AI/ML Service Responsibility and Limitation of Liability Agreement
PART I - THE NATURE OF AI AND ALLOCATION OF RESPONSIBILITY
Article 1. The inherent characteristics of AI and their legal consequences
1.1. The customer understands and acknowledges the technical characteristics of AI systems that affect the allocation of responsibility:
- (a) Hallucination: a large language model (LLM) can produce inaccurate or fabricated information with a high degree of confidence. The Customer must always independently verify important information;
- (b) Non-determinism: the same input can produce a different output each time. AI is not a deterministic system;
- (c) Bias: AI models may reflect bias present in their training data. Outputs should be checked for fairness and neutrality;
- (d) Explainability: most modern AI models (deep learning) are “black boxes” - how they arrive at a decision cannot be fully explained;
- (e) Context limitations: AI models have a finite context window; information outside that window is ignored.
Article 2. Responsibility allocation framework
2.1. HiTechCloud's responsibilities:
- (a) Ensure the API infrastructure meets the committed SLA (Article 2, File 08);
- (b) Ensure the AI model does not breach legal requirements on content;
- (c) Give timely notice of model changes that may affect output;
- (d) Maintain API data security measures under Decree 13/2023/NĐ-CP;
- (e) Provide technical documentation, example prompts and safe-use guidance.
2.2. Customer responsibilities:
- (a) Design systems with human oversight (human-in-the-loop) for significant decisions;
- (b) Verify and quality-check AI output before using it in practice;
- (c) Ensure legal compliance for each specific AI application;
- (d) Carry out an AI risk assessment before deploying applications that affect people;
- (e) Disclose transparently to end users when content or decisions are generated by AI.
▸ Legal basis: EU AI Act 2024 (Articles 9–17 on high-risk AI systems); the National AI Strategy 2021 (responsible AI principles); Decision 127/QD-TTg (Quyết định 127/QĐ-TTg); Decree 13/2023/ND-CP (Nghị định 13/2023/NĐ-CP).
PART II – AI-SPECIFIC LIMITATIONS OF LIABILITY
Article 3. HiTechCloud's limitation of liability
3.1. HiTechCloud is not legally liable for:
- (a) Damage arising from relying on inaccurate AI output without verification;
- (b) Business, medical, legal or financial decisions made on the basis of AI output;
- (c) AI-generated content that infringes a third party's intellectual property rights (the Customer is responsible);
- (d) Changes to AI models by third-party providers (OpenAI, Anthropic, Google, etc.) that affect output;
- (e) Damage caused by malicious input (prompt injection, adversarial attacks) directed at the Customer's AI application;
- (f) Damage caused by the AI being jailbroken or manipulated by the Customer's end users.
3.2. MAXIMUM COMPENSATION LIMIT:
HiTechCloud's total liability for compensation relating to AI services shall not, under any circumstances, exceed the total AI service fees paid by the Customer in the 12 months preceding the claim, or VND 20,000,000, whichever is lower. This cap is lower than the general cap in Article 15 due to the specific nature of AI services.
Article 4. Human-in-the-loop requirements for high-risk AI applications
4.1. Under the EU AI Act 2024 and responsible AI principles, the Customer MUST implement human oversight (human-in-the-loop) when using AI for:
- (a) Decisions affecting an individual's legal rights (loan refusal, hiring, scoring);
- (b) Medical diagnosis or assistance (AI assists only; the doctor makes the final decision);
- (c) Security decisions and access control;
- (d) Educational systems that assess students;
- (e) Any application that affects children.
4.2. Failing to meet the human-in-the-loop requirement may itself constitute a breach of law, and HiTechCloud is not liable for the legal consequences to the Customer.
Article 5. AI transparency and end-user rights
5.1. When deploying AI applications to end users, the Customer has a legal obligation to:
- (a) Clearly disclose when a user is interacting with an AI system (it must not pretend to be human);
- (b) Provide an opt-out for users who do not want to interact with AI;
- (c) Notify users when a decision affecting them is made entirely automatically;
- (d) Provide the right to an explanation of, and to object to, AI decisions under Article 19 of Decree 13/2023/NĐ-CP.
▸ Legal basis: EU AI Act 2024 (Article 50 on transparency obligations); Decree 13/2023/ND-CP (Nghị định 13/2023/NĐ-CP), Article 19 – the right not to be subject to automated decisions; the Law on Protection of Consumer Rights 2023 (Luật Bảo vệ Quyền lợi Người tiêu dùng 2023).
Article 6. AI testing and evaluation
6.1. For high-risk AI applications, HiTechCloud strongly recommends that the Customer:
- (a) Carry out an AI Privacy Impact Assessment under Decree 13/2023 (Nghị định 13/2023);
- (b) Algorithmic Fairness Testing to detect and mitigate bias;
- (c) Red-teaming: testing whether the AI can be exploited through adversarial inputs;
- (d) Check EU AI Act compliance if you have users in the EU.
6.2. HiTechCloud provides AI governance consulting on request. Contact: info@photuesoftware.com.