[codicts-css-switcher id=”346″]

Global Law Experts Logo
ai vendor contracts france

Our Expert in France

  • GOLD

How to Draft AI Vendor Contracts in France (2026): IP Warranties, Training Data & Liability

By Global Law Experts
– posted 2 hours ago

AI vendor contracts France buyers sign in 2026 carry a distinct legal fingerprint: French copyright law (droit d’auteur), the EU sui generis database right, GDPR obligations enforced by the CNIL, and the phased obligations of the EU AI Act all converge in a single procurement decision. In-house counsel, procurement leads and product owners negotiating access to AI models, datasets and SaaS integrations must now allocate risk across intellectual property, data protection and product-liability domains simultaneously. This guide sets out practical drafting positions, sample clause language and negotiation redlines tailored to French law, so that legal and procurement teams can move from a vendor’s standard paper to a defensible, France-ready contract.

Every recommendation below is framed as a drafting position, not a legal conclusion, adapt each clause to your facts and take advice before signing.

This content is for general information and does not constitute legal advice.

1. Quick summary & TL;DR, what French buyers need to know

Busy readers should focus on five immediate risks before signing any AI vendor contract in France:

  • Training-data provenance. Demand documented chain-of-title and warranties that training data was lawfully sourced, licensed or consented, this is the single biggest source of downstream IP and GDPR exposure.
  • IP warranties and non-infringement. Insist on representations covering copyright, droits voisins (neighbouring rights), sui generis database rights and open-source licence compliance, backed by a broad indemnity.
  • Model ownership and export rights. Never assume you own a model trained on your data, spell out licences, weights, and extractability expressly.
  • Liability allocation. Negotiate caps, carve-outs for IP infringement and wilful misconduct, and require professional indemnity (E&O) and cyber insurance.
  • Regulatory compliance. Confirm the lawful basis for processing personal data, a completed DPIA where required, and clear controller/processor roles consistent with CNIL guidance and the EU AI Act.

2. Legal background: IP, database rights, contract & liability law in France

Before drafting any AI vendor contracts France teams should understand the legal architecture that governs the deal. French AI contracting sits at the intersection of the Code de la propriété intellectuelle, the Code civil, the GDPR, CNIL guidance and the EU AI Act. Each layer imposes obligations that cannot be waived away by boilerplate.

Key statutes to cite

The Code de la propriété intellectuelle (CPI) governs copyright, the exclusive rights of reproduction and representation, and, critically for France, the author’s moral rights (droit moral). Moral rights in France are generally regarded as perpetual, inalienable and imprescriptible, and cannot be fully waived in advance, which affects any clause purporting to secure unrestricted downstream use of protected works within training data or outputs. On the contractual side, the Code civil governs the formation of contracts, remedies for breach, and the enforceability of limitation-of-liability clauses. French courts scrutinise liability caps that would deprive an essential obligation of its substance, so caps must be drafted with care to remain enforceable.

Sui generis database right and its implications

The EU sui generis database right (droit sui generis des bases de données), derived from Directive 96/9/EC and implemented in French law within the CPI, protects the substantial investment made in obtaining, verifying or presenting the contents of a database, independently of any copyright in the underlying content. For AI training, this matters enormously: extracting and reusing a substantial part of a protected database to train a model can infringe the database maker’s rights, subject to applicable exceptions (including the text-and-data-mining exceptions introduced by Directive (EU) 2019/790 and transposed into French law).

Your vendor’s IP warranty should therefore expressly cover lawful extraction and reuse under any applicable database right, and require evidence of consent or a licence for third-party databases incorporated into the training corpus.

GDPR, CNIL and the EU AI Act

Where training data includes personal data, the GDPR (Regulation (EU) 2016/679), together with the French Loi Informatique et Libertés, requires a lawful basis for processing, and a Data Protection Impact Assessment (DPIA) where the processing is likely to result in high risk to individuals. The CNIL, France’s data protection regulator, has published guidance (“how-to sheets”/recommendations) on artificial intelligence and data protection setting out its expectations on lawful basis, data minimisation, documentation of provenance and data subject rights. Layered on top, the EU AI Act (Regulation (EU) 2024/1689) introduces obligations calibrated to risk classification, including transparency and technical documentation, and, for high-risk systems, conformity requirements for providers, phased in over a transition period following its 2024 entry into force.

A well-drafted contract should allocate these obligations expressly between vendor and buyer rather than leaving them to statutory default.

3. Drafting IP warranties and title assurances (copyright, database & OSS)

IP warranties are the backbone of any AI vendor contract. In France, generic “the vendor warrants it has all necessary rights” language is inadequate because it does not engage the specific French rights, copyright, neighbouring rights, database rights and moral rights, that can be asserted against a deployed AI system. The goal is to obtain specific, actionable representations with meaningful remedies.

Types of representations

At a minimum, the buyer should extract representations that the vendor:

  • Owns or is validly licensed to use all training data, models, software and third-party content supplied under the agreement.
  • Has authority to grant the licences and rights described in the contract, including for training and inference.
  • Warrants non-infringement of any third-party copyright, droits voisins, sui generis database rights, trade marks and patents.
  • Has cleared moral rights to the extent lawfully possible, and discloses any residual moral-rights constraints that could affect use of outputs.
  • Complies with open-source licence terms for every open-source component embedded in the model or delivery stack.

Model clause, sample language (for negotiation only, adapt to facts): “The Supplier represents and warrants that (i) it holds all rights, licences and consents necessary to provide the Model and Training Data and to grant the rights set out in this Agreement; (ii) the Model, Training Data and Outputs do not and will not infringe any third-party intellectual property right, including any copyright, neighbouring right (droits voisins) or sui generis database right under French or EU law; and (iii) all open-source components are used in compliance with their applicable licences.”

Sublicensing and rights to use third-party content

Many AI vendors aggregate third-party data and pre-trained components. The buyer needs assurance that the vendor’s own upstream licences permit sublicensing to the buyer for the buyer’s intended uses, including internal training, fine-tuning and commercial inference. Require the vendor to warrant the scope of upstream licences and to flag any field-of-use or territorial restrictions. Where the vendor cannot warrant a clean chain, negotiate a corresponding narrowing of your permitted uses or an enhanced indemnity.

Open-source components and compliance warranties

Open-source software (OSS) is ubiquitous in AI stacks, and licence non-compliance, for example, failing to meet copyleft obligations under the GPL, or attribution requirements under Apache 2.0, creates real legal exposure. Ask the vendor to deliver a software bill of materials (SBOM) listing all OSS components and their licences, and to warrant that its use complies with each licence. Where copyleft licences appear in components that touch your proprietary code, insist on architectural separation or a written explanation of why no copyleft obligation is triggered.

Remedies, escrow and repair obligations

Warranties are only as good as their remedies. Tie a breach of the IP warranties to a layered remedy: first, the vendor must, at its cost, procure the right to continue use, modify the deliverable to make it non-infringing, or replace it with equivalent non-infringing functionality; and second, the vendor must indemnify the buyer for third-party claims (see Section 6). For business-critical models, consider a source-and-documentation escrow so that the buyer can maintain the system if the vendor defaults or becomes insolvent.

4. Training-data licensing, provenance and audit rights in AI vendor contracts France

Training-data licensing is where IP, data protection and provenance risk concentrate. In AI vendor contracts France buyers should treat the data licence as a distinct, carefully scoped grant, not an afterthought bundled into the software licence.

Licence form: scope and permitted uses

Define the licence with precision along several axes:

  • Duration: limited term versus perpetual, and what happens to models already trained if the licence expires.
  • Exclusivity: exclusive versus non-exclusive access to the dataset.
  • Permitted uses: training, fine-tuning, validation, inference, and whether outputs may be commercialised.
  • Derivatives: whether the buyer may create and retain derived datasets or fine-tuned model variants.

Model clause, sample language (for negotiation only, adapt to facts): “The Supplier grants the Customer a non-exclusive, worldwide, royalty-free licence to use the Training Data solely for the purpose of training, fine-tuning, validating and operating the Model, and to use resulting Outputs for the Customer’s internal and commercial purposes, subject to the Supplier’s warranties in Clause [X].”

Provenance documentation and seller warranties

Provenance is the chain-of-title for data. The CNIL’s guidance on artificial intelligence and data protection stresses documenting the sources of training data, the legal basis for processing personal data, and records of consent where consent is relied upon. Require the vendor to warrant the provenance of every dataset and to deliver supporting records: data source registers, licence agreements with upstream providers, consent records where applicable, and any records of web-scraping methodology and the rights basis on which it relied. Inadequate provenance should be a defined breach with specific remedial obligations.

Audit and inspection rights

Warranties without verification are weak. Negotiate a right to inspect provenance records, to sample dataset records, and to review processing logs, and the ability to appoint an independent auditor bound by confidentiality, on reasonable notice. Specify what happens if an audit reveals inadequate provenance: rectification, replacement of the offending data, re-training at the vendor’s cost, or termination with a refund.

Data subject rights, deletion and erasure

Where personal data is involved, the contract must operationalise data subject rights under the GDPR, including access, rectification and erasure. Address the practical difficulty of “unlearning” personal data from a trained model: require the vendor to describe its process for honouring erasure requests, to delete personal data from active training corpora, and to document mitigations where full removal from model weights is technically infeasible. Allocate controller and processor roles clearly, and include instructions consistent with Article 28 of the GDPR where the vendor acts as a processor.

5. Model ownership, model training rights and derived outputs

One of the most contested questions in AI contracting is deceptively simple: who owns the model? The answer in France is contractual, there is no statutory default that automatically transfers ownership of a model trained on a customer’s data to the customer. Silence generally favours the vendor.

Who owns the model?

There are three principal structures. First, the vendor retains ownership of the model but grants the customer a broad licence, ideally covering training, inference, export and continued use after termination. Second, the vendor assigns the model weights to the customer, transferring ownership outright. Third, the parties agree joint ownership, which sounds equitable but creates operational friction over exploitation and improvement rights. For most buyers, an explicit, broad and irrevocable licence delivers the commercial benefits of ownership without the negotiation cost of an assignment.

Rights in model parameters, weights and outputs

Distinguish carefully between the model architecture, the trained parameters or weights, and the outputs the model generates. A buyer may negotiate rights to the weights (the trained artefact reflecting the buyer’s data) even where the vendor retains its underlying architecture and platform. Outputs raise separate questions: address ownership of, and rights to use, generated content, and confirm that the buyer is free to use outputs commercially without further royalty. Note the French copyright constraint that droit d’auteur requires a human author and an original creation reflecting the author’s own intellectual creation; purely machine-generated outputs without sufficient human creative input may not attract copyright protection, a factor for buyers relying on IP protection for AI-generated deliverables.

Assignment vs. licence vs. contractual extractability

If ownership is not transferred, “extractability” becomes vital: the practical right to export the trained model, weights and associated documentation on termination so the buyer is not locked in. Draft an express extractability clause specifying formats, timelines and the technical assistance the vendor must provide. A negotiation checklist for model rights should confirm: licence scope, weight export rights, permitted derivatives, post-termination continuation, and whether the vendor may reuse insights derived from the buyer’s data to improve models sold to competitors.

6. Liability allocation, indemnities and insurance for AI harms

Liability allocation is where AI vendor contracts France negotiations most often stall, because the risks, third-party IP claims arising from training data, and downstream harm caused by model outputs, are novel and potentially large. The Code civil governs the enforceability of limitation-of-liability clauses, and French courts will generally not enforce a cap that empties an essential contractual obligation of meaning.

Carve-outs and triggers

Identify the risk events that must be addressed: IP infringement arising from the training data or model; personal-data breaches; and harm caused by erroneous or unsafe model outputs. Each requires a defined trigger. IP infringement and data-protection breaches should typically be carved out of the general liability cap or subject to a higher, separate cap, because they can generate open-ended third-party exposure.

Indemnity vs. warranty remedies

A warranty gives the buyer a claim for breach; an indemnity provides a direct promise to cover defined losses, often including third-party claims, without the buyer needing to prove breach in the same way. For third-party IP infringement claims, insist on an indemnity that covers defence costs, settlements and damages, with the vendor conducting or funding the defence subject to the buyer’s reasonable involvement.

Caps, baskets and exclusions

Negotiate the overall liability cap by reference to contract value (for example, a multiple of annual fees), with a higher or unlimited cap for IP indemnities, data-protection breaches, confidentiality breaches, and losses arising from gross negligence (faute lourde) or wilful misconduct (faute dolosive), categories that French law generally will not permit a party to exclude by contract. Use a basket or threshold to filter trivial claims, but ensure it does not apply to indemnified third-party claims.

Insurance considerations

Contractual promises are only as good as the vendor’s balance sheet. Require the vendor to maintain professional indemnity / errors-and-omissions (E&O) cover and cyber insurance with defined minimum limits, to provide certificates on request, and, where appropriate and available under the relevant policy, to name the buyer as an additional insured. Insurance backstops the indemnity if the vendor cannot pay.

Comparison: Indemnity vs. Liability Cap vs. Insurance, when each protects you

Mechanism What it covers Pros for buyer Limitations Recommended drafting points
Indemnity for IP infringement Third-party claims that the model or training data infringes IP, including defence costs, settlements and damages Direct, loss-shifting promise; can cover claims without proving breach; vendor conducts/funds defence Only as good as vendor’s solvency; may be capped or carved down; conduct-of-claims disputes Carve out of general cap or set higher sub-cap; cover defence costs; define notice and conduct-of-claim procedure; include replacement/procure-rights remedy
Contractual liability cap Caps the vendor’s aggregate financial exposure for breach and general liability Predictable exposure; standard commercial mechanism May be unenforceable if it guts an essential obligation; excludes categories French law won’t allow to be capped Link to contract value; exclude gross negligence, wilful misconduct, IP and data breaches; ensure the cap does not defeat the essential obligation
Professional indemnity / E&O insurance Insurer-backed cover for the vendor’s errors, omissions and, via cyber cover, data incidents Financial backstop independent of vendor’s balance sheet; supports indemnity recovery Policy exclusions and limits; claims-made timing; insurer defences Specify minimum limits; require certificates; consider named-insured status; align policy scope with indemnified risks

7. Operational & technical clauses to reduce IP and compliance risk

Beyond the headline IP and liability terms, operational clauses materially reduce risk over the life of the deployment and preserve evidence for any future dispute.

Logging, provenance, versioning and rollback

Require the vendor to maintain audit logs, provenance records, model version histories and rollback capability. Model versioning lets the buyer identify which model produced a given output, and rollback allows a return to a known-good version if a new release introduces infringing or unsafe behaviour. Where regulatory compliance or safety demands it, include explainability and transparency obligations, documented model descriptions, known limitations, and access to model cards or technical documentation consistent with EU AI Act transparency expectations.

Model clause, sample language (for negotiation only, adapt to facts): “The Supplier shall maintain, for a period of not less than [X] years, complete audit logs of Model versions, training-data provenance and material configuration changes, and shall provide the Customer with the ability to roll back to the immediately preceding Model version on request.”

Security, patching and subprocessing controls

Impose security standards, timely patching obligations, and controls over subprocessors, including a right to approve or object to new subprocessors and to receive notice of changes, consistent with GDPR requirements where personal data is processed.

SLA service credits and mitigation

Define service levels, remedies for failure (service credits), and mitigation obligations, so that operational failures have contractual consequences short of termination and litigation.

8. Negotiation checklist & sample redlines (practical playbook)

Use a priority matrix to focus negotiation capital where it matters most:

  • Must have: Specific IP warranties (copyright, droits voisins, sui generis database right, OSS); uncapped or high-cap IP indemnity; provenance warranties and audit rights; lawful-basis and DPIA confirmation; model licence/export rights; carve-outs for gross negligence and wilful misconduct.
  • Should have: Source/documentation escrow for critical models; independent-auditor rights; E&O and cyber insurance with minimum limits; model versioning and rollback; SBOM delivery.
  • Nice to have: Joint governance forum; enhanced explainability documentation; extended data-retention and log-retention periods; most-favoured-customer improvements.

Typical buyer-side redlines include: converting a bare “sufficient rights” warranty into an enumerated non-infringement warranty; adding sui generis database right and neighbouring rights to the infringement carve-out; moving IP and data-protection claims outside the general cap; and inserting an express extractability clause. A useful fallback where a vendor resists an uncapped IP indemnity is a materially higher sub-cap combined with mandatory E&O insurance and a procure/modify/replace obligation.

9. Conclusion and next steps

Drafting robust AI vendor contracts France buyers can rely on in 2026 requires treating IP warranties, training-data licensing, model ownership and liability allocation as interlocking components rather than isolated clauses. The recurring theme is specificity: enumerate the French rights at stake, demand documented provenance, define model and output rights expressly, and back warranties with meaningful indemnities and insurance. Legal and procurement teams should build a standard clause library, a provenance-evidence checklist, and a priority matrix so that each new AI procurement starts from a defensible baseline rather than the vendor’s paper. As an immediate next step, preserve logs and provenance records from day one to support any future dispute, and confirm your GDPR lawful basis and DPIA position before deployment.

Consult qualified Intellectual Property lawyers in France before finalising any agreement.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Nathalie Marchand at d’Alverny Avocats, a member of the Global Law Experts network.

Sources

  1. Code de la propriété intellectuelle (consolidated), Legifrance
  2. Code civil (consolidated), Legifrance
  3. GDPR, Regulation (EU) 2016/679 (EUR-Lex)
  4. CNIL, Artificial Intelligence and Data Protection guidance
  5. INPI, Institut national de la propriété industrielle
  6. EU AI Act, Regulation (EU) 2024/1689 (EUR-Lex)
  7. Directive 96/9/EC on the legal protection of databases (EUR-Lex)
  8. Directive (EU) 2019/790 on copyright in the Digital Single Market (EUR-Lex)

FAQs

What IP warranties should I insist on from an AI vendor in France?
Require representations on title to training data, non-infringement of copyright, droits voisins and sui generis database rights, authority to license, and open-source compliance, plus a clear scope of permitted uses. Tie remedies to repair, replacement and indemnity for third-party claims, referencing the Code de la propriété intellectuelle.
Ownership is contractual, there is no automatic transfer under French law. Options are: the vendor retains the model but grants a broad licence (training, inference and export rights); assignment of the model weights to you; or joint ownership. Prefer an explicit, broad licence rather than an assumed ownership position.
Yes, provided you have a lawful basis (such as consent, legitimate interest or contract, depending on the circumstances), complete a DPIA where the processing is high-risk, and apply CNIL-recommended safeguards. The contract should allocate controller and processor roles clearly and define deletion and erasure protocols.
Negotiate a cap linked to contract value, carve out wilful misconduct and gross negligence (categories French law generally will not let a party exclude), separately treat IP and data-protection claims, and require the vendor to maintain E&O and cyber insurance with minimum limits and, where appropriate, named-insured status.
Include the right to inspect provenance records, sample dataset records and processing logs, and to appoint an independent auditor subject to confidentiality and reasonable notice. Specify remedial steps, rectification, re-training at the vendor’s cost, or termination, if provenance is inadequate.
Yes. If datasets are protected by the EU sui generis database right, ensure the vendor’s warranty covers lawful extraction and reuse and request proof of consent or licences for any third-party databases used in the training corpus, taking into account any applicable text-and-data-mining exceptions.
Where necessary for regulatory compliance or safety, include obligations for documented model descriptions, high-level explanations, known limitations and access to model cards or technical documentation, consistent with EU AI Act transparency expectations.
Preserve logs and provenance records immediately, notify the vendor as the contract requires, activate the indemnity procedures, seek remediation or replacement, and follow the dispute escalation clause (chosen court or ADR). Robust logging from day one is essential to defend such claims.
By Dr. Hassan Elhais

posted 4 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Draft AI Vendor Contracts in France (2026): IP Warranties, Training Data & Liability

Send welcome message

Custom Message