Est.

Limitation of Liability Caps in B2B Contract Negotiations

Negotiators focus on cap size while missing two separate mechanisms that actually control risk.

Features Editor · · 9 min read
Cover illustration for “Limitation of Liability Caps in B2B Contract Negotiations”
Contract Negotiation · October 2, 2026 · 9 min read · 2,119 words

Most B2B negotiators spend their time arguing about a number, the multiple attached to the liability cap, while the clause doing the real work of allocating risk gets far less scrutiny than its consequences deserve. The limitation of liability clause moves more risk than the indemnity, the warranty, and the SLA combined, and World Commerce & Contracting's Most Negotiated Terms 2024 report ranks it the single most-negotiated commercial contract term, ahead of price and indemnification itself. Most negotiators treat it as one lever, asking only what the cap number is, when the clause is actually running two independent mechanics at the same time. Conflating those two mechanics is the most common drafting error in commercial contracting, and it's also the reason sophisticated parties routinely end up with far less protection than they believe they negotiated.

The two independent mechanics inside a single clause

A well-drafted limitation of liability clause contains two entirely separate mechanisms, and a counterparty can lose a claim because of either one on its own. The first mechanic is the damages exclusion, which sets limits by type of harm rather than by dollar amount. It bars recovery of indirect, incidental, special, consequential, exemplary, and punitive damages, along with lost profits and lost data in most drafting, regardless of whether the claim arises in contract, tort, or strict liability. The exclusion does not cap a number at all. It removes entire categories of harm from consideration before any cap is reached.

The second mechanic is the liability cap, which limits the dollar amount of what remains after the exclusion has done its work. It sets a ceiling, typically tied to fees paid in a defined look-back window, on everything that survives the exclusion, usually direct damages. The cap applies no matter what legal theory the claim is framed under: contract, negligence, and warranty claims all funnel into the same number.

A simple scenario shows why the distinction matters. A vendor's SaaS platform goes down for a week, and the customer loses a meaningful amount of revenue during the outage. That lost revenue is a consequential damage, and the exclusion wipes it out before the cap is ever relevant. The cap, in this scenario, never even enters the conversation, because the exclusion already decided the outcome.

Lost profits aren't automatically treated as consequential damages. Some courts treat lost profits as direct damages when they represent the profits the contract itself promised, so a waiver written as "consequential damages, including lost profits" can leave the most painful loss sitting outside the waiver. The safer approach is to define lost profits as excluded regardless of how a court might characterize them, rather than relying on the consequential-versus-direct distinction to do that work.

Diagram: One Clause, Two Independent Mechanics. Visualizes: Visualize how a single limitation of liability clause runs two entirely separate mechanisms in sequence before any recovery is possible.

How the cap is sized

Once the exclusion and the cap are understood as separate jobs, the next question is how the cap itself gets measured, and the headline multiple turns out to be only one of several variables that decide the real number. Two structural choices, the cap basis and whether the cap applies on an aggregate or per-claim basis, can move the real dollar amount more than the multiple does, so a "1x" cap can mean wildly different things depending on how it's built.

The fees-paid basis, measured on a trailing 12-month look-back, is the market standard for recurring SaaS and subscription arrangements. Drafting it as "fees paid or payable" rather than "fees actually paid" matters in practice, because a cap tied strictly to money already collected can be close to zero early in a contract term, long before the relationship has generated any meaningful payment history. Other bases show up depending on deal type: total contract value, which buyers often push for early in a term when fees paid so far are small, and insurance-linked caps, common in manufacturing and supply chain contracts, where the ceiling is the greater of a fee-based cap or the vendor's available insurance proceeds. A fixed dollar floor can also be layered on top of the multiple, setting the cap at the greater of a stated amount or 12 months' fees, so low-spend customers still retain a meaningful cap.

The cap also varies by deal type and risk profile. Conservative, vendor-favorable drafting sets the cap at 1x fees actually paid, aggregate across all claims. The standard in technology and retail contracts runs closer to 1x annual fees or annual contract value. Regulated, data-heavy deals, healthcare, financial services, critical infrastructure, routinely push the multiple to one to three times fees, with the highest-risk categories pushed further into supercap territory.

The gap between what a cap allows and what real-world harm costs can be enormous. If a vendor's platform failure causes significant damages but the liability cap equals only the annual subscription fee, the maximum recovery can amount to a small fraction of the actual loss. In Zirkelbach Construction Inc. v. In Taylor Morrison of Colorado Inc. v. Terracon Consultants Inc., also decided in 2017, a limitation of liability clause reduced recovery to $550,000 out of a jury verdict of $9.5 million. Neither case involved a weak cap on paper. Both show what a cap, properly enforced, actually does to a judgment once the number is set.

Vendors frame all of this as a pricing decision rather than a legal abstraction. The price of the deal reflects the risk the vendor has agreed to absorb, and a customer asking the vendor to take on more liability is, in effect, asking the vendor to reprice the entire engagement. That framing is what makes carve-out negotiation the real fight, because carve-outs are where a customer gets specific protection without renegotiating the whole deal's economics.

What carve-outs do

Carve-outs are the only mechanism that moves a specific category of claim outside the cap, the exclusion, or both, and they define how much protection the clause actually provides more than the multiple ever does. The standard carve-outs that sit outside or above the general cap are well established across the market. IP-infringement indemnity is the most commonly fully uncapped category. Confidentiality and data-protection breaches typically get their own treatment. Fraud, gross negligence, and willful misconduct sit outside the cap almost universally. A party's payment obligations are usually excluded from any cap as well, and death or bodily injury claims are carved out because most jurisdictions mandate it regardless of what the contract says.

A carve-out does two jobs at once: as a sword, it restores recourse that the cap and the exclusion would otherwise eliminate, giving a customer a real path to recovery for the risks that matter most to it. As a shield, it pulls the counterparty back to the table during negotiation, because leaving a category of conduct fully exposed changes how seriously a vendor treats that risk internally.

The most dangerous drafting trap is how carve-outs interact with the consequential-damages waiver. A mutual waiver that excludes lost profits "for any claim" can gut an indemnification right almost entirely, because the damages the indemnity was meant to cover turn out to be the same damages the waiver already excluded. The carve-out list has to be checked against the exclusion clause, not just the cap, or the carve-out ends up doing half the job its drafters intended.

A dollar example shows how much a single carve-out can decide. Picture a SaaS contract where a misconfiguration exposes customer data and the fallout costs $900,000 in breach notification and regulatory response. With a standard 12-month-fees cap and no data carve-out, the customer recovers only a fraction of that amount. With a data-breach supercap in place, the customer recovers the full $900,000. Same incident, same contract term, same vendor. The carve-out is the only variable that changed, and it changed the outcome completely.

Diagram: The Carve-Out That Changed the Outcome. Visualizes: Show a single before/after comparison using the article's explicit dollar example: a SaaS misconfiguration exposes customer data, breach notification and regulatory response cost $900,000.

Data breach, IP, and AI risk

Three categories, data breach liability, IP infringement, and AI-related risk, produce the widest gap between the general cap and what a loss actually costs, and that's where carve-out drafting carries the most weight.

Data breach exposure makes the standard fees-paid cap look structurally inadequate the moment a breach touches customer records. Notification obligations, regulatory fines, and class actions can run far past any annual fee a cap might reference. Sophisticated parties increasingly negotiate specific data-breach carve-outs that set a higher cap, often a multiple of the standard cap or fully uncapped, for claims tied to unauthorized access or disclosure of personal data. Courts typically read breach-of-confidentiality carve-outs as covering the voluntary sharing of confidential information rather than a security failure that exposed data without anyone choosing to share it, so a carve-out written for "data security" violations can still fail to unlock consequential damages in a breach dispute. The language has to name the risk specifically or it won't reach it. More recently, parties have started citing carve-outs tied to GDPR violations and other data privacy statutes as an additional route to recovery above the general cap.

IP infringement sits as the most commonly fully uncapped carve-out in standard commercial drafting, largely because the vendor controls the product and therefore controls the infringement risk the product creates. Major large language model providers have started offering IP indemnity for third-party infringement claims tied to their outputs, but most mid-tier and enterprise AI SaaS vendors haven't followed that lead, and some have gone the other direction, explicitly carving AI-generated content out of their standard IP indemnity. A year of fees on a modest monthly AI subscription will never come close to covering a copyright damages award. IP infringement claims tied to AI outputs need their own carve-out rather than living inside the general cap.

AI risk more broadly is putting pressure on the old "low cap plus broad disclaimer" formula, because AI errors can produce regulatory fines, reputational damage, and mass litigation with no relationship at all to the fees the customer paid. Practitioners are increasingly structuring differentiated caps, a lower ceiling for general damages, a higher or separate ceiling for privacy and security breaches, alongside specific carve-outs for discriminatory outputs, third-party IP infringement, and data breaches, with mandatory impact assessments such as DPIAs and AI risk assessments written directly into the contract.

What happens when the clause is missing entirely makes the stakes concrete. In one AI-drafted development agreement with no limitation of liability clause at all, a client alleged that a security flaw introduced after delivery caused a large data exposure, and there was no contractual ceiling anywhere limiting what the developer could owe. A clause running four to six sentences would have capped six-figure exposure from what started as a modest engagement. The absence of the clause turned a routine dispute into open-ended exposure, not a poorly drafted version of it.

The structural imbalance in vendor paper

Vendor paper almost always drafts the cap as one-sided. It limits what the vendor can owe without imposing any matching ceiling on what the customer can owe, and that asymmetry is the starting point for nearly every B2B negotiation over this clause. The default vendor position tends to follow a predictable pattern: a cap set at 1x fees actually paid in the trailing 12 months, aggregate across all claims; a mutual consequential-damages waiver with no carve-backs; carve-outs that are narrow or simply absent for data and IP; and customer-side obligations, payment chief among them, that sit outside any cap or remain fully uncapped, with no equivalent sentence limiting what the customer itself can owe.

Customers pushing back on this template tend to raise the same set of asks, roughly in priority order. The first is switching the cap basis from "fees paid" to "fees paid or payable," so a claim that arises early in year one isn't capped against only a few months of billing history. The second is adding a fixed floor, so a small or heavily discounted deal still carries a cap that means something in a real dispute. The third is carving out data breach, IP infringement, and confidentiality breaches into a higher supercap or an uncapped category entirely. The fourth is making the consequential-damages waiver genuinely mutual and checking that the carve-outs restore the losses the indemnity was built to cover.

A service provider is typically positioned to cause far greater damage to its customer than the reverse is true, while the customer's primary exposure in most deals is simply the obligation to pay. A liability cap that treats both sides identically ignores that asymmetry rather than correcting for it. The practical landing point in most sophisticated negotiations is a supercap structure: a baseline cap for ordinary claims, paired with a materially higher ceiling, or no ceiling at all, for the narrow set of claims, data breach, IP infringement, fraud, that the parties agree carry risk the baseline number was never built to cover.

Sources

  1. Limitation of Liability: What's Standard (2026)
  2. Limitation of Liability Clause: Caps, Carve-Outs, and Fallbacks

More in Contract Negotiation