Skip to content
Legal

AI Services Supplement

Terms for the AI-enabled features of the Platform, including the MAAV AI assistant. It names the failure modes AI systems actually have, sets your verification obligation, and sharpens the no-training restriction.

Incorporated by reference into the Master Subscription Agreement at MSA §6.8.

All legal documents

NECESSITYWORKS, INC. — AI SERVICES SUPPLEMENT

Version: 1.0 Published at: https://necessityworks.com/legal/ai-supplement Applies to: NecessityWorks, Inc. (Delaware) Governs: AI-enabled features of the Platform, including the MAAV AI assistant and any successor AI/ML functionality


How this Supplement is accepted

This Supplement is incorporated by reference into the NW Master Subscription Agreement (“Agreement”) under §6.8 and applies automatically whenever Customer uses AI Services. No separate signature is required: Customer is bound by this Supplement by the same acceptance event that binds Customer to the Agreement (click-through, Order Form, or first use of the Platform). This Supplement sharpens (but does not replace) the no-AI-training restriction in Agreement §6.3 and DPA §3.3.


THE SUPPLEMENT

This AI Services Supplement (“Supplement”) supplements and forms part of the Master Subscription Agreement (the “Agreement”) between NecessityWorks, Inc. (“NW”) and the Customer that has accepted the Agreement as defined therein (“Customer”). This Supplement governs Customer’s access to and use of AI Services and allocates responsibility for AI Inputs and AI Outputs.


1. Definitions

Capitalized terms used but not defined in this Supplement have the meanings given in the Agreement. The following terms apply throughout:

1.1 “AI Input” means any prompt, query, document, telemetry, configuration, or other data submitted by or on behalf of Customer (including by its Authorized Users) to an AI Service for Processing.

1.2 “AI Output” means any text, content, recommendation, classification, summary, code, chart, or other data generated by an AI Service in response to AI Input.

1.3 “AI Service” means any AI- or ML-enabled feature, capability, or module made available to Customer as part of the Platform, including without limitation the MAAV AI assistant, AI-generated recommendations, AI-generated summaries, AI-generated compliance mappings, and successor features.

1.4 “Foundation Model” means a pre-trained machine-learning model made available by a third party (e.g., Anthropic, OpenAI) that NW incorporates into the Platform to provide AI Services.

1.5 “Model Provider” means the third party that provides a Foundation Model to NW, subject to that provider’s then-current commercial terms with NW.

1.6 “Tenant-Scoped Artifact” means a fine-tune, retrieval index, memory store, embedding, or other Processing artifact that is created from Customer’s data and is made available only to Customer within Customer’s own tenant or account.


2. Scope

This Supplement applies to all AI Services. Where an AI Service is delivered through a Foundation Model provided by a Model Provider, NW remains the contracting party to Customer and is responsible for Model Provider’s performance to the extent set forth in the Agreement and this Supplement.


3. Use Rights and Ownership

3.1 License to Use AI Services. Subject to the Agreement and this Supplement, Customer may access and use the AI Services solely for Customer’s and its Affiliates’ internal business purposes.

3.2 AI Input Ownership. As between the Parties, Customer retains all right, title, and interest in AI Inputs. Customer grants NW a limited, worldwide, non-exclusive license during the Term to Process AI Inputs as reasonably necessary to (a) generate AI Outputs for Customer, (b) operate and improve the AI Services as permitted under §4, and (c) comply with legal obligations.

3.3 AI Output Ownership. As between the Parties, Customer owns AI Outputs generated specifically for Customer, subject to (a) NW’s and its licensors’ retained ownership of the underlying models, algorithms, prompts, system architecture, and any pre-existing components reflected in AI Outputs, and (b) the following: AI Outputs of AI Services may be non-unique — identical or similar outputs may be generated for other customers in response to different inputs. Customer does not acquire exclusive rights in any AI Output.

3.4 AI Outputs Will Sometimes Be Wrong — Acknowledged Failure Modes. AI Services rely on probabilistic foundation models, which by their nature produce outputs that are unreliable in identifiable and recurring ways. Customer expressly acknowledges and assumes the risk of each of the following failure modes, any of which can occur in any AI Output without warning:

  1. Hallucination / Fabrication — AI Output may state facts, citations, statutes, regulations, code, file paths, configuration values, vendor capabilities, vulnerabilities, control mappings, or technical details that do not exist or are materially wrong, while presenting them in a confident, well-formatted manner.

  2. Inaccuracy — Even where the underlying fact exists, AI Output may misstate it (e.g., wrong CVE number, wrong control identifier, wrong regulator, wrong date, wrong CVSS score, wrong API parameter, wrong policy citation, wrong dollar amount).

  3. Incompleteness — AI Output may omit material facts, alternative explanations, conflicting evidence, exceptions, prerequisites, or downstream consequences that a human expert would identify.

  4. Out-of-Date Information — Foundation Models have training-data cutoffs and limited or no real-time awareness of changes in law, regulation, vendor configurations, threat landscape, or Customer’s environment after the cutoff. AI Output may reflect superseded standards, retired CVEs, or deprecated APIs.

  5. Bias — AI Output may reflect bias present in training data, including biased recommendations affecting individuals (employment, credit, healthcare, etc.) and biased threat-classification or risk-prioritization that disadvantages certain populations or technologies.

  6. Inconsistency — Identical or near-identical AI Inputs may produce materially different AI Outputs across requests, models, or model versions. Reproducibility is not warranted.

  7. Misclassification — In detection, triage, prioritization, and mapping use cases, AI Output may produce false positives (flagging benign activity as malicious) and false negatives (failing to flag malicious activity). Customer must not rely on AI classification alone for high-impact decisions.

  8. Prompt-Injection and Adversarial Manipulation — Malicious content embedded in documents, web pages, code, telemetry, or other inputs may cause AI Services to behave outside their intended function, including following instructions hidden in the input. AI Output produced under adversarial influence may be especially unreliable.

  9. Confident-but-Wrong Tone — AI Output is generated to be persuasive and well-formatted regardless of correctness. The fluency of an AI Output is not evidence of its accuracy.

  10. Code, Configuration, and Command Errors — AI-generated code, scripts, infrastructure-as-code, queries, regular expressions, and command-line strings may contain syntax errors, security vulnerabilities, destructive side effects, or logic errors. Customer must review and test before execution.

  11. Compliance and Legal Output Errors — AI-generated control mappings, policy text, risk assessments, regulatory citations, contract clauses, audit responses, attestations, and similar artifacts may misstate applicable law, miss controls, propose inadequate remediations, or be unsuitable for Customer’s regulatory posture. AI Output is never a substitute for qualified legal, compliance, financial, medical, or other professional advice.

  12. Security and Threat-Related Output Errors — AI-generated threat intelligence, attack-path analyses, kill-chain reconstructions, IOC enrichment, and remediation recommendations may be incorrect or incomplete, may miss real threats, and may suggest actions that would not actually mitigate the threat or that would degrade Customer’s environment.

3.5 Customer’s Affirmative Verification Obligation. Because of §3.4, Customer is solely responsible for verifying AI Output before relying on it for any purpose that could result in loss, harm, regulatory violation, or operational impact. Customer agrees that:

  1. AI Output is decision-support, not a decision — every action proposed, classified, recommended, or generated by AI Services is the Customer’s decision when acted upon;

  2. Customer will apply meaningful human review to AI Output before any material action, where “meaningful” means review by a person with the qualification, context, and authority necessary to evaluate the AI Output for the intended use;

  3. Customer will not delegate to AI Services any function that requires regulatory accountability, professional licensure, fiduciary duty, or judicial determination absent independent human verification by a qualified person; and

  4. Customer’s failure to verify AI Output before acting on it is a Customer-side risk that NW does not assume, regardless of any representation, demonstration, or marketing material to the contrary.

3.6 No Warranty of Accuracy — Disclaimer. NW DISCLAIMS ALL WARRANTIES THAT AI OUTPUT IS ACCURATE, COMPLETE, RELIABLE, CURRENT, BIAS-FREE, FREE OF HARMFUL CONTENT, FIT FOR ANY PARTICULAR PURPOSE, OR SUITABLE AS THE BASIS FOR ANY DECISION. No statement by NW personnel, in NW documentation, in marketing material, in product UI, or otherwise creates a warranty of accuracy. AI Output is provided “AS IS” and “AS AVAILABLE.” This §3.6 is a fundamental allocation of risk and is reflected in the fees Customer pays for the Services.


4. Data Handling and Model Training

4.1 No Training on Customer Data. NW shall not use AI Inputs, Customer Data, Customer Personal Data, or Customer Confidential Information to train, fine-tune, or otherwise improve any Foundation Model, shared AI model, or other AI artifact that is made available to any other customer or third party. This restriction applies to NW and flows through to NW’s Subprocessors and Model Providers, each of whom NW has contracted with on terms no less protective than this §4.1.

4.2 Tenant-Scoped Artifacts Are Permitted. Subject to §4.1, NW may create and maintain Tenant-Scoped Artifacts for Customer’s use within Customer’s tenant. A Tenant-Scoped Artifact is not a breach of §4.1 provided that (a) it is isolated to Customer’s tenant, (b) it is not made accessible to any other customer, and (c) it is deleted in accordance with §10 of the Agreement and §10 of the DPA.

4.3 Aggregate Operational Metrics. NW may collect and use aggregate, de-identified operational metrics regarding the performance and reliability of the AI Services (e.g., latency distributions, error rates, model-selection outcomes), provided that such metrics (a) do not contain AI Inputs, AI Outputs, or Customer Data in identifiable form, and (b) cannot reasonably be reverse-engineered to identify Customer, any individual, or the content of Customer Data.

4.4 Safety Filtering and Abuse Monitoring. NW may apply automated safety filters, abuse-detection, and policy-enforcement processes to AI Inputs and AI Outputs, and may refuse or modify Processing that violates NW’s published safety, abuse, or acceptable-use policies. NW’s retention of data for abuse-monitoring purposes will be limited to the minimum duration and scope reasonably necessary and subject to §4.1.

4.5 Foundation Model Providers as Subprocessors; Transparency and Switching.

  1. Model Providers are Subprocessors. Each Foundation Model Provider that Processes AI Inputs or Customer Personal Data on NW’s behalf is a Subprocessor under DPA §1.10 and is published at NW’s authoritative Subprocessor list at https://necessityworks.com/legal/subprocessors. As of the Effective Date, NW’s current Foundation Model Providers include Anthropic, PBC, and OpenAI, L.L.C., as further described at the Subprocessor list URL.

  2. Switching Between Listed Foundation Model Providers. NW operates a multi-Model-Provider architecture in order to (i) maintain availability, (ii) optimize for capability, latency, and cost per use case, and (iii) reduce concentration risk. NW may, at any time and without separate notice, route, switch, fail over, or load-balance Customer’s use of an AI Service between Foundation Model Providers that are already disclosed on the Subprocessor list, in each case subject to the no-training restriction in §4.1 and the data-handling restrictions in this Supplement and the DPA. Routing decisions are an operational matter and do not constitute a “new Subprocessor” under DPA §4.3.

  3. Adding a New Foundation Model Provider. Adding a Foundation Model Provider that is not already on the Subprocessor list is a Subprocessor change governed by DPA §4.3 (30-day advance notice via the published Subprocessor list and the change-notification list).

  4. Ongoing Model Provider Compliance — Commercially Reasonable Efforts. NW will use commercially reasonable efforts to maintain contractual no-training and data-handling protections from each Foundation Model Provider that are at least as protective as §4.1 of this Supplement, and to monitor each provider’s published terms for material adverse changes. If a Foundation Model Provider materially weakens its no-training or data-handling commitments after the Effective Date, NW will: (i) promptly assess whether the change is acceptable under §4.1, (ii) where the change is not acceptable, suspend routing of AI Inputs through that provider while it works to remediate or replace the provider, and (iii) reflect any such replacement on the Subprocessor list.

  5. Customer Transparency Tooling. Where the Platform exposes a per-model selector, model-identity indicator, or model-opt-out control, Customer may use those controls to constrain which Foundation Model Providers receive Customer’s AI Inputs. Absent such controls or absent Customer’s explicit configuration, NW selects the Foundation Model Provider for each request consistent with this §4.5.

4.6 Audit Right — No-Training Compliance. Once per calendar year (or more frequently following a confirmed material breach of §4.1), Customer may, on at least thirty (30) days’ prior written notice to [email protected], exercise the following limited audit right:

  1. Scope. A confidential review limited to NW’s compliance with §4.1 (No Training on Customer Data), §4.2 (Tenant-Scoped Artifact isolation), and §4.5(d) (Ongoing Model Provider Compliance). This audit right does not extend to NW’s general source code, infrastructure, or internal business operations beyond what is reasonably necessary to verify the foregoing.

  2. Method. NW will, at its election, satisfy the audit by (i) providing Customer with a written attestation, third-party audit report, or SOC 2 / ISO 27001 / equivalent control evidence covering the relevant scope; (ii) responding to a written questionnaire; or (iii) where the foregoing is insufficient and a material breach has been confirmed, permitting a Customer-engaged independent auditor (bound by confidentiality obligations at least as protective as Agreement §9) to inspect relevant records at NW’s premises during normal business hours.

  3. Cost. Each audit is at Customer’s expense, except that NW will reimburse reasonable audit costs if the audit reveals a material breach of §§4.1, 4.2, or 4.5(d) that NW has not promptly remediated.

  4. Confidentiality. All information disclosed to Customer or its auditor in connection with this §4.6 is NW’s Confidential Information under Agreement §9.


5. Prohibited Uses

In addition to the AUP, Customer will not, and will not permit any Authorized User or third party to, use AI Services:

  1. For legally regulated high-stakes decisions without human review. Customer will not rely on AI Output as the sole basis for any decision that produces legal effects concerning an individual or similarly significantly affects an individual, including credit, employment, housing, insurance, healthcare, education, law enforcement, or immigration decisions. Customer will ensure meaningful human review of AI Output before acting on it in such contexts.

  2. For deceptive or manipulative purposes, including generating content intended to impersonate a real person without authorization, to deceive another person into transferring money or Personal Data, or to manipulate through subliminal techniques.

  3. To generate unlawful content, including child sexual abuse material (CSAM), non-consensual intimate imagery, instructions for manufacturing prohibited weapons, or content that facilitates criminal activity.

  4. For biometric categorization, except for strictly lawful purposes with appropriate consent and safeguards.

  5. For untargeted scraping or collection of facial or other biometric data from the internet or other sources to build or expand identification databases.

  6. For real-time remote biometric identification in publicly accessible spaces by law-enforcement actors, except as strictly permitted by law.

  7. For social scoring — classifying individuals based on personal characteristics for purposes that may result in detrimental or unfavorable treatment unrelated to the context of the original data collection.

  8. For emotional-state inference from physical or behavioral signals other than for legitimate security and fraud-detection purposes.

  9. To reverse-engineer, extract, or attempt to discover the underlying weights, training data, system prompts, or architectures of Foundation Models or AI Services.

  10. To develop a competing AI service or Foundation Model. Customer will not use AI Inputs, AI Outputs, or other Service-derived information to train, fine-tune, or evaluate a model offered as a competitor to the AI Services.

  11. In violation of the AUP, applicable law, Model Provider terms, or NW’s published AI-safety policies.


6. Customer Responsibilities

6.1 Review of AI Output. Customer acknowledges the failure modes in §3.4 and is responsible for verifying AI Output per §3.5 before acting on it in any material respect. Customer will:

  1. Visibly flag AI Output as AI-generated to Customer’s downstream Authorized Users, end customers, and recipients where reliance is reasonably foreseeable;
  2. Validate AI-generated code, configurations, queries, and commands before execution in production or production-adjacent environments;
  3. Apply qualified human review to AI-generated compliance mappings, policies, risk assessments, contract clauses, audit responses, threat analyses, and security recommendations before adoption or external distribution; and
  4. Not represent AI Output as professional advice or as NW’s representation about Customer’s environment.

6.2 Legal and Regulatory Compliance. Customer is responsible for ensuring that its use of AI Services, including its reliance on AI Output, complies with all laws applicable to Customer’s industry and jurisdiction, including laws regulating the use of AI in specific sectors (e.g., financial services, healthcare, employment, public sector, EU AI Act high-risk classifications).

6.3 Disclosure to End Users. Customer is responsible for providing any disclosures about AI use to its own employees, end users, customers, and regulators as required by law (including transparency obligations under the EU AI Act, U.S. state AI disclosure laws, and applicable industry regulations).

6.4 Sensitive AI Inputs. Customer will not submit as AI Input any (a) special-category Personal Data not reasonably necessary for the Services, (b) authentication credentials, API keys, or secrets, or (c) data subject to a heightened regulatory regime (e.g., ITAR, classified information) unless NW has expressly agreed in writing to Process such data.

6.5 Acknowledgment of AI Risk. As a condition of accessing AI Services, Customer’s Authorized Users may be required to acknowledge an in-product AI Risk Acknowledgment the first time they engage with AI features. The Acknowledgment restates the failure modes in §3.4 and Customer’s verification obligation in §3.5. Click-acceptance of the Acknowledgment is recorded by NW. Customer is responsible for ensuring that all of its Authorized Users complete the Acknowledgment before substantive use.


7. Availability and Modification of AI Services

7.1 AI Services Evolve. AI Services are rapidly evolving. NW may modify, replace, or discontinue specific Foundation Models, features, or behaviors of AI Services from time to time. NW will not materially reduce the overall functionality of AI Services for which Customer has a paid subscription during a Subscription Term.

7.2 Model Identity and Versioning. NW does not warrant that AI Services will use any particular Foundation Model or version. NW may change, upgrade, or substitute Foundation Models in its discretion, subject to §4.1 and to any specific model-availability commitment stated on the Order Form.

7.3 Preview and Beta AI Features. AI Services designated as “preview,” “beta,” “experimental,” or “evaluation” are provided without any SLA, warranty, or indemnity, and NW may change or discontinue them at any time without notice.


8. Feedback

Customer grants NW a perpetual, irrevocable, worldwide, royalty-free, sublicensable, non-exclusive license to use Feedback (as defined in the Agreement) about AI Services for any purpose, consistent with MSA §8.3. NW is under no obligation to attribute Feedback to Customer or to compensate Customer for Feedback.


AI Output may include, reference, or hyperlink to third-party content, data, or services. NW does not endorse and is not responsible for third-party content or services that may be referenced in AI Output.


10. AI-Specific Indemnification by Customer

In addition to Customer’s indemnification obligations under MSA §11.2, Customer will defend, indemnify, and hold harmless NW from and against any third-party claim, loss, liability, judgment, or settlement arising from or related to:

  1. Customer’s or any Authorized User’s reliance on AI Output without the verification required by §3.5 or §6.1;
  2. Customer’s use of AI Output to make a decision producing legal effects or similarly significantly affecting any individual without the meaningful human review required by §5(a);
  3. Customer’s distribution, publication, or filing of AI Output as Customer’s own work product or as professional advice (legal, medical, financial, regulatory, or otherwise);
  4. Customer’s failure to disclose AI use to Customer’s employees, end customers, or regulators where disclosure is required by law;
  5. Customer’s submission as AI Input of data Customer was not authorized to provide, including third-party Confidential Information, third-party Personal Data, regulated data outside agreed scope, or content prohibited by §5; and
  6. Any breach by Customer or its Authorized Users of §§3.5, 5, or 6.

This §10 applies notwithstanding any negligence (other than gross negligence) by NW in the design, training, deployment, or operation of the AI Services.


11. Intellectual Property in AI Outputs

11.1 No NW IP Warranty for AI Outputs. AI Outputs are generated by probabilistic Foundation Models trained on third-party data over which NW has limited visibility and no control. NW does not warrant that any AI Output is non-infringing, original, or free from third-party intellectual-property claims, and (subject to §11.2 below) NW provides no indemnification to Customer for third-party claims that an AI Output infringes or misappropriates a third party’s copyright, trademark, patent, trade secret, or other intellectual-property right. The NW IP indemnification in MSA §11.1 applies to the Platform itself, not to AI Outputs.

11.2 Pass-Through of Model Provider IP Protections. Where a Foundation Model Provider offers a customer-facing IP indemnification, defense commitment, or “copyright shield” for outputs of its Foundation Models (collectively, “Model Provider Output IP Protection”), and where Customer’s use of the relevant AI Service falls within the scope of the Model Provider’s program, NW will use commercially reasonable efforts to pass through the available protection to Customer, subject to:

  1. the Model Provider’s then-current eligibility criteria, scope, exclusions, and conditions (e.g., that Customer did not deliberately prompt for infringing content, did not bypass safety filters, did not knowingly modify the Output to introduce infringement, and uses the Output consistent with the Service Description);
  2. Customer’s reasonable cooperation in establishing eligibility and tendering the claim through NW; and
  3. the cap, sub-cap, or other liability limit applicable under the Model Provider’s program, which is the maximum recovery available to Customer under this §11.2.

NW does not guarantee that any specific Foundation Model Provider offers Output IP Protection or that Customer will qualify for it. NW will publish, at the Subprocessor list URL (https://necessityworks.com/legal/subprocessors) or a linked page, the current Model Providers for which an Output IP Protection pass-through is available and the conditions of eligibility.

11.3 Customer Indemnification for IP Misuse. Customer will defend, indemnify, and hold harmless NW from third-party intellectual-property claims to the extent arising from:

  1. Customer’s or any Authorized User’s submission as AI Input of material Customer was not authorized to provide (including third-party copyrighted material, trade secrets, or trademarks);
  2. Customer’s prompts that requested, instructed, induced, or were reasonably likely to produce infringing or misappropriating AI Output;
  3. Customer’s modification of an AI Output in a manner that introduces or aggravates an IP issue not present in the unmodified Output;
  4. Customer’s distribution, publication, filing, or sale of an AI Output outside the scope of Customer’s permitted internal use under the Agreement; or
  5. Customer’s use of an AI Output after NW has notified Customer of a credible IP claim relating to that Output or to the underlying Foundation Model’s training data.

Customer’s indemnification under this §11.3 does not apply to the portion of any claim arising from NW’s own breach of this Agreement, NW’s gross negligence, or NW’s willful misconduct; comparative-fault allocation applies where multiple causes contribute.


12. EU AI Act and Analogous AI Regulatory Frameworks

12.1 Roles. Under Regulation (EU) 2024/1689 (the “EU AI Act”) and analogous AI-specific regulatory frameworks, the Parties acknowledge that, for AI Services made available through the Platform:

  1. NW acts as a provider of general-purpose AI (GPAI) capabilities incorporated into the Platform, and as a distributor of those capabilities to Customer through the Platform; and
  2. Customer acts as the deployer of the AI Services within Customer’s organization and is solely responsible for determining whether and how Customer uses the AI Services in any context that would be classified as high-risk under Article 6 / Annex III of the EU AI Act or under any analogous regulatory framework (e.g., U.S. state or federal AI accountability regimes that classify AI uses by risk).

12.2 NW’s GPAI / Provider Commitments.

  1. No marketing for inherently high-risk use. NW does not market or position the AI Services for use cases that would, by their nature, be classified as high-risk under EU AI Act Article 6 / Annex III (e.g., as safety components of critical infrastructure, for biometric identification, for employment decisions about a specific individual, for credit scoring of a natural person, for risk assessment in law enforcement, or for migration / asylum / border-control decisions). The §5 Prohibited Uses list implements (and may exceed) the prohibitions of EU AI Act Article 5.
  2. Provider transparency. NW will publish reasonable technical documentation, intended-purpose descriptions, model-card-style information (where applicable to the Foundation Models NW deploys), and instructions for use that enable Customer to evaluate the AI Services and to meet Customer’s deployer obligations under the EU AI Act or analogous frameworks. This documentation will be available at NW’s Documentation URL or, where required, on Customer’s reasonable written request.
  3. Human-oversight capability. The Platform provides Customer with the technical means to (i) require human review before any AI Output produces an automated effect on Customer’s data or systems, (ii) disable AI features for specific Authorized Users or workloads, and (iii) audit AI usage through NW’s logs. NW will not remove these capabilities during a paid Subscription Term in a manner inconsistent with Agreement §2.5.
  4. Cooperation with regulators. NW will cooperate, on reasonable terms and at Customer’s expense, with Customer’s reasonable requests for information necessary to respond to inquiries from competent AI regulators, supervisory authorities, or national authorities under the EU AI Act or analogous frameworks, subject to confidentiality obligations.

12.3 Customer’s Deployer Obligations. Customer is solely responsible for:

  1. assessing whether its specific use of any AI Service constitutes a high-risk deployment under the EU AI Act, U.S. state or sectoral AI laws, or other applicable frameworks;
  2. obtaining any conformity assessment, registration, impact assessment (e.g., fundamental-rights impact assessment under EU AI Act Article 27), or regulatory clearance required by Customer’s deployer role;
  3. implementing human-oversight processes appropriate to Customer’s use case;
  4. providing required disclosures and information to affected individuals about the use of AI Services;
  5. monitoring AI Output for accuracy, bias, and fitness for Customer’s purpose; and
  6. compliance with any AI-specific obligations that apply to Customer as an employer, financial institution, healthcare provider, educational institution, or other regulated actor.

12.4 Customer Acknowledgment of High-Risk Use. If Customer chooses to use any AI Service in a manner that constitutes high-risk deployment under any applicable AI regulatory framework, Customer (a) does so at its own risk and on its own regulatory responsibility, (b) will notify NW in writing in advance to [email protected] so that NW can assess whether NW’s published technical documentation is adequate to support Customer’s deployer obligations or whether additional documentation is required (which NW may decline to provide or may make available on a separately negotiated basis), and (c) will indemnify NW under §10(e) and §11.3 for third-party claims arising from such use to the extent within the scope of those provisions.


13. Limitation of Damages — AI-Specific

The Parties acknowledge that AI Services are inherently probabilistic and that no allocation of liability is sufficient if Customer treats AI Output as authoritative without verification. Accordingly, in addition to the limitations in MSA §12:

  1. No damages for unverified reliance. NW will have no liability for any loss, harm, or claim arising from Customer’s or its Authorized Users’ reliance on AI Output without verification meeting the standard in §3.5, regardless of the magnitude or source of the loss.

  2. No damages for high-stakes use without human review. NW will have no liability for any loss, harm, or claim arising from Customer’s use of AI Output as the sole basis for a decision producing legal effects or similarly significantly affecting any individual.

  3. AI Output is not a “deliverable” with conformance warranty. AI Outputs are not subject to the Service Description conformance warranty in MSA §10.2(a) or to the Professional Services workmanship warranty in MSA §10.2(b). Service Description conformance applies to the availability and behavior of the AI Services as a system, not to the truth or accuracy of any specific AI Output.

  4. Aggregate cap. Any liability not eliminated under (a)–(c) above remains subject to the MSA §12 aggregate cap and super-cap structure. The “no AI training” breach (§4.1 and MSA §6.3) is the only AI-related obligation for which liability is uncapped, per MSA §12.3(h).


14. Precedence

In the event of a conflict between this Supplement and the Agreement, this Supplement controls with respect to matters relating specifically to AI Services; otherwise, the Agreement controls.


ACCEPTANCE

This Supplement does not require a separate signature. It is binding on the Parties by operation of the Agreement, which incorporates this Supplement by reference. A Customer that requires a signed counterpart of this Supplement may request one in writing to [email protected] under the same procedure described in the Agreement’s ACCEPTANCE section; a signed counterpart is evidentiary only and does not modify the substantive terms of this Supplement.

Join the Waitlist