CyberCode.ph · Philippines

AI Vendor Contracts: Who Owns Prompts, Inputs and Outputs in the Philippines?

Last updated October 3, 2026 · Practical privacy, cybersecurity and technology-law guidance

By Cybercode.ph Editorial Team · Research on Philippine technology contracts, AI governance and intellectual property.

Last materially reviewed: September 5, 2026

Intellectual Property → AI-Generated Works

Direct Answer

An AI vendor contract should distinguish prompts, customer inputs, generated outputs, model improvements and vendor technology instead of using one broad ‘ownership’ sentence. A contract can allocate use and assignment rights between the parties, but it cannot guarantee that purely AI-generated output qualifies for copyright under Philippine law.

Key Takeaways

  • Define customer data, prompts, outputs and vendor IP separately.
  • State whether inputs are used to train or improve the vendor’s models.
  • Address confidentiality and personal-data processing.
  • Review IP warranties, exclusions and indemnity caps.
  • Preserve the customer’s rights in pre-existing materials.

Contract Matrix

Asset Contract question
Prompts Who may store, reuse or disclose them?
Customer inputs Does the customer retain ownership and confidentiality?
Outputs What use rights or assignments are granted, and what if copyright does not exist?
Model improvements Can customer activity be used to improve shared models?
Vendor platform What remains the vendor’s software, models and documentation?

Annotated AI Vendor Contract Pack

Targeted update: 3 October 2026. These sample clauses are negotiation starting points for business users, not a complete agreement or NPC-approved terms. Replace placeholders, confirm the actual parties and data roles, and have the complete contract reviewed for your use case. Statutory duties and proposed commercial protections are distinguished in the notes.

First complete the vendor evidence matrix. Then define “Customer Data” to include the prompts, uploads, outputs and related personal/confidential information you intend to protect; separately identify service-account and diagnostic records. Definitions should match the provider’s technical operation.

1. Processing instructions and confidentiality

Sample wording: Vendor will use Customer Data only to provide the services described in Schedule A and follow Customer’s documented lawful instructions. Authorised personnel will be subject to confidentiality obligations. Vendor will promptly flag instructions it believes unlawful.

Review note: Complete Schedule A with purposes, data categories, people affected, duration, locations and roles. Check whether the provider also acts independently for account or security data; do not mislabel every activity as processing on your behalf.

2. Model training and service improvement

Sample wording: Vendor shall not use Customer Data, prompts or outputs to train, fine-tune or improve shared models without a separate written agreement identifying the permitted data and purpose. Necessary abuse monitoring and diagnostic processing must be specifically listed, limited and subject to the agreed safeguards.

Review note: Proposed restriction, not a universal ban imposed by Philippine law. Define feedback, human review, embeddings and derived datasets. Check default settings and service tiers; avoid allowing a broad analytics exception to defeat the clause.

3. Retention, return and deletion

Sample wording: Schedule B will identify retention for each data class. On exit, Vendor will return or delete personal data at Customer’s choice, subject to lawful storage requirements, and confirm completion. Any permitted backup retention will have a stated expiry and restricted use.

Review note: List active copies, logs, backups and support tickets separately. Insert agreed export format, timing and costs. No immediate-erasure promise if backups cannot deliver it; establish a documented method and review the remaining risk.

4. Subprocessors and processing locations

Sample wording: Vendor will identify proposed subprocessors, their work and processing locations. Further processing engagements require Customer’s prior documented instruction and equivalent data-protection obligations. Changes follow the notice, review and objection process in Schedule C.

Review note: Check overseas support and remote access as well as storage. Agree workable remedies if a material change cannot be accepted, including suspension or exit. A selected data region alone does not establish transfer compliance.

5. Security, evidence and assistance

Sample wording: Vendor will maintain the controls in Schedule D, provide compliance evidence and support agreed audit arrangements. Vendor will assist Customer with data-subject requests and relevant compliance enquiries.

Review note: Make the schedule testable: access, isolation, encryption, logging and incident handling. Define assistance contacts and response times; evidence reports do not automatically replace all audit rights. The baseline processor obligations come from the DPA IRR.

6. Incident notification and cooperation

Sample wording: Vendor will notify Customer without undue delay after becoming aware of a security incident affecting Customer Data, with an initial report no later than [agreed hours]. Initial notice will include available facts and be followed by updates, evidence preservation and remediation support.

Review note: The bracket is a negotiated operational limit, not a statutory deadline. Do not wait for a final forensic report. Define trigger, recipients and secure channel. The controller separately assesses any NPC/data-subject notification duty; this clause does not extend legal deadlines.

7. Inputs, outputs and vendor technology

Sample wording: Customer retains its rights in supplied materials. Vendor retains its pre-existing technology. To the extent it holds transferable rights in outputs, Vendor assigns those rights to Customer and grants the use permissions required for the agreed service, subject to identified third-party restrictions.

Review note: Commercial drafting option, not a guarantee of copyright, uniqueness or non-infringement. Define output and background technology. Negotiate infringement-claim handling, defence control, exclusions and liability caps separately; do not infer indemnity from an ownership sentence.

8. Order of precedence, change and exit

Sample wording: The signed AI/data schedules prevail over conflicting online terms for the matters they address. Material changes to data use or safeguards require the agreed change procedure. On termination, Vendor will support the agreed export and transition before completing deletion.

Review note: Name the documents and versions, notice period, remedy and transition costs. Negotiate governing law, dispute process, payment, liability, warranties and termination elsewhere in the full agreement.

Schedules to Complete Before Signing

  • A — Processing: named use case, purposes, data/people, duration, roles, instructions and locations.
  • B — Data lifecycle: retention, export, deletion, backups and lawful exceptions.
  • C — Provider chain: approved subprocessors, functions, access locations and change process.
  • D — Controls and support: security measures, evidence, rights assistance, incident contacts and service commitments.

Worked negotiation example: the fictional retailer’s vendor says prompts are excluded from training, but its online terms permit general service improvement and its backup policy is unclear. Ask for an explicit scope/precedence provision and a deletion schedule. If the vendor declines, document the gap; keep live customer data out unless the design changes and the privacy assessment supports proceeding. A signature alone does not resolve a technical limitation.

Primary legal anchors: DPA IRR, Sections 38 and 43–45; RA 10173, Sections 14, 20 and 21; NPC Advisory 2024-04. Contract timing, no-training restrictions, IP allocation and exit mechanics require negotiation; the sample does not displace legal obligations.

Clauses To Review

  • IP ownership and licenses;
  • training and model-improvement rights;
  • confidentiality;
  • data processing and security;
  • retention and deletion;
  • third-party content;
  • IP indemnity;
  • warranty disclaimers;
  • liability caps;
  • termination and export of customer data.

Why ‘You Own the Output’ May Not Be Enough

A vendor can promise to assign whatever rights it has, but copyright law still determines whether protectable copyright exists. The customer should also ask whether similar output can be generated for other users and whether the vendor gives any exclusivity guarantee.

Related Cybercode Guides

Frequently Asked Questions

Can a vendor use our prompts to train its model?

That depends on the contract, privacy settings and service configuration. Businesses should not assume the answer; verify it before uploading confidential material.

Should we require an IP indemnity?

For material commercial use, it is worth negotiating. Read the scope, exclusions, notice requirements, defense-control provisions and liability cap carefully.

Official Sources

Featured image: Photo by Matthew Fournier on Unsplash.

Disclaimer

Important: This article provides general educational information about Philippine law, regulation, cybersecurity, technology, or business compliance. It is not legal advice and does not create an attorney-client relationship. Laws, agency procedures, technical standards, platform rules, and the facts of each situation may change the result. Verify current requirements through the cited official sources and seek qualified professional advice when your rights, deadlines, money, safety, or legal exposure may be affected.

CyberCode updates

Get practical updates on Philippine technology law, data privacy, cybersecurity, and AI.

Email activity tracking

Unsubscribe any time. See our privacy policy below.