Skip to content

Software companies

Will R&W insurance exclude AI and training-data risk in your software deal?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An RWI AI exclusion is not automatic, but underwriters can carve AI and training-data risk out of a representation and warranty insurance policy when diligence cannot show where training data came from or what rights cover it. A documented provenance record for each dataset is the most practical way to keep any exclusion narrow.

Key takeaways

  • Underwriters exclude what they cannot diligence, so thin records on AI and data use invite exclusions.
  • A narrow exclusion names a specific dataset, model or contract cohort; a broad one removes all AI-related loss.
  • Losses inside an exclusion fall back on the buyer unless the purchase agreement shifts them to the seller.
  • A provenance record that maps each dataset to its source, rights basis and privacy treatment gives the underwriter something to underwrite.
  • Data licensed out to AI developers is part of the review, not only the models trained in-house.

What does R&W insurance cover in a software deal?#

Representation and warranty insurance covers a buyer's loss when a seller's representations in the purchase agreement turn out to be untrue, subject to the policy's retention, limit and exclusions. In software deals it often replaces much of the seller's indemnity, which is why sellers care about what it leaves out.

The underwriter does not repeat diligence from scratch. It reviews the buyer's diligence reports, asks follow-up questions on an underwriting call and then binds a policy. Matters the buyer already knew about, purchase price adjustments, covenants and forward-looking statements are common standard exclusions.

Deal-specific exclusions are different. They appear when the underwriter sees an area where diligence was thin or the risk is hard to size. AI and training data can fit that description in software deals, because the facts sit across contracts, code, data pipelines and privacy notices.

Why AI and training data attract exclusions#

AI and training-data risk attracts exclusions because one dataset can touch several representations at once and the evidence is scattered. The intellectual property, privacy, data security and material contracts reps can all be breached by data used without the right permission.

Typical concerns include models trained on customer data under terms that say nothing about training, datasets scraped from the web, third-party datasets with restrictive licenses, records licensed out to AI developers and AI vendor tools that may retain inputs. An underwriter facing these without documents has little choice but to exclude them.

Software sellers often sit on both sides. Many train product features on their own platform data, and some license operational records outward. Both activities belong in the diligence file.

Narrow vs broad AI exclusions#

A narrow AI exclusion removes coverage for a defined dataset, model or group of contracts, while a broad AI exclusion removes coverage for any loss connected to developing, training or using AI. The difference decides how much of the seller's AI exposure the buyer must cover some other way.

Sellers usually prefer the bottom rows of the table. Getting there depends less on argument than on what the diligence file can prove.

Narrow vs broad AI exclusions
Exclusion typeWhat it typically removesEffect for the seller
Broad AI exclusionAny loss arising from the target's development, training, deployment or use of AIThe buyer seeks a special indemnity, escrow or price change for the whole gap
Training-data exclusionLoss arising from data used to train or fine-tune any modelSimilar pressure, focused on the data rights and privacy reps
Dataset or model exclusionLoss tied to one named dataset, model or data sourceExposure limited to a known item that can be priced or indemnified
Contract cohort exclusionLoss tied to data from customers on specific contract versionsA gap confined to legacy terms the seller can describe precisely
Rep-specific carve-outCoverage under one representation as applied to AI mattersNarrower than a full exclusion, but still a negotiated gap

What underwriters and buyer counsel ask about AI and data#

Underwriters and buyer counsel ask about AI and data in a predictable order: what models exist, what trained them, what rights covered that data and what went out the door. Answers backed by documents move the conversation toward narrow exclusions.

  • A register of models and AI features, with their purpose and where they run.
  • Training data sources by category: customer product data, company records, licensed-in data, public or scraped data.
  • The customer contract versions that apply to each source, including usage data and AI clauses.
  • Any data licensed to third parties, with permitted use, term, exclusivity and privacy treatment.
  • Privacy notices and processor commitments that touch training or analytics.
  • Third-party AI tools in use and their terms on retention and training.
  • Complaints, claims or customer objections about data use.

How a documented provenance record narrows exclusions#

A documented provenance record narrows exclusions because it lets the underwriter separate known, covered facts from the residual gap. Instead of excluding everything that touches AI, the underwriter can carve out only the dataset or cohort the record shows is uncertain.

Build the record per dataset, not per model. Each entry should be short enough to walk through on an underwriting call and specific enough to match a disclosure schedule.

The same record helps outside the policy. Buyers use it to scope any special indemnity, and it gives the seller a factual basis for resisting a broad exclusion.

How a documented provenance record narrows exclusions
Record elementQuestion it answers
Source system and date rangeWhere did this data come from, and which period does it cover?
Rights basisWhich contract clause, ownership position or license permits this use?
Permitted useWhat was the data used for, and what is prohibited?
Privacy treatmentWhich personal and confidential details were removed or excluded, and how?
ApprovalsWho authorized the use or release, and when?
Downstream recipientsDid any copy leave the company, and under what terms?

Illustrative: a field service SaaS seller faces a broad exclusion#

Illustrative: a fictional field service scheduling software company is selling to a private equity buyer that plans to use R&W insurance. The company trained a route-suggestion model on customer job data and had separately licensed de-identified support tickets to an AI developer.

The first draft of the policy carried a broad AI exclusion. The company's counsel then produced a provenance record. It showed that customers on current terms had agreed to aggregated use of job data for service improvement, that the support tickets were company records released under a signed license with a privacy record, and that a group of legacy customers had signed older terms that said nothing about training.

The underwriter replaced the broad exclusion with a narrow one covering the route model's use of data from the legacy cohort. Buyer and seller handled that gap with a special indemnity, and the support-ticket license was reviewed like any other material contract.

Steps to take before the underwriting call#

Preparation before the underwriting call matters more than negotiation during it. Most of the work is assembling documents the company already has, in a form a stranger can follow.

  • Ask deal counsel early whether the buyer intends to use R&W insurance and which reps cover data and AI.
  • Build the model register and dataset provenance record before the data room opens.
  • Map every customer contract version to the datasets it touches.
  • Gather the documents for any outbound data license, including the privacy record and release approvals.
  • Close gaps you can close now, for example by retraining a model without a disputed cohort.
  • Agree with counsel how residual gaps will be disclosed rather than discovered.

Where SourceX records fit in diligence#

When a seller has licensed records through SourceX, the outbound side of AI diligence is already written down. Every package carries a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization, produced through the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery.

SourceX does not advise on insurance or deal terms, and the packet does not replace deal counsel or your broker. It gives them a consistent, dated record to work from.

Frequently asked questions

Can an AI exclusion be narrowed after the first draft of the policy?

Often, if seller and buyer can supply the missing diligence before the policy binds. Underwriters usually respond to documents rather than assurances. A provenance record, a contract map and evidence of remediation give them a reason to replace a broad exclusion with a narrower one.

Who bears a loss that falls inside an exclusion?

The buyer bears it unless the purchase agreement shifts it back to the seller. Common tools include a special indemnity, a dedicated escrow or a price adjustment. Each is negotiated between the parties, so the scope of the exclusion directly affects the seller's residual exposure.

Does licensing our records to an AI developer cause an exclusion?

Not by itself. A documented, time-limited license with a clear rights basis and privacy record is a known contract the underwriter can review. Undocumented data releases, or licenses whose rights basis rests on unclear customer terms, are what tend to draw exclusions.

Is a SOC 2 report enough for AI diligence?

No. A SOC 2 report addresses controls such as security and confidentiality. It does not show whether the company had the right to use particular data for training or licensing. Underwriters treat it as useful context, not as evidence of data rights.

Should we expect AI-specific representations in the purchase agreement?

Buyers may ask for them, so sellers should be ready for the conversation. Whether they help or hurt depends on drafting and on what the diligence file can support. Deal counsel should align the reps, the disclosure schedules and the policy wording so they describe the same facts.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify