The Legal AI 'Indemnity Stack' Blind Spot: Why AI Contract Review Tools Are Missing the Difference Between a Cap on Liability and a Cap on Indemnification — and Why That Gap Is Where Deals Blow Up
There is a quiet confidence problem spreading through in-house legal teams, and it is being seeded by the very tools designed to make contract review faster and more reliable. AI contract review platforms — Ironclad, Kira, Luminance, Spellbook, and a growing field of embedded AI...
There is a quiet confidence problem spreading through in-house legal teams, and it is being seeded by the very tools designed to make contract review faster and more reliable. AI contract review platforms — Ironclad, Kira, Luminance, Spellbook, and a growing field of embedded AI copilots — have gotten genuinely good at spotting liability limitation clauses. They flag them, score them, and surface them in dashboards with satisfying red-amber-green clarity. The problem is that a substantial portion of those risk assessments are structurally wrong, not because the AI misread the clause, but because it misunderstood what the clause does and does not govern.
The specific failure: these tools systematically conflate limitation of liability provisions with indemnification caps, treating them as equivalent expressions of financial exposure when they are, in practice, entirely different legal instruments operating in different procedural postures with different exposure ceilings.
This is not a minor technical quibble. In SaaS and enterprise software agreements, this confusion is where deals blow up — during due diligence, post-breach, or in litigation.
Liability Caps and Indemnification Caps Are Not the Same Thing
A limitation of liability clause caps what a party can recover in a direct breach of contract action. A typical SaaS agreement might read: aggregate liability of either party shall not exceed the fees paid in the twelve months preceding the claim. That is a bilateral, direct-claims ceiling.
Indemnification is categorically different. It is a third-party mechanism. When your vendor's IP is alleged to infringe a patent held by a non-party and that non-party sues you, the indemnification obligation is triggered — not the limitation of liability clause. The question of whether that indemnity is subject to the aggregate liability cap depends entirely on a separate carve-out structure that many AI tools are not reliably parsing as a distinct risk signal.
In Leaseway Transportation Corp. v. Wesco Manufacturing and in more recent software licensing disputes, courts have repeatedly held that indemnification obligations survive or exist outside the general liability cap when the agreement does not expressly subject indemnity to the cap. Several jurisdictions have been willing to treat these as separate contractual regimes entirely. The contractual architecture matters enormously.
The Indemnity Stack in SaaS Agreements
Enterprise SaaS agreements do not carry one indemnification obligation. They carry a stack, and each layer has distinct exposure logic:
IP Indemnity covers third-party claims that the vendor's product infringes intellectual property rights. This is where uncapped exposure is most commonly buried. Vendors often exclude their IP indemnity from the aggregate liability cap because — at the negotiation stage — they want to signal product confidence. In-house counsel at the buying company frequently accepts this without pressure-testing what "uncapped" means when a non-practicing entity sues at scale.
Third-Party Claims Indemnity covers claims by non-parties arising from the vendor's breach of the agreement, negligence, or gross misconduct. Depending on the drafting, this can reach well beyond the contract value. A $200,000-per-year SaaS subscription agreement with an uncapped indemnity for third-party negligence claims is not a $200,000 risk. It is an open exposure.
Data Breach Indemnity is the fastest-evolving layer. Post-Dittman v. UPMC and the cascade of state-level privacy legislation from the CCPA through the American Privacy Rights Act's ongoing implementation battles, vendor agreements that indemnify against data breach claims by affected individuals carry exposure that scales with user base, not contract value.
When an AI contract review tool flags a "$5M aggregate liability cap — medium risk" without separately surfacing that the IP indemnity is explicitly carved out and uncapped, it is producing a false confidence reading. The GC seeing that dashboard summary may conclude the agreement has been adequately reviewed. The actual risk picture looks nothing like $5 million.
What Sophisticated Procurement Lawyers Are Actually Doing
Senior procurement counsel at companies like Salesforce, Microsoft, and large financial institutions are compensating for this gap in predictable ways: they are using AI tools for issue-spotting on standard terms and then running a manual second pass specifically on the indemnification stack using their own internal playbooks. They are building clause libraries that tag each indemnification category as a separate risk object — not a subset of the liability limitations section.
Several GCs I have spoken with are also requiring that any AI-generated review summary include explicit confirmation that indemnification carve-outs were reviewed independently of the general liability cap. If the tool cannot produce that granularity, the AI summary does not go to the deal team as a completed review. It goes back for human escalation.
That is a reasonable workaround. It is also an indictment of the current tool generation.
Why Vendors Have Been Slow to Fix This
The honest answer is training data structure. Most AI contract review models were trained on clause-level datasets that categorize contract terms by section heading and surface keyword patterns. "Limitation of liability" as a heading pulls in everything beneath it, including — in many poorly structured agreements — indemnification caps that vendors have buried there for tactical readability reasons. The model learns to associate the section with the risk, not the operative mechanism with the exposure.
Fixing this requires rearchitecting how the training taxonomy distinguishes first-party capped exposure from third-party indemnification obligations. That is not a prompt engineering problem. It is a retraining and annotation investment that most vendors are not prioritizing because the existing feature is generating satisfactory NPS scores from users who do not know what they are missing.
The Gap Is Where Deals Blow Up
Legal AI tools are not failing because they are unsophisticated. They are failing in specific, consequential ways that are invisible to the users trusting them most. In-house counsel deploying these tools for enterprise agreement review need to treat the indemnification stack as a manual review checkpoint until the tooling catches up.
The $5M liability cap on your dashboard is not the ceiling on your exposure. Find out what is above it.