The last invoice settles payment. It settles neither the warranties still running, nor the claims not yet made, nor the question of who pays when something discovered next year turns out to have been wrong all along.

What survives which event

Acceptance, operational handover, expiry, and termination are four events that need not coincide, and each interacts differently with each obligation.

Acceptance is not automatically a waiver. One federal services warranty applies notwithstanding inspection and acceptance, warranting workmanship and conformity at acceptance and leaving the notice period to be specified, with correction, reperformance, and price adjustment among its remedies.

Warranty drafting guidance is explicit that scope, obligations, remedies, and duration all have to be clear — and that duration is distinct from the time allowed to notify a discovered defect. Those two get conflated constantly, and they run on different clocks.

The survival register extracts eight fields per obligation: the exact warranted property and state; the trigger event; the duration and what starts it; the notice recipient, form, content, and deadline basis; the remedy; the treatment of later modification or misuse; the survival and termination wording with its links to indemnity and liability limits; and the evidence owner who can find the promise when it is needed.

Four sceptical checks go with them. Was continuing performance promised, or conformity at a particular event? Does handover actually trigger this clause? Is a template blank being mistaken for an agreed period? And is the technical support contact being treated as the contractual notice route — because that is what teams reach for, and it is not the notice route.

An agreement with a warranty notice period left blank in an unexecuted draft, where the receiving team assumes the example period applies, has an unresolved deadline. The reviewer requests the executed provision rather than inventing a term from the template.

Five layers, and what each cannot conclude

A loss discovered after transfer is five questions, and answering one does not answer the others.

Event. What failed, when, in which version and environment? This supplies neither a cause nor a breach of duty.

Mechanism. Which observations support or weaken each causal account? This does not supply the legal standard of causation.

Obligation. What promise or allocation applied to that actor in that state? This does not prove the obligation was breached.

Remedy. What cure, damages, indemnity, or limitation provisions might apply? This does not establish enforceability or the value of a recoverable claim.

Recovery. Which counterparty resources, guarantees, or insurance might respond? This does not establish coverage, solvency, or payment.

The failure this structure guards against is last-change blame. An erroneous output following both a provider model update and a receiving-team retrieval change, where the earlier evaluation record never covered the affected use, presents three candidate explanations. The visible change is not thereby the cause, and attributing the failure to the AI label rather than to a specific mechanism is not an explanation.

Which is why the transferred baseline and subsequent changes get preserved. Alleged pre-existing defects, recipient modifications, supplier updates, and operational decisions are all investigable only against a record of what was handed over and what changed after — with dates reconciled across model and provider versions, retrieval data, prompts, configuration, code releases, and human decisions.

Insurance is not a category

Professional indemnity and errors-and-omissions are market labels rather than interchangeable policy forms, and four dates matter separately: contract completion, policy expiry, the date of the act, and the date of the claim.

A claims-made policy responding to the claim date and an occurrence policy responding to the act date behave completely differently for a defect built in one year and discovered in another. That is the standard shape of a post-transfer AI claim.

The related gap is the training-data indemnity, which sits between three parties. What the model provider indemnifies its customer for, what the supplier indemnifies the client for, and what the client is exposed to are three scopes that do not nest, and the space between them is where an intellectual-property claim about generated output lands.

Contractual allocation does not eliminate harm. It determines who bears the cost, and the practical source of recovery is a separate question from the contractual one.

When a claim arrives

Preservation comes before conclusions, and it comes before the investigation is finished.

Loss of electronically stored information that should have been preserved for anticipated or ongoing litigation, where reasonable steps were not taken and the information cannot be restored or replaced, carries consequences that distinguish prejudice from an intent to deprive. Routine deletion and ordinary repair are how material evidence disappears while everyone waits for the root-cause report.

The claim file records the original allegation as an allegation, with sender and receipt date, rather than rewriting it as a finding. It maps the executed instruments — not drafts. It builds a timeline that keeps publication, logging, and actual event times distinct. It preserves contrary material alongside supporting evidence. And it tracks required notices with their triggers and deadlines, because an internal ticket is not an external notice.

Roles stay separated: whoever coordinates the technical investigation is not thereby authorised to make an admission or a settlement. Pre-action conduct expectations call for proportionate exchange of claim facts and key documents, and pre-action steps do not alter statutory limitation periods.

The rule

What stays fixed is that detection, occurrence, obligation, and recovery are four separate determinations. What changes is which of them the available evidence can actually answer, and preserving the record is what keeps the later ones answerable.

Not to be confused with

A liability cap recommendation. Amounts and exceptions depend on the actual risk, the agreement, and applicable constraints. No general figure follows from any of this.

Hypercare. Support arrangements describe who helps during a period. They are not the measure of continuing legal liability, and ending one does not end the other.