Summary. The working documents of an AI licensing practice, annotated.
Template 1 — Data provenance manifest
The foundation. Cannot be reconstructed after the fact.
| Field | Entry |
|---|---|
| Source ID | |
| Source name and location | |
| Collection method | Crawl / API / purchase / license / contribution / internal |
| Collection date range | |
| Archived copy of governing terms | File reference + capture date |
| Machine-readable restrictions observed | Robots directives, reservations |
| License or agreement asserted by source | Reference |
| Consideration paid | |
| Volume (records / tokens / bytes) | |
| Personal information present? | Categories |
| Lawful basis for personal information | |
| Third-party confidential information? | |
| Identifiable persons (voice, likeness)? | |
| CMI preserved? | Bears on 17 U.S.C. § 1202 |
| Filtering and exclusions applied | |
| Deduplication method | |
| License tier assigned | Free / permissive / restricted / excluded |
| Retention and deletion policy | |
| Owner | |
| Last verified |
Two rules. Archive the terms as of the collection date — sites change and reconstruction is an evidentiary problem. Tag license tier at ingestion, because a corpus that mixes tiers is usable only at its most restrictive level and cannot be remediated if components cannot be separated.
Template 2 — Model and corpus inventory
| Field | Entry |
|---|---|
| Model name and version | |
| Base model and its license | |
| License type | Proprietary / open weight with restrictions / permissive |
| Field-of-use restrictions | |
| Scale threshold | Trigger and current position |
| Output-training restriction | |
| Attribution / notice obligations | |
| Flow-down obligations to customers | |
| Fine-tuning permitted? Ownership of result? | |
| Corpora used (with versions) | |
| Deployed versions in production | |
| Indemnity received | Scope, conditions, cap |
| Does current deployment satisfy indemnity conditions? | Y/N + which fail |
| Indemnity granted downstream | Scope, cap |
| Retained risk | Gap between the two rows above |
| Provider rights over our inputs | |
| Next review |
The two bolded rows are the point of the document. Most organizations cannot answer either.
Template 3 — Procurement intake form
AI PROCUREMENT INTAKE REQUESTER: ____ DATE: ____
1. WHAT IS BEING ACQUIRED?
[ ] Data corpus [ ] Model weights [ ] Hosted model service
[ ] Fine-tuning service [ ] Application built on a model
2. WHAT WILL WE DO WITH IT?
[ ] Train from scratch [ ] Fine-tune [ ] Inference only
[ ] Retrieval at query time [ ] Evaluation only
[ ] Embed in a distributed product [ ] Distribute the model
3. WHAT DATA WILL WE SEND IT?
[ ] None [ ] Internal non-sensitive [ ] Customer data
[ ] Personal information [ ] Regulated (health/financial/biometric)
[ ] Third-party confidential information
4. WHO SEES THE OUTPUTS?
[ ] Internal [ ] Customers [ ] Public
Do outputs enter a record of legal or regulatory significance? Y/N
5. IF THE VENDOR DISAPPEARED NEXT TUESDAY
Migration effort: ______ Business impact: ______
6. BUDGET / TIMELINE / SPONSOR
Route by risk. Internal, non-sensitive, low-consequence outputs get a short review. Regulated data or outputs entering official records get the full exercise.
Template 4 — Diligence request list
Data
- Source manifest for the corpus.
- Archived copies of the governing terms as of collection, for each scraped or collected source.
- Agreements under which contributed or purchased components were obtained.
- Description of machine-readable restrictions encountered and how handled.
- Statement of personal information present and the lawful basis.
- Filtering, deduplication, and exclusion documentation.
- Confirmation whether copyright management information was preserved.
- All claims, demands, takedown or deletion requests relating to the corpus.
- Confirmation whether the corpus is segregated by license tier.
Model 10. The complete license text and any acceptable use policy. 11. All field-of-use restrictions and scale thresholds. 12. Restrictions on using outputs to train other models. 13. Attribution, notice, and flow-down obligations. 14. Fine-tuning terms, including ownership of resulting artifacts. 15. Provider rights over customer inputs, prompts, outputs, and tuning data. 16. Indemnity text with all conditions and exclusions. 17. Version deprecation policy and notice periods. 18. Security, subprocessor, and data residency documentation.
Template 5 — Grant clause (data)
2.1 Grant. Subject to this Agreement, Licensor grants Licensee a [non-exclusive, worldwide] license during the Term to: (a) reproduce and use the Data to train machine learning models; (b) reproduce and use the Data to fine-tune machine learning models; (c) reproduce and use the Data for evaluation and benchmarking; (d) use models resulting from (a)–(c) ("Resulting Models") for Licensee's internal business purposes; and (e) incorporate Resulting Models into products and services distributed by Licensee, provided that Licensee does not distribute the Resulting Models themselves except as embedded components not separately extractable.
2.2 Reservations. No right is granted to redistribute the Data, to sublicense except to Affiliates and contractors acting on Licensee's behalf, or to use the Data for any purpose not expressly permitted.
2.3 Excluded Components. The components identified in Schedule B are excluded from the Data and this grant. Licensee will not use them.
Note: enumerate the acts. "Use for AI purposes" allocates nothing, and the difference between (d) and (e) is frequently the difference between two price points.
Template 6 — Segregation and records clause
Segregation. Licensee will maintain records sufficient to identify, for each machine learning model Licensee trains or fine-tunes, (a) each dataset and dataset version used, (b) the dates of training, and (c) the model versions produced (the "Model Mapping"). Licensee will maintain the Model Mapping for the longer of the Term plus [three] years or the period during which any Resulting Model remains in use.
Verification. Upon [30] days' notice and not more than [once] per year, Licensor may engage an independent third party, subject to confidentiality obligations, to verify Licensee's compliance with Sections [grant] and [deletion] by reviewing the Model Mapping.
Why this is the most important operational clause in the agreement: without a model-to-corpus mapping, the survival provision, the deletion obligation, and the excluded-components restriction are all unenforceable as factual matters.
Template 7 — Termination and model survival clause
Effect of Termination. (a) Resulting Models survive. Upon expiration or termination for any reason other than Licensee's material breach of Section [grant], Licensee may continue to use, and to distribute in accordance with Section 2.1(e), all Resulting Models trained or fine-tuned during the Term. This right is perpetual and irrevocable. (b) Data must be deleted. Within [90] days after termination, Licensee will delete all copies of the Data and all derived datasets, including embeddings and indices generated from the Data, and will certify deletion in writing signed by an officer. (c) Exception for legal holds. Licensee may retain Data to the extent required by law or by a litigation hold, provided it is segregated, access-restricted, and used for no other purpose. (d) Termination for material breach of the grant. Licensee will additionally cease use of any Resulting Model trained on Data used in breach, subject to a [six]-month wind-down. (e) Indemnity survival. Licensor's obligations under Section [indemnity] survive termination as to claims arising from Licensee's use during the Term.
This is the clause to negotiate first, not last. For most licensees it is the deal.
Template 8 — Customer data restriction (licensee-side)
No Use of Customer Data. Provider will not use Customer Data, including inputs, prompts, outputs, and fine-tuning data, to train, fine-tune, evaluate, or improve any model or service, except (a) within Customer's dedicated instance solely for Customer's benefit, and (b) as necessary to provide the Services to Customer. Provider will not use Customer Data to develop any product or service offered to any third party.
Aggregate data. Provider may use aggregated, de-identified usage telemetry that does not include Customer Data content and from which Customer cannot be identified, solely for operating and securing the Services.
Deletion. Provider will delete Customer Data within [30] days of termination and certify deletion. Customer may request deletion of specified Customer Data at any time; Provider will comply within [30] days and confirm the extent to which deletion has been effected in any derived artifact.
Note the last sentence. It is honest about the limits of deletion from trained artifacts and commits to what can actually be done, which is better than a commitment that cannot be performed.
Template 9 — Output provisions
Outputs. (a) Assignment. As between the parties, Provider assigns to Customer all right, title, and interest Provider may have in Outputs generated for Customer. (b) No representation as to protectability. Provider makes no representation that Outputs are subject to copyright or any other intellectual property right. Customer acknowledges that material generated without sufficient human authorship may not be protectable. (c) Use. Customer may use Outputs for any lawful purpose, including commercially, without field restriction. (d) Non-uniqueness. Customer acknowledges that other customers may receive Outputs that are the same as or similar to Customer's Outputs, and that Provider may generate similar Outputs for others. (e) No residual license. Provider retains no license to use Customer's Outputs except as necessary to provide the Services. (f) Attribution. [Where required by the use case: Customer will identify Outputs as machine-generated in [specified contexts].]
Template 10 — Indemnity clause with negotiated conditions
Provider Indemnity. (a) Base model. Provider will defend and indemnify Customer against any third-party claim alleging that the Model, as provided by Provider and used in accordance with this Agreement, infringes any intellectual property right. This obligation is not subject to the conditions in Section (c) and is not subject to the cap in Section (e). (b) Outputs. Provider will defend and indemnify Customer against any third-party claim alleging that Outputs infringe any intellectual property right, subject to Sections (c) and (e). (c) Conditions applicable to Section (b) only. Customer (i) used a Model version released within the preceding [12] months; (ii) did not disable content filtering features that Provider identifies in writing as required; and (iii) did not provide as input any material Customer knew it lacked rights to provide. Fine-tuning performed through Provider's own service on Customer's own data does not affect this indemnity. (d) Process. Customer will notify Provider within [30] days of becoming aware of a claim. Provider will control the defense; Provider will not settle in a manner imposing any obligation on Customer without Customer's consent, not to be unreasonably withheld. (e) Cap. Provider's aggregate liability under Section (b) will not exceed [amount / multiple of fees paid in the preceding 24 months]. (f) Survival. This Section survives termination as to claims arising from use during the Term.
Drafting notes. Separating base-model risk (which the vendor created and can price) from output risk (which depends on customer behavior) is the structure that closes deals. The bolded sentence in (c) is the one most worth fighting for on the customer side.
Template 11 — Open-weight model compliance record
| Field | Entry |
|---|---|
| Model and version | |
| License name and URL | |
| Is it OSI-approved open source? | Y/N — usually N |
| Acceptable use policy — prohibited fields | |
| Does our use fall near any prohibition? | If yes, obtain written interpretation |
| Scale threshold (users / revenue / compute) | Trigger and current position |
| Output-training restriction | |
| Attribution text required and where displayed | |
| License text distribution requirement | |
| Flow-down: must our customers accept terms? | |
| Modification and redistribution terms | |
| Fine-tuned artifact ownership | |
| Indemnity | Usually none — record retained risk |
| Approved by / date |
Treat this exactly as a mature organization treats open source compliance. The failure modes are identical: engineering assumes permissiveness, obligations are discovered at scale, and remediation means rebuilding.
Template 12 — Pilot agreement (short form)
1. Purpose. The parties will conduct a limited evaluation of [Service] from [date] to [date] (the "Pilot"). 2. Data. Customer will provide only the data identified in Exhibit A. Provider will not use any Customer data for training, fine-tuning, evaluation, or improvement of any model or service, and will delete it within 15 days of the Pilot's end, with written certification. 3. No production use. The Pilot is for evaluation only. No Output may be used in production, relied upon for any decision affecting any person, or incorporated into any record without a superseding agreement. 4. No commitment. Neither party is obligated to enter any further agreement. 5. Confidentiality. Mutual, [three]-year term. 6. Liability. Each party's liability under this Pilot is limited to [amount]. Neither party is liable for indirect or consequential damages. 7. Term. This Pilot terminates automatically on [date] unless extended in writing.
What it prevents: the recurring failure of a pilot run under a click-through agreement that grants the vendor broad rights over real production data.
Template 13 — Exit deliverables schedule
| Deliverable | Format | Deadline after termination |
|---|---|---|
| Fine-tuned weights or adapters | [format] | 15 days |
| Customer training and evaluation data | Native | 15 days |
| Embeddings and indices derived from Customer data | [format] | 30 days |
| Configuration, prompts, and system instructions | Text | 15 days |
| Logs required for Customer's audit and retention obligations | [format] | 30 days |
| Certification of deletion of Customer data | Signed by an officer | 45 days |
| Transition services | Continued Service access | [6–12] months at [rate] |
Add the honest note: where fine-tuned artifacts are unusable without the provider's base model, say so in the negotiation and address it with a longer wind-down or an architecture that keeps proprietary content in a retrieval layer rather than in weights.
Template 14 — Upstream/downstream risk reconciliation
| Risk | Received upstream | Granted downstream | Gap (retained) |
|---|---|---|---|
| Base model IP infringement | |||
| Output IP infringement | |||
| Training data claims | |||
| Privacy / data protection | |||
| Security incident | |||
| Regulatory non-compliance | |||
| Clinical / professional outcome |
Review before every customer contract signature. Organizations that grant customers broader protection than they received have assumed the difference across the entire customer base, usually without pricing it.
Related documents
- Licensing Data and Models for Artificial Intelligence: Training Rights, Outputs, and Indemnities
- Negotiating an AI Data or Model License: A Practical Guide
- AI Licensing Diligence Checklist: A Practical Checklist
- AI Governance Toolkit: Inventory, Risk Classification, and Controls
- Fair Use Toolkit: Analysis Memoranda, Clearance Decisions, and Litigation Positions
- Software and Open Source Licensing Toolkit: From IP Layers to Compliance Programs
- Privacy and Data Protection Toolkit: Building and Running a Privacy Program
- Contract Lifecycle Toolkit: From Term Sheet to Termination
