Marquee Background
Marquee Background

Offit Kurman Blogs

Business

AI Reps & Warranties: Emerging Issues in Deals and Commercial Contracts

June 19, 2025
AI Reps & Warranties: Emerging Issues in Deals and Commercial Contracts

Artificial intelligence quickly became embedded into business operations, software platforms, internal workflows, and consumer-facing applications. This means the legal risks associated with its development and growth are moving from the abstract to the real world. AI is not only changing how businesses operate, but also how leaders and legal practitioners must structure and negotiate contracts. Legal teams, in-house counsel, and M&A deal professionals can no longer consider this a niche issue and should consider it a negotiated deal point involving risk allocation, liability exposure, and asset valuation.

While there is significant attention paid to the disruptive operational power of AI, its implications on representations and warranties in commercial agreements and corporate transactions deserve just as much attention within the legal community.

Some tailored legal frameworks are already emerging to address the novel concerns around data privacy, intellectual property, indemnity, and operational continuity. These issues are especially critical in the context of software acquisitions, SaaS contracts, and any M&A deal involving AI-derived intellectual property or business processes.

AI-Specific Representations in Deals

The National Venture Capital Association (NVCA) model forms were updated at the end of 2024 to incorporate AI-specific representations and warranties. These terms are increasingly reflected in market practice:

  • Targets must affirm that AI tools were used in compliance with applicable licenses, regulations, and data use agreements.
  • Targets must represent that they did not input any personal, confidential, or protected information into AI tools, unless those tools guarantee that such data is not used for training or product enhancement.
  • Targets must represent that data was deidentified or anonymized prior to use in training models to avoid running afoul of applicable data protection standards.
  • Targets must disclose any generative AI platforms used to develop proprietary IP and warrant that such use does not jeopardize any ownership rights being acquired.

The above issues are only the tip of the iceberg. Transactions and agreements involving complex AI products must include increasingly technical reps concerning:

  • Model training logs and documentation
  • Fine-tuning methods and retention of model weights
  • Mechanisms used in retrieval-augmented generation (RAG)
  • Use of synthetic or auto-generated content in commercial workflows
  • Model validation performance thresholds, including floating point operation limits and accuracy ranges

As the technology matures, the legal community is catching up by embedding operational guardrails directly into transactional documentation.

Practical Contractual Risk Areas in AI Licensing

Commercial licensing agreements involving AI must now be viewed through a much more detailed legal lens. Counsel should be prepared to negotiate contract terms specifically addressing:

  • Non-infringement guarantees concerning both source code and training data, especially where data scraping or aggregation may have occurred
  • Explicit ownership claims over AI outputs, derivatives, and model weights
  • Training data auditability, including the legal basis for data collection, classification, and labeling
  • Compliance with global privacy and cybersecurity laws, including GDPR, CPRA, and HIPAA when applicable
  • Robust indemnification obligations for breaches of data usage restrictions, IP violations, or algorithmic harms
  • Tech E&O and cyber liability insurance provisions, ensuring recourse exists if generative tools malfunction, hallucinate, or produce defamatory content

In many cases, the liability profile of AI is uncertain and difficult to quantify. Because many models operate as "black boxes," licensees are often left without a clear explanation of how certain outputs were generated or what datasets were used in training. This makes traditional warranties about performance or fitness for a particular purpose difficult to enforce.

As a result, buyers and licensees are demanding broader representations, heightened disclosure obligations, and post-closing audit rights to mitigate these unknowns (while sellers are seeking to disclaim warranties and narrow representations).

M&A and AI Due Diligence

AI risk has quickly become a key diligence category in M&A deals, especially in transactions involving software, e-commerce, analytics, or consumer engagement platforms. Buyers are now expected to conduct diligence not just on IP rights and customer contracts, but also on how AI has been implemented and governed.

Pre-Acquisition Diligence

Key diligence areas include:

  • Training data sourcing: Was the data obtained lawfully and under enforceable terms?
  • Privacy risk: Was any personally identifiable information (PII) used in training or prompting without consent?
  • Third-party code and APIs: Does the AI product depend on third-party components that might limit assignability or trigger license fees?
  • Model update and retraining rights: Who controls the model lifecycle, including patches and performance tuning?
  • Export control risks: Could the AI model be subject to ITAR, EAR, or other national security controls due to its capabilities?

Post-Closing Continuity

Buyers should also require:

  • Complete AI architecture diagrams and component inventories
  • Documentation of ethical safeguards and bias mitigation processes
  • Retention policies around input prompts and AI-generated output logs
  • Model deployment playbooks and downtime risk disclosures

Transition services agreements, software escrow, and founder retention may also be needed to ensure business continuity and proper knowledge transfer where AI is a critical but complex asset.

IP, Privacy, and Employment Triggers

This isn't only an issue for "tech transactions." As AI expands across business functions, its legal implications multiply. Core issues include:

  • Intellectual property ownership, particularly whether AI-generated outputs are protectable under U.S. copyright law or must be secured as trade secrets
  • Privacy and cybersecurity risks stemming from unstructured data ingestion and prompt leakage, especially when sensitive information is processed or used
  • Employment law exposure, including discriminatory hiring algorithms or opaque automated decision-making processes that may violate EEOC or state-level labor rules

Recent case law and regulatory action suggest that companies using AI for decision-making will be held to explainability and fairness standards, even if they do not fully control or understand the model.

Additionally, companies leveraging AI in consumer products or safety-critical environments must consider product liability exposure under traditional tort theories, especially if AI contributes to physical or economic harm. Think about the auto-driving taxi that must decide whether to hit the pedestrian or crash the car.

AI and IP Security Agreements

As more companies develop proprietary AI tools, models, and datasets, lenders and investors are increasingly taking security interests in these intangible assets. This requires a rethinking of traditional IP Security Agreements.

When collateral includes AI-generated or AI-driven intellectual property, legal teams should evaluate:

  • Whether model weights, training datasets, or prompt libraries are clearly documented and listed as pledged assets
  • Whether the borrower can demonstrate ownership and provenance of the training data and model code
  • If the model is fine-tuned from a third-party foundation model, whether the underlying license permits encumbrance or assignment
  • If retrieval-augmented generation (RAG) is used, whether the underlying corpuses and connectors are part of the security package
  • The existence of source code escrow to ensure access in the event of default or bankruptcy
  • Any restrictions in open source or SaaS agreements that may limit foreclosure or reassignment rights

Moreover, the lender’s enforcement rights may be limited if the AI model or data is co-owned, cloud-hosted, or reliant on third-party APIs. Security interests must be carefully drafted to reflect operational dependencies, and perfection of those interests may require filings beyond the USPTO, including notice to cloud vendors or consent from licensors.

IP Security Agreements for AI assets must go beyond standard boilerplate and should be tailored to the unique hybrid nature of AI systems combining software, services, and data streams. In many cases, a supplemental AI-specific collateral schedule may be appropriate.

Takeaways for Legal and Deal Teams

AI is no longer a novel technology element to be glossed over in standard reps and warranties. It is a high-stakes business driver that intersects with every major legal category: IP, privacy, cybersecurity, employment, antitrust, and contract liability.

Actionable takeaways include:

  • Draft AI-specific reps and warranties that cover data sourcing, training protocols, model rights, and use case restrictions
  • Build diligence frameworks that include discussions with technical teams and review of logs, policies, and product roadmaps
  • Negotiate indemnification mechanisms that allocate financial risk from misuse, error, or regulatory exposure
  • Ensure insurance provisions cover AI incidents, from hallucinated content to data leakage
  • Establish post-closing governance and monitoring structures, particularly in acquisitions involving live AI models or mission-critical algorithms
  • Review and update IP Security Agreements to specifically address AI collateral and embedded third-party dependencies

Ultimately, the central legal question becomes: When AI makes a mistake, who pays? Whether drafting a commercial SaaS agreement or executing a strategic acquisition, every deal team must be ready to answer that.

As legal and technological standards continue to evolve, ongoing adaptation will be essential.

  • Posts
  • About
  • Subscribe

Firm Highlights

  • Events
    MACFO's Inside Successful CEO & CFO Partnerships
    Please join us on September 18 for an event that’s sure to be a home run! ***We will lead off by interviewing our Spotlight Speaker Series guest, Baltimore Orioles CFO, Darline Llamas Llopis.*** After, we will ask ourselves, what separates great companies from good ones? We believe that more often than not, it is the strength of the partnership between the CEO and CFO that matters, so we are bringing you three CEO/CFO leadership teams to learn from. The Associated: Jewish Federation of Baltimore – Andrew Cushnir and Sam Klein Canusa Paper & Packaging – Mike Walter and Vince Salamone Secom, LLC – Toni Toomey and Mourad Awad Join us for an exclusive executive briefing – three tandem presentations followed by a panel discussion - featuring CEOs and CFOs from different but leading organizations as they share candid insights into building trust, navigating difficult decisions, driving strategic growth, and leading through today's business challenges. You'll hear firsthand how these executive teams navigate conflict, align on priorities, and build high-performing organizations. Whether you're a CFO, controller, finance executive, or an aspiring business leader, you'll leave with practical ideas and fresh perspectives you can apply immediately. Meet Our Speakers: Darline Llamas Llopis • Orioles  Chief Financial Officer Darline Llamas Llopis is in her second season with the Orioles as Chief Financial Officer (CFO). Prior to joining the Orioles, Llamas Llopis spent four seasons with the Miami Dolphins, Hard Rock Stadium, and the F1 Miami Grand Prix as Vice President of Finance and Retail. In this capacity, she managed the finance, accounting, payroll, account payables, procurement and merchandise operations for the team and race. She also previously served for four years as the Director of Finance and Controller at the Los Angeles Rams. Llamas Llopis started her career in public accounting with Ernst & Young and PricewaterhouseCoopers as a member of the Commercial Real Estate practice.  Llamas Llopis completed her MBA at UCLA Anderson School of Management and received her Master of Accountancy from the University of Southern California (USC) where she also graduated cum laude with an undergraduate degree in business. She is a member of the American Institute of Certified Public Accountants (CPA) and is an active CPA. She resides in Baltimore with her husband, Devin, and their son, Santiago. Andrew Cushnir • The Associated: Jewish Federation of Baltimore   President & Chief Executive Officer Andrew Cushnir is the President and Chief Executive Officer of The Associated, having started in the role in May 2024. He is the eighth person to serve in this role since The Associated’s founding over 100 years ago. Andrew brings a wealth of experience and a profound dedication to strengthening and enriching the Jewish community. His journey within the Jewish Federation system began as a passionate lay leader and volunteer before he transitioned into serving as a professional. He worked for the Jewish Federation of Los Angeles for twenty years, including in the roles of Chief Planning and Program Officer and Chief Development Officer. During this time, Andrew played a crucial role in reshaping the allocation process and fostering a culture of collaboration and partnership and he also led all annual, project, and emergency fundraising, as well as planned giving efforts. As a member of the Federation’s executive team, he also addressed complex community and organizational issues. Andrew and his wife Sharon Spira-Cushnir, a seasoned nonprofit human services executive, are the proud parents of two children in their early 20s. Sam Klein • The Associated: Jewish Federation of Baltimore  Chief Financial Officer Sam Klein is a seasoned nonprofit finance executive with nearly two decades of experience leading financial strategy, operations, budgeting, and organizational transformation for mission-driven institutions. As Chief Financial Officer of The Associated: Jewish Federation of Baltimore, he oversees the organization's financial operations, investment stewardship, budgeting processes, risk management, and long-term financial planning, helping advance the Federation's mission of strengthening and supporting Jewish life in Baltimore, Israel, and around the world. Throughout his career, Sam has been recognized for his ability to align financial stewardship with organizational mission, drive process improvements, implement technology solutions, and build high-performing teams. His expertise includes nonprofit finance, strategic planning, budgeting and forecasting, investment oversight, financial reporting, compliance, operational excellence, and organizational growth. Sam earned a Master of Business Administration in Finance from the Johns Hopkins Carey Business School and a Bachelor of Science in Finance and Marketing from Syracuse University. Mike Walter • Canusa's Paper & Packaging Chief Executive Officer As Chief Executive Officer of Canusa Paper & Packaging (CPP), Mike Walter leads one of the world's leading independent international brokerages of containerboard and packaging papers. Mike recently celebrated his 20th anniversary with Canusa and has overseen a doubling of the business in the past five years. Mike’s first role at Canusa was an intern before moving into a risk management role. Progressive promotions over the years led Mike to serve as Canusa's Chief Operating Officer and General Counsel, as well as General Counsel for its affiliate, Canusa Hershman before becoming the CPP CEO on January 1st, 2025. Mike graduated with a B.S. in Commerce & Engineering from Drexel University before earning his J.D. at the University of Baltimore’s School of Law. Vince Salamone • Canusa's Paper & Packaging Chief Financial Officer Vince Salamone serves as Chief Financial Officer of Canusa Paper & Packaging, overseeing the company's global financial strategy and overall operations, risk management, and other shared services. Since joining Canusa in 2018, Vince has advanced from Corporate Controller to CFO. Prior to Canusa, Vince held senior accounting and financial reporting roles at modular space leader Algeco Scotsman and supply chain real estate operator Realterm, bringing extensive expertise in finance and corporate accounting. He began his career with Deloitte, providing assurance services to clients in aerospace and defense, software, and manufacturing throughout the Mid-Atlantic. Vince attended the University of Maryland and Towson University, earning his B.S. in Accounting in 2012 and his CPA license in 2014. Toni Toomey • Secom, LLC Chief Executive Officer As Chief Executive Officer of Secom, LLC, Toni Toomey leads the company's external vision, culture, and strategic growth. A Howard County native, Toni brings an entrepreneurial spirit and a people-first philosophy to one of Maryland's leading commercial security firms — championing internal promotion and a culture of integrity. Toni serves on the Board of Directors for Maryland Tech Council, the Howard County Chamber, as well as the Steering Committee for the Maryland Rural Tech Network. Mourad Awad • Secom, LLC Chief Financial Officer As Chief Financial Officer of Secom, LLC, Mourad Awad architects the company’s financial strategy, performance, and value creation. A leader, by example, Mourad believes in empowering people and fostering communication. With 20+ years of leadership across private equity, federal contracting, construction, and infrastructure services, Mourad brings a strategic approach to partnering with Toni – CEO to turn vision into precision execution, delivering exceptional value to Secom customers and sustainable growth for SECOM.  Thank You to Our Sponsors