Abnormal AI Product Specific Terms
Effective August 21, 2026
Abnormal AI
Product Specific Terms
These Abnormal Product Specific Terms, which may be updated from time to time by Abnormal (“Product Specific Terms”) form part of the Abnormal Cloud Terms of Service or other existing customer agreement between Abnormal and Customer applicable to use of the Service (the “Agreement”) and apply only to the extent Customer uses the applicable feature, service, or product named in the numbered section heading below (“Product”) as part of the Service. All capitalized terms not defined in these Product Specific Terms have the meanings given to them in the Agreement. In the event of any conflict between these Product Specific Terms and the Agreement, these Product Specific Terms control.
Acceptance. By (1) clicking to indicate your acceptance of these Product Specific Terms, (2) executing an order for the Product under the Agreement, or (3) accessing the Product, you accept these Product Specific Terms on behalf of Customer and represent that you have read, understood, and agree to be bound by them, and that you have the authority to bind the company or other organization you represent to these Product Specific Terms.
General Terms. Customer is responsible for: (1) using the Product in accordance with the Documentation; (2) managing User accounts, Users’ actions with the Product, and Users’ compliance with these Product Specific Terms; (3) how Customer configures the Product, including, without limitation, automation settings or Customer-created detection criteria, detection rules, or custom models (e.g., these Customer configurations may result in communications being quarantined, blocked, or misclassified); (4) complying with the Acceptable Use Policy, the terms of which are incorporated herein by reference; and (5) providing any required notices and obtaining all necessary rights and consents in connection with use of the Product. The foregoing shall each be considered “Customer Responsibilities” or similar term as set forth in the Agreement. Abnormal has no obligation to monitor Customer’s use, configuration, or deployment of any Product or the Services for compliance with these Product Specific Terms or the Agreement. For each Product, Abnormal makes available on Abnormal AI - Security Hub a Privacy Data Sheet describing the processing activities Abnormal conducts in providing that Product, including the categories of personal data processed and applicable retention periods. Customer's election to enable, configure, or use a Product, including through the configurations described in item (3) above, constitutes a reasonable, documented Customer Instruction, consistent with the terms of the Agreement, to process Customer Data in connection with that Product as described in the applicable Privacy Data Sheet, including Customer Data not identified as a security risk, malicious, or a loss-inducing activity.
GenAI Features
The following terms apply to GenAI Features:
“GenAI Feature(s)” means the Service or Support features used by Customer that utilize large language models (LLMs) to curate Outputs for Customer in response to Inputs.
“Input(s)” means prompts, queries, or pre-configured context, conditions, triggers, or other information that is submitted to and/or otherwise processed with any GenAI Features.
“Output(s)” means content that is curated by the GenAI Features, which may incorporate ADs, Threat Intelligence, or other general security information.
Ownership. Each Party will continue to own any component element contained within Output that such Party previously owned prior to its curation. For example, Customer will continue to own Customer Data contained in the Output, and Abnormal will continue to own the ADs and Threat Intelligence contained in the Output.
Limitations; Disclaimer. Customer acknowledges that Outputs provided to Customer may be similar or identical to Outputs independently provided by Abnormal to other customers. Abnormal makes no warranty as to the accuracy, completeness, or reliability of the Output and disclaims liability for Customer’s use of Output or any omissions or errors therein.
Use and Obligations. Customer may reproduce, distribute, and prepare derivative works of Outputs in connection with its use of the Service and solely for its internal business purposes. Abnormal may use Outputs in performance of its obligations under the Agreement.
Improving the Service. Abnormal may use insights derived from Inputs and Outputs to improve the Service and Support, but only if such insights have been (i) de-identified so that they do not identify Customer or its Users, and (ii) to the extent practicable, aggregated with data across other customers. Abnormal will not use Inputs to train or otherwise improve the LLMs of any third-party resource providers that underlie such GenAI Features.
AI Phishing Coach - Risk Management
Intended Purpose. The intended purpose of AI Phishing Coach - Risk Management is to provide Customer with additional human security risk awareness and proposed training opportunities to mitigate human security risk.
AI Governance
Intended Purpose. The intended purpose of AI Governance is cybersecurity governance of AI, including identifying “shadow AI” usage.
AI Chat Insights. If Customer elects to use the AI Chat Insights feature for AI Governance, Customer acknowledges and agrees that: (1) AI Chat Insights monitors communications (e.g., chats, prompts, and responses) between Users and AI systems and may report usage data, including, in some cases, the contents of these communications, to Customer and to Abnormal as its service provider; and (2) it will comply with applicable data protection, privacy, employment, labor, works council, and workplace monitoring laws in connection with its use of AI Chat Insights.
Browser extension. If Customer elects to use the web browser extension (Abnormal AI Governance Monitor) for AI Governance (the “Browser Extension”), Customer acknowledges and agrees that: (1) it will comply with applicable data protection, privacy, employment, labor, works council, and workplace monitoring laws in connection with its use of the Browser Extension; (2) it will at all times comply with all applicable laws administered by the U.S. Commerce Bureau of Industry and Security, U.S. Treasury Office of Foreign Assets Control, or other governmental entity imposing export controls and trade sanctions (“Export Laws”), including designated countries, entities, and persons (“Sanctions Targets”); (3) it will not directly or indirectly export, re-export, or otherwise deliver the Brower Extension or any Service to a Sanctions Target, or broker, finance, or otherwise facilitate any transaction in violation of any Export Laws; (4) the Browser Extension is installed on devices and may be deemed to be a tracking technology installed on terminal equipment that stores and/or accesses information and subject to the EU ePrivacy Directive, as implemented under national law of EU countries; and (5) the Browser Extension and any tracking technology it utilizes are strictly necessary to provide the Service the Browser Extension provides. Additional disclosures about the technologies used in the Browser Extension can be found in the Data Privacy Sheet for AI Governance on Abnormal AI - Security Hub.
Custom AI Models
Intended Purpose. The intended purpose of Custom AI Models is to permit Customer to create, configure, and deploy Abnormal-operated AI models for Customer-determined detection of messages for cybersecurity and other lawful business purposes.
WARNING: PHYSICAL-THREAT USE PROHIBITED. "Physical-Threat Use" means the use of any technology (1) to detect, assess, or respond to actual or potential threats of physical violence or other risks to life, health, or physical safety, or (2) as a safety system or control where failure could result in death or personal injury. USE OF CUSTOM AI MODELS OR ANY OTHER ABNORMAL PRODUCT OR SERVICE FOR PHYSICAL-THREAT USE IS PROHIBITED. CUSTOM AI MODELS IS NOT DESIGNED, INTENDED, OR TESTED FOR PHYSICAL-THREAT USE AND MUST NOT BE RELIED ON FOR ANY SUCH USE. The foregoing shall each be considered a “Restriction” or similar term as set forth in the Agreement.
No Duty to Warn. The Product was not designed or tested to alert or warn Customer, any User, or any third party, including, without limitation, law enforcement, of any actual or potential threats of physical violence or other risks to life, health, or physical safety. Customer acknowledges and agrees that Abnormal has no duty to provide any such alert or warnings in connection with the Product or otherwise.
Indemnification. Customer, at its own cost, will defend Abnormal from and against any third-party claim arising out Customer’s breach or alleged breach of the prohibition on Physical-Threat Use, INCLUDING CLAIMS ALLEGING ABNORMAL'S NEGLIGENCE, STRICT LIABILITY, OR FAILURE TO WARN, and will indemnify Abnormal from and against any damages or costs finally awarded against Abnormal by a court of competent jurisdiction (including reasonable attorneys’ fees) or agreed in settlement by Customer resulting from such claim; these obligations survive termination of the Agreement but do not apply to the extent a claim is caused by Abnormal's sole negligence, gross negligence, recklessness, willful misconduct, or fraud, and applies only as permitted by applicable laws. THIS INDEMNIFICATION IS EXCLUDED FROM ANY LIMITATION ON LIABILITY OR DAMAGES IN THE AGREEMENT.
Identity Threat Protection
Intended Purpose. The intended purpose of Identity Threat Protection is for cybersecurity detection, investigation, and containment of identity-based attacks.
Infiltration Prevention
Intended Purpose. The intended purpose of Infiltration Prevention is for use as a tool to alert security teams to potential cyberattacks risks so they can investigate them.
FCRA disclaimer. Abnormal is not a consumer reporting agency and none of its services or the data contained therein constitute a “consumer report” as such term is defined in the U.S. federal Fair Credit Reporting Act (FCRA), 15 U.S.C. sec. 1681 et seq. Data provided by Abnormal to Customer may not be used as a factor in establishing any consumer’s eligibility for employment or for any other purpose regulated by FCRA. Customer agrees not to use the Product or any Service or any data received from or made available to Customer by Abnormal for any purpose regulated by FCRA or in relation to taking any action, including, without limitation, any adverse action relating to a consumer application.
Prohibited Uses.
Customer acknowledges that the Service and the Products are not designed or intended to be used for, and Customer will not use, and will not permit any User or third party to use, the Service or any Product: (1) to make, or assist in making, any decision affecting employment, eligibility for employment, hiring, or recruitment, or affecting any other work-related relationship, including any decision regarding compensation, promotion, discipline, or termination; (2) to evaluate the job performance of, or to conduct unlawful monitoring, surveillance, or profiling of, employees or other individuals; (3) for automated decision-making that produces legal or similarly significant effects on individuals; (4) for any purpose regulated by FCRA or any similar laws governing consumer reporting or eligibility determinations, including employment eligibility determinations; or (5) for any Physical-Threat Use or for any purpose that is prohibited by, or that is classified, designated, or regulated as "high-risk" (or a substantially similar designation) under applicable laws. The foregoing shall each be considered a “Restriction” or similar term as set forth in the Agreement.
Trials and Beta AI Services
Abnormal may offer optional access to the Service (or Service features) on a free, trial, beta, or early access basis (“Trials and Betas”). Use of Trials and Betas is permitted only for Customer’s internal evaluation during the period designated on the Order (or if not designated in an Order or otherwise, 30 days). If Customer provides Abnormal with feedback or suggestions regarding Trials and Betas, Abnormal may use the feedback or suggestions without restriction or obligation. Either Party may terminate Customer’s use of Trials and Betas at any time for any reason. Trials and Betas may be inoperable, incomplete, include features never released, or may process personal data with subprocessors not listed on Abnormal’s Subprocessor Page. Customer's election to access or use Trials and Betas, including any configuration of their scope, settings, or Customer-created detection criteria, detection rules, or custom models, constitutes a reasonable, documented Customer Instruction, consistent with the terms of the Agreement, to process Customer Data in connection with such Trials and Betas as described in the applicable Privacy Data Sheet, regardless of whether such Customer Data is identified as a security risk, malicious, or a loss-inducing activity. NOTWITHSTANDING ANYTHING ELSE IN THIS AGREEMENT, ABNORMAL OFFERS NO WARRANTY, INDEMNITY, SLA, OR SUPPORT FOR TRIALS AND BETAS AND ITS LIABILITY FOR TRIALS AND BETAS WILL NOT EXCEED $50,000.