I Read the Terms for 19 AI Agent Products. Zero Indemnify You for What the Agent Does.
Aug 15, 2026 · 7 min read · by Jordan Kwan
TL;DR: You do. I read the public terms of 19 AI agent products on 15 August 2026 and coded five liability questions in each. Zero of the 19 indemnities name autonomous or agentic decisions, and zero give the customer a contractual right to decision logs or to suspend the agent. Fifteen cap the vendor's total liability at fees paid or a fixed sum, and the number $100 or less appears in seven of them.
In February 2026 a team at Clifford Chance published a short argument: the software contracts everyone signs were not written for software that acts. Their piece says suppliers provide service "on an 'as is' basis, disclaiming responsibility for accuracy, reliability and fitness for purpose," cap "the supplier's total liability at the fees paid," and exclude exactly the losses an agent produces, naming "lost profits from a mispriced product" and "loss of data, such as an AI coding agent deleting a database."
That is a claim about documents, and documents are checkable. I am not a lawyer and this is not legal advice: it is a reading of what nineteen companies wrote down.
What did I actually count?
I picked 25 named agent products across consumer assistants, coding agents and enterprise automation platforms, opened each one's public terms of service, master agreement or acceptable use policy on 15 August 2026, and recorded the vendor's own published version date. Then five binaries each:
- Does the document disclaim liability for AI output or for actions the agent takes, in language that names them?
- Is total liability capped, and at what?
- Does the document put an obligation on the customer to review output before it takes effect?
- Does any indemnity name autonomous or agentic decisions?
- Does the customer get a contractual right to decision logs or to suspend the agent?
Six of the 25 are not in the results. Manus, Glean, Windsurf and Salesforce's master agreement returned no document text to a fetcher, and Sierra and n8n returned 404 at every legal URL I tried. I did not substitute replacements to keep a round number. The denominator is 19: OpenAI, Anthropic, xAI, Google, Microsoft, Perplexity, Cursor, GitHub, Replit, Lovable, Vercel, Cognition, Zapier, LangChain, Slack, Intercom, Atlassian, HubSpot and Lindy.
All of these can change tomorrow without notice, which is why the version dates matter: Cursor's was updated two days before I read it.
Who is on the hook when the agent acts?
You are, and eight of the nineteen say so in language that names the agent rather than the software. xAI is the only one that builds a defined term for it: its terms, effective 26 June 2026, define "Agentic Actions" as Grok taking "autonomous actions on your behalf... including web browsing, code execution, sending communications, modifying files... or interactions with third-party services, including financial institutions," then states that "xAI makes no representations regarding the accuracy, safety, or legality of any Agentic Action and disclaims all liability for Agentic Actions."
Vercel is nearly as direct: "Vercel is not responsible for any loss, damage, liability or other consequence arising from actions taken on your behalf by any Third Party Tools or AI Functionality." Cursor's section 1.7, covering auto-run, is one sentence in capitals: "YOU ARE SOLELY RESPONSIBLE FOR ANY IMPACT RESULTING FROM USE OF THIS FEATURE." The other eleven rely on the generic warranty disclaimer, which reaches the same place less honestly.
Seven documents go further and put a positive duty on you. GitHub section J: "You are responsible for reviewing, testing, and validating any Output before use." Anthropic: it is the customer's responsibility to evaluate outputs "including where human review is appropriate, before using or sharing Outputs." Vercel says the same, adding "including human review as appropriate or legally required."
Read that against the sales pitch. The product is sold on the promise that it acts without you. The contract is written on the assumption that you check its work, and nobody sells the instrumentation for that assumption: zero of 20 agent platforms rate-limit approval requests or acknowledge reviewer fatigue.
How much can you actually recover?
Fifteen of the nineteen state a number. Fourteen of those fifteen tie it to fees. OpenAI, Anthropic, Lovable, LangChain, Intercom and Atlassian all land on twelve months of fees paid. Microsoft's consumer agreement caps at one month's fee, "or up to $10.00 if the Services are free."
Seven documents contain the figure $100 or less. Four use it as a floor: xAI, Perplexity, Cursor and Vercel cap at the greater of $100 or some months of fees, which protects a free user and does nothing for a paying one. Slack's user terms set a flat ceiling: "OUR MAXIMUM AGGREGATE LIABILITY TO YOU FOR ANY BREACH OF THE USER TERMS IS ONE HUNDRED DOLLARS ($100) IN THE AGGREGATE." Lindy, whose agents send email and place phone calls, caps at "THE LESSER OF THE AMOUNT PAID... DURING THE SIX (6) MONTH PERIOD PRIOR... OR $100.00 USD." Lesser, not greater. It is the tightest cap in the sample, under a product that transacts on your behalf.
Worth knowing what those fees are before treating the cap as meaningful. The full frontier AI stack now runs about $1,400 a month, so twelve months of fees is real money, and still not what a deleted production database costs.
Does any indemnity mention the agent?
No. Zero of nineteen. Every indemnity I read runs on one of two rails: the vendor defends you against third-party intellectual property claims about the service, or you defend the vendor against claims arising from your content or misuse. Neither rail is where an agent error lands. Clifford Chance predicted exactly this, calling standard indemnities "generally narrow in nature" and noting they "do not typically extend to an AI agent's acts or omissions." I looked for the counterexample in nineteen documents and did not find one.
Can you get the logs or pull the plug?
Also no, same score. Zero of nineteen give the customer a contractual right to decision traces or to suspend the agent. Suspension rights exist in almost every document and all point one way: the vendor may suspend you. xAI reserves the right to "disable Agentic Actions" that violate its policies, which is a control the vendor holds, not one you are granted. LangChain's terms give you thirty days to export your data after termination, the closest thing to a customer-side right in the set, and that is data portability, not an audit trail.
Why is a card network filling the gap?
Because contracts did not. On 14 April 2026 American Express announced its Agentic Commerce Experiences developer kit alongside Amex Agent Purchase Protection, which the release calls "an industry-first commitment to extend its backing to Card Member purchases made by registered AI agents across its network." (The newsroom page renders client-side, so I read the release text off its wire distribution.) Fortune's coverage quotes Amex innovation head Luke Gebb noting there have so far been "as many press releases as transactions" in agentic commerce.
Read the scope before you relax. The protection is for Amex cardmembers, on Amex's closed-loop network, for agents that have been through Amex's own Agent Registration service, where the agent transmits authenticated purchase intent. That is not "cards now cover agent mistakes." It is one issuer selling trust into a gap that nineteen software contracts leave open, which tells you the gap is real enough to underwrite even while the consumer surface stays tiny: 8 of 33 named merchants serve a live agent-checkout manifest, and all eight are Shopify stores.
What does this not prove?
It does not prove any of these terms would hold up. Caps get read down, consumer statutes override, and negotiated enterprise agreements differ from the public ones I read: if you are on a signed MSA with a bespoke indemnity, my count says nothing about you. It also does not prove the vendors are wrong to write it this way. A supplier that cannot inspect your prompts, tool grants or approval settings has a defensible reason to disclaim what the agent does with them.
What it does prove is that the default is uniform and the default is you. Which makes the operator question narrower than "is this agent good." The question is what a wrong branch costs, because the contract has already answered who pays for it. And if the answer is "more than twelve months of subscription fees," you are not buying a vendor's risk appetite. You are renting their optimism. The other half of that bet is whether the framework underneath it is still maintained next year.
Written by Jordan Kwan, founder of Reachium.
I build Reachium, the LinkedIn outreach platform behind the tactics you just read. Same brain, live product.
See what Reachium does ↗