Abnormal AI Product Specific Terms
Effective July 31, 2026
Abnormal AI
Product Specific Terms
These Abnormal Product Specific Terms, which may be updated from time to time by Abnormal (“Product Specific Terms”) form part of the Abnormal Cloud Terms of Service or other existing customer agreement between Abnormal and Customer applicable to use of the Service (the “Agreement”) and apply only to the extent Customer uses the applicable feature, service, or product named in the numbered section heading below (“Product”) as part of the Service. All capitalized terms not defined in these Product Specific Terms have the meanings given to them in the Agreement. In the event of any conflict between these Product Specific Terms and the Agreement, these Product Specific Terms control.
Acceptance. By (1) clicking to indicate your acceptance of these Product Specific Terms, (2) executing an order for the Product under the Agreement, or (3) accessing the Product, you accept these Product Specific Terms on behalf of Customer and represent that you have read, understood, and agree to be bound by them, and that you have the authority to bind the company or other organization you represent to these Product Specific Terms.
General Terms. Customer is responsible for: (1) using the Product in accordance with the Documentation; (2) managing User accounts, Users’ actions with the Product, and Users’ compliance with these Product Specific Terms; (3) how Customer configures the Product, including automation settings; (4) complying with the Acceptable Use Policy, the terms of which are incorporated herein by reference; and (5) providing any required notices and obtaining all necessary rights and consents in connection with use of the Product. For each Product, Abnormal makes available on Abnormal AI - Security Hub a Privacy Data Sheet describing the processing activities Abnormal conducts in providing that Product, including the categories of personal data processed and applicable retention periods.
GenAI Features
The following terms apply to GenAI Features:
“GenAI Feature(s)” means the Service or Support features used by Customer that utilize large language models (LLMs) to curate Outputs for Customer in response to Inputs.
“Input(s)” means prompts, queries, or pre-configured context, conditions, triggers, or other information that is submitted to and/or otherwise processed with any GenAI Features.
“Output(s)” means content that is curated by the GenAI Features, which may incorporate ADs, Threat Intelligence, or other general security information.
Ownership. Each Party will continue to own any component element contained within Output that such Party previously owned prior to its curation. For example, Customer will continue to own Customer Data contained in the Output, and Abnormal will continue to own the ADs and Threat Intelligence contained in the Output.
Limitations; Disclaimer. Customer acknowledges that Outputs provided to Customer may be similar or identical to Outputs independently provided by Abnormal to other customers. Abnormal makes no warranty as to the accuracy, completeness, or reliability of the Output and disclaims liability for Customer’s use of Output or any omissions or errors therein.
Use and Obligations. Customer may reproduce, distribute, and prepare derivative works of Outputs in connection with its use of the Service and solely for its internal business purposes. Abnormal may use Outputs in performance of its obligations under the Agreement.
Improving the Service. Abnormal may use insights derived from Inputs and Outputs to improve the Service and Support, but only if such insights have been (i) de-identified so that they do not identify Customer or its Users, and (ii) to the extent practicable, aggregated with data across other customers. Abnormal will not use Inputs to train or otherwise improve the LLMs of any third-party resource providers that underlie such GenAI Features.
AI Phishing Coach - Risk Management
Intended Purpose. The intended purpose of AI Phishing Coach - Risk Management is to provide Customer with additional human security risk awareness and proposed training opportunities to mitigate human security risk.
AI Governance
Intended Purpose. The intended purpose of AI Governance is cybersecurity governance of AI, including identifying “shadow AI” usage.
AI Chat Insights. If Customer elects to use the AI Chat Insights feature for AI Governance, Customer acknowledges and agrees that: (1) AI Chat Insights monitors communications (e.g., chats, prompts, and responses) between Users and AI systems and may report usage data, including, in some cases, the contents of these communications, to Customer and to Abnormal as its service provider; and (2) it will comply with applicable data protection, privacy, employment, labor, works council, and workplace monitoring laws in connection with its use of AI Chat Insights.
Browser extension. If Customer elects to use the web browser extension (Abnormal AI Governance Monitor) for AI Governance (the “Browser Extension”), Customer acknowledges and agrees that: (1) it will comply with applicable data protection, privacy, employment, labor, works council, and workplace monitoring laws in connection with its use of the Browser Extension; (2) it will at all times comply with all applicable laws administered by the U.S. Commerce Bureau of Industry and Security, U.S. Treasury Office of Foreign Assets Control, or other governmental entity imposing export controls and trade sanctions (“Export Laws”), including designated countries, entities, and persons (“Sanctions Targets”); (3) it will not directly or indirectly export, re-export, or otherwise deliver the Brower Extension or any Service to a Sanctions Target, or broker, finance, or otherwise facilitate any transaction in violation of any Export Laws; (4) the Browser Extension is installed on devices and may be deemed to be a tracking technology installed on terminal equipment that stores and/or accesses information and subject to the EU ePrivacy Directive, as implemented under national law of EU countries; and (5) the Browser Extension and any tracking technology it utilizes are strictly necessary to provide the Service the Browser Extension provides. Additional disclosures about the technologies used in the Browser Extension can be found in the Data Privacy Sheet for AI Governance on Abnormal AI - Security Hub.
Identity Threat Protection
Intended Purpose. The intended purpose of Identity Threat Protection is for cybersecurity detection, investigation, and containment of identity-based attacks.
Infiltration Prevention
Intended Purpose. The intended purpose of Infiltration Prevention is for use as a tool to alert security teams to potential cyberattacks risks so they can investigate them.
FCRA disclaimer. Abnormal is not a consumer reporting agency and none of its services or the data contained therein constitute a “consumer report” as such term is defined in the U.S. federal Fair Credit Reporting Act (FCRA), 15 U.S.C. sec. 1681 et seq. Data provided by Abnormal to Customer may not be used as a factor in establishing any consumer’s eligibility for employment or for any other purpose regulated by FCRA. Customer agrees not to use the Product or any Service or any data received from or made available to Customer by Abnormal for any purpose regulated by FCRA or in relation to taking any action, including, without limitation, any adverse action relating to a consumer application.
Prohibited Uses.
Customer acknowledges that the Service and the Products are not designed or intended to be used for, and Customer will not use, and will not permit any User or third party to use, the Service or any Product: (1) to make, or assist in making, any decision affecting employment, eligibility for employment, hiring, or recruitment, or affecting any other work-related relationship, including any decision regarding compensation, promotion, discipline, or termination; (2) to evaluate the job performance of, or to conduct unlawful monitoring, surveillance, or profiling of, employees or other individuals; (3) for automated decision-making that produces legal or similarly significant effects on individuals; (4) for any purpose regulated by FCRA or any similar laws governing consumer reporting or eligibility determinations, including employment eligibility determinations; or (5) for any purpose that is prohibited by, or that is classified, designated, or regulated as "high-risk" (or a substantially similar designation) under applicable laws. The foregoing shall each be considered a “Restriction” or similar term as set forth in the Agreement.
Trials and Beta AI Services
Abnormal may offer optional access to the Service (or Service features) on a free, trial, beta, or early access basis (“Trials and Betas”). Use of Trials and Betas is permitted only for Customer’s internal evaluation during the period designated on the Order (or if not designated in an Order or otherwise, 30 days). If Customer provides Abnormal with feedback or suggestions regarding Trials and Betas, Abnormal may use the feedback or suggestions without restriction or obligation. Either Party may terminate Customer’s use of Trials and Betas at any time for any reason. Trials and Betas may be inoperable, incomplete, include features never released, or may process personal data with subprocessors not listed on Abnormal’s Subprocessor Page. NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, ABNORMAL OFFERS NO WARRANTY, INDEMNITY, SLA, OR SUPPORT FOR TRIALS AND BETAS AND ITS LIABILITY FOR TRIALS AND BETAS WILL NOT EXCEED $50,000.