Artificial intelligence is transforming accounting workflows, but what happens when AI-generated work leads to a lawsuit? Does your AI vendor defend you, or could your accounting firm be left paying the legal bills?
In this episode of Accounting Technology Lab, Randy Johnston and Brian Tankersley examine AI indemnification commitments from Microsoft, Google, OpenAI, and Anthropic, including what these technology giants promise to cover, the exclusions that matter, and the responsibilities that remain with business customers.
We explore how contractual protections differ across Microsoft Copilot, Google’s AI services, OpenAI’s commercial offerings, and Anthropic’s Claude ecosystem. Particular attention goes to intellectual property disputes, copyrighted training materials, generated content, required safeguards, and the implications of accessing AI through third-party platforms.
For accounting professionals, the stakes extend beyond copyright. Client confidentiality, professional liability, data governance, and the accuracy of AI-assisted deliverables create exposures that vendor indemnification provisions generally do not eliminate. The discussion offers practical considerations for evaluating agreements, documenting AI workflows, and managing risk before deploying generative AI in client-facing services.
The Accounting Tech Lab is an ongoing series that explores the intersection of public accounting and technology.
View the video below:
Transcript (may contain typos, due to automated transcription):
Brian F. Tankersley, CPA.CITP, CGMA 00:00
Welcome to the Accounting Technology Lab, brought to you by CPA Practice Advisor, with your hosts Randy Johnston and Brian Tankersley.
Randy Johnston 00:09
Welcome to the Accounting Technology Lab. I’m Randy Johnston with co-host Brian Tankersley, and we’ve been talking about how to keep your businesses safe and what AI liability risks that you have, and it is quite different between Microsoft or Google or OpenAI and Anthropic. So, Brian, I know all of this privacy and security related to AI is so near and dear to your heart. So, what would you like our listeners to know about?
Brian F. Tankersley, CPA.CITP, CGMA 00:39
Well, I you know I think I think you have to. I think when we’re thinking about this, you know, we we talked a lot about Microsoft and their their capabilities and their their promise to indemnify you here, and and you know, again, Microsoft says that they they defend commercial customers against third party IP claims involving Copilot or Azure OpenAI output. They pay covered adverse judgments or settlements, okay. But here’s the thing, okay. If you if you look at at this, if you look at this, the devil is always in the fine print, okay. And and so you know if you if you think about you know the you know because the title of this episode is covered covered-ish, you know. This is somewhat analogous to a covered dish dinner that you get at church. Okay, sometimes it’s Miss McGillicuddy’s broccoli casserole that you get that you love. Sometimes somebody goes out and they bring hamburgers from McDonald’s in a bag, or they bring chicken from KFC, something I can’t stand in a in a in a bucket because I I worked for KFC when I was 16 and I just can’t see fried chicken the same way again, but but but again, no matter what it is, this covered dish may be may be what you think it is, and it may be something different, and so that’s the that’s again the major the major topic in here is that you know Microsoft has made promises and they seem to be the most generous in general with these with the things that they that they’re giving but understand that none of the none of these are absolute
Randy Johnston 02:20
yeah so you know to Brian’s point, Microsoft we think currently has the best position. They announced this AI indemnification on september 7 of 2023, and so over the last three years they’ve stayed true to their word. We don’t see them changing, but you know your mileage may vary. Microsoft may change their mind, but you know, in the big picture of stuff right now, Microsoft’s Copilot copyright commitment was announced in September on september 7, 2023.
Brian F. Tankersley, CPA.CITP, CGMA 02:54
Yeah. Now, now again, the claim arrives after the work ships, and and again, the the problem here is that nobody’s going to indemnify you that I can think of for the product giving you an incorrect answer. Okay, so so that’s the first thing. You know, the the it’s not everything not everything is covered. But again, if we look at contractual indemnification, I’ve been learning this because I’ve been studying for some some insurance exams lately, and you know, again, when you think about contractual indemnification, you have a covered claim that has to fall within the defined scope, so it has to match the fine print. You have to give timely notice. The agreement identifies who selects counsel and controls settlement. That is, who pays the lawyers and who controls how this works, and then the payment says who’s going to pay covered judgments or approve settlement. Okay, so again, what I want you to see is that it’s similar to insurance, but the contract controls the promise. And so again, the devil the the devil is indeed in the details. If you think about these, if you think about this, there are a lot of different liability types that are not covered and not contemplated in these indemnifications. Okay, so you know again there there are there are a lot of IP issues beyond copyright. So you know it could be training data allegations that that something was used. You know this is this is what this is what the New York Times used in its litigation against OpenAI a while back. We can also have generated output that infringes a third party’s rights of copyright or trademark. You could have covered defense cost judgments or settlements that again may or may not be covered. You also have a lot of other business exposures in here. Again, we think about confidentiality and privacy and professional liability from incorrect advice, and defamation, and regulatory violations, and cybersecurity access. Again, what I want you to see here is that just because you you’re covered from an IP perspective, that is, you haven’t stepped on it, you haven’t trampled on anybody else’s rights, doesn’t mean that you’re. Home free from any perspective. Now, again, I want to remind you here that this is an educational summary. We are not we are not insurance experts. We are not lawyers. We are not trying to give you advice here. And you’re listening in not only multiple states and multiple jurisdictions, but literally multiple countries. And so we we are not and cannot be competent to to give you this. But we do want to let you know that there are more perils that you may encounter than than than there are many more than what you’re indemnified for. So we have to again kind of think about that.
Randy Johnston 05:31
And you know, I’ll just call out for Brian’s purposes: the day that we’re recording this, the New York Times case is active, and in fact, there were hearings just yesterday on this, and of course, the Trump administration has filed a briefing on this. The judges are hearing from OpenAI and from the New York Times as we record. In fact, they’re probably in court right now on this, so there may be some outcomes after the fact, but the bottom line is, in my reading of the case, it is clear that the New York Times copyrights have been violated. Other people will make that call, but you know I say that as an author where my books were hoovered up off the internet, and Google has a comparable, and so do the AI companies, violation of my copyright on the books that I have written, because they didn’t pay me a thing to hoover up my intellectual property.
Brian F. Tankersley, CPA.CITP, CGMA 06:35
And and let me say that this is exactly what we were talking about with when we talked about regulatory certainty not existing for AI right now, because we don’t know until the courts decide decisions like this New York Times one, and they tell us what what copyright really means in the real world with this this particular application. You know the problem here is that we have so many new things happening with AI that have never really been contemplated before. That you know, again, if you think about if you think about you know Andy Warhol’s Campbell soup cans that he created back in the 1960s and 70s, you know, did that violate Campbell’s copyright copyright or not? Okay, that’s you know where he’s using silk screening in photos. That’s a whole different thing than what we’re trying to do here with AI. And and so defining what a derivative work is is is different. And again, defining the you know defining what the fair use is is different. And so that’s what we mean when we talk about not having a lot of regulatory certainty around AI is that this we don’t know which way this is going to go. Nobody does.
Randy Johnston 07:46
We don’t. And the wheels of justice turn so slowly because this lawsuit was originally filed in December of 2023, and so here we are three years later, just kind of getting to it. And just think about how many things have occurred in the last year or two related to AI that there’s just been no judgments on, and so you know we can look at a kind of a recent cultural funny, you know the Bucky’s lawsuits, which you know Bucky is the Bucky legal team files against everybody that has a yellow and red logo, it’s it’s fascinating, and I’ve actually been in the convenience store in Beaver Creek, Ohio, that kind of lit this whole thing up, and you know that’s those guys weren’t trying to violate a copyright. You know,
Brian F. Tankersley, CPA.CITP, CGMA 08:37
I want to what what I want to see. I want to see them. I want to see them go after because it seems like the Canadians have have a beaver on one unit of their of their money, and I really I want to see I want to see Bucky go after go after Mark Carney and really try to try to collect something on that. That’ll be interesting.
Randy Johnston 08:58
We we we we actually are a little off topic, so I’m the one that caused the problem. So let’s get back on it. Where yeah,
Brian F. Tankersley, CPA.CITP, CGMA 09:06
so so so as we look at the access channel in here, I want to remind you here that how you how you buy and what you pay makes a big difference with respect to this. Okay, and so the access channel does change the contract. There’s a good example. If you look at the privacy policy summaries for Claude Anthropic that I’ve analyzed at wiki.cpate.ch, there’s actually a comparison table that compares your rights when when you’re using Claude with a commercial contract versus with API versus a personal contract, and and you know the rights you get are vastly different. Okay, and the indemnification is vastly different. But I want you to so I want you to know here that that again you need to think through: Are you buying it directly from the model company? Are you going. Through a cloud platform, are you going through one of these aggregators that we’ve talked about in previous? You know, the oh the routers that are out there that allow you to use multiple models. Is it embedded in another application? Okay, so so again, I want you to get here that you may be three end user license agreements deep in this because you may have a EULA with the application you’re running, which may be going through a router or marketplace, which may then be going through a an engine, and so the the complexity of figuring out and and nailing down what what what what if any protection you have is is very different. So so just be be very careful here. Now, Google has Google again has two pronged indemnity, and so again, looking at this now, they have explicit protection for allegations related to Google’s use of training data. They also have some protection from generated output from from certain listed indemnified services. Okay, but only certain things are covered, and intentional infringement and failure to use responsible use tools can defeat protection. Okay, so so Google does do some protection on this. So I guess I guess Randy, you know, if if somebody has a grievance, if somebody somebody creates a grievance off of off of your book being hoovered up by Google, I guess they’re paying for it. At least is the theory there. So, so we’ll see what we have there. With OpenAI, they have API indemnity. It covers third-party use claims that distribute output that infringes an IP right. They also have a commercial agree in the commercial agreement only. It applies to identified business and developer services. So, you know, again, I want you to see that some stuff’s covered and some stuff’s not here, and and so notice that trademarks in particular are expressly expressly excluded from the API. So you know, to your to your comment, to bring it back to Bucky the Beaver, to your comment here, if if somebody uses uses OpenAI, you know, Dally to create a logo that looks very similar to Bucky’s. OpenAI isn’t going to help you. Okay. Now looking at Anthropic, they’ll defend commercial customers against copyright claims. They they will cut the covered settlements may be paid under the commercial terms. It is tied to authorized commercial use and the applicable agreement, but I want you to see here that that again, as you as you’re as you’re looking at this again, your rights. If you’re just using the using this on at Anthropic.com or again Claude AI, it’s a very different. Your your rights are very very different than if you have a commercial use license. Now Meta Meta has the Llama engine, and again, I will tell you that I I I would not trust any use of the Llama engine on on Meta’s site from a privacy perspective. And again, they they say, look, you’re you’re a big boy or girl. You’re using an open source application. You get open source liability, so you get all of it. Okay, and and so that’s a, you know, again, this this gives you some flexibility. So, for example, I have I have a container running Open Llama on on one of my servers in my lab, and I use it sometimes. It is dog slow because it’s not running on a on a great you know, doesn’t have great processing capability on that server, but but it is running offline now.
Brian F. Tankersley, CPA.CITP, CGMA 13:27
You know, again, I don’t know exactly how much how much data is getting shared with Meta out of that engine, but but this does bring up the concept of the conversation that needs to be had about about the about I guess these these AI engines and running them offline instead of running them in somebody else’s data centers and the impact there on compliance. You know, again, there’s a lot of stuff that’s open. Randy, you have something here?
Randy Johnston 13:52
Yes, I was just going to say, Brian. As you said that, I’m thinking that seems like a great place to use your Wireshark. You know, over the next few weeks, just letting that that server get watched to see if it’s like ET phoning home, because one of our approaches, friends, have been to run a local AI server using Olama on hardware, as Brian described, but NVIDIA is going to do the same type of thing, and today both IBM, Lenovo, and Dell have very inexpensive Blackwell-based hardware that you could run premise-based, and we’ve not found a resource like that that is available in the cloud today because most people want to charge you for every token consumed, but this basically gives you an unlimited AI token budget. So again, I’m off topic a little bit, but you know it just seems to me that wire sharking that darn Olama Meta server of yours isn’t a bad deal because we are concerned. Legitimately about the indemnification for all of you, and what your risks are on using OpenAI, ChatGPT Enterprise, for example, versus a free version versus a paid version, and the same way with every one of these engines out there. Free, well, you know, as Dr. Bob, our friend, used to say, Dr. Bob Spencer, if you don’t pay for it with money, you’re paying for it somehow. So when you’re trying to use a free AI, you’re paying for it with your data and your prompts, which become the property of all of these AI companies. And we’re thinking that it is a bad idea in general for CPA firms and accountants to let any of their client data or the company data that they work for be owned by an AI company.
Brian F. Tankersley, CPA.CITP, CGMA 15:50
Yeah, yeah, agreed, agreed. And and again, there’s a there’s a graphic that that the AI created for me in here that I thought was pretty. And so for those of you, you know, for those of you that don’t see it here, you know, the point here is that you deploy, you operate, you bear the risk. And so, if you’re again, if again, this this whole concept, because again, the the concept of legal privilege has not been fully worked out yet, but it looks like the stuff you put into public AI servers is going to be discoverable, so this means that if you want if you want attorney-client privilege, you may have to run this offline. Well, suddenly now you have all of the risk, but you also may retain, and I don’t say will, I say may retain some level of legal privilege with respect to that, and so you know, I think I think we’re going to have to watch the legal profession in particular because their their stock in trade is is attorney client privilege, and honestly, if they can’t speak frankly with their clients, then and get good advice from outside outside advisors, then we may have to just throw AI completely out, and so it’s a it’s going to be an interesting time. But I’ve
Speaker 1 17:05
got to,
Randy Johnston 17:05
and it’s almost too early, Brian, to pull in the Apple announcements where they’re talking about their new AI privacy approach. So, friends, many of you use iPhones and iPads, and you know, with the iOS 27 announcements in September. We’ll just have to do a little bit of a wait and see for analysts to figure that out. Obviously, we’ll be watching it too. But Brian has a pretty good summary of the provider risks.
Brian F. Tankersley, CPA.CITP, CGMA 17:33
Yeah. So, so just kind of looking at the big five here. Microsoft says that for covered commercial offerings, they they they will cover you for output claim for some output claims. They will not they will not for the principal public framing stuff. You know again they they have their you have to use guardrails. You have to use covered covered product that is paid services, proper inputs, and and again use those use those guardrails. You also for Google. Google has output will says yes they’ll do some coverage for listed services. They explicitly state what they’ll cover and what they won’t. It does require responsible use. OpenAI says says they will do this some chiefly with the API calls and business scope. It’s not explicitly cited in the cited output indemnity for training data. There are very detailed exclusions, and in particular, beta and third-party output is also excluded. Then, for anthropic, you have they they will do this for commercial use. Meta will Meta has no comparable public shield in here. Okay, so I guess what I want you to what I want you to look at here is I want to tell you that first off, it’s a very complex topic. Secondly, there’s a lot of depth to these privacy policies, and there are a lot of things, frankly, that are not publicly stated in the privacy policies and the terms of use and the indemnification claims that you need to make decisions to make good decisions here, and there’s not regulatory certainty. So just know that that this is a that that there’s a lot a lot to think about here, and so I just kind of want you to again just kind of kind of take you through here. So so I guess you know again looking at this, there’s other issues too. Can you prove that you complied with what what you needed to comply with? Okay, what records do you preserve? Yeah, I’ll bet that most of you don’t preserve records. You know, for for example, long enough for three years from the time you file a lawsuit to to the time that you have to file a claim, unless you know you’re going to be litigating it. Okay, so most of you are not going to keep those logs that long. I’ve got seven legal questions for this. Again, these are some of the some some questions to consider. There are many many other questions that could be considered, but but again, I want you to I want you. To again think about this, and and again, just remember that like everything in life, the lot the deep the the the usability and the value associated with any kind of indemnification comes from the details and the fine print. Okay, and the challenge here is that the fine print is not is not explicitly detailed enough in most cases with with folks like subprocessors and and other things like this. Again, the the legal requirements haven’t kept up with this to help you make all the great decisions, and so there’s going to be some level of risk. There’s no way to eliminate your risk in this area. So with that, Randy
Randy Johnston 20:37
Brian, some questions on AI indemnity are worth hearing. What exact product and customer tier covered? Which number two? Which agreement covers this access route? Number three. Which claims qualify training output, copyright, or other IP? Number four. Which conduct, tools, or modifications eliminate protection? Number five. What liability cap or remedy limit applies? Number six. Who controls the council defense strategy and settlement? And number seven: What notice cooperation and evidence duties must we meet? So when you think about the ownership here, your legal can review the terms, IT can configure the controls, but you, as a business owner, have to monitor the actual use. And you know this monitoring of AI-it’s a tough nut to cut right now. Microsoft is trying with their purview capabilities. We do not see comparable AI controls in enough other places. We’re hopeful that agents will give us some of these type of controls, and private AI will give us some of those type of controls, but you know we have to make that the AI that we’re using is owning home. So Brian, such a brilliant bit of conceptual preparation on your side. It’s appreciated, listeners. We appreciate you being along, and hopefully you sleep okay after hearing about all your AI indemnification and risk, we’ll here we’ll be with you again in a future AI, future accounting technology lab. And Brian, I appreciate your time.
Brian F. Tankersley, CPA.CITP, CGMA 22:15
Good day. Thank you for sharing your time with us. We’ll be back next Saturday with a new episode of the Technology Lab from CPA Practice Advisor. Have a great week.
= END =
Sign in to get access to this free resource, and all of our whitepapers and reports.
Download this content today!
Register Now Already registered? Click here to Log In