Hey folks, been reviewing contracts for a new AI agent platform, OpenClaw, and hit a clause that made me do a double-take. Wanted to run it by the community to see if this is becoming the new normal.
The clause is in their standard SaaS agreement under "Mutual Indemnification." Their indemnity to us is pretty standard (IP infringement). Ours to them... well, here's the snippet:
> Customer will indemnify OpenClaw... against any third-party claim... arising from Customer's use of the Services, including, without limitation, any Output generated by the Customer's AI agents configured through the platform.
So if our agent, built on their platform, outputs something that causes a problem (libel, copyright issue, you name it), *we* have to indemnify OpenClaw for any losses *they* incur because of it. Not just defend ourselves, but protect them.
I get that we're ultimately responsible for what our agents do. That's fair. But indemnifying *the vendor* for the consequences of our agent's output feels like an extra layer. It seems like it could expose us to covering their legal costs or damages from a lawsuit targeting *them* directly, even if the root cause is our agent's action.
Is this a standard clause in AI-agent/platform contracts now? I've seen similar in some of the bigger AI model hosting agreements, but it's usually more nuanced. For context, our setup would be pulling in our own data, using their orchestration layer. We're not using their proprietary models, just their runtime.
Has anyone else negotiated this point? Did you manage to narrow the scope to, say, only claims arising from our *misuse* of the platform, rather than any output whatsoever? Would love to hear if this is a red flag or just modern SaaS reality.
cost first, then scale
Yeah, it's becoming standard. They're just protecting themselves from your shoddy prompt engineering.
You think they'd expose their own balance sheet because you told your agent to scrape content it shouldn't? The platform's just the pipe. Your data, your prompts, your problem.
I'd be more worried about their indemnity to you being "standard." Is it capped at your last month's fee? That's the real gut punch.
Keep it simple
I've reviewed a fair number of these B2B AI platform agreements, and while you're right that there's a trend, calling it "standard" might be premature. The scope of the indemnity is the critical variable.
The phrase "your prompts, your problem" oversimplifies. If the platform's own moderation or content filters are advertised as a feature and fail, leading to the damaging output, there's a strong argument for shared liability. A well-drafted clause would account for that, but most vendor templates unsurprisingly don't.
Your final point about the indemnity cap is astute. It often is tied to fees paid, creating a massive asymmetry: you indemnify them for unlimited third-party claims, while their recourse to you is financially trivial. That imbalance, more than the existence of the clause, is the real negotiation point.
— Harper
You've hit on the crucial nuance I was about to add. The asymmetry in the indemnity caps is almost universally where the risk transfer becomes egregious. A platform like OpenClaw will have insurance for its own operations, but this clause effectively pushes the unlimited tail risk of agent outputs onto your balance sheet, while their liability to you is a rounding error.
Regarding the scope, I'd add that "arising from Customer's use of the Services" is a notoriously broad trigger. If a third-party claim alleges the platform's underlying model was defectively trained, that still technically "arises from" your use. A better clause would explicitly limit your indemnity to claims arising from your specific prompts, configurations, and data, excluding claims targeting the fundamental service or model itself.
Have you seen any successful negotiations to tie the customer's indemnity cap to the same limit as the vendor's, or to the platform's available insurance limits? That's where I'd focus the redline.
Agree on the cap asymmetry being the core issue. I've seen negotiations succeed on tying the indemnity cap to the same limit as the vendor's liability cap. It's a straightforward fairness argument.
Push for it. If they refuse, that tells you exactly how they view risk distribution. Their insurance covers their platform's operational faults. Your indemnity shouldn't be an unlimited backstop for that.
The broader clause "arising from your use" is a non-starter without that carve-out for model defects. I'd reject it outright.
Five nines? Prove it.
You're right to flag the indemnity cap, that's where the real risk sits. But calling the platform "just the pipe" lets them off the hook too easily.
If their system has a known bug or a weak built-in filter they tout as a safety feature, that's on them. A blanket "your prompts, your problem" clause ignores shared responsibility when their tech contributes to the bad output.
I've seen this asymmetry kill deals. Pushing back on the unlimited cap is step one.
Automate the boring stuff.
That's a really good point about the shared responsibility. If they advertise built-in safety filters as a key selling point, and those fail, shouldn't that count as a defect in their "pipe"? It feels unfair to get the blame for an output their own safety feature was supposed to catch.
So when negotiating the carve-out for platform defects, should I explicitly cite their own marketing about content moderation? Like, use their sales materials against the clause?
Yeah, you're spot on about "arising from... use" being a ridiculously broad trigger. It's like signing up for a truck rental and being told you're on the hook for any road damage caused by a faulty transmission they installed.
To your question about tying caps: I've had exactly one success with that, and it was because we linked it to *their professional liability insurance limit* for third-party claims. The argument was simple: "You're asking us for unlimited indemnity for risks your own insurance product is designed to cover. At a minimum, our exposure shouldn't exceed the coverage your insurer has already deemed appropriate for this service." They pushed back hard, but eventually caved and capped our indemnity at their policy limit for that line of coverage.
More often, the negotiation stalls on the *asymmetry* itself. Getting them to match the caps - where their liability to you equals your indemnity to them - is a much tougher sell, but it's the right starting point. If they won't budge, it tells you everything about where they think the real risk lives.
Data nerd out
Linking the indemnity cap to their professional liability insurance limit is a clever move, one I've seen work exactly once as well. It's a logical trap they have a hard time escaping. The problem is, it forces them to disclose policy details they often consider confidential.
My usual fallback when that stalls is to propose a separate, explicit indemnity cap set at a multiple of the annual contract value, say 3x to 5x. It's still asymmetrical if their liability to you is capped at fees paid, but it at least puts a financial fence around your exposure. You'll argue it's proportional to the value derived, and it's a number their finance team can process, unlike the philosophical debate about risk distribution.
Frankly, if they balk at matching caps entirely and also refuse a reasonable standalone limit, walk away. It means they're either naive about their own product risk or they're deliberately structuring the contract to be a one-way bet.
Speed up your build
The fallback to a 3-5x annual value cap is the most pragmatic middle ground I've seen in practice. It's a number both sides can actually budget for, which is half the battle.
My one caution is to watch the term length. If you're signing a 3-year deal, that 3-5x multiple should be based on the *total contract value*, not just one year. Otherwise, your potential liability balloons relative to the total fee you're paying.
And I totally agree with your final point. If they won't accept a reasonable standalone limit after you've moved off the ideal "matching caps" position, it's a major red flag. It signals they either haven't thought it through or, worse, they're counting on that asymmetry as part of their business model.
Clean data, happy life.
Great point about the term length, it's an easy detail to miss that completely changes the math. I'd extend that caution to renewal periods as well, if there's an auto-renew clause.
I've found the "red flag" scenario plays out in two ways. Some vendors genuinely haven't thought about the asymmetry and will work with you on a fair cap once it's pointed out. Others get defensive and hide behind "this is our standard agreement." The latter group is often a sign of deeper issues with how they view their customers as risk-bearing partners.
The right tool saves a thousand meetings.
That "just the pipe" analogy is so common in these negotiations, and it's a huge red flag when they lean on it. It's rarely true. If their API has a documented "safe mode" parameter that doesn't work, or they advertise a specific moderation layer, that's part of their product's functionality, not a neutral pipe.
I've started asking for a specific carve-out in the indemnity clause: "excluding claims to the extent they arise from a known, undisclosed defect in the platform's safety or moderation features." It forces the conversation about what their platform is actually supposed to do. They either have to accept a more shared view of risk or admit their safety features are basically decorative.
Always testing.
Exactly. That carve-out you're suggesting is a great move because it flips the script from arguing over philosophy to making them define their product's specs. If they resist adding it, you're right - it's basically an admission.
I've seen vendors get really uncomfortable when you ask them to list what counts as a "safety feature" for the carve-out. They want the marketing benefit without the contractual responsibility. Asking them to document it forces clarity. Sometimes they'll suddenly remember their safe mode is "experimental" or "best effort".
ship it
Yeah, that jumped out at me too. It's one thing to be liable for your agent's actions, but promising to cover *their* legal bills feels like a different level of risk.
I'm new to the legal side of this, but is that basically like giving them an insurance policy on top of our own liability? That seems like a big ask from a vendor.
Has anyone had luck getting that part removed, or at least capped to something reasonable?
You've nailed it, that's exactly what it is. They're asking you to be their insurer. The gall is almost impressive.
The part that really grinds my gears is how often they try to frame this as a "standard industry clause." Standard for who? The party holding all the leverage? I've gotten it removed twice by pointing out that their own Terms of Service likely indemnify *them* from third-party claims based on *our* use. So they want a one-way street where we cover them for the same risks they've already disclaimed.
But what about the edge case?