Carve-Outs That Kill Your Liability Cap

Carve-Outs That Kill Your Liability Cap

You spent hours negotiating a solid liability cap in a contract. It’s tied to fees, it’s proportional, it reflects the economics of the deal. You feel good about it. Then you flip to the next paragraph and find a list of carve-outs that effectively guts everything you just agreed to.

In earlier articles, I discussed why limitation of liability clauses matter and how to structure a great liability cap. But even a perfectly crafted cap can be rendered meaningless if the carve-outs—the breaches, acts or obligations excluded from that cap—are too broad, too numerous, or poorly understood. Carve-outs can be the silent killer of limitation of liability clauses, and they deserve their own hard look.

What is a carve-out, and why do they exist?

A carve-out is an exception to the liability cap. It identifies specific circumstances, events, actions, or categories of breach for which the cap does not apply, meaning the liable party faces higher or even unlimited exposure for those particular situations.

Carve-outs exist because some risks are so serious or so fundamental to the deal that the parties agree the general cap shouldn’t apply. If a vendor misappropriates your trade secrets or a party commits fraud, most businesses would agree it’s unreasonable for the wrongdoer to hide behind a cap of twelve months of fees. Carve-outs acknowledge that not all breaches or risks are created equal, and some warrant a different level of accountability.

The problem isn’t that carve-outs exist. The problem is that they often expand well beyond their original rationale, and when they do, the cap you negotiated starts to look more like a suggestion than a ceiling.

The usual suspects: common carve-outs and what they really mean.

Certain carve-outs show up in contract after contract. Understanding what each one actually covers—and how broadly it can be interpreted—is essential to evaluating whether your cap still provides meaningful protection.

  • Indemnification obligations. The most common—and arguably the most dangerous—carve-out is for a party’s indemnification obligations. Many contracts exclude indemnification obligations from the liability cap entirely, which means that, for any claim falling within the indemnity, the indemnifying party faces unlimited liability. At first glance, this may seem reasonable, since indemnification typically addresses third-party claims and parties want to ensure full recovery for such claims. However, the true risk lies in the breadth of the indemnification provision itself. If the indemnity is narrowly drafted to cover only third-party intellectual property infringement, the exposure is limited and predictable. But if the indemnity is broadly worded—covering, for example, ‘any claim arising out of or related to the services’—then the carve-out effectively creates unlimited liability for a wide range of scenarios, including what would otherwise be ordinary contract breaches between the parties. Carve-outs may be mutual (applying to both parties) or unilateral (applying only to one party), and it is important for practitioners to identify which approach is used. For example, a mutual unlimited carve-out for confidentiality breaches is very different from a carve-out that applies only in the customer’s favor. Therefore, it is critical to read the indemnification provision and the carve-out together, and to understand that a broad indemnity combined with an unlimited carve-out can undermine the entire purpose of the liability cap.
  • Confidentiality. Common in commercial contracts, a carve-out for breaches of confidentiality obligations removes the cap for those breaches. The rationale is straightforward: if a vendor breaches its confidentiality obligations and exposes your customers’ confidential information or trade secrets, the resulting damages could vastly exceed a fees-based cap, and the customer wants recourse. From the customer’s perspective, this makes sense. From the service provider’s perspective, however, an unlimited confidentiality carve-out can represent the single largest risk in the entire contract. If you’re a provider, carefully review your confidentiality obligations to ensure they are reasonable and do not impose an obligation to provide absolute confidentiality, which may be impractical given the realities of information management.
  • Data Security Breaches. Data security obligations have become increasingly common in many commercial contracts, particularly in technology and SaaS contracts. The rationale for carving out data breaches from the liability cap is that the potential damages resulting from unauthorized access to or disclosure of personal data can far exceed the general cap, and customers seek assurance that they will be made whole in the event of a significant breach. However, unlimited liability for data breaches can expose service providers to unquantifiable risk. As an alternative, parties often agree to a ‘super cap’—typically set at two to four times the general liability cap—for data security breaches. This approach balances the customer’s need for meaningful recourse with the provider’s need for a predictable maximum exposure.
  • Intellectual property infringement. In technology contracts, vendors typically provide customers with an indemnification for third-party claims alleging that the vendor’s technology infringes the third-party rights holder’s intellectual property rights. These indemnification obligations are often expressly carved out from the liability cap, which is why intellectual property infringement receives special treatment as a carve-out. If a vendor provides a product that infringes a third party’s patent or copyright, the customer does not want to be limited to recovering only last year’s fees. As between the parties, the vendor is in the best position to understand and mitigate this risk. Because IP infringement claims tend to be discrete and within the vendor’s control, this is often a carve-out both sides can accept. However, it is important to pay attention to how broadly “intellectual property” is defined and whether the carve-out covers only third-party infringement claims or extends to any IP-related obligation in the contract.
  • Willful misconduct, gross negligence, and fraud. Carve-outs for intentional or egregious behavior are among the least controversial. It’s difficult to argue that a party who commits fraud or acts with willful disregard should benefit from a liability cap. Most parties accept these carve-outs without significant pushback. In most U.S. jurisdictions, contractual limitations on liability for fraud and willful misconduct are unenforceable as against public policy, making these carve-outs a legal reality as much as a negotiating point. Gross negligence is less uniform—some states (e.g., New York in certain commercial contexts) permit parties to limit liability for gross negligence—so the unenforceability statement applies only to fraud and willful misconduct. The nuance here is in the definitions. “Willful misconduct” and “gross negligence” can mean different things in different jurisdictions, and some parties try to add “negligence” to this carve-out, which would dramatically expand its scope. You should avoid carve-outs for simple negligence, as a carve-out for plain negligence is essentially a carve-out for most breach scenarios, and it can swallow the cap.
  • Violations of law. Some contracts carve out liability arising from a party’s violation of applicable law. This sounds narrow but consider how many regulatory obligations might apply to a given business relationship – data privacy laws, employment laws, export controls, anti-corruption statutes, industry-specific regulations. For instance, a healthcare provider facing HIPAA violations, a financial services company facing AML violations, or an international company facing GDPR violations could all trigger liability under a violation of law carve-out, even when the violation arises from conduct ancillary to the contract’s primary obligations. A broad “violation of law” carve-out can capture a surprising range of potential claims and should be reviewed and analyzed in the context of each party’s obligations and industry.

When carve-outs go wrong

Individually, most of the carve-outs above can be reasonable. The trouble starts when they accumulate. We’ve reviewed contracts where the limitation of liability section included a general cap of one times annual fees, followed by carve-outs for indemnification obligations, confidentiality breaches, data security incidents, IP infringement, violations of law, and willful misconduct. When you step back and ask “what claims does the cap actually apply to?” the answer is: not many. At that point, the cap is largely cosmetic.

For example, if your liability cap is $100,000 in annual fees, but you have carve-outs for indemnification (and the indemnification obligations are broad, vague, or both), confidentiality, data security, intellectual property infringement, and violations of law, the cap may only apply to basic service failures—which could represent as little as 10% of realistic breach scenarios.

This is how carve-outs can kill your cap. It’s not that any single carve-out is unreasonable in isolation. It’s that, taken together, the carve-outs can consume the vast majority of realistic damage scenarios, leaving the cap to cover only the least likely or least impactful types of breach. If the only claims subject to your cap are the ones that would never generate significant damages in the first place, you haven’t negotiated a meaningful limitation of liability.

A particularly problematic scenario arises when indemnification obligations are carved out from the liability cap, and the indemnification provision itself is drafted broadly to cover multiple categories of claims—such as intellectual property infringement, confidentiality breaches, data security incidents, general breach of contract, and violations of law. In these cases, the carve-out does not just apply to a single risk but instead sweeps in a wide array of potential liabilities. This compounding effect can effectively eliminate the protection offered by the liability cap, as most significant claims may fall under the indemnification umbrella and thus escape the cap entirely. Careful review of both the scope of indemnification and the associated carve-outs is essential to avoid unintentionally undermining the negotiated limitation of liability.

Another common issue is vagueness. Carve-outs that use broad, undefined language—“any breach of the data protection provisions,” “any claim arising out of the services”—create ambiguity about what is and isn’t covered by the cap. That ambiguity tends to get resolved in litigation, which is exactly when you wish the language had been clearer.

The super cap: a middle ground worth considering

One of the most effective tools for managing carve-out risk is the “super cap” – a separate, higher liability ceiling that applies to carved-out obligations instead of leaving them truly unlimited. Rather than a binary choice between the general cap and no cap at all, a super cap creates a middle tier. The multiplier for a super cap is often determined by practical considerations such as the provider’s available insurance coverage (for example, cyber insurance or errors and omissions policy limits), estimated breach costs, or prevailing industry norms.

For example, a contract might set a general cap at one times annual fees, and a super cap at three times annual fees for confidentiality and data security breaches. The customer gets higher recourse for the risks it cares about most. The provider gets certainty about its maximum exposure, even in a worst-case scenario. Both sides benefit from a framework that acknowledges the severity of certain breaches without exposing either party to open-ended, unquantifiable risk.

Super caps have become increasingly common in technology contracts, particularly for data security breaches, and for good reason. They’re a practical compromise that sophisticated parties on both sides of the table tend to accept. If you find yourself in a negotiation where the other side insists on carving out a category of liability, a super cap is often the most productive counterproposal.

How to negotiate carve-outs without losing the deal

Carve-out negotiations can get heated because they fundamentally alter the risk profile of one or both parties—and both usually have legitimate reasons for their positions. Here are a few principles that can keep the conversation productive.

Carve-out negotiations are often asymmetric: customers typically push for more carve-outs to maximize their recourse, while providers seek to limit carve-outs to manage their risk exposure. Each side must approach these negotiations with different strategies. Customers should focus on identifying the most critical risks that justify exceptions to the liability cap, while providers should prioritize narrowing the scope and number of carve-outs and consider proposing super caps as a compromise. Recognizing these differing perspectives can help keep the conversation productive and lead to a more balanced outcome. With this asymmetry in mind, consider the following principles.

  1. First, negotiate the cap and the carve-outs as a single package. Do not agree to the cap in one meeting and then discover the carve-outs in a later redline. They are inextricably linked, and you cannot evaluate one without understanding the other. A generous cap with no carve-outs may represent less risk than a tight cap with broad carve-outs.
  2. Second, for each proposed carve-out, ask: what is the realistic damage scenario this is designed to address, and does unlimited liability actually make sense for that scenario? Sometimes the answer is yes—fraud is a good example. But often, the answer is that a higher cap or a super cap would adequately address the risk without leaving either party exposed to unlimited liability.
  3. Third, push for specificity. The narrower and more precisely defined the carve-out, the more predictable the risk. “Breaches of Section 7 (Data Security)” is far more manageable than “any breach of any confidentiality or data-related obligation in this Agreement or any related agreement.” Precision benefits both parties because it reduces the likelihood of disputes about what the carve-out covers.
  4. Fourth, consider a party’s overall risk holistically. If you’re a provider being asked to accept a carve-out for data breaches, carefully assess what security measures you have in place, and how likely a breach actually is given your architecture. Additionally, regarding data breaches in particular, it’s often considered a shared risk—customers may be able to control the sensitivity of the data that’s provided to the vendor. If you’re a customer pushing for carve-outs, consider whether the provider will actually have the financial capacity to pay unlimited damages—a carve-out is only as good as the counterparty’s ability to make you whole.

The bottom line

A liability cap without scrutinized carve-outs is an incomplete negotiation. The cap determines your maximum exposure in theory; the carve-outs determine your maximum exposure in practice. To truly understand your risk, do not focus solely on the cap number—read down to the carve-outs and assess what is actually covered by the cap and what is not. Pressure-test the breadth of each exception and always review the indemnification provision alongside the limitation of liability, as this is often where the real exposure resides. If the gap between the theoretical cap and the practical exposure created by carve-outs is large, your company could be exposed to more risk than intended.

The best limitation of liability clauses aren’t the ones with the most aggressive cap. They’re the ones where the cap, the carve-outs, the damages waivers (the interaction between carve-outs and damages waivers of consequential damages is a complex and heavily negotiated and litigated area and warrants its own dedicated discussion to fully appreciate the risks and nuances involved), and the indemnification obligations all work together as a coherent system. As contracts continue to grow more complex and business risks evolve, carve-outs will remain a key battleground in negotiations. Thoughtful attention to their scope and impact will be essential for parties seeking to balance protection with commercial practicality.

For guidance on structuring and negotiating liability caps that align with your business and risk profile, reach out to KO partner Matt McKinney at [email protected].

Looking for a new partner?

We are changing the status quo in the legal industry one client at a time. Why not be next?

Related Articles