Limitations of Liability

A limitation of liability is a contract clause that caps or restricts how much one party can be required to pay the other if something goes wrong. It sets a ceiling on damages, and often excludes certain kinds of loss entirely, which shifts where risk lands between a vendor and its customer.

In Depth

Almost every commercial contract has one. A limitation of liability clause usually does two things. It caps total liability, often at the fees paid over some period such as the trailing twelve months. And it excludes categories of damages, most commonly indirect, consequential, and punitive damages, so a party is not on the hook for a customer's lost profits or downstream losses. The clause is where two parties decide who absorbs a bad outcome before one ever happens.

Some liabilities are usually carved out of the cap, meaning they stay uncapped. Indemnification obligations, breaches of confidentiality, intellectual-property infringement, and gross negligence or willful misconduct are the common examples. These excluded items are the ones a customer refuses to limit, because they are the failures that can cause the most harm.

For a vendor, the clause is a direct lever on risk, but it has limits of its own. A cap is only as good as the counterparty's willingness to accept it, and enterprise customers routinely push for higher caps or uncapped carve-outs, especially on indemnities, right where AI failures create exposure. A contractual cap also does nothing if you lack the assets or the insurance to pay up to it.

What It Looks Like

A software vendor's standard contract caps its liability at twelve months of fees and waives consequential damages. A customer suffers a loss and sues. The cap holds for a routine breach, limiting the vendor's exposure to the fees paid. But the customer routes its claim through the indemnity clause, which the contract left uncapped, and the consequential-damages waiver is contested. The vendor learns that the comfortable-looking cap did not apply to the one obligation that mattered.

Why It Matters For AI Vendors

A limitation of liability clause and an insurance policy solve overlapping problems from opposite directions. The clause tries to shrink what you can owe. Insurance funds what you do owe. Neither is enough on its own: a cap you negotiated can be pierced by an uncapped carve-out, and coverage you bought can fall short of the liability you actually agreed to. Reading the two together, how much you can be liable for and how much of that is actually funded, is how a vendor understands its real exposure. It matters more with AI, where customers increasingly demand uncapped indemnities for the exact failure modes a legacy policy now excludes.

Common Questions

Indirect, consequential, and punitive damages are commonly waived. Several obligations are also carved out so they stay uncapped: indemnities, confidentiality breaches, IP infringement, and gross negligence or willful misconduct.
No. The clause limits what you can be required to pay. Insurance provides the money to pay it. A cap does not help if a carve-out makes the liability uncapped, and it does not matter if you cannot fund the amount within the cap. See AI Liability Insurance.
Because a low cap shifts risk onto them. When they deploy a vendor's product into their own environment, they want the vendor's liability high enough, or uncapped for key obligations, to actually cover the harm a failure could cause.
← PreviousJailbreak Next →MITRE ATLAS

See where your AI agents stand.

Get an Agent Trust Score, map your liability exposure, and find out what it takes to make your AI agents insurable.