Anthropic's Enterprise Terms: What Procurement Teams Miss
Anthropic's commercial terms offer industry-leading data ownership and no-training protections, but they're silent on output accuracy guarantees, service availability SLAs, and operational assurances that ISO 42001 and NIST AI RMF require. Procurement teams need to read the terms, identify the gaps, and fill them with internal controls. The contract won't do it for you.
The Terms Nobody Reads Until Something Goes Wrong
Anthropic has built a reputation as the safety-first AI lab. Its Claude models are marketed as aligned, trustworthy, and enterprise-ready. Companies sign up for the API, integrate Claude into customer-facing workflows, and move on. The commercial terms, the document that actually governs the relationship, sits unread until the legal team needs it during a security incident or an audit.
I read those terms. The full commercial terms of service, the data processing addendum, and the referenced policies. This is not a hit piece. Anthropic's terms are genuinely better than most of the market on data ownership and training policy. But there are gaps that enterprise procurement teams should understand before they build critical workflows on top of Claude. Here's what the terms actually say.
What Anthropic Gets Right
Let's start with the wins, because they're real. The data ownership clause (Section B of the commercial terms) is the strongest I've seen from a frontier AI lab: "Anthropic may not train models on Customer Content from Services." That's not qualified. It's not "may not train without consent" or "may not train on personal data." It's a flat prohibition, and it's a material differentiator from competitors whose terms reserve training rights on enterprise data.
Customer also retains all rights to inputs and owns the outputs. Anthropic even assigns any right, title, and interest it might have in outputs back to the customer. For an AI Strategy audience evaluating vendors, this is the gold standard. It eliminates the intellectual property contamination risk that keeps legal teams up at night.
The data processing addendum is equally solid on privacy fundamentals. Anthropic acts as processor, customer as controller. Standard Contractual Clauses are incorporated for EU/UK transfers. Security breach notification within 48 hours. Customer audit rights, SOC 2 reports available at trust.anthropic.com, and a subprocessor list with an objection mechanism. This covers the baseline enterprise privacy requirements.
The Gaps That Procurement Teams Should Flag
Here's where it gets less comfortable. The terms are well-written, but they're written to protect Anthropic, not to give enterprises the assurances they need for regulated use cases.
1. The Accuracy Disclaimer Is a Regulatory Void
Section D.3 of the commercial terms states that "factual assertions in Outputs should not be relied upon without independently checking their accuracy, as they may be false, incomplete, misleading or not reflective of recent events or information." This is honest. It's also a problem for any enterprise integrating Claude into a workflow where output accuracy matters, and that's most of them.
ISO 42001 Clause 8.2 requires organisations to implement operational planning and control for AI systems, including documented criteria for acceptable system performance. If your vendor's terms explicitly disclaim output accuracy, you have a gap between what the standard requires and what the contract provides. The vendor says "verify everything." The standard says "verify the system meets criteria." You need to bridge that gap yourself. The terms won't do it for you.
NIST AI RMF takes the same view. The Measure function requires organisations to evaluate AI system trustworthiness, including accuracy, reliability, and robustness. If the vendor contract assigns that entire burden to you, your governance framework needs to account for it explicitly.
2. Service Suspension Has No Liability Cap
Section I.3 of the commercial terms gives Anthropic broad suspension rights: a risk to the Services, a vendor suspending Anthropic's own infrastructure, a belief that providing Services to you is prohibited by law. In each case, Anthropic "will have no liability for any damage, liabilities, losses (including any loss of data or profits), or any other consequences that Customer may incur because of a Service Suspension."
For a business that's integrated Claude into a production workflow, think customer support, document processing, real-time analysis, a suspension without liability means you eat the downtime cost. ISO 42001 Clause 8.1 requires organisations to plan for operational control of AI systems, which includes business continuity considerations. If your vendor contract disclaims downtime liability, your business continuity plan needs to account for that exposure.
3. Pricing Flexibility Cuts One Way
Section H.1 allows Anthropic to update published rates with 30 days' notice. No cap on increases. No long-term rate lock. For enterprises budgeting AI costs across a fiscal year, this is an exposure point. Most SaaS contracts include rate-lock provisions or escalation caps. Anthropic's terms don't. It's not unusual for API pricing, but it's something procurement should factor into total cost models.
The ISO 42001 Lens: What Would an Auditor Ask?
If your organisation is pursuing ISO 42001 certification, an auditor will examine how you evaluate and manage external providers of AI systems. The standard requires you to define criteria for selecting and evaluating these providers and to maintain documented information about them.
Here's what that means in practice for an Anthropic deployment. You need documented evidence that you've assessed the provider's data practices, security controls, subprocessor relationships, and service level commitments. The DPA gives you some of this. The audit rights (Section F) give you more. But the commercial terms' silence on output accuracy guarantees, system availability commitments, and performance criteria means those are gaps your organisation must fill with internal controls. An auditor won't accept "the vendor's terms say outputs might be wrong" as a substitute for a documented accuracy verification process.
The NIST AI RMF's Map function pushes further: understand the AI system's context, categorize it, and document its capabilities, goals, and potential impacts. If you're using Claude in a regulated domain like finance, healthcare, or legal, the Map function requires you to document what the system can and can't reliably do. The vendor's terms won't tell you that. You have to test it yourself. I covered how to structure these evaluations in our vendor DPA checklist.
What Buyers Should Verify Before Signing
Five questions every procurement team should ask before building critical workflows on Anthropic's API:
- What's the actual availability SLA? The terms don't include one. If Claude is mission-critical, negotiate a separate agreement or document your assumption of risk.
- Which subprocessors handle your data, and where? The DPA lists them in Schedule 4. Read it. Map the data flows. If a subprocessor is in a jurisdiction your compliance framework doesn't permit, object within the 15-day window.
- How will you verify output accuracy for your use case? The terms put this on you. Document your verification process, especially if ISO 42001 or NIST AI RMF apply.
- What's your plan if the service is suspended? The terms disclaim liability. Your business continuity plan is your only protection.
- Have you read the Usage Policy? It's incorporated by reference. Restrictions on use cases can change. Know what you're agreeing to.
The Bigger Picture
Anthropic's terms are strong on the fundamentals that matter most: data ownership, training policy, and privacy compliance. They are silent on the operational assurances enterprises need for regulated deployments. This is not unusual. Most AI vendors' standard terms have the same gap. What matters is whether buyers recognise it.
The gap between what a vendor's terms provide and what ISO 42001 and NIST AI RMF require is where independent verification becomes essential. A SOC 2 report tells you the vendor's infrastructure is secure. It doesn't tell you whether the AI system itself meets your governance requirements. That's the gap our AI Trust Badge is designed to fill: live, continuous verification that goes beyond what any terms of service can promise. For a deeper look at how vendor security questionnaires miss these points, see our analysis of AI vendor security questionnaire gaps.
Read the terms. Then verify what they don't cover. Your auditor will thank you.
Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.
Frequently asked questions
Does Anthropic train on enterprise customer data?
No. Section B of Anthropic's commercial terms (effective June 17, 2025) explicitly states: 'Anthropic may not train models on Customer Content from Services.' This is a flat prohibition without qualification.
What happens if Claude goes down and my business depends on it?
Anthropic's commercial terms (Section I.3) state that Anthropic 'will have no liability for any damage, liabilities, losses (including any loss of data or profits)' resulting from a service suspension. Enterprises need their own business continuity plan.
Does Anthropic's DPA cover ISO 42001 requirements?
Partially. The DPA covers data privacy (GDPR, SCCs, breach notification, audit rights) but ISO 42001 also requires documented evaluation of AI system performance, accuracy, and operational controls. The DPA is silent on these AI-specific governance requirements.
Can I audit Anthropic's security and compliance controls?
Yes. Section F of the DPA provides audit rights, including access to SOC 2 reports and the ability to conduct your own audit (with mutually agreed scope, at your expense, typically no more than once per 12 months unless required by regulators).
How does Anthropic's pricing work for enterprise customers?
Pricing is based on published rates on the Model Pricing Page, with Anthropic able to update rates with 30 days' notice (Section H.1). There are no rate-lock provisions or escalation caps in the standard commercial terms, so procurement should model for potential increases.


