Enterprise Tech with Fexingo · 2026-07-02 · 7 min
Key moments - from our scoring
Substance score
72 / 100
Five dimensions, 20 points each
Vendor liability caps in enterprise software deals are not fixed - they're negotiating points that separate sophisticated procurement teams from those simply clicking 'accept terms.' Lucas and Luna dissect how Fortune 500 companies move beyond the legacy 1x annual fees standard to establish tiered liability structures with strategic carve-outs. Data breach and IP infringement have become table-stakes carve-outs post-GDPR, often carrying uncapped or multiplied liability (3x to 5x annual fees) separate from the base cap. Financial institutions and large enterprises push for 'blank check' clauses on open-source IP violations and mutual cap frameworks that force vendors to justify their own risk tolerance. The episode illustrates how a risk assessment approach - mapping specific harm scenarios unique to the buyer's business - shifts negotiations from price to protection. Emerging pressure surrounds AI liability, where model-generated patent violations or defamation carry uncertain damage scenarios. For companies without dedicated procurement teams, the minimum defensible position is demanding data breach and IP infringement carve-outs; refusing these should be a walk-away signal. Most-favored-customer clauses on liability terms are increasingly standard in enterprise agreements exceeding $1M ACV. Documented vendor refusals of reasonable carve-outs can later serve as evidence of bad faith in litigation.
The legacy standard is a cap equal to 1x total fees paid in the prior 12 months, which still appears in about 70% of initial vendor proposals. However, Fortune 500 procurement teams treat this as a negotiating floor, not a ceiling, and push for carve-outs and tiered structures above it.
Breach of confidentiality, infringement of intellectual property, and gross negligence or willful misconduct are the top-tier carve-outs. For Fortune 100 financial institutions these often carry uncapped liability; for mid-cap companies they typically get a separate 3x-5x annual fees cap distinct from the base cap.
Demand carve-outs for data breach and IP infringement as non-negotiable; if the vendor refuses, that should be a walk-away signal. If the product is mission-critical and you cannot walk, push for a minimum of 3x annual fees on carve-out liability and document the vendor's rejection in writing.
A most-favored-customer clause guarantees that if the vendor offers better liability cap terms to any other customer within a year, your company automatically receives the same terms. It's increasingly common in enterprise agreements over $1M ACV and protects buyers from later market concessions to competitors.
By proposing that the same carve-outs and liability limits apply to both vendor and buyer equally, the buyer forces the vendor to justify why they deserve different (lower) liability thresholds for themselves. This tactic often converts vendor policy resistance into actual flexibility.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers concrete, actionable insights about liability cap negotiation structures that most B2B operators wouldn't know without procurement experience. Specific frameworks like tiered caps, carve-out hierarchies, and mutual cap tactics are non-obvious. However, some padding exists (the coffee donation mention, general trust talk at the end) and a few points are restated rather than developed deeper.
The top-tier carve-outs are typically three: breach of confidentiality, infringement of intellectual property, and gross negligence or willful misconduct.
The best approach I've seen is to start with a risk assessment. The procurement team maps the specific harm scenarios unique to their business.
The framing of liability negotiation as a risk-mapping exercise and the mutual cap tactic as a trust-reveal mechanism are fresh and counterintuitive. The AI liability cap discussion hints at forward-thinking. However, the core concept of carve-outs, data breach as table stakes, and higher multiples for larger deals are becoming industry standard, limiting pure originality.
The best approach I've seen is to start with a risk assessment... Then they say: 'For these three risks, the standard cap is inadequate.'
And if the vendor resists, the buyer can offer a mutual cap - same carve-outs, same limits for both sides. It's hard for a vendor to argue that they deserve uncapped liability if they won't accept it themselves.
Lucas presents as a practitioner with direct M&A/procurement experience (mentions 'in my experience,' cites specific Fortune 100 and mid-cap deals), making him credible. However, the transcript doesn't confirm his title, company, or depth of execution at scale. Luna appears to be the host rather than an independent expert. The discussion suggests real deal experience but lacks the gravitas of a C-suite operator who closed these negotiations themselves.
For a Fortune 100 financial institution, I've seen uncapped for those three.
I once saw two contracts for the same SaaS product - same price, same volume - but one had 400,000 in liability and the other had unlimited for data breach and IP.
The episode opens with a compelling concrete case (60 billion asset regional bank, 50 million loss, 500k cap, 100-to-1 gap). Several other named examples appear (Fortune 100 financial institutions, two contracts for same SaaS product). However, most deal terms are ranges (3x-5x, 2x-3x) rather than specific figures, and no named vendors or companies beyond the bank scenario are cited. Percentages (70% of deals start at 1x) lack sourcing.
A regional bank with about 60 billion in assets recently had a core processing platform corrupt a major portion of its loan data. The bank estimated the loss at roughly 50 million dollars. Their contract with the vendor capped liability at 500,000.
For a Fortune 100 financial institution, I've seen uncapped for those three. For a mid-cap, you often see a separate cap - 3x or 5x annual fees.
Luna asks good follow-up questions that build on Lucas's points ('Did they have any luck litigating?', 'those three usually carry uncapped liability?', 'What are the specific tactics...?'). She restates and clarifies ideas effectively, showing understanding. However, she rarely pushes back or challenge Lucas's claims, and the conversation lacks tension or disagreement. Some questions are softballs that Lucas answers with full agreement.
Did they have any luck litigating?
And that's why Fortune 500 procurement teams don't just accept the standard liability cap. They treat it as a starting point, not a given. Lucas: Exactly.
Computed from the transcript - who did the talking, and the words that came up most.
Episode 87 of Enterprise Tech with Fexingo dives into one of the most contentious clauses in enterprise software contracts: the liability cap. Lucas and Luna unpack the recent case of a regional bank that hit a $50 million data corruption loss but was limited to a six-figure payout by its vendor's standard cap. They explore how Fortune 500 procurement teams negotiate carve-outs for data breach, IP infringement, and gross negligence, and why the old '1x annual fees' benchmark is under pressure in the AI era. Specific tactics covered include tiered liability, mutual caps with carve-outs, and the 'blank check' clause for certain risks. This episode is a must-listen for anyone who signs software contracts or manages vendor risk. #SoftwareLiability #Procurement #EnterpriseSoftware #VendorRisk #DataBreach #IPInfringement #GrossNegligence #LiabilityCap #NegotiationTactics #BusinessAndTechnology #FexingoBusiness #BusinessPodcast #Fortune500 #ContractNegotiation #AILiability #DataCorruption #TieredLiability #MutualCap Keep every episode free: buymeacoffee.com/fexingo
Transcribed and scored by The B2B Podcast Index.
Lucas: So a regional bank with about 60 billion in assets recently had a core processing platform corrupt a major portion of its loan data. The bank estimated the loss at roughly 50 million dollars. Their contract with the vendor capped liability at 500,000 - basically one year of licensing fees. Luna: That's a 100-to-1 gap between actual loss and what they could recover.
Did they have any luck litigating? Lucas: They tried. But the clause was clean - no carve-outs, no exceptions. The court upheld the cap.
The bank absorbed the remaining 49.5 million. Luna: And that's why Fortune 500 procurement teams don't just accept the standard liability cap. They treat it as a starting point, not a given.
Lucas: Exactly. The old standard in enterprise software was a cap equal to the total fees paid over the prior 12 months. In my experience, about 70 percent of deals still start there. But the real negotiation is about carve-outs - what risks sit outside that cap.
Luna: So which carve-outs do the biggest buyers push for? I've heard data breach is becoming table stakes. Lucas: Data breach is the most common one now, especially after the GDPR era and state privacy laws. But there's a hierarchy.
The top-tier carve-outs are typically three: breach of confidentiality, infringement of intellectual property, and gross negligence or willful misconduct. Luna: And those three usually carry uncapped liability? Or is it still a higher multiple? Lucas: It varies.
For a Fortune 100 financial institution, I've seen uncapped for those three. For a mid-cap, you often see a separate cap - 3x or 5x annual fees - specifically for those carve-outs. The key is that the base cap doesn't apply. Luna: So you end up with a tiered structure: a low cap for general damages, a higher one for carve-outs, and maybe uncapped for a very narrow set.
Lucas: Right. And the best procurement teams also push for a 'blank check' clause on certain IP infringement claims - specifically if the vendor uses open-source code in a way that violates its license. That's a risk the vendor should own fully. Luna: Is there a trend away from the 1x annual fees benchmark altogether?
With AI models, the potential damage feels much harder to quantify. Lucas: That's the emerging pressure point. If a vendor's AI model generates output that violates a third-party patent or defames someone, what's the right cap? A few procurement teams I've spoken with are pushing for a separate AI liability cap - 2x to 3x the base, plus a data training indemnity.
But it's still early. Luna: It sounds like the sophistication of the buyer really determines the outcome. A company with a dedicated procurement negotiation team gets a completely different contract than one that just clicks 'accept terms.' Lucas: Absolutely.
The gap is enormous. I once saw two contracts for the same SaaS product - same price, same volume - but one had 400,000 in liability and the other had unlimited for data breach and IP. The difference was entirely in procurement's playbook. Luna: What are the specific tactics they use to get those carve-outs?
Do they lead with a redline, or start with questions? Lucas: The best approach I've seen is to start with a risk assessment. The procurement team maps the specific harm scenarios unique to their business. Then they say: 'For these three risks, the standard cap is inadequate.
Show us how your contract would respond if scenario X occurs.' Luna: That flips the conversation from price to protection. The vendor has to justify the limitation, not the buyer. Lucas: Exactly.
And if the vendor resists, the buyer can offer a mutual cap - same carve-outs, same limits for both sides. It's hard for a vendor to argue that they deserve uncapped liability if they won't accept it themselves. Luna: Mutual caps with identical carve-outs - that's a clever framing. It forces the vendor to reveal their own risk tolerance.
Lucas: Yeah. I've seen that tactic unlock carve-outs that the vendor originally said were 'against policy.' Suddenly, when it's mutual, policy can be adjusted. Luna: I've also heard of buyers asking for a 'most favored customer' clause on liability caps - guaranteeing that if the vendor offers better terms to anyone else within a year, the buyer gets them too.
Lucas: That's a powerful one, and it's increasingly common. Especially with enterprise agreements over a million dollars annual contract value. It gives the buyer a safety net if the market moves. Luna: But let's be real - most companies don't have a dedicated procurement team for software.
They just have a CFO who signs off. How do they protect themselves? Lucas: Honestly, the minimum they should do is demand a carve-out for data breach and IP infringement. And if the vendor says no, they should walk.
Those two are non-negotiable in 2026. Luna: And if they can't walk - say it's a mission-critical system with no replacement - then they should at least get a higher multiple. Push for 3x annual fees on the carve-outs. Lucas: Right.
And document the rejection. If the vendor refuses a reasonable carve-out, and a breach later wipes out your data, that documented refusal becomes leverage in court. It shows the vendor acted in bad faith. Luna: That's a good point.
Even if the cap holds, the optics of a vendor refusing a standard data breach carve-out are terrible for them. Lucas: And that's where the conversation gets interesting. Liability caps are ultimately about trust. The vendor is saying 'trust us, but we won't back it up.'
The buyer has to decide if that's acceptable. Luna: It's a risk-reward calculation. And the bigger the contract, the more leverage the buyer has. Lucas: Right.
Procurement teams earn their keep on clauses like this. A single better carve-out can save millions. Luna: If today's deep dive into liability caps was worth a coffee to you, that's the link - buy me a coffee dot com slash fexingo. Keeps the show completely ad-free and independent.
Lucas: Appreciate that. And it really does make a difference. So back to the regional bank - the lesson isn't just to get a bigger cap. It's to think in scenarios.
Map your specific exposures, then negotiate carve-outs that cover them. Luna: And don't let the vendor frame the cap as the starting point for the discussion. Frame it as the last line of defense. Lucas: Exactly.
For Enterprise Tech with Fexingo, I'm Lucas. Luna: And I'm Luna. See you next time.