business impact: ______

6. BUDGET / TIMELINE / SPONSOR

Route by risk. Internal, non-sensitive, low-consequence outputs get a short review. Regulated data or outputs entering official records get the full exercise.


Template 4 — Diligence request list

Data

  1. Source manifest for the corpus.
  2. Archived copies of the governing terms as of collection, for each scraped or collected source.
  3. Agreements under which contributed or purchased components were obtained.
  4. Description of machine-readable restrictions encountered and how handled.
  5. Statement of personal information present and the lawful basis.
  6. Filtering, deduplication, and exclusion documentation.
  7. Confirmation whether copyright management information was preserved.
  8. All claims, demands, takedown or deletion requests relating to the corpus.
  9. Confirmation whether the corpus is segregated by license tier.

Model 10. The complete license text and any acceptable use policy. 11. All field-of-use restrictions and scale thresholds. 12. Restrictions on using outputs to train other models. 13. Attribution, notice, and flow-down obligations. 14. Fine-tuning terms, including ownership of resulting artifacts. 15. Provider rights over customer inputs, prompts, outputs, and tuning data. 16. Indemnity text with all conditions and exclusions. 17. Version deprecation policy and notice periods. 18. Security, subprocessor, and data residency documentation.


Template 5 — Grant clause (data)

2.1 Grant. Subject to this Agreement, Licensor grants Licensee a [non-exclusive, worldwide] license during the Term to: (a) reproduce and use the Data to train machine learning models; (b) reproduce and use the Data to fine-tune machine learning models; (c) reproduce and use the Data for evaluation and benchmarking; (d) use models resulting from (a)–(c) ("Resulting Models") for Licensee's internal business purposes; and (e) incorporate Resulting Models into products and services distributed by Licensee, provided that Licensee does not distribute the Resulting Models themselves except as embedded components not separately extractable.

2.2 Reservations. No right is granted to redistribute the Data, to sublicense except to Affiliates and contractors acting on Licensee's behalf, or to use the Data for any purpose not expressly permitted.

2.3 Excluded Components. The components identified in Schedule B are excluded from the Data and this grant. Licensee will not use them.

Note: enumerate the acts. "Use for AI purposes" allocates nothing, and the difference between (d) and (e) is frequently the difference between two price points.


Template 6 — Segregation and records clause

Segregation. Licensee will maintain records sufficient to identify, for each machine learning model Licensee trains or fine-tunes, (a) each dataset and dataset version used, (b) the dates of training, and (c) the model versions produced (the "Model Mapping"). Licensee will maintain the Model Mapping for the longer of the Term plus [three] years or the period during which any Resulting Model remains in use.

Verification. Upon [30] days' notice and not more than [once] per year, Licensor may engage an independent third party, subject to confidentiality obligations, to verify Licensee's compliance with Sections [grant] and [deletion] by reviewing the Model Mapping.

Why this is the most important operational clause in the agreement: without a model-to-corpus mapping, the survival provision, the deletion obligation, and the excluded-components restriction are all unenforceable as factual matters.


Template 7 — Termination and model survival clause

Effect of Termination. (a) Resulting Models survive. Upon expiration or termination for any reason other than Licensee's material breach of Section [grant], Licensee may continue to use, and to distribute in accordance with Section 2.1(e), all Resulting Models trained or fine-tuned during the Term. This right is perpetual and irrevocable. (b) Data must be deleted. Within [90] days after termination, Licensee will delete all copies of the Data and all derived datasets, including embeddings and indices generated from the Data, and will certify deletion in writing signed by an officer. (c) Exception for legal holds. Licensee may retain Data to the extent required by law or by a litigation hold, provided it is segregated, access-restricted, and used for no other purpose. (d) Termination for material breach of the grant. Licensee will additionally cease use of any Resulting Model trained on Data used in breach, subject to a [six]-month wind-down. (e) Indemnity survival. Licensor's obligations under Section [indemnity] survive termination as to claims arising from Licensee's use during the Term.

This is the clause to negotiate first, not last. For most licensees it is the deal.


Template 8 — Customer data restriction (licensee-side)

No Use of Customer Data. Provider will not use Customer Data, including inputs, prompts, outputs, and fine-tuning data, to train, fine-tune, evaluate, or improve any model or service, except (a) within Customer's dedicated instance solely for Customer's benefit, and (b) as necessary to provide the Services to Customer. Provider will not use Customer Data to develop any product or service offered to any third party.

Aggregate data. Provider may use aggregated, de-identified usage telemetry that does not include Customer Data content and from which Customer cannot be identified, solely for operating and securing the Services.

Deletion. Provider will delete Customer Data within [30] days of termination and certify deletion. Customer may request deletion of specified Customer Data at any time; Provider will comply within [30] days and confirm the extent to which deletion has been effected in any derived artifact.

Note the last sentence. It is honest about the limits of deletion from trained artifacts and commits to what can actually be done, which is better than a commitment that cannot be performed.


Template 9 — Output provisions

Outputs. (a) Assignment. As between the parties, Provider assigns to Customer all right, title, and interest Provider may have in Outputs generated for Customer. (b) No representation as to protectability. Provider makes no representation that Outputs are subject to copyright or any other intellectual property right. Customer acknowledges that material generated without sufficient human authorship may not be protectable. (c) Use. Customer may use Outputs for any lawful purpose, including commercially, without field restriction. (d) Non-uniqueness. Customer acknowledges that other customers may receive Outputs that are the same as or similar to Customer's Outputs, and that Provider may generate similar Outputs for others. (e) No residual license. Provider retains no license to use Customer's Outputs except as necessary to provide the Services. (f) Attribution. [Where required by the use case: Customer will identify Outputs as machine-generated in [specified contexts].]


Template 10 — Indemnity clause with negotiated conditions

Provider Indemnity. (a) Base model. Provider will defend and indemnify Customer against any third-party claim alleging that the Model, as provided by Provider and used in accordance with this Agreement, infringes any intellectual property right. This obligation is not subject to the conditions in Section (c) and is not subject to the cap in Section (e). (b) Outputs. Provider will defend and indemnify Customer against any third-party claim alleging that Outputs infringe any intellectual property right, subject to Sections (c) and (e). (c) Conditions applicable to Section (b) only. Customer (i) used a Model version released within the preceding [12] months; (ii) did not disable content filtering features that Provider identifies in writing as required; and (iii) did not provide as input any material Customer knew it lacked rights to provide. Fine-tuning performed through Provider's own service on Customer's own data does not affect this indemnity. (d) Process. Customer will notify Provider within [30] days of becoming aware of a claim. Provider will control the defense; Provider will not settle in a manner imposing any obligation on Customer without Customer's consent, not to be unreasonably withheld. (e) Cap. Provider's aggregate liability under Section (b) will not exceed [amount / multiple of fees paid in the preceding 24 months]. (f) Survival. This Section survives termination as to claims arising from use during the Term.

Drafting notes. Separating base-model risk (which the vendor created and can price) from output risk (which depends on customer behavior) is the structure that closes deals. The bolded sentence in (c) is the one most worth fighting for on the customer side.


Template 11 — Open-weight model compliance record

Field Entry
Model and version
License name and URL
Is it OSI-approved open source? Y/N — usually N
Acceptable use policy — prohibited fields
Does our use fall near any prohibition? If yes, obtain written interpretation
Scale threshold (users / revenue / compute) Trigger and current position
Output-training restriction
Attribution text required and where displayed
License text distribution requirement
Flow-down: must our customers accept terms?
Modification and redistribution terms
Fine-tuned artifact ownership
Indemnity Usually none — record retained risk
Approved by / date

Treat this exactly as a mature organization treats open source compliance. The failure modes are identical: engineering assumes permissiveness, obligations are discovered at scale, and remediation means rebuilding.


Template 12 — Pilot agreement (short form)

1. Purpose. The parties will conduct a limited evaluation of [Service] from [date] to [date] (the "Pilot"). 2. Data. Customer will provide only the data identified in Exhibit A. Provider will not use any Customer data for training, fine-tuning, evaluation, or improvement of any model or service, and will delete it within 15 days of the Pilot's end, with written certification. 3. No production use. The Pilot is for evaluation only. No Output may be used in production, relied upon for any decision affecting any person, or incorporated into any record without a superseding agreement. 4. No commitment. Neither party is obligated to enter any further agreement. 5. Confidentiality. Mutual, [three]-year term. 6. Liability. Each party's liability under this Pilot is limited to [amount]. Neither party is liable for indirect or consequential damages. 7. Term. This Pilot terminates automatically on [date] unless extended in writing.

What it prevents: the recurring failure of a pilot run under a click-through agreement that grants the vendor broad rights over real production data.


Template 13 — Exit deliverables schedule

Deliverable Format Deadline after termination
Fine-tuned weights or adapters [format] 15 days
Customer training and evaluation data Native 15 days
Embeddings and indices derived from Customer data [format] 30 days
Configuration, prompts, and system instructions Text 15 days
Logs required for Customer's audit and retention obligations [format] 30 days
Certification of deletion of Customer data Signed by an officer 45 days
Transition services Continued Service access [6–12] months at [rate]

Add the honest note: where fine-tuned artifacts are unusable without the provider's base model, say so in the negotiation and address it with a longer wind-down or an architecture that keeps proprietary content in a retrieval layer rather than in weights.


Template 14 — Upstream/downstream risk reconciliation

Risk Received upstream Granted downstream Gap (retained)
Base model IP infringement
Output IP infringement
Training data claims
Privacy / data protection
Security incident
Regulatory non-compliance
Clinical / professional outcome

Review before every customer contract signature. Organizations that grant customers broader protection than they received have assumed the difference across the entire customer base, usually without pricing it.


Related documents