OpenAI
Weighted across nine legal categories. Lower is worse.
Executive summary
This is a B2B-focused Services Agreement that explicitly excludes general consumers, which inherently limits direct consumer exposure but shifts bargaining power heavily toward OpenAI in operational clauses. While intellectual property, liability limitations, and modification notice periods are well-drafted and consumer-friendly in principle, mandatory arbitration, strict non-refundable payment terms, and abrupt suspension rights significantly reduce overall consumer safety.
Category breakdown
Acceptance of Terms & Scope
Contract formation and service boundaries
Explicit clickwrap agreement is present, but silent acceptance via "use of the Services" introduces browsewrap risk. The scope is narrowly defined to business and developer accounts, explicitly excluding general consumers.
Key findings
- Clickwrap and browsewrap hybrid acceptance
- Explicit exclusion of consumer services
- Clear definition of covered platforms
Evidence from the document
By clicking “I agree,” accepting the Order Form, or using the Services, Customer agrees to this Agreement.
This OpenAI Services Agreement only applies to use of OpenAI’s APIs, ChatGPT Enterprise, ChatGPT Business, ChatGPT for Clinicians, and other services for customers who are businesses and developers, and does not apply to OpenAI services used by consumers or individuals unless specified above.
Recommendations
- Remove silent acceptance clause to require affirmative consent
- Add plain-language summary for non-technical users
User Accounts
Registration, suspension, and termination
Suspension can occur immediately for policy violations or security emergencies without a cure period, and the contract lacks explicit data export rights upon termination. Account closure relies on a 30-day deletion window rather than proactive data portability.
Key findings
- Immediate suspension allowed for security/policy breaches
- No explicit data export or portability guarantee
- 30-day post-termination content deletion
Evidence from the document
OpenAI may limit or suspend Customer’s access to the Services if: (a) it is required to do so by law; (b) Customer violates the Agreement or OpenAI Policies; or (c) doing so is necessary to prevent or terminate a Security Emergency.
OpenAI will delete all Customer Content from its systems within thirty days, unless: (i) OpenAI is legally required to retain it; or (ii) Customer has agreed otherwise in writing.
Recommendations
- Add a mandatory cure period for non-security violations
- Guarantee data export/download rights before account closure
- Require human review for automated suspensions
Intellectual Property & UGC
Content ownership and licensing
Customers retain full ownership of input and output, with OpenAI granted only a narrow license necessary to deliver the service. The contract explicitly prohibits training models on customer content without separate consent.
Key findings
- Customer retains ownership of Input and Output
- OpenAI license limited to service delivery
- Explicit ban on model training without consent
Evidence from the document
Customer: (a) retains all ownership rights in Input; and (b) owns all Output.
OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use.
Recommendations
- Clarify that feedback licenses expire upon termination
- Add attribution requirements for commercial derivative works
Data Privacy
Data collection, usage, and protection
Security commitments and independent audit reports are strong, but the document defers to a separate DPA for personal data handling and omits explicit breach notification timelines or direct consumer rights invocation.
Key findings
- References external DPA for Personal Data processing
- Annual independent security audits available
- No explicit breach notification timeline in main text
Evidence from the document
If Customer uses the Services to process Personal Data, OpenAI and Customer will comply with the DPA, which is incorporated by this reference into the Agreement.
OpenAI has completed audits, conducted by an independent auditor, that evaluated the design and effectiveness of OpenAI security policies, procedures, and controls for the Services.
Recommendations
- Incorporate explicit GDPR/CCPA rights directly into the agreement
- Mandate breach notification within 72 hours
- Specify cross-border transfer safeguards
Payment & Subscriptions
Billing and subscription management
Fees are strictly non-refundable and minimum commitments are non-cancellable, creating significant financial lock-in. While price changes require 14 days' notice, the lack of proration or transparent cancellation mechanics harms consumer flexibility.
Key findings
- Strictly non-refundable fees
- Non-cancellable minimum commitments
- 14-day advance notice for price changes
Evidence from the document
Fees are non-refundable except as required by law or as otherwise specifically permitted in the Agreement.
If Customer’s Order Form includes a minimum commitment, the minimum commitment amount is non-cancellable except as required by law or as otherwise specifically permitted in the Agreement.
Recommendations
- Allow prorated refunds for unused prepaid credits
- Enable self-service cancellation matching the signup method
- Remove finance charges on disputed invoices during investigation
Limitation of Liability
Risk allocation and legal protection
Liability caps are reasonable and tied to actual payments, with clear carve-outs for gross negligence, willful misconduct, and non-waivable statutory rights. The language is conspicuous and preserves meaningful remedies.
Key findings
- Cap tied to 12-month payment history
- Carve-outs for gross negligence and willful misconduct
- Preserves statutory rights where applicable
Evidence from the document
TO THE FULLEST EXTENT PERMITTED BY LAW, EXCEPT FOR: (A) A PARTY’S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT... EACH PARTY’S TOTAL LIABILITY UNDER THE AGREEMENT WILL NOT EXCEED THE TOTAL AMOUNT CUSTOMER PAID TO OPENAI DURING THE TWELVE MONTHS IMMEDIATELY PRIOR TO THE EVENT GIVING RISE TO LIABILITY.
Recommendations
- Lower the liability cap for data breaches or security failures
- Explicitly preserve consumer protection statutes regardless of jurisdiction
Indemnification
Legal responsibility allocation
Customer indemnification is reasonably scoped to breaches, applications, and customer content, excluding OpenAI’s own negligence. However, the asymmetry leaves customers bearing broader third-party claim risks than OpenAI.
Key findings
- Customer indemnifies for own violations/content/apps
- OpenAI indemnifies only for IP infringement
- Settlements require mutual consent if liability exists
Evidence from the document
Customer agrees to indemnify, defend, and hold OpenAI and its affiliates and licensors harmless against any liabilities, damages, and costs... arising out of a Claim related to: (a) use of the Services in violation of this Agreement; (b) Customer Applications, if any; or (c) Customer Content.
Recommendations
- Add reciprocal indemnification for privacy violations or security failures
- Cap customer indemnification exposure at contract value
Modification of Terms
How agreements can be changed
Material changes require at least 30 days’ advance notice and apply prospectively, with a clear right to terminate if the customer disagrees. Silent acceptance via continued use is standard but slightly less protective than active re-consent.
Key findings
- 30-day notice for material updates
- Prospective-only application
- Right to terminate upon disagreement
Evidence from the document
If OpenAI determines in its sole judgment that an update materially impacts Customer’s rights or obligations, OpenAI will provide Customer at least thirty days notice before the update is effective...
Customer’s continued use of, or access to, the Services after an update is effective constitutes acceptance of the update.
Recommendations
- Replace continued-use acceptance with explicit re-click confirmation
- Maintain a public changelog with version dates
Governing Law & Disputes
Jurisdiction and conflict resolution
Mandatory individual arbitration, combined with class action and jury trial waivers, severely restricts access to justice. The initiating party bears all filing fees, and potential venue requirements in San Francisco or Dublin create geographic and financial barriers.
Key findings
- Mandatory pre-dispute individual arbitration
- Class action and jury trial waivers
- Initiating party pays all arbitration filing fees
Evidence from the document
Customer and OpenAI agree to resolve any Disputes, regardless of when they arose, even if it was before this Agreement existed, through final and binding arbitration.
Disputes must be brought on an individual basis only and may not be brought as a plaintiff or class member in any purported class, consolidated, or representative proceeding.
The initiating Party will pay all filing fees for the arbitration and payment for other administrative and arbitrator’s costs will be governed by the arbitration provider’s rules.
Recommendations
- Eliminate mandatory arbitration and preserve court access
- Waive class action restrictions and allow representative proceedings
- Shift arbitration fee burden to the company or split equally
Ex-TerCo provides automated analysis of legal documents for informational purposes. This is not legal advice. Terms can change at any time.