AI News

AI coding agents under scrutiny: indemnity, prompts, audit, and the true 500-seat cost

What does indemnity cover, where do prompts live, what can admins log, and what do 500 seats cost? We compare GitHub Copilot, AWS Kiro, Cursor, and Cognition using current terms.

2026-09-27 ·Hai Anton

This piece is for people making risk calls, not feature picks. Procurement leads, counsel, and security reviewers ask four questions before rollout: who pays if generated code triggers an IP claim? Where do prompts live? What can admins log? What do 500 seats really cost? We read current terms for GitHub Copilot, AWS Kiro, Cursor, Devin, and Windsurf. Every term was checked against vendor pages as of September 26, 2026. This is reporting, not legal advice. Run final language past your counsel.

Who pays if generated code triggers an IP claim?

In short: Copilot offers uncapped indemnity for unmodified output. Kiro covers copyright claims on output. Cursor explicitly includes “Suggestions” and puts indemnity outside the fee cap. Cognition excludes “Outputs” from standard indemnity and caps liability.

Start with brands. Five brands are really four contracts. Cognition acquired Windsurf and, on June 2, 2026, renamed the editor Devin Desktop. Devin and Windsurf now share one pricing table and one set of terms. That consolidation matters for a single buying strategy.

Substantively, the key GitHub Copilot change landed on April 3, 2026. A prior admin requirement could void coverage; the duplicate detection filter is no longer required. The standing limit is “unmodified” output. Most shipped code gets edited, so ask counsel when edits move code outside scope.

AWS Kiro inherits AWS’s generative indemnity. It is uncapped for copyright claims on output, provided your inputs do not infringe and you do not disable filtering. The free tier is not covered. Cursor’s MSA names Suggestions and removes indemnity from the 12‑month fee cap. Exclusions still apply when a claim relates to a modification or an unapproved combination, if filters are disabled, or you knew it likely infringed.

Cognition is the outlier. Its MSA defines Customer Data to include Outputs, and Customer Data is excluded from indemnity. Generated code therefore sits outside the standard promise. The supercap is 2x of fees paid in the prior 12 months. On self‑serve paid tiers, indemnity applies only to paid customers with a lower cap: the greater of six months of fees or US$100. Any Devin or Devin Desktop enterprise rollout needs fixes in the order form.

“uncapped IP indemnification for unmodified outputs” and “Kiro offers indemnity for its output” — these phrases set two crucial boundaries.

Where do prompts live, and how are they controlled?

For Copilot Business and Enterprise, IDE chat and completion prompts are not retained. Other surfaces — github.com, mobile, and CLI — retain prompts for 28 days. User engagement data is kept for two years. Business and Enterprise data is not used for training. With Enterprise Cloud data residency, you can pin inference to the US or EU, adding +10% to AI credits and narrowing the model list.

Per AWS Kiro’s data protection page, enterprise content is never used for service improvement. It is stored in the region set in your Kiro profile. Inference stays in the US or Europe, except for experimental models. Admins can encrypt data with customer‑managed KMS keys. That’s essential when security demands ownership of secrets.

With Privacy Mode on, Cursor holds zero data retention agreements with all model providers and does not train on your code. File contents are cached temporarily and encrypted with client‑generated keys. Cursor’s public pages do not offer a customer‑selectable processing region. Every request still passes through Cursor’s backend, so that layer remains in the processing chain.

Under Cognition’s MSA, training on Customer Data requires written consent. The Customer Dedicated Deployment runs Devin’s devbox in a single‑tenant VPC linked via AWS PrivateLink. The agent’s reasoning layer still runs in Cognition’s cloud. On self‑serve paid tiers, Cognition may train on Customer Data until the customer opts out. On Teams, only an admin can opt out. Build your data policy accordingly.

“IDE: not retained. Other surfaces: 28 days.” — a pragmatic balance between utility and retention in Copilot.

What can admins actually see, and how does audit work?

In GitHub Copilot, the enterprise audit log records Copilot events under action:copilot. Agent activity appears as actor:Copilot and is retained for 180 days. GitHub is explicit: prompts sent locally do not appear in the audit log. Admins also set model, preview‑feature, and spending policies. That mix balances control with privacy.

AWS Kiro supports SSO via IAM Identity Center, Okta, or Entra ID. Admins can enable prompt logging and daily user activity reports. Both land in an S3 bucket inside the customer’s AWS account. Prompt records therefore remain under your control and within your data jurisdiction.

Cursor Teams includes SAML or OIDC SSO, team‑wide Privacy Mode, and usage analytics. However, audit logs, SCIM, repository and model access controls, and an AI code tracking API require Enterprise. In practice, the full corporate levers appear only under a custom contract.

Cognition Teams offers an admin dashboard with analytics. SAML or OIDC SSO, centralized admin controls, and VPC deployment are Enterprise‑only. Cognition’s Enterprise API exposes audit log endpoints. If you need strict event trails and network isolation, consider Enterprise only.

What do 500 seats really cost per month and per year?

List prices are monthly in USD, before overages and taxes. For Copilot Business, $19 per seat equals $9,500 per month or $114,000 per year at 500 seats. But SAML SSO and data residency require GitHub Enterprise Cloud. The true figure often becomes $40 per seat ($20,000/month, $240,000/year) or $60 with Copilot Enterprise ($30,000/month, $360,000/year), which also raises included credits to 3,900 per seat from 1,900.

For AWS Kiro Pro, $20 per seat delivers $10,000 per month and $120,000 per year at 500 users. The plan includes 1,000 credits per user, with add‑ons at $0.04 each. Self‑serve tiers cover teams up to 500. Pro+ at $40 doubles the allowance to 2,000 credits per user, with the same indemnity as Pro. This is the simplest path to indemnity, SSO, and customer‑owned prompt logs at 500 seats.

Cursor Teams is $40 per seat, or $20,000 per month and $240,000 per year at 500 seats. However, it lacks audit logs and SCIM at that tier. Enterprise is custom‑priced, so budget requires separate negotiation. If you need full audit and centralized access control, plan for an Enterprise conversation.

Cognition Teams (Devin, Devin Desktop) is $40 per seat plus an $80 team fee. But Teams is capped at 200 users and has daily and weekly quotas. At 500 seats you need Enterprise with custom pricing. Remember two meters sit on top of every seat. On June 1, 2026, GitHub moved Copilot to AI credits where 1 credit equals $0.01. Kiro bills extra credits at $0.04, and enterprise overages are off by default. Agent‑heavy teams should model usage, not just seats.

What belongs in the RFP, and how should you conclude risk?

In your RFP, ask each vendor to confirm in writing whether edited or agent‑written code remains within indemnity scope. For Cognition, redline the Customer Data exclusion so Outputs are covered and lift the 2x supercap. For Copilot, confirm whether you buy under GitHub terms or Microsoft Product Terms, because the governing document differs. Require region commitments inside the order form, not just on a settings page.

Price 12 months of agent usage at your real model mix, not the seat line alone. Remember, Copilot offers uncapped indemnity for unmodified output, with no filter requirement since April 3, 2026. Kiro is the cheapest 500‑seat path with indemnity, SSO, and customer‑owned prompt logs. Cursor’s MSA names Suggestions and removes indemnity from the fee cap. Cognition’s standard terms exclude Outputs, covering Devin and Windsurf alike.

How should you test scenarios? Step through a claim, trace how a prompt travels, and price your seat count. This reveals where policy collapses on edited code, or where a processing hop exits your desired region. That’s how you avoid surprises in production.

Finally, this is a journalistic snapshot of terms as of September 26, 2026, not legal advice. Run final language past your legal team. That’s how you convert risk into clear contractual promises and real data control.

Based on source article.

Ready to automate your store?

We'll analyze your workflows, find the bottlenecks, and propose a concrete automation plan. First consultation is free.

Message us on Telegram →
Hai Anton
Hai Anton

Founder of HAIQ — AI Automation Agency. Founder of HAIQ. I build automations and AI solutions for Ukrainian e-commerce on n8n. I write about automation, chatbots, and AI for business.