← Terms Watch archive

AI Vendor Terms Watch

What the AI vendors' contracts actually say — and the week they change it
Issue 001 Friday 18 September 2026 A Bleu Nickel publication
Corrections — 18 September 2026

Three items in this issue ran ahead of their sources and have been corrected in place, and one has been withdrawn. This notice is permanent. All four were caught by re-reading the vendors' own pages against what we published.

1. Amazon Bedrock retention. As first published, this issue said the model provider “holds a veto” over retention and that your own account setting was “not the deciding vote.” That is not what AWS publishes. AWS's documentation states that “you always control your retention policy” — an account set to no retention causes the request to be blocked, not overridden — and that “the model provider does not review your content.” The issue also said retention is expressed as one of four modes; AWS names five. Corrected.

2. Mistral stateful exceptions. As first published, this issue implied batch processing sits outside Mistral's retention rule. Mistral's Privacy Policy names the Agents API and the Fine-Tuning API; the word “batch” does not appear. Corrected.

3. “Trains by default” — Mistral and Cohere. The comparison table stated as fact that both train on customer data by default. Neither company publishes that. Mistral's commercial terms make the default product-dependent without naming which products are which; Cohere documents an opt-out control without ever stating what happens if you leave it on. Both rows now report what the sources say and flag the rest as something to confirm in your own agreement.

4. DeepSeek price-change notice — withdrawn, not corrected. The price-notice table carried a row stating that DeepSeek's pricing page sets no notice period. That is a negative claim about another company's terms — the hardest kind to stand behind — and we have not been able to re-retrieve the page to confirm it. The row has been removed rather than left standing. It will return if and when the page has been read and captured.

Your rate card is reviewed by three people before you sign. The terms behind it are reviewed by nobody, and they move without an announcement. This is a weekly read of what the frontier AI vendors publish, what changed, and the question worth asking before you sign.

The Lead

“Zero data retention” is not a setting. It is a contract term with a scope, and the scope has holes the trust page does not describe.

A client answers a security questionnaire: does your AI provider retain customer data? They read the vendor's trust page, see “zero data retention,” and answer no.

That answer is usually wrong — and not because the vendor lied. A questionnaire has a checkbox. The reality has four separate mechanisms, and answering for one while assuming it covers the others is how a confident answer becomes a false one.

MechanismWhy it gets missed
Training useEveryone assumes “no by default” is universal across providers. It is not — see below.
Abuse monitoringData held so the vendor can investigate misuse. This survives most ZDR arrangements.
Operational loggingData a feature needs in order to work at all. Eligibility is decided per feature, not per account.
Sub-processor retentionWhat the vendor's own vendors keep. The weakest-documented leg across every provider — nobody publishes it.

Provider position, side by side

Provider Trains on API data by default The exclusion that matters most
OpenAINo Safety-retention override for severe-risk investigations; API inputs and outputs may be securely retained up to 30 days, except for certain endpoints and features listed in OpenAI's platform documentation.
AnthropicNo Covered Models are unavailable under ZDR unless expressly authorized by Anthropic. Flagged sessions held up to two years regardless of arrangement — including under ZDR and under a HIPAA agreement.
Google GeminiNo on paid tiers. Free tier and AI Studio usage may be human-reviewed Search and Maps grounding retain 30 days, with no opt-out. ZDR is applied for per project.
MistralTerms make the default product-dependent without naming which products; an account-level opt-out control is published. Confirm for your agreement. Privacy Policy names Agents API and Fine-Tuning API as the stateful exceptions. ZDR is a written request that can be denied.
CohereNot stated — Cohere documents an opt-out Data Controls toggle but does not publish that it trains by default. Confirm for your agreement. Usage metadata is never covered. ZDR is enterprise-agreement only.
AWS BedrockNo Retention is a mode setting — but only for models that permit it. AWS states “you always control your retention policy” — an account set to no retention has the request blocked rather than overridden, and review is carried out by AWS within the AWS boundary.

⚠ Provider positions verified 8 September 2026 against each provider's own published documentation. Re-verify before any live negotiation — these pages change without announcement, which is the point of this newsletter.

The finding worth your attention

The Covered Models carve-out is a one-line diff. Anthropic designates certain models as Covered Models — currently the Claude Fable and Mythos 5 and 5.1 families. Those carry a 30-day retention requirement and are unavailable under zero data retention unless expressly authorised, even for a customer already holding an org-wide ZDR arrangement.

An engineer swaps a model string in a config file, doing exactly what you would want them to do. Code review does not flag it. The API response does not signal it. The contractual data posture has changed on one line, and the first anyone notices is the next audit.

And eligibility is per feature, not per account. Anthropic's published table: batch jobs retain 29 days · code-execution containers 30 days · Files API content persists until deleted. Mistral's Privacy Policy names two stateful exceptions to its thirty-day rule — the Agents API (input and output kept until you terminate the account) and the Fine-Tuning API (data kept until you delete it or terminate). So a client with a signed ZDR arrangement who turns on an agent framework, starts uploading files, or moves a workload onto batch processing to cut cost has moved data outside the arrangement. Nobody signed anything. Somebody used a feature.

One more structural point on Bedrock. Retention is expressed as one of five named modes rather than in days, and each model declares which modes it allows. AWS states that “you always control your retention policy” — but control and access are not the same thing. If your account is set to no retention and you invoke a model that requires retention, Bedrock blocks the request and returns an error. Your setting holds; the model becomes unavailable to you. AWS also states that review under aws_review is carried out within the AWS boundary and that “the model provider does not review your content.” The practical consequence is a procurement one: a model your team names in a config file may simply not run under the retention posture you signed up to, and nobody will tell you in advance which ones.

Also This Week

The price-change clock starts when a web page is edited — not when anyone tells you

Every AI procurement reviews the rate card. Almost none reviews the clause governing what the vendor must do before that rate card changes. The answers diverge far more than the prices do.

VendorWhere the clause livesStated notice before a price change
OpenAIServices Agreement §6.614 days after posting on the Pricing Page
AnthropicCommercial Terms §H.130 days after posting, or when the customer otherwise receives notice — whichever is earlier
GoogleGemini API Additional Terms30 days after posting; new paid services can take effect immediately

⚠ Clause text pulled live 14 August 2026. Section numbers cited so you can check them yourself. A DeepSeek row was withdrawn on 18 September 2026 — see the corrections notice at the top.

Read the trigger: “after they are posted.” The clock does not start when the vendor tells the customer. It starts when the vendor edits a web page. If nobody on your side is watching that page, a full 30-day notice period can elapse without a single person at your company seeing it.

The same structure governs model deprecation and rate limits at most providers. Three clause families, one root defect: the vendor's obligation is discharged by publishing, not by communicating.

Diary

Dated items already on the record

The Ask

Five questions for vendor selection — ask them now, not at questionnaire time

  1. Which specific models are in scope for the retention arrangement — and is that scope written into the contract, or assumed?
  2. Which features are excluded? Batch, file storage, code execution, agent frameworks and caching are commonly outside the arrangement even when the base API is inside it.
  3. What does abuse monitoring retain, and for how long? Ask this one separately from everything else. It is the question most likely to produce a number that contradicts the trust page.
  4. Does the arrangement cover a second organisation or project under the same account? At both Anthropic and Google it does not automatically inherit.
  5. What do your sub-processors retain? You probably will not get a satisfying answer. Getting “we do not publish that” in writing is still better than assuming a number that does not exist.

“You told me you have zero data retention. I believe you. Now show me which models, which features, and what the abuse-monitoring team keeps — because the honest answer to that question is a table, and the questionnaire only has a checkbox.”