03 · What You Need to Know
The Terms Define More Than Whether You Can Open an Account
First, Make Sure You Are Reading the Terms That Actually Apply
AI providers may offer consumer products, paid individual plans, APIs, team accounts, enterprise services, educational offerings, and institutionally negotiated versions. These may not all operate under identical contractual conditions.
Before interpreting a clause, identify the product and account type you will actually use. An enterprise agreement negotiated by your university should not automatically be assumed to apply to a personal account registered with the same provider.
The same caution applies when comparing free and paid AI tools for research. Payment may coincide with different contractual arrangements, but the relevant differences must be verified rather than inferred.
Check What You Are Allowed to Upload
Terms may require users to have the necessary rights, permissions, or authority to provide content to the service.
This matters because researchers routinely work with material they did not create or do not own outright. Examples include publisher PDFs, licensed database content, confidential peer-review manuscripts, third-party datasets, collaborator documents, student work, participant information, copyrighted instruments, photographs, or proprietary code.
Your ability to access material does not necessarily mean you have permission to provide it to an external AI service.
NIST's Generative AI Profile specifically identifies third-party generative AI as creating potential intellectual-property, data-privacy, and information-security risks and recommends risk-management processes for external AI technologies and service providers.
Check Who Owns Your Inputs
Many AI services distinguish between user inputs and generated outputs. Read what the agreement says about ownership of material you provide.
Do not stop at a sentence saying that you retain ownership. The next question is whether you grant the provider a license to process, host, reproduce, modify, distribute, or otherwise use that material for specified purposes.
Ownership and licensing are not opposites. You can retain ownership of something while granting another party substantial rights to use it.
Ownership
Who holds the relevant rights in the content, subject to applicable law and any pre-existing rights.
License
Permission granted to another party to use the content in specified ways without transferring ownership itself.
Read the License You Grant the Provider
If the terms grant the provider a license over inputs or other content, examine its scope.
Questions may include what purposes the license permits, how long it lasts, whether it is worldwide, whether sublicensing is allowed, whether it survives account deletion or termination, and whether different terms apply to particular products.
Do not interpret a broad legal phrase in isolation. Read the surrounding clauses and related privacy documentation to understand the provider's stated purposes and data practices.
Check What Rights Apply to AI-Generated Outputs
Researchers may want to use AI-generated text, code, images, summaries, classifications, or other output in subsequent work. Terms may address whether the provider assigns or disclaims rights in generated outputs and what responsibilities remain with the user.
Contractual permission from the AI provider does not necessarily settle copyright or other intellectual-property questions under applicable law. Nor can the provider grant you rights that belong to someone else.
Generated output may also resemble third-party material, contain protected content, or incorporate information that you are not entitled to publish. Treat “you may use the output” as a contractual statement, not a universal guarantee that every conceivable use is legally risk-free.
Check Whether the Service Promises Confidentiality
A researcher may intuitively treat a private account or one-to-one AI conversation as confidential. The terms may not support that assumption.
Look for explicit confidentiality provisions where confidentiality matters. A service can restrict public visibility of your content without entering into the type of confidentiality obligation required by a research agreement, non-disclosure agreement, peer-review process, or institutional policy.
Watch Out
“Not publicly visible” is not necessarily the same as “contractually confidential.” Do not upload confidential research material merely because the interface feels private.
The European Commission's 2026 Living Guidelines caution researchers about protecting unpublished work, privacy, intellectual property, and sensitive knowledge when generative AI is used in research.
Check the Acceptable-Use Rules
AI services commonly restrict particular activities through their terms, usage policies, acceptable-use policies, or related documents incorporated into the agreement.
Researchers should determine whether the planned activity is permitted, especially when work involves sensitive personal information, automated decision-making, high-risk domains, security research, regulated activities, or other restricted uses.
The important point is not to memorize every prohibited category. It is to recognize that technical capability does not equal contractual permission.
Check What You Promise About the Content
Terms may require you to represent or warrant that you have the rights and permissions necessary to submit content or use the service.
That can shift responsibility back to the researcher. If you upload material belonging to a publisher, participant, collaborator, employer, or data provider without the necessary authority, the fact that the AI platform accepted the file does not resolve the underlying problem.
Read these clauses carefully when the research uses third-party or licensed content.
Look for Accuracy and Warranty Disclaimers
Researchers should not assume that an AI provider contractually promises that outputs will be accurate, complete, reliable, or appropriate for a particular research purpose.
Terms commonly contain warranty disclaimers or statements limiting reliance on generated output. The precise wording varies by provider.
These clauses reinforce a methodological point already familiar from evaluating AI reliability for research: access to a sophisticated system does not transfer responsibility for verifying research claims to the provider.
Check the Limitation of Liability
Terms may limit the provider's liability if the service produces errors, becomes unavailable, loses data, infringes third-party rights, or otherwise causes harm. They may also impose caps or exclude particular categories of damages.
This matters because researchers may be using the service for activities whose consequences greatly exceed the cost of the subscription.
If an AI system incorrectly extracts study data or exposes confidential material, the scientific, ethical, contractual, or reputational consequences may fall primarily on the researcher or institution even when the software contributed to the problem.
Check Whether You Indemnify the Provider
Some agreements contain indemnification provisions under which users agree, in specified circumstances, to cover claims, losses, or expenses arising from their use of the service or content.
The meaning and enforceability of these provisions depend on the agreement and jurisdiction. Researchers working under institutional accounts should not assume they personally have authority to accept contractual obligations on behalf of their university or research organization.
Where a clause has material legal or financial implications, institutional legal or procurement review may be appropriate.
Check the Rules for Accounts and Team Use
Researchers sometimes share subscriptions or credentials within a laboratory or project team to save money. Terms may prohibit credential sharing, impose user limits, or require separate seats.
Account rules can also affect auditability. If several researchers use one personal account, it may become difficult to establish who uploaded particular information or generated particular outputs.
Use the account in accordance with the provider's rules and your institution's access-management requirements.
Check Third-Party Integrations and External Services
An AI application may connect to cloud storage, scholarly databases, search engines, plugins, APIs, or other external services. The provider's terms may state that third-party services operate under their own agreements.
That can create a chain of contractual and data-governance relationships rather than one simple agreement.
NIST recommends organizations manage AI risks arising from third-party software, data, and service providers and specifically identifies legal and intellectual-property risks in the AI supply chain.
Check What Happens if the Service Changes or Disappears
Terms may allow providers to modify features, suspend accounts, discontinue services, change pricing, or revise contractual conditions.
That matters when an AI tool becomes part of a long-term research method. A workflow built around one proprietary feature may become difficult to reproduce if that feature changes or disappears midway through a project.
Look for provisions concerning modification, suspension, termination, notice, and access to data after termination.
Check Governing Law and Dispute Terms When They Matter
Terms may specify governing law, jurisdiction, arbitration, dispute procedures, or other legal mechanisms.
Most researchers will not need to analyze these clauses for every low-risk AI interaction. They become more relevant when an institution is procuring a service, substantial research data are involved, or contractual risk is material.
Researchers should avoid providing legal interpretations outside their expertise. The practical task is to identify clauses that may require institutional legal, procurement, privacy, or research-governance review.
Privacy Policy and Terms of Service Answer Different Questions
| Document |
Primary question |
Examples of issues |
| Privacy policy |
What happens to information about you and the data you provide? |
Collection, processing purposes, retention, sharing, transfers, privacy rights |
| Terms of service |
What contractual rules govern your use of the service? |
Content rights, licenses, permitted use, warranties, liability, account rules, termination |
| Institutional agreement |
What additional or different conditions has your organization negotiated? |
Security, data processing, confidentiality, support, liability, procurement conditions |
| Research protocol or agreement |
What are you permitted or obligated to do with the research material? |
Consent, confidentiality, ethics approval, data-use restrictions, collaborator obligations |
This is why reviewing an AI tool's privacy policy does not eliminate the need to examine the contractual terms.