Vendr called 2024 “the year of the descope,” with buyers aggressively downsizing and rightsizing their SaaS commitments. This impacted companies of all sizes. Jamin Ball’s analysis in Clouded Judgement showed public companies reporting earnings where Net new ARR added was down 28% in Q1 of 2025 compared to Q1 2024.
Faced with slowing growth in net new ARR, vendors responded by shifting their focus to a more reliable revenue source: existing customers. These price increases were largely justified by the inclusion of new AI capabilities. Jason Lemkin covered this in The Great SaaS Price Surge of 2025 and Growth Unhinged’s Kyle Poyar tracked this trend across more than 1,800 public pricing changes at top SaaS and AI companies in 2025.
It’s no surprise then that in 2026, we are seeing customers push back on automatic price increases. Automatic fee increase clauses nearly halved, from 23% of all Cloud Service Agreements (CSAs) to 13%. In addition, we’re seeing a decided shift on expectations of AI training allowances.
In 2024, less than 1% of CSAs disallowed AI training on their data. In 2025, that number shot up to 11% and is continuing to grow. Customers are accepting that they will pay more for AI features, but are unwilling to risk more pricing surprises, and increasingly, unwilling to have their own data used to improve the product they are paying for.
Another notable trend we’re seeing in this year’s data is that the liability fight is moving from whether a supercap exists to how much. Increased claims are still not the norm, but they are showing up more often. Where increased claims appear, the 2x increased cap overtook 5x in a single year: 0.3% to 2.7% of all CSAs, while 5x fell 2.5% to 1.7%. Unlimited claims have jumped from 1.1% of CSAs to 10.2%.
Common Paper makes free, open-source standard agreements that companies use to sell and buy software. Because these contracts start from a shared standard, we can see exactly which terms companies keep, change, or remove, and how those choices shift over time. This report is based on 16,000 signed agreements across 2,000+ companies using the Cloud Service Agreement (also known as a Master Service Agreement), Non-Disclosure Agreement, and Design Partner Agreement.
Cloud Service Agreements
A Cloud Service Agreement (CSA) covers the terms of a SaaS subscription: what the customer gets, what they pay, and the vendor’s obligations to the customer.
Risk and Liability
Covered claims are the claims one party agrees to indemnify the other against. These are most often third-party claims, like an allegation that the product infringes someone’s intellectual property. When a covered claim is triggered, the indemnifying party defends it and covers the resulting losses. In some cases, covered claims will be subject to the applicable liability cap. In other cases, the customer will negotiate for uncapped indemnity obligations. Covered claims appear in more than 4 in 5 SaaS agreements, holding between 85% and 90% over the past three years.
General Liability
The general cap is a ceiling on the total amount either party can be liable to the other under the contract for most kinds of claims. Almost all SaaS contracts express it as a multiple of fees paid rather than a fixed dollar amount, so the cap scales with the size of the deal.

99% of SaaS contract agreements include a multiplier cap, with 96% capping at 1x. The 0.5x cap, a vendor-favorable position that limits customer recovery to half of fees paid, has declined from 7% in 2024 to 2.5% in 2026. This is another small indicator of customers holding greater leverage in negotiations compared to what they held even two years ago.
Exceptions to the Limitation of Liability
Exceptions to the Limitation of Liability include increased claims, specific issues where a party’s monetary liability is above the general cap but not wholly unlimited (often referred to as a supercap), and unlimited claims. These exceptions specify particular scenarios in which a party would hold greater liability.
Increased claims appeared in 6.9% of CSAs in 2026, up from 4.1% in 2025. Unlimited claims saw a much more dramatic increase, jumping to 10.2% of CSAs in 2026, up from 1.1% in 2025. In the case of unlimited claims, the specific claims meeting this criteria tend to include the most extreme cases such as gross negligence, willful misconduct, and fraud.
For increased claims, the negotiation has moved from whether the increased claim exists to the size of the supercap. 2x supercaps appear in 2.7% of agreements signed in 2026, ahead of 5x at 1.7%. In 2025, the order was reversed: 5x at 2.5% and 2x at 0.3%. further action required. With invoice billing, the provider sends an invoice and the customer initiates payment.

In Common Paper agreements, the cover page is where the editing happens. Contracting parties use the cover page to list out what types of claims are subject to the supercap. Confidentiality, privacy and security, and indemnification are the default claims subject to the supercap when using the Common Paper platform.
In 2024, agreements with increased claims mostly kept that default list. Across all CSAs:
- privacy and security breach appeared as an increased claim in 4.6%
- indemnification in 2.9%
By 2026, more than half of these agreements had removed at least one default increased claim:
- indemnification in 1.0%
- privacy and security breach appears in 3.8%

Insurance minimums
An insurance minimums clause commits the provider to carry insurance policies meeting specified coverage levels for the duration of the subscription. It is a risk mitigation mechanism requested by customers that proves the vendor has coverage if something goes wrong. Upon request, the provider must supply a certificate of insurance as evidence.
Overlooking some fluctuation in 2025, the share of contracts that require insurance at all has barely moved, from 2024 to 2026 – 11% to 13%. But among the contracts that do require it, customers are asking for more types of coverage in 2026 than they were in 2024, with E&O the notable exception.
Measured against all CSAs, cyber insurance requirements grew from 9% in 2024 to 12% in 2026, general liability from 8% to 11%, and workers’ comp from 6% to 8%. E&O is the exception, flat at about 7%.

E&O covers professional errors in service delivery: mistakes made in the course of providing a service, as distinct from product defects or data breaches. That distinction becomes harder to apply as AI-generated output plays a larger role in what SaaS products deliver. Common Paper’s standard agreement already notes that AI-generated output “may be incorrect or inaccurate.” In 2026 we began to see vendors go further, adding language that shifts responsibility for AI output onto the customer, for example:
- Customer specifically acknowledges the risks of AI-generated outputs that are probabilistic, incomplete, or incorrect.
- Provider specifically not guaranteeing the accuracy of any AI-generated result
- Customer stated as being solely responsible for the accuracy of the outputs and the provider holding no liability for how the customer uses the outputs
When an AI model produces incorrect analysis, a flawed recommendation, or a fabricated citation, it is not obvious whether that constitutes a professional error, a product defect, or something the existing insurance framework does not cover cleanly. E&O is the only coverage type that has not grown since 2024, at the same time vendors are adding language that puts responsibility for AI outputs on the customer. If that language holds up, the risk of AI errors increasingly sits with the customer.
AI and machine learning
The Common Paper CSA includes a machine learning clause that sets whether a vendor can use a customer’s content and usage data to train its AI models. It ships in the standard, but it can be removed when a product doesn’t use AI so it mainly appears where the product itself involves AI. Where it’s kept, the clause permits training on aggregated, de-identified data by default and notes that AI output may be inaccurate. Language mentioning AI appeared in 53% of CSAs signed in the year ending June 2026, up from 47% in 2025 and 38% in 2024.

Beyond simply mentioning AI, about one in five CSAs (20%) now negotiate an AI-specific edit to the standard terms, up from under 4% in 2024.
As we saw in the prior section on insurance, vendors are mostly focused on defending against liability for AI outputs. In contracts, this shows up as new “AI configuration and liability” language like:
- The customer controls how the AI behaves, so the customer is responsible for its outputs
- The vendor does not guarantee AI-generated results are accurate
An increasing number of companies find that AI is such a central issue in their contracts that a single clause isn’t sufficient. For cases like this, an AI Addendum can be added onto the main contract to cover data usage, intellectual property, training rights, liability, and ethical considerations.
Prohibiting AI Training language went from showing up in under 1% of all CSAs in 2024 to 11% in 2025 and 14% in 2026, while language granting the vendor training rights stayed flat at about 3%.

Steve Hind, Co-founder at Lorikeet added additional context to this data: “We work with a lot of complex and regulated businesses, and over even the last six months we’ve watched their legal teams get noticeably more sophisticated about AI training clauses. It’s stopped being a yes-or-no question about whether we train on customer data and become a much more precise set of questions about where data goes and what everyone in the chain is allowed to keep.”
Operational terms
Taken together, the service level agreement (SLA), security policy, and technical support provisions represent the performance commitments a vendor makes beyond the core product. The past three years have shown minimal change in the inclusion of these terms, and technical support is the only one beginning to become a majority practice.
Service level agreement
A service level agreement defines the performance targets the provider commits to, typically uptime availability and response time, and the remedies available to the customer when those targets are missed. Remedies most commonly take the form of service credits: a percentage of subscription fees credited back to the customer for the affected period.

The inclusion of SLAs hasn’t changed much over the past three years, 29% of agreements included SLAs in 2024 and that’s down just slightly to 26% in 2026.
Security policy
A security policy clause commits the provider to a defined standard of care for protecting the cloud service and customer data, and requires the provider to make supporting security documentation available to the customer.
Security policies appear in about a third of contracts, little changed since 2024 (37% in 2024, 34% in 2026). Nearly all of them use the “reasonable efforts” standard (90% in 2024, 91% in 2026): it requires safeguards proportionate to the size of the business, the sensitivity of the data, and available resources, rather than a rigid checklist. Contracts linking to an external security policy grew from 22% of all CSAs in 2024 to 26% in 2026.

When customers ask for a security policy, they increasingly expect specifics on what exactly that policy includes. “Reasonable efforts” are still the industry standard, but both customer and vendor are being more explicit about what, exactly, “reasonable” entails.
Dispute resolution
Dispute resolution terms set the ground rules if the relationship breaks down: which law governs the contract and which courts hear a dispute. These are the most settled terms in the data set. Nearly every agreement makes the same choices, and those choices have changed very little over the course of three years covered in this report.
Governing law
The governing law clause specifies which state’s or country’s laws will apply if there’s a dispute about the contract. Governing law remains almost entirely US-based, a rate that hasn’t changed over the past three years.

Among US choices, Delaware leads by a wide margin, though its share compressed in 2026 (83% in 2025 to 74%) as California recovered from a 2025 dip and Florida entered the top three for the first time. The same state distribution holds for chosen courts.
Subscription terms
Subscription and payment terms are the commercial core of the agreement. This is where buyer leverage showed up most clearly in 2026. Automatic fee increases nearly halved while renewal mechanics held steady.
Auto-renewal
An auto-renewal clause allows a contract to automatically extend for a new term unless one party gives notice of non-renewal within a defined window. SaaStr’s Jason Lemkin wrote that AI-era buyers “have more leverage than they’ve ever had purchasing B2B software,” with switching costs collapsing as prompts become portable. While we see evidence of this pressure in other areas, we don’t see this pressure in auto-renewals, which are holding constant in 2026 at 87% compared to 85% in 2024.
The notice window is the deadline by which either party must give notice of non-renewal before the contract automatically extends for another Subscription Period. Buyers have leverage at that moment, but only if they use it in time. The 30-day notice window is the standard, appearing in about 70% of all CSAs.
Automatic fee increases
An automatic fee increase clause authorizes the provider to raise fees at renewal without renegotiating. The benchmark data measures how often signed agreements include the clause at all.

Pricing increases had become the unhappy norm for customers over the prior two years. Kyle Poyar called 2025 “the year when seemingly everybody lost confidence in their pricing.” In this environment, we are seeing customers less likely to accept a clause that allows vendors to automatically raise their prices.
In 2026, only 13% of contracts include auto fee increases, the rate has nearly halved from 23% in 2024. When we look at custom language, we see customers adopting an even stronger stance on price, examples include:
- Specific language that states the current fee will not increase for the first 24 months of the subscription period
- The addition of a money-back guarantee, no questions asked for a stated period
Billing method
The billing method specifies how payment is collected under the contract. With automatic billing, the provider charges a payment method on file, like a credit card, on a set schedule without further action required. With invoice billing, the provider sends an invoice and the customer initiates payment. Because of the release of a new version of the standard in 2025, 2024 agreements are omitted from this analysis.

Invoice billing tends to be more common for higher dollar value contracts where the CFO wants to exert greater control over cash flow. This shift we’re seeing in Common Paper data is small, but likely points to the fact that the addition of AI features is raising prices for SaaS overall and, with that, more companies are opting for invoiced billing.
Payment Period
The payment period defines how long a customer has to pay the vendor. You might also hear this called Net 30 (a 30-day payment period), Net 60, etc. Larger companies with more complex finance processes often require longer payment periods to account for internal processing, and they also want the cash flow benefit of paying later. Smaller companies have less leverage and tend to be more agile, often accepting shorter payment periods.
Among agreements billed by invoice, a 30-day payment period is the norm.
Mutual NDAs
A mutual non-disclosure agreement (NDA or MNDA) establishes confidentiality obligations for both parties. NDAs are one of the most frequently used agreements in the early stages of a B2B sales cycle. Customers might require an NDA before they share sensitive information that is necessary for the vendor to quote a price. Or the vendor might sign an NDA with a potential partner in order to share customer lists. While other agreements, like a Cloud Service Agreement, do include a confidentiality clause, using an NDA in your sales cycle establishes a confidential relationship earlier in the business relationship before a formal commercial agreement has been signed.
NDA term
The NDA term sets how long the agreement is active. Only information shared during this period falls within the agreement’s protection.

Fixed-length terms have grown from 71% to 78% over three years with “No expiration” NDAs falling from 29% to 22%. These are small shifts toward time-bounded obligations. Fixed-length terms are growing in dominance, with fixed 1-year term length being the single most common structure.
Term of confidentiality
The term of confidentiality specifies how long the parties must protect confidential information, an obligation that survives the NDA’s expiration. 79% of agreements in 2026 contain a fixed confidentiality period (21% are unlimited). These numbers haven’t changed meaningfully since 2024. In cases where the confidentiality period is fixed, two years is the standard at 75%, a small increase from 68% in 2024.
Governing law
The governing law clause specifies which state’s or country’s laws will apply if there’s a dispute about the contract. Like with the CSA, the majority of contracts in our benchmark report use US governing law (96%).
For the NDA, we saw Delaware’s share of governing law climb from 73% in 2024 to 84% in 2026, the opposite of its slide in CSAs. California shows up in 6% of agreements and New York in 4%.
Design Partner Agreements
A design partner agreement formalizes a relationship between a vendor and its earliest users. It sets expectations on both sides, what the customer commits to and what the vendor commits to in return, while protecting the vendor’s intellectual property during development.
Our data shows design partnerships moving toward more formal arrangements that the customer pays for, while customers push back on marketing-side commitments.
Fee provision
A fees provision specifies whether the design partner pays for access during the partnership and, if so, on what terms. Design partner fees were included in 34% of agreements in 2024 and that grew to 47% in 2026.

Customer obligation
Customer obligations set out what the customer commits to in exchange for early access: feedback sessions, marketing use rights (including customer lists and case studies), and references.

2025 showed an uptick in companies requiring fees for design partner agreements, and by 2026 customers began pushing back on marketing obligations. Marketing commitments climbed through 2025, then eased off that peak in 2026. Most design partner agreements still include marketing commitments, but customers are now less likely to agree to be named as a design partner, provide a case study, or serve as a reference.
In addition, customers have pushed back on the feedback commitments. Feedback sessions have fallen from 80% in 2024 to 73% in 2026.
Partner Obligations
Provider obligations set out what the vendor commits to in exchange for the design partner’s participation, most commonly a discount on future fees, a commitment to build requested functionality, or both. In 2026, the standard is:
69% of design partner agreements are six months or less, with 20% requiring a 1-year commitment.
49% of design partner agreements include a discount on a future subscription (unchanged since 2024)
A 20% discount on a future subscription is the most common level, appearing in 21% of design partner agreements.
37% include commitments to build functionality (up slightly from 33% in 2024)
Methodology
This report is based on 16,140 signed agreements sent by 2,223 unique companies using the Cloud Service Agreement (also known as a Master Service Agreement), Non-Disclosure Agreement, and Design Partner Agreement.
Prior versions of our benchmark reports have snapshotted a specific quarter. Our approach this year was a little different. We looked at the trailing 12 months for each year. So the 2026 figures cover June 2025 to June 2026, and the 2025 figures covers June 2024 to June 2025. Because of this, the numbers in this report will not match the 2024 benchmark report.