What Anthropic's Commercial Terms Reveal About AI Governance
Anthropic's Commercial Terms contain strong data ownership and training prohibition clauses, but gaping holes around model change governance, uptime commitments, and one-sided suspension rights. Enterprise procurement teams should verify the DPA, negotiate suspension terms for regulated workloads, and build their own output evaluation pipelines. The contract is the governance infrastructure. Read it before you sign.
The Vendor: Anthropic's Enterprise Position
Anthropic sells itself as the safety-first AI company. Its Commercial Terms of Service (effective June 17, 2025) are the legal foundation for every enterprise API customer. If you procure Claude through the API or a cloud marketplace, these are the terms that define your rights.
But enterprise AI governance is not just about model safety research papers. It is about what the contract actually guarantees. Can you prove to your board that the vendor does not train on your data? That you own your outputs? That the vendor will tell you before it changes the model you depend on?
We read the Commercial Terms so you do not have to. Here is what they reveal about Anthropic's governance posture and the gaps your procurement team should probe.
What the Terms Actually Guarantee
Data Ownership: Customer Retains Everything
Section B is the strongest governance provision in the document. Anthropic agrees that the customer retains all rights to its Inputs and owns its Outputs. More importantly, Anthropic disclaims any rights it might receive and assigns its own right, title, and interest in Outputs to the customer. This is not a licence. It is an assignment.
The training prohibition is explicit: "Anthropic may not train models on Customer Content from Services." This is a hard contractual commitment, not a policy statement that can change tomorrow. For enterprises subject to GDPR, APRA CPS 230, or ISO 42001 clause 7.5 (documented information), this clause is the single most important governance signal in the agreement.
Data Processing Addendum: Incorporated by Reference
Section C incorporates the Anthropic Data Processing Addendum (DPA) by reference. This is standard practice for enterprise SaaS, but the governance team needs to read the DPA separately. It is not included in the Terms body and can be updated independently. The DPA covers cross-border transfers, sub-processor management, and breach notification timelines. If your organisation has not read it, you are relying on terms you have not seen.
Confidentiality: Customer Content Is Protected
Section E classifies Customer Content as the customer's Confidential Information. Anthropic as recipient must protect it with "no less than reasonable care" and can only share it with employees, agents, and advisors who need to know. On request, Anthropic must destroy the customer's Confidential Information, subject to automated backup retention. This aligns with ISO 42001 clause 7.5.3 (control of documented information) and the NIST AI RMF Govern function, which requires accountability structures for third-party data management.
What the Terms Do Not Cover
No Model Version Governance
The Commercial Terms contain no commitment to notify customers before model changes, deprecations, or retirements. Anthropic can swap the model behind your API endpoint without telling you. If your organisation validates outputs against a specific model version for regulatory compliance, you need to negotiate this separately. The NIST AI RMF Measure function calls for ongoing monitoring of AI system performance. But you cannot monitor what you do not know changed.
No SLA on Uptime
There are no uptime commitments, no service credits, and no remedy for outages in the Commercial Terms. Section I.3 gives Anthropic broad suspension rights and explicitly states: "Anthropic will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer may incur because of a Service Suspension." For enterprises running customer-facing workloads, this is a material governance gap.
Output Accuracy: Entirely Your Problem
Section D.3 places full responsibility on the customer to evaluate outputs. It requires the customer to notify its own users that "factual assertions in Outputs should not be relied upon without independently checking their accuracy, as they may be false, incomplete, misleading or not reflective of recent events or information." This is a candid admission, and it is legally binding. If your compliance framework requires AI outputs to be verifiable, the Terms place that burden squarely on you.
The Suspension Clause Is One-Sided
Anthropic can suspend your access if it "reasonably believes" there is a risk to the Services, a violation of the Usage Policy, or a legal prohibition. "Reasonably believes" is a low bar. There is no cure period before suspension and no liability for the consequences. In regulated industries where service continuity is a compliance requirement (financial services under APRA CPS 230, healthcare under HIPAA), this clause needs attention during procurement.
What Procurement Teams Should Verify
Based on this analysis, here are five questions every enterprise buyer should ask before signing:
1. Can we see the current DPA before committing? The Terms reference a separate document that governs data processing. If your legal team has not reviewed it, you are buying blind on the most important governance issue.
2. What model change notifications do you provide? If Anthropic cannot commit to advance notice of model updates, ask about API versioning, pinned model endpoints, or custom contractual terms for change management.
3. What happens to our outputs if you terminate? Section I.4 says you lose access to the Services on termination. Does Anthropic provide an export window? Are Outputs retrievable after termination? The Terms are silent on this.
4. Can we negotiate the suspension clause? For regulated enterprises, a suspension without cure period or liability is a material risk. Ask for notice before suspension and a path to remedy for non-critical violations.
5. How do you handle sub-processors? The DPA likely covers this, but you need to see it. Ask whether Anthropic notifies customers of new sub-processors and whether you can object. Without a DPA review, you do not know.
Mapping Anthropic's Terms to NIST AI RMF
The NIST AI Risk Management Framework 1.0 structures AI governance around four functions: Govern, Map, Measure, and Manage. Here is how Anthropic's Commercial Terms align, and where they fall short:
Govern: The data ownership and training prohibition in Section B align well with the RMF's requirements for accountability around third-party data. The Usage Policy provides some guardrails. But the absence of model change governance and the one-sided suspension clause weaken the Govern function for enterprises relying on Anthropic for critical workloads.
Map: Section D.3's output accuracy disclaimer effectively maps risk back to the customer. Anthropic does not claim to understand your use case context. This is appropriate, but it means your Map function needs to account for unknown model drift.
Measure: The Terms provide no mechanism for independent testing, no model card commitments, and no transparency into training data composition. Enterprises that need ongoing monitoring per the NIST AI RMF Measure function must build their own evaluation pipelines.
Manage: The termination and suspension provisions give Anthropic broad control over service continuity. Enterprises with Manage obligations under ISO 42001 clause 10 (improvement and corrective action) should ensure their continuity planning accounts for sudden API access loss.
The Bigger Picture: Terms Are Governance Infrastructure
Most enterprises treat vendor terms as legal boilerplate. They are not. The Commercial Terms are the governance infrastructure that determines whether your AI risk management framework has teeth. A SOC 2 report tells you the vendor passed an audit. The Terms tell you what happens when something breaks.
Anthropic's Commercial Terms are stronger on data ownership than most competitors. The training prohibition is contractual, not aspirational. The output assignment clause is unusual and valuable. But the gaps (model change governance, uptime commitments, suspension without liability) are material for regulated enterprises.
AI governance is not about picking the safest vendor on a marketing page. It is about reading the contract and verifying that the promises hold up against frameworks like NIST AI RMF and ISO 42001. If your procurement team has not mapped vendor terms to your governance framework, start with Section B. It is the most important paragraph in the document. Read more about our approach to AI governance at our contact page, or see how we evaluate vendors in a sample report. For a broader framework on evaluating AI vendor governance claims, see our post on enterprise trust signals and our DPA procurement checklist.
Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.
Frequently asked questions
Does Anthropic train on enterprise customer data?
No. Section B of the Commercial Terms states: 'Anthropic may not train models on Customer Content from Services.' This is a contractual prohibition, not a policy statement.
Who owns the outputs from Anthropic's API?
The customer owns its Outputs. Section B states that Anthropic 'assigns to Customer its right, title and interest (if any) in and to Outputs.' This is an assignment, not a licence.
Does Anthropic notify customers before changing API models?
No. The Commercial Terms contain no commitment to notify customers of model changes, deprecations, or retirements. Enterprises that validate outputs against specific model versions should negotiate this separately.
What happens to customer data if Anthropic terminates the agreement?
Section I.4 states the customer may no longer access the Services on termination. The Terms are silent on whether customers can export their Outputs after termination. Enterprises should clarify this during procurement.
Does Anthropic provide an uptime SLA?
No. The Commercial Terms contain no uptime commitments or service credits. Section I.3 gives Anthropic broad suspension rights and explicitly disclaims liability for any consequences of service suspension.
How do Anthropic's terms align with NIST AI RMF?
The data ownership and training prohibition provisions align well with the NIST AI RMF Govern function. However, the absence of model change governance, independent testing mechanisms, and uptime commitments creates gaps in the Measure and Manage functions.


