Skip to content
KStart free
AI InfrastructureDefenseQuantumAll studies →

LPSN US Equity

Liveperson IncInformation Technology · Services-Prepackaged Software · CIK 1102993 · FY ends Dec 31
$2.83
+0.09 (+3.28%)
USD · as of 2026-08-21 · marketstack

LPSN · 10-K · period ended 2024-12-31

← all LPSN documents
filed 2025-03-14 · EDGAR original ↗

Our rendering of the filing — original pagination and typography are not reproduced, and tables are reduced to their short label cells (the figures live on FA). Nothing is summarized: every line below is the filing's own text.

blocks 1409 of 1,544413k characters rendered

lpsn-20241231

UNITED STATES

SECURITIES AND EXCHANGE COMMISSION

Washington, D.C. 20549

FORM 10-K

☒ANNUAL REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the Fiscal Year Ended December 31, 2024

OR

☐TRANSITION REPORT PURSUANT TO SECTION 13 OR 15(d) OF THE SECURITIES EXCHANGE ACT OF 1934

For the Transition Period from _____ to _____

Commission File Number 000-30141

LIVEPERSON, INC.

(Exact name of registrant as specified in its charter)

(Address of Principal Executive Offices) (Zip Code)

(212) 609-4200

(Registrant’s telephone Number, including area Code)

Securities registered pursuant to Section 12(b) of the Act:

Title of each class Trading Symbol(s) Name of each exchange on which registered

Common Stock, par value $0.001 per share LPSN The Nasdaq Stock Market LLC

Securities registered pursuant to Section 12(g) of the Act: None

Indicate by check mark if the registrant is a well-known seasoned issuer, as defined in Rule 405 of the Securities Act. Yes ☐No☒

Indicate by check mark if the registrant is not required to file reports pursuant to Section 13 or Section 15(d) of the Act. Yes ☐No☒

Indicate by check mark whether the registrant: (1) has filed all reports required to be filed by Section 13 or 15(d) of the Securities Exchange Act of 1934 during the preceding 12 months (or for such shorter period that the registrant was required to file such reports), and (2) has been subject to such filing requirements for the past 90 days. Yes☒ No ☐

Indicate by check mark whether the registrant has submitted electronically every Interactive Data File required to be submitted pursuant to Rule 405 of Regulation S-T during the preceding 12 months (or for such shorter period that the registrant was required to submit such files). Yes☒ No ☐

Indicate by check mark whether the registrant is a large accelerated filer, an accelerated filer, a non-accelerated filer, smaller reporting company or an emerging growth company. See definition of “large accelerated filer,” “accelerated filer,” “smaller reporting company” and “emerging growth company” in Rule 12b-2 of the Exchange Act.

Large Accelerated Filer ☐ Accelerated Filer ☐

Non-accelerated Filer ☒ Smaller Reporting Company ☒

Emerging Growth Company ☐

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

Indicate by check mark whether the registrant has filed a report on and attestation to its management’s assessment of the effectiveness of its internal control over financial reporting under Section 404(b) of the Sarbanes-Oxley Act (15 U.S.C. 7262(b)) by the registered public accounting firm that prepared or issued its audit report. ☐

If securities are registered pursuant to Section 12(b) of the Act, indicate by check mark whether the financial statements of the registrant included in the filing reflect the correction of an error to previously issued financial statements. ☐

Indicate by check mark whether any of those error corrections are restatements that required a recovery analysis of incentive-based compensation received by any of the registrant’s executive officers during the relevant recovery period pursuant to §240.10D-1(b). ☐

Indicate by check mark whether the registrant is a shell company (as defined in Rule 12b-2 of the Exchange Act). Yes ☐ No ☒

The aggregate market value of the voting common stock held by non-affiliates of the registrant as of June 30, 2024 (the last business day of the registrant’s most recently completed second fiscal quarter) was $44,140,772(computed by reference to the last reported sale price on The Nasdaq Global Select Market on that date). The registrant does not have any non-voting common stock outstanding.

On February 28, 2025, 91,313,969 shares of the registrant’s common stock were outstanding.

DOCUMENTS INCORPORATED BY REFERENCE

The information called for by Part III will be incorporated by reference from the Registrant’s definitive Proxy Statement for its Annual

Meeting of Stockholders to be filed pursuant to Regulation 14A, or will be included in an amendment to this Form 10-K.

LIVEPERSON, INC.

ANNUAL REPORT ON FORM 10-K

FOR THE FISCAL YEAR ENDED DECEMBER 31, 2024

TABLE OF CONTENTS

Page

PART I

Item 1. Business 1

Item 1A. Risk Factors 8

Item 1B. Unresolved Staff Comments 41

Item 1C. Cybersecurity 41

Item 2. Properties 43

Item 3. Legal Proceedings 43

Item 4. Mine Safety Disclosures 43

PART II

Item 6. [Reserved] 45

Item 7A. Quantitative and Qualitative Disclosures About Market Risk 54

Item 8. Financial Statements and Supplementary Data 55

Item 9A. Controls and Procedures 99

Item 9B. Other Information 100

Item 9C. Disclosure Regarding Foreign Jurisdictions that Prevent Inspections 100

PART III

Item 10. Directors, Executive Officers and Corporate Governance 100

Item 11. Executive Compensation 100

Item 14. Principal Accountant Fees and Services 101

PART IV

Item 15. Exhibits and Financial Statement Schedules 102

i

FORWARD-LOOKING STATEMENTS

Statements in this Annual Report on Form 10-K about LivePerson, Inc. (“LivePerson”, the “Company”, “we”, “our” or “us”) that are not historical facts are forward-looking statements. These forward-looking statements are based on our current expectations, assumptions, estimates and projections about LivePerson and our industry. Our expectations, assumptions, estimates and projections are expressed in good faith, and we believe there is a reasonable basis for them, but we cannot assure you that our expectations, assumptions, estimates and projections will be realized. Examples of forward-looking statements include, but are not limited to, statements regarding future business, future results of operations or financial condition (including statements regarding expectations for retention rates, customer attrition and revenue and other statements based on examinations of historical operating trends) and management strategies. Many of these statements are found in the “Business” and “Management’s Discussion and Analysis of Financial Condition and Results of Operations” sections of this Annual Report on Form 10-K. When used in this Annual Report on Form 10-K, the words “anticipates,” “believes,” “estimates,” “expects,” “intends,” “plans,” “projects,” and variations of such words or similar expressions are intended to identify forward-looking statements. However, not all forward-looking statements contain these words. Forward-looking statements are subject to risks and uncertainties that could cause actual future events or results to differ materially from those expressed or implied in the forward-looking statements. Important factors that could cause our actual results to differ materially from the forward-looking statements we make in this Annual Report on Form 10-K include those set forth in the section entitled Part 1, Item 1A., “Risk Factors.” It is routine for our internal projections and expectations to change as the year or each quarter in the year progresses, and therefore it should be clearly understood that the internal projections and beliefs upon which we base our expectations may change prior to the end of each quarter or the year. Although these expectations may change, we are under no obligation to inform you if they do. Our policy is generally to provide our expectations only once per quarter, and not to update that information until the next quarter. We do not undertake any obligation to revise forward-looking statements to reflect future events or circumstances. All forward-looking statements are made pursuant to the safe harbor provisions of the Private Securities Litigation Reform Act of 1995.

ii

PART I

Item 1. Business

Overview

LivePerson, Inc. (“LivePerson”, the “Company”, “we”, “our” or “us”) is a leader in digital customer conversation. Over the past two decades, consumers have made digital conversations their primary mode of communication with others. Since 1998, we have enabled meaningful connections between consumers and our customers through our platform and currently power more than one billion conversational interactions each month. These digital and artificial intelligence (“AI”)-powered conversations decrease costs and increase revenue for our brands, resulting in more convenient, personalized and content-rich journeys across the entire consumer lifecycle, and across consumer channels. Our customers’ existing investments in Generative AI and Large Language Models (“LLMs”) are fully compatible with LivePerson’s enterprise-class digital customer conversation platform (the “LivePerson Platform”).

The LivePerson Platform is trusted by the world’s top brands to accelerate their contact center transformation, orchestrate conversations across all channels, departments and systems, increase agent productivity, and deliver more personalized, AI-empowered customer experiences in a safe and secure environment. The LivePerson Platform powers conversations across each of a brand’s primary digital channels, including mobile apps, mobile and desktop web browsers, short messaging service (“SMS”), social media and third-party consumer messaging platforms. Brands can also use the LivePerson Platform to connect conversations across voice and digital channels to give customers additional options and ensure their interactions with brands are seamlessly integrated no matter where they choose to reach out. Agents can manage all conversations with consumers through a single console interface, regardless of where the conversations originated. The LivePerson Platform has been enhanced to provide security with appropriate guardrails where Generative AI and LLMs can be deployed and continually optimized in ways that help consumers and drive results for brands without sacrificing trust.

LivePerson’s robust, cloud-based suite of rich messaging, real-time chat, Generative AI, AI and automation, and conversation orchestration offerings features LLM powered automation (Autopilot), LLM powered agent tools (Copilot: Assist, Summary, Rewrite), Conversation Intelligence tools (Generative Insights, Analytics Studio), integrations (omnichannel solution through Avaya, Inc. partnership, Salesforce connector, iHub workflows powered by Workato), and engagement solutions (proactive messaging, voice to messaging) among others. An extensible application programming interface (“API”) stack facilitates a lower cost of ownership by facilitating robust integration into back-end systems, as well as enabling developers to build their own programs and services on top of the platform. More than 40 APIs and software development kits are available on the LivePerson Platform.

The LivePerson Platform enables what the Company calls “the tango” of humans, LivePerson bots, third-party bots, and LLMs, in which humans oversee and are assisted by AI and can seamlessly step into conversations as needed. Agents become highly efficient, are able to leverage the AI engine (including generative AI capabilities) to surface relevant content, define next-best actions and take over repetitive transactional work so that the agent can focus on relationship building. By integrating customer engagement channels, LivePerson’s proprietary AI, and third-party bots and AI, the LivePerson Platform offers brands a comprehensive approach to scaling automations across all customer conversations.

Complementing the Company’s proprietary digital customer conversation offerings are teams of technical, solutions and consulting professionals that have developed deep domain expertise in the implementation and optimization of conversational services across industries and messaging endpoints. LivePerson’s products, coupled with our domain knowledge, industry expertise and professional services, have been proven to maximize the impact of digital customer service. LivePerson supports and unlocks the power of AI in safe and responsible ways, and delivers measurable return on investment (“ROI”) for our customers.

Customers can realize the following advantages from our offerings:

•the ability for each agent to manage dozens of messaging conversations at a time, as compared to one at a time for a voice agent and two to four at a time for a chat agent. Adding AI and bots provides even greater scale to the number of conversations managed;

•labor efficiency gains of at least two times that of voice agents, effectively cutting labor costs;

1

•improving the overall customer experience, thereby fueling customer satisfaction score increases by double digit percentage points, and enhancing retention and loyalty;

•more convenient, personalized and content-rich conversations that increase sales conversion by double digit percentages, and increase average order value and reduce abandonment;

•more satisfied contact center agents, thereby substantially reducing agent churn;

•a valued connection with consumers via mobile devices, either through native applications, websites, text messages, or third-party messaging platforms; and

•leveraged spending that drives visitor traffic by increasing visitor conversions.

As a “cloud computing” or software-as-a service (“SaaS”) provider, LivePerson provides solutions on a hosted basis. This model offers significant benefits over premise-based software, including lower up-front costs, faster implementation, lower total cost of ownership, scalability, cost predictability, and simplified upgrades. Organizations that adopt a fully-hosted, multi-tenant architecture that is maintained by LivePerson eliminate the majority of the time, server infrastructure costs, and information technology (“IT”) resources required to implement, maintain, and support traditional on-premise software.

Hundreds of the world’s biggest brands, including HSBC, Virgin Media, and Burberry use our digital customer conversation solutions to integrate humans and AI, at scale, and create a convenient personalized relationship with their customers.

LivePerson was incorporated in the State of Delaware in November 1995 and the LivePerson service was introduced in November 1998. The Company completed an initial public offering in April 2000 and is currently traded on The Nasdaq Global Select Market and the Tel Aviv Stock Exchange (“TASE”).

Market Opportunity

LivePerson’s proprietary digital customer conversation solutions enable consumers and businesses to communicate with each other on conversational channels such as voice, messaging apps, a brand’s own website and apps, and social platforms, in order to get answers to questions, make purchases and resolve customer care inquiries.

Consumers today expect seamless, personalized, and AI-driven digital experiences, yet many brands still rely on outdated, disconnected communication channels. LivePerson is transforming customer engagement by enabling brands to shift from legacy systems to a modern digital core powered by messaging and AI. We see a significant opportunity in voice as a channel, seamlessly integrating voice and messaging to enhance both agent and customer experiences with AI-driven insights and automation. Additionally, our conversational commerce solutions empower brands to drive revenue by allowing buyers to engage on their own terms—when, where, and how they choose. The next generation of customer engagement is being shaped by Generative AI-powered agent and customer experiences, where LivePerson’s AI capabilities work alongside human agents and automation to deliver exceptional efficiency and value. Finally, our unified conversational analytics unlock the power of conversation data across channels, providing deep insights that maximize business outcomes. As brands increasingly shift investments from legacy systems to AI-powered, digital-first experiences, LivePerson is at the forefront of this transformation, enabling businesses to drive efficiency, revenue, and customer satisfaction at scale.

LivePerson believes that AI and automation are the foundation for transforming the conversational experience, disrupting how agents operate and how brands engage with consumers. With AI at the center of the solution and by harnessing data from all primary channels, including voice, messaging, chat, and human agents, LivePerson is in a unique position to provide the best conversational experiences for consumers. In addition, our deep integrations with CRM, service, and IT systems allows us to deliver a unified agent experience through a single pane of glass.

We believe that LivePerson’s proprietary digital customer conversation offerings provide a superior alternative to traditional customer experiences. Brands that shift to digital-first customer service and support stand to outperform their competitors by giving consumers the experiences they clearly prefer.

2

Products and Services

Business solutions offerings

The LivePerson Platform enables businesses and consumers to connect through conversational channels, such as voice, in-app and mobile messaging, while leveraging bots and AI to increase efficiency. The platform, which is marketed primarily to customer care, contact center, customer experience, e-commerce, marketing, and technology executives, combines sophisticated mobile and online engagement technology with robust business intelligence and operational and conversational data to produce compelling, measurable results by intelligently engaging consumers based on a real-time understanding of consumer needs. Rich, contextually aware targeting, actionable insights and personalized experiences empower businesses to get the most out of their existing online, mobile and social platforms. Benefits of the LivePerson Platform include increased agent efficiency, decreased customer care costs, improved customer experiences, higher conversion rates and increased customer lifetime value.

The LivePerson Platform powers the Conversational Flywheel, a powerful framework for driving velocity and continuous improvement across our brands’ conversational AI journey. The Conversational Flywheel, comprising four stages, empowers brands to: (1) understand what customers want by analyzing conversational data to drive actionable business decisions through proprietary analytics utilizing data to target end users with compelling engagement options at any step in the conversion funnel and throughout the customer lifecycle; (2) connect business systems to channels, engaging consumers where they are and feeding those conversations back into the systems brands use every day, maximizing online revenue opportunities, improving conversion rates and reducing shopping cart abandonment by proactively engaging the right visitor, using the right channel, at the right time; (3) assist teams with AI-powered tools and insights designed to help them focus on the tasks and interactions that matter most, providing real-time recommendations to human agents, and leveraging automation and human agents working together seamlessly to support consumers, all over our best-in-class agent workspace; and (4) automate to enable self-service and drive faster resolutions, through personal, connected interactions; all feeding data back into the system. This comprehensive solution blends a proven value-based methodology with an active rules-based engagement engine and deep domain expertise to increase first-contact resolution, improve consumer satisfaction, and reduce attrition rates.

LivePerson’s Conversational AI. LivePerson’s Conversational AI, announced in December 2018, operates as the brains behind LivePerson AI-based products, and was developed using our conversational data set of billions of brand-to-consumer interactions. The LivePerson Platform enables what we call “the tango” of humans, LivePerson bots, third-party bots, and LLMs, in which humans oversee and are assisted by AI and can seamlessly step into conversations as needed. Through the LivePerson Platform, agents become highly efficient, leveraging the AI engine (including generative AI capabilities) to surface relevant content, define next-best actions and take over repetitive transactional work so that the agent can focus on relationship building. By seamlessly integrating the LivePerson Platform with our proprietary AI, as well as bots, the platform provides businesses with a comprehensive view of all AI-based and human-based conversations from a single console. Products developed on LivePerson’s Conversational AI engine include:

•Conversation Builder, which non-technical staff such as contact center agents use to design high-quality automated conversations. The conversations are not built from scratch. Conversation Builder creates the initial versions by mining a brand’s existing conversation transcripts. Prebuilt industry templates are also available, providing the dialogue and integrations necessary for common use cases such as billing.

•Conversation Manager, a console that suggests automated responses and next best actions to contact center agents, who edit and select from them. Edits and selections dynamically improve the responses and next best actions. When the content reaches a brand-set accuracy threshold, it can be offered to consumers without human intervention. Conversation Manager also includes sentiment monitoring to alert contact center agents to conversations that require their attention. Designed for use in large contact centers, Conversation Manager sends these requests to agents who have the capacity and appropriate skills to respond. A major retail brand that adopted this approach in its sales operation increased agent productivity up to 220% within 12 weeks of launch.

•Conversational Intelligence, dashboards and reporting which take the true voice of the customer - their direct discussions with a brand, spoken in their natural language - and turn it into actionable sales and service intelligence. Generative Insights discovers trends in what customers are saying and delivers them in an LLM-powered conversational experience that is easy to understand. Report Center measures how both AI and human-powered messaging and voice conversations are performing. Analytics Studio converts the content of voice and messaging conversations into actionable data that makes sense of customer behaviors, preferences, and signals across channels. A major wireless provider using Conversational Intelligence reported the product identifies the root cause of service

3

issues faster than monitoring software, enabling the provider to accelerate the fix and reduce inbound customer inquiries. A leading hospitality firm used Conversational Intelligence to identify and add new, top-selling items to its menu selection.

•Intent Manager, a real-time intent recognition and classification engine that analyzes consumer intentions at every turn of the conversation. Intent Manager is powered by LivePerson’s proprietary natural language understanding (“NLU”) capabilities and machine learning algorithms, which are grounded in over 20+ years of conversational data and more than one billion messaging transcripts across a variety of industries. Intent Manager is currently being used by top brands to gain real-time insights and take action to improve customer service, marketing, and sales automation.

Professional Services

The mission of our LP 360 Professional Services team is to help customers optimize the performance of our products in order to drive incremental value through their mobile and online sales and/or service channel(s). This talented group utilizes their deep domain expertise and years of hands-on experience to provide customers with detailed analyses and measurements of their LivePerson deployment that drive strategies and decisions on how to optimize mobile and online messaging, real-time chat, and bot and AI integration. Deliverables of the team include scorecards that measure and chart performance trends, analyses and recommendations for conversational design, web design and process improvement, transcript reviews to discover both voice of the consumer insight and agent improvement opportunities, custom training of call center agents and management, and ongoing management of messaging programs to ensure alignment with current business practices and objectives. The team’s value-added methodology and approach to guiding customers towards messaging channels and human/bot agent optimization is an important component of the LivePerson offering, and gives our customers a competitive advantage in the digital world.

Customers

Our solutions benefit organizations of all sizes conducting business or communicating with consumers through messaging and chat. Our customers include Fortune 500 companies, dedicated internet businesses, a broad range of online merchants, automotive dealers, educational institutions, the public sector and not-for-profit organizations. We plan to continue to focus on key target markets: telecommunications, financial services, travel/hospitality, technology, healthcare, automotive, and consumer/retail within the United States of America (“U.S.”) and Canada, Latin America, Europe, and the Asia-Pacific (“APAC”) region.

No single customer accounted for or exceeded 10% of our total revenue for 2024, 2023, or 2022.

Sales and Marketing

Sales. Our mobile and online messaging solutions are targeted at corporate executives whose primary responsibility is optimization of customer care, sales and marketing, or optimizing a consumer’s journey across the brand’s digital properties. Our solutions enable organizations to provide effective customer service, sales and marketing by orchestrating conversations across all channels, departments and systems and delivering more personalized, AI-empowered customer experiences in a safe and secure environment. We focus on the value that our solutions deliver in the form of increased agent efficiency, reduced contact center costs, increased customer satisfaction, improved customer lifetime value, maximized digital consumer acquisition, and optimized website and mobile business outcomes.

Within the business solutions segment we have aligned our field organization to address the different sales strategies of our target markets:

Enterprise and large mid-market. We target enterprises which have thousands of agents in their contact centers and collectively connect with billions of consumers each year. We leverage thought leadership and related events to showcase our strength in messaging and AI, and highlight existing reference customers who share their successes on our platform and how they achieved positive ROIs. Increasingly, we are working with large third-party system integrators, technology providers and business process outsourcers to supplement our direct sales effort.

Small business and small mid-market. We target small business and small mid-market customers with a mix of direct, online self-service, and third-party partner channels. Our customer acquisition strategy centers on leveraging customer word-of-

4

mouth, our leading brand name, online marketing and partnerships. We also leverage marketing programs and partner resources to promote increased usage and product adoption within these customers.

Customer Support. Our LP 360 Professional Services team provides deployment support and ongoing business consulting to enterprise and mid-market customers and maintains involvement throughout the engagement lifecycle. All LivePerson customers have access to 24/7 help desk services through messaging, chat, and technical support ticketing.

Marketing. We have a global team, spread across key geographies, that is focused on marketing our brand, products and services to executives responsible for the digital channel, the consumer experience, marketing, sales, IT, and consumer service operations of their organization.

Our marketing strategy encompasses a strategic communications approach that integrates public relations, social media, and analyst/influencer relations. Communications seek to highlight key customer success stories, and promote executive thought leadership via contributed content, speaking opportunities and press interviews, to raise LivePerson’s profile and reinforce our position as an industry leader.

Competition

The markets for AI-enhanced customer interaction, mobile and online business messaging, and digital engagement technology are intensely competitive, rapidly changing and characterized by aggressive marketing, pricing pressure, evolving industry standards, rapid technology developments, and frequent new product introductions.

We believe that most contact center technology vendors incorrectly view messaging as simply a feature or channel. They are content with building integrations to a messaging endpoint and offering messaging as just another product in their suite. We believe that messaging and AI are the foundation for conversational experiences, which transform how agents operate and how brands engage with consumers across service, sales, marketing, and brick and mortar. Brands must adapt their contact centers to an asynchronous messaging environment and leverage a combination of human agents, bots and AI to achieve scale and efficiencies.

We believe that our differentiated approach to enterprise conversations, combined with our unique technology and expertise, has established the Company as a market leader, with an ability to deliver superior returns on investment:

•The LivePerson Platform was designed for AI-assisted and human-powered messaging in mobile and online channels. The platform is designed for security and scalability, offers the broadest ecosystem of messaging endpoints, is designed for ease of use, and features an AI engine custom built for enterprise conversations, intent recognition, robust real-time reporting, role-based real-time analytics, predictive intelligence, and innovations in customer satisfaction and connection measurement. Additionally, our platform offers pre-built, enterprise-grade integrations into back-end systems as well as the ability to work across NLU providers.

•The platform has expanded to power conversations across a broad spectrum of channels and use cases, from traditional sales and customer service, to marketing, social, email, advertising and brick and mortar.

•We have billions of conversations across industries, geographies and use cases. This data is used to feed machine learning models that can understand and handle conversations, and can customize generative AI for enterprise-level performance and safety.

•LivePerson has deep domain expertise across verticals and messaging endpoints, a global footprint, referenceable enterprise brands and a team of technical, solutions and consulting professionals to assist customers along their transformational journeys.

We believe this focus on technological innovation, expertise and enterprise-class capabilities is positioning LivePerson as a leader in digital customer conversations.

We have current and potential competition from providers of messaging and digital engagement solutions that enable companies to engage and connect with their consumer customers, as well as technology providers that offer customer relationship management and contact center solutions. We have current and potential competitors in many different industries, including:

5

•technology or service providers offering or powering competing digital engagement, contact center, communications, or customer relationship management solutions such as eGain, Genesys, Nuance, Oracle, Salesforce.com, and Twilio;

•service providers that offer basic messaging products or services with limited functionality free of charge or at significantly reduced entry level prices;

•social media, social listening, messaging, AI, bots, e-commerce, and/or data and data analytics companies, such as Facebook, Google, and WeChat, which may leverage their existing or future capabilities and consumer relationships to offer competing business-to-business solutions; and

•customers that develop and manage their messaging solutions in-house.

Technology

Four key technological features distinguish the LivePerson services:

•LivePerson’s powerful Conversational AI capabilities have historically enabled brands to successfully automate conversations, and these tools are now made even more powerful with the advent of generative AI. To make generative AI systems usable for the enterprise, proprietary data integrations are required, along with Conversational AI test and release management capabilities, and the ability to leverage human feedback and customize models and other system behavior. LivePerson’s Conversational AI systems have these capabilities, and are integrated with best-in-class generative AI systems including OpenAI, Microsoft, Google, and others, situating the LivePerson technology stack to benefit from the anticipated growth in the generative AI space.

•We support our customers through a secure, scalable server infrastructure. Currently, in North America, our servers are hosted in a secure, top-tier, third-party server center located in the Mid-Atlantic United States, and have data backups in a top-tier facility located in the Western United States. In Europe, our servers are hosted in a secure, top-tier, third-party server center located in the United Kingdom (“U.K.”) and have data backups in a top-tier facility located in The Netherlands. In the Asia Pacific region, our servers and data backups are hosted in secure, top-tier, third-party server centers located in Australia. Utilizing scalable network infrastructure and protocols, our network, hardware and software are designed to accommodate our customers’ demand for secure, high-quality 24/7 service, including during peak times such as the holiday shopping season. We have begun the process of migrating our technology infrastructure to the public cloud. Components of our platform are currently hosted on various hyperscalers, and we intend to continue to shift our footprint to the public cloud over the coming years.

•As a hosted service, we are able to add additional capacity and new features quickly and efficiently. This has enabled us to provide these benefits simultaneously to our entire customer base. In addition, it allows us to maintain a relatively short development and implementation cycle.

•As a SaaS provider, we focus on the development of tightly integrated software design and network architecture. Dedicated resources are allocated to designing our software and network architecture based on the fundamental principles of security, reliability and scalability.

Network Architecture and Security. Our network is scalable. Our backup data is housed in separate locations from our primary hosting facilities. We comply with security standards such as System and Organization Controls (“SOC”) 2, and Payment Card Industry (“PCI”) Data Security Standards (“DSS”), and International Standards Organization / International Electrotechnical Commission (“ISO/IEV”) 27001. For increased security, through a multi-layered approach, we use next-generation endpoint detection and response, offer enterprise encryption standards and employ third-party independent service providers to further validate our systems’ security. We also enable our customers to mask certain sensitive data.

Government Regulation

We and our customers are subject to numerous laws and regulations applicable to our and their businesses throughout the world, including laws regarding data privacy, data protection, information security, cybersecurity, restrictions on the collection, use, storage, protection, disposal, transfer or other processing of consumer data, content, consumer protection, advertising,

6

taxation, provision of online payment services (including credit card processing), and intellectual property rights, which are continuously evolving and developing. Compliance with these laws and regulations may be costly, and any failure to comply could have a material adverse effect on our and our customers’ reputation and results of operations.

Intellectual Property and Proprietary Rights

We own a portfolio of patents and patent applications in the United States and internationally and regularly file patent applications to protect intellectual property that we believe is important to our business. As of December 31, 2024, we have 372 patents issued in the U.S. and abroad, and 222 patents pending. We had 27 patents awarded in the U.S. during 2024, and added 65 global patents. Our patents cover Conversational AI and insights, messaging across various consumer channels, behavioral analytics and personalization, and agent effectiveness and call center operations.

We rely on a combination of patent, copyright, trade secret, trademark and other common law protections in the United States and other jurisdictions, as well as confidentiality requirements and contractual provisions, to protect our proprietary technology, processes and other intellectual property.

Human Capital Management

As a leading provider of digital customer conversation solutions, we are at the forefront of a consumer-led shift to Conversational AI, and our platform is setting the industry standard for this future.

As of December 31, 2024, we had 928 full-time employees worldwide, located in more than 20 countries. Of these, 356 were located in the Americas, 380 in Europe, the Middle East, and Africa (“EMEA”), and 184 in APAC. Although we have statutory employee representation obligations in certain countries, our U.S. employees are not covered by collective bargaining arrangements. We believe we have good relations with our employees. For 2024, our key human capital management efforts focused on the following:

We place a high priority on attracting, recruiting, developing and retaining diverse global talent. As a company, we are focused on benefits and programs that support our employees across the entire employee lifecycle, from recruitment and onboarding, to well-being, learning and development. Our recruiting processes are designed to ensure that we bring on employees who are aligned to our values and culture, and we follow a comprehensive process in order to solicit multiple perspectives and eliminate bias.

We support employee training and development through our online Learning Management Systems which provides access to LivePerson product and process training. In addition, employees have access to thousands of learning courses focused on a myriad of topics that include professional skills, technical skills, leadership skills, communication skills, time management skills, AI and machine learning, project management, professional certification prep courses, and additional topics that support an engaged and balanced workforce. We encourage employees to create developmental goals to support their ongoing learning.

We strive to foster an environment in which all employees are supported and enabled to perform at their best individually and collectively. We value a wide range of perspectives, and believe this supports our successful delivery of innovative AI solutions and consumer experience products and services to our global customer base.

Website Access to Reports

We make available on our website (ir.liveperson.com), our annual reports on Form 10-K, our quarterly reports on Form 10-Q, and our current reports on Form 8-K and any amendments to those reports filed or furnished pursuant to Sections 13(a) or 15(d) of the Securities Exchange Act of 1934 as soon as reasonably practicable after we have electronically filed such material with, or furnished it to, the Securities and Exchange Commission (“SEC”). The Company’s website address provided above is not intended to function as a hyperlink, and the information on the Company’s website is not and should not be considered part of this Annual Report on Form 10-K and is not incorporated by reference herein. The SEC maintains an internet site that contains reports, proxy and information statements, and other information regarding issuers that file electronically with the SEC at www.sec.gov.

7

Item 1A. Risk Factors

The following are certain of the important risk factors that make an investment in our securities speculative or risky. The risks described below are not the only ones we face. Additional risks not presently known to us, or that we currently deem to be immaterial, could also materially and adversely affect our business, results of operations, financial condition, cash flows or prospects, or the price of our outstanding securities.

Summary of Risk Factors

Our business is subject to risks and uncertainties that make an investment in our securities speculative or risky and could materially adversely affect our business, results of operations, financial condition, cash flows or prospects, or the price of our outstanding securities. These risks are discussed more fully below and include:

•The success of our business depends on retention of existing customers and their purchase of additional services, and attracting new customers.

•Supporting our customer base requires intensive personnel, infrastructure and resource commitment, and if we are unable to scale our operations and increase productivity, we may not be able to successfully implement our business plan.

•Our business depends significantly on our ability to retain our key personnel, attract new personnel, and manage attrition.

•Our contingent pricing arrangement program offers contingent pricing and if we are unsuccessful at achieving customer objectives, the program could result in operating losses.

•Our expansion into new products, services, and technologies could subject us to additional risks.

•If we do not successfully integrate past or potential future acquisitions, we may not realize the expected business or financial benefits and our business could be adversely impacted.

•We may not be able to refinance our substantial indebtedness before it becomes due. In addition, capital needs necessary to execute our business strategy could increase substantially. There is a significant risk that we may not be able to secure necessary financing on commercially reasonable terms, or at all.

•Our sales cycles can be lengthy, and the timing of sales can cause our operating results to vary significantly.

•Delays in our implementation cycles could have an adverse effect on our results of operations.

•Our quarterly revenue and operating results may fluctuate significantly, which may cause a substantial decline in the trading price of our securities.

•In the past we have experienced losses, we had an accumulated deficit of $991.3 million as of December 31, 2024 and we may incur losses in the future.

•The non-payment or late payment of amounts due to us from a significant number of customers may negatively impact our financial condition or make it difficult to forecast our revenues accurately.

•There are inherent limitations on the effectiveness of our controls.

•As a “smaller reporting company,” we may comply with certain reduced reporting and disclosure requirements which could make our common stock less attractive to investors.

•Because we recognize revenue from subscriptions for our service over the term of the subscription, declines in business may not be immediately reflected in our operating results.

•If our goodwill or long-lived assets become impaired, we may be required to record a significant charge to earnings.

•If we are unable to develop and maintain successful relationships with partners, service partners, social media, and other third-party consumer messaging platforms and endpoints, our business, results of operations, and financial condition could be adversely affected.

•If we are unable to effectively operate on mobile devices, our business could be adversely affected.

•The markets in which we participate are highly competitive, and we may lose customers and revenue if we are not able to innovate or effectively compete.

•Downturns in the global economic environment or in particular industries in which our sales are concentrated may adversely affect our business and results of operations.

•Failures or security breaches in our services or systems, those of our third-party service providers, or in the websites of our customers, including those resulting from cyber-attacks, security vulnerabilities, defects, or errors, could harm our business.

8

•We may be liable if third parties access or misappropriate confidential or personal data from our systems or services.

•We provide service-level commitments to certain customers. If we do not meet these contractual commitments, we could be obligated to provide credits or refunds or face contract terminations, which could adversely affect our revenue and harm our reputation.

•Failure to license necessary third-party software for use in our products and services, or failure to successfully integrate third-party software, could cause delays or reductions in our sales, or errors or failures of our service.

•Our business is subject to a variety of U.S. and international laws and regulations regarding privacy, data protection, and AI, and increased public scrutiny of privacy, security, and AI issues could result in increased government regulation, industry standards, and other legal obligations that could adversely affect our business.

•We are the subject of a number of ongoing actions that have resulted in significant expense, and adverse developments in our ongoing actions and/or future actions could have a material adverse effect on our business results of operations and financial condition.

•We may be subject to governmental export controls and economic sanctions regulations that could impair our ability to compete in international markets due to licensing requirements and could subject us to liability if we are not in compliance with applicable laws.

•Industry-specific regulation is evolving and unfavorable industry-specific laws, regulations, or interpretive positions could harm our business.

•Future regulation of the internet or mobile devices may result in decreased demand for our services and increased costs of doing business.

•Our products and services may infringe upon intellectual property rights of third parties and any infringement could require us to incur substantial costs and may distract our management.

•Our business and prospects would suffer if we are unable to protect and enforce our intellectual property rights.

•Issues in the use of AI in our product offerings or by our vendors may result in reputational harm or liability.

•Our results of operations may be adversely impacted due to our exposure to foreign currency exchange rate fluctuations.

•We may be unsuccessful in expanding our operations internationally due to additional regulatory requirements, tax liabilities, currency exchange rate fluctuations, and other risks, which could adversely affect our results of operations.

•Our operations may expose us to greater than anticipated income, non-income, and transactional tax liabilities, which could harm our financial condition and results of operations.

•Our ability to use our net operating losses to offset future taxable income may be subject to certain limitations.

•Political, economic, and military conditions in Israel could negatively impact our Israeli operations.

•Servicing our debt may require a significant amount of cash, and we may not have sufficient cash flow from our business to pay our indebtedness.

•The terms of our First Lien Convertible Senior Notes due 2029 require us to meet certain operating and financial covenants and place restrictions on our operating and financial flexibility. If we raise additional capital through debt financing, the terms of any new debt could further restrict our ability to operate our business.

•We may not have the ability to raise the funds necessary to settle conversions of our outstanding convertible debt securities and cash-settled warrants in cash or to repurchase our outstanding convertible debt securities upon a fundamental change, and any future debt may contain limitations on our ability to pay cash upon conversion or repurchase of our outstanding convertible debt securities and cash-settled warrants.

•Provisions in the indentures for our outstanding convertible debt securities may deter or prevent a business combination that may be favorable to security holders.

•Our stock price has been, and may continue to be, highly volatile, which could reduce the value of your investment and subject us to litigation.

•If our common stock continues to trade below $1.00, we may fail to meet the continued listing requirements of The Nasdaq Stock Market LLC, which could result in a delisting of our common stock.

•Our common stock is traded on more than one market and this may result in price variations.

•Provisions in our charter documents, Delaware law and the indentures for our outstanding convertible debt securities could discourage, delay or prevent a takeover that stockholders may consider favorable.

9

Risks Related to Operating our Business

The success of our business depends on retention of existing customers and their purchase of additional services, and attracting new customers.

Our customers typically subscribe for our services for a twelve-month term and have no obligation to renew their subscription after expiration of the twelve-month term. In some cases, our agreements are terminable or may terminate upon 30 to 90 days’ notice without penalty. Factors including dissatisfaction with the nature or quality of our services as well as reductions in our customers’ spending levels, or declines in customer activity as a result of general economic conditions or uncertainty in financial markets, could lead customers to terminate our service. If a significant number of our customers, or any one customer to whom we provide a significant amount of services, were to terminate services, reduce the amount of services purchased, or fail to purchase additional services, our results of operations may be negatively and materially affected.

We depend on monthly fees and interaction-based fees from our services for substantially all of our revenue. As part of our strategy, we frequently offer customers subscriptions with interaction-based fees. While this interaction-based fee model has demonstrated success in our business to date, it could potentially produce greater variability in our revenue as revenue in this model is impacted by the number of interactions that our customers generate through use of our products.

Because of the small amount of services historically sold in initial orders, we depend significantly on the growth of our customer base, sales to new customers and sales of additional services to our existing customers. If we are able to obtain additional customers or if existing customers decline to purchase additional services, our revenues will be adversely affected.

Supporting our customer base requires intensive personnel, infrastructure and resource commitment, and if we are unable to scale our operations and increase productivity, we may not be able to successfully implement our business plan.

We anticipate that additional investments in our infrastructure, research; and development and customer support and development will be required to scale our operations and increase productivity, to address the needs of our customers, to further develop and enhance our services; and to expand our business into new geographic areas. The additional investments we are making will increase our cost base, which will make it more difficult for us to offset any future revenue shortfalls by reducing expenses, and there can be no assurance that they will be successful or meet our customers’ needs.

We regularly upgrade or replace our various software systems. If the implementations of these new applications are delayed, or if we encounter unforeseen problems with our new systems or in migrating away from our existing applications and systems, our operations and our ability to manage our business could be negatively impacted.

Our success depends in part upon the ability of our senior management to manage our business effectively. If we fail to successfully scale our operations and increase productivity, we may be unable to execute our business plan and the market price of our securities could decline.

Our business depends significantly on our ability to retain our key personnel, attract new personnel, and manage attrition.

Our success depends largely on the continued services of our senior management team. The loss of one or more members of senior management could have a material adverse effect on our business, results of operations, and financial condition. We are also substantially dependent on the continued service of other key personnel, including key sales executives responsible for revenue generation and key development personnel accountable for product and service innovation and timely development and delivery of upgrades and enhancements to our existing products and services. Changes to senior management and key employees could also lead to additional unplanned losses of key employees. The loss of key employees could seriously harm our ability to release new products and services and upgrade existing products and services on a timely basis, and put us at a competitive disadvantage.

In the technology industry, there is substantial competition for key personnel, including skilled engineers, sales executives and operations personnel. We may not be able to successfully recruit, integrate and retain qualified personnel in the future, which could impact our ability to innovate and deliver new or updated products to our customers, which could harm our business. If our retention and recruitment efforts are ineffective, employee turnover could increase and our ability to provide services to our customers would be materially and adversely affected.

10

Following the onset of the global novel coronavirus disease (“COVID-19”) pandemic, we vacated most of our physical offices around the world, and transitioned to a work-from-anywhere model. While we have been able to operate effectively from remote locations, the long-term impact of such work arrangements remains unknown. For example, such remote work arrangements may present workplace culture challenges.

We expect to evaluate our needs and the performance of our staff on a periodic basis and may choose to make adjustments in the future. If the size of our staff is significantly reduced, either by our choice or otherwise, it may become more difficult for us to manage existing, or establish new, relationships with customers and other counterparties, or to expand and improve our service offerings. It may also become more difficult for us to implement changes to our business plan or to respond promptly to opportunities in the marketplace. Further, it may become more difficult for us to devote personnel resources necessary to maintain or improve existing systems, including our financial and managerial controls, billing systems, reporting systems and procedures. Thus, any significant amount of staff attrition could cause our business and financial results to suffer.

Our contingent pricing arrangement program offers contingent pricing and if we are unsuccessful at achieving customer objectives, the program could result in operating losses.

The Company has developed a fully managed solution where LivePerson provides messaging and AI automation technology as well as labor, automation, and end-to-end program management. This program pricing is contingent on the degree to which a customer achieves its financial objectives, such as increased revenue or reduced operating costs. If we are unsuccessful in achieving these objectives for our customers (including as a result of broader market events, such as inflation and recessionary pressures or decreased consumer confidence), it will reduce the revenue that we recognize and could result in our operating the program at a financial loss, which could have a materially adverse impact on our financial results.

Our expansion into new products, services, and technologies could subject us to additional risks.

We have invested in new products, services, and technologies. We may have limited or no experience in new market segments that we enter or new services that we decide to offer, and customers may not choose to buy or use our service offerings. These offerings, which can present new and difficult technology challenges, may subject us to claims if customers of these offerings experience service disruptions or failures or other quality issues. Our newer activities may involve significant risks and uncertainties, including diversion of resources and management attention from current operations, as well as, in certain circumstances, the use of alternative investment, governance, or revenue strategies that may fail to adequately align incentives across our business or otherwise accomplish our objectives. In addition, new and evolving products, services, and technologies, including those that use AI, machine learning, and blockchain, can raise ethical, technological, legal, regulatory, and other challenges, which may negatively affect our business and demand for our products and services. Profitability, if any, in our newer activities may not meet our expectations, and we may not be successful enough in these newer activities to recoup our investments in them. Failure to realize the benefits of amounts we invest in new technologies, products, or services could result in the value of those investments being written down or written off.

If we do not successfully integrate past or potential future acquisitions, we may not realize the expected business or financial benefits and our business could be adversely impacted.

As part of our business strategy, we have made and may continue to make acquisitions to add complementary businesses, products, technologies, revenue and intellectual property rights. Acquiring and integrating technology companies presents unique risks including difficulties in adapting and developing new software technologies and systems protocols, increased software integration expenses, and incompatibility of acquired technologies. Acquisitions and investments also involve numerous other risks to us, including:

• potential failure to achieve the expected benefits of the combination or acquisition;

• inability to generate sufficient revenue to offset acquisition or investment cost;

• difficulties in integrating operations, technologies, products, and personnel;

• diversion of financial and management resources from efforts related to existing operations;

• risks of entering new markets in which we have little or no experience or where competitors may have stronger market positions;

• potential loss of our existing key employees or key employees of the company we acquire;

11

• inability to maintain relationships with customers and partners of the acquired business;

• potential unknown liabilities associated with the acquired businesses; and

• the tax effects of any such acquisitions.

These difficulties could disrupt our ongoing business, expose us to unexpected costs, distract our management and employees, increase our expenses, and adversely affect our results of operations. Furthermore, we may incur debt or issue equity securities to pay for any future acquisitions. The issuance of equity securities could be dilutive to our existing stockholders.

If we do not effectively implement our plans to migrate our technology infrastructure to the public cloud, our operations could be significantly disrupted.

We have begun the process of migrating our technology infrastructure to the public cloud. This initiative is a major undertaking as we migrate and reconfigure our current system processes, transactions, data and controls to a new cloud-based platform. It could have a significant impact on our business processes, financial reporting, information systems and internal controls.

As we implement the transition of our technology infrastructure to the public cloud, we may need to divert resources and management attention away from other important business operations. While we are implementing business contingency and other plans to facilitate continuous internet access, sustained or concurrent service denials or similar failures could limit our ability to provide our customers access to cloud-based services or otherwise operate our business. Additionally, we have experienced and may continue to experience issues with customer migration, as many of our customers may not migrate to cloud-based technologies on a timely basis or at all or may choose not to utilize our products and services during and after our transition to cloud-based technologies, which could negatively impact our revenue. Additionally, we may experience difficulties as we manage these changes and transition our technology infrastructure to the public cloud, including loss or corruption of data, interruptions in service and downtime, increased cyber threats and activity, delayed financial reporting, unanticipated expenses including increased costs of implementation and of conducting business, and lost revenue.Although we are conducting design validations and user testing, these may cause delays in transacting our business due to system challenges, limitations in functionality, inadequate management or process deficiencies in the development and use of our systems. Difficulties in implementing or an inability to effectively implement our migration plans could disrupt our operations and harm our business.

As we increase our reliance on public cloud infrastructure, our products and services will become increasingly reliant on continued access to, and the continued stability, reliability, and flexibility of third-party public cloud services. Additionally, we may in the future be unable to secure additional cloud hosting capacity on commercially reasonable terms or at all. If any of our public cloud providers increases pricing terms, terminates or seeks to terminate our contractual relationship, establishes more favorable relationships with our competitors, or changes or interprets their terms of service or policies in a manner that is unfavorable to us, we may be required to transfer to another provider and may incur significant costs and experience service interruptions. We have limited control over the public cloud operations and facilities on which we plan to host our technology infrastructure. Any changes in third-party service levels or any disruptions or delays from errors, defects, hacking incidents, security breaches, computer viruses, misconfigurations, distributed denial of service attacks, bad acts or performance problems could harm our reputation, damage our customers’ businesses, and harm our business. Our public cloud providers are also vulnerable to damage or interruption from earthquakes, hurricanes, floods, fires, war, public health crises, terrorist attacks, power losses, hardware failures, systems failures, telecommunications failures and similar events. Although our transition and migration to the public cloud may increase our risk of liability and cause us to incur significant technical, legal or other costs, we may have limited remedies against third-party providers in connection with such liabilities.

Additionally, our public cloud providers may not be able to effectively manage existing traffic levels or increased demand in capacity requirements, especially to cover peak levels or spikes in traffic, and as a result, our customers may experience delays in accessing our solutions or encounter slower performance in our solutions, which could significantly harm the operations of our customers. Interruptions in our services might reduce our revenue, cause us to issue credits to customers, subject us to potential liability, and cause customers to terminate their subscriptions or harm our renewal rates.

We may not be able to refinance our substantial indebtedness before it becomes due. In addition, capital needs necessary to execute our business strategy could increase substantially. There is a significant risk that we may not be able to secure necessary financing on commercially reasonable terms, or at all.

12

Our substantial level of indebtedness increases the possibility that we may be unable to generate cash sufficient to refinance our outstanding indebtedness. In particular, we have $361.2 million in aggregate principal amount of 0% Convertible Notes due in December 2026 (“2026 Notes”) and $207.1 million in aggregate principal amount of First Lien Convertible Senior Notes due 2029 (“2029 Notes”). Further, our 2029 Notes will come due 91 days before the maturity of the 2026 Notes, if greater than $60.0 million principal amount of our 2026 Notes remains outstanding on such date. From time to time, we have explored, and expect to continue to explore, a variety of transactions to improve our liquidity and/or to refinance our indebtedness, including issuing new debt or equity and repurchasing outstanding notes in the open market with available liquidity. We cannot assure you that we will enter into or consummate successfully any liquidity-generating or debt refinancing transactions, and we cannot currently predict the impact that any such transactions, if consummated, would have on us.

If additional funds are raised through the issuance of debt or preferred equity securities, or borrowing from financial institutions under credit facilities, these instruments could require materially higher interest payments than we have historically paid, have rights, additional preferences, and privileges senior to holders of common stock, and could have terms that impose further restrictions on our operations. If additional funds are raised through the issuance of additional equity or convertible securities, our stockholders could suffer dilution. We cannot assure you that additional funding, if required, will be available to us in amounts or on terms acceptable to us. If sufficient funds are not available or are not available on acceptable terms, our ability to refinance our existing indebtedness, fund any potential expansion, take advantage of acquisition opportunities, develop or enhance our services or products, or otherwise respond to competitive pressures would be significantly limited. Those limitations would materially and adversely affect our business, results of operations, cash flows, and financial condition. If we cannot make scheduled payments on our indebtedness, we will be in default under one or more of the agreements governing our indebtedness, and as a result, we could be forced into bankruptcy or liquidation.

Our sales cycles can be lengthy, and the timing of sales can cause our operating results to vary significantly.

The sales cycle for our products can be several months or more and varies substantially from customer to customer, particularly for sales to enterprise customers. Because we sell complex, integrated solutions, it can take many months to close sales as customers evaluate our product offering against available alternatives and define their requirements. We are often required to spend substantial time, effort, and money educating potential customers about the value of our offerings. The increasingly complex needs of our customers can further contribute to a longer sales cycle.

Additionally, our quarterly sales have historically reflected an uneven pattern in which a disproportionate percentage of a quarter’s total sales occur in the last month, weeks and days of each quarter. This makes prediction of revenue especially difficult and uncertain and increases the risk of unanticipated variations in our results of operations. In addition, historically a large portion of our revenue has derived from large orders from large clients. Consequently, delays in the closing of sales, especially from large clients, could have a material impact on the timing of revenue and results of operations.

Delays in our implementation cycles could have an adverse effect on our results of operations.

Certain of our products require some implementation services, including but not limited to training our customers. As an open platform, we also work with third parties on implementing a variety of integrations into our platform. We have historically experienced a lag between signing a customer contract and recognizing revenue from that customer. Although this lag has typically ranged from 30 to 90 days, it may take more time between contract signing and recognizing revenue in certain situations. If we experience delays in implementation or do not meet project milestones in a timely manner, we could be obligated to devote more customer support, engineering and other resources to a particular project. If new or existing customers cancel or have difficulty deploying our products or require significant amounts of our professional services, support, or customized features, revenue recognition could be canceled or delayed and our costs could increase, which could negatively impact our operating results.

Our services are subject to payment-related risks.

For certain payment methods, including credit and debit cards, we pay interchange and other fees, which may increase over time and raise our operating costs and lower our profit margins. We rely on third parties to provide payment processing services, including the processing of credit cards and debit cards and it could disrupt our business if these companies become unwilling or unable to provide these services to us. We are also subject to payment card association operating rules, certification requirements and rules governing electronic funds transfers, which could change or be reinterpreted in such a way as to make compliance infeasible. If we fail to comply with these rules or requirements, we may be subject to fines and higher transaction

13

fees and lose our ability to accept credit and debit card payments from our customers or facilitate other types of online payments, and our business and operating results could be adversely affected.

We are also subject to a number of other laws and regulations relating to money laundering, international money transfers, privacy and information security, and electronic fund transfers. If we were found to be in violation of applicable laws or regulations, we could be subject to civil and criminal penalties or forced to cease our payments services business.

Our reputation depends, in part, on factors which are partially or entirely outside of our control.

Our services typically appear under the LivePerson brand or as a LivePerson-branded icon on our customers’ websites. The customer service operators who respond to the inquiries of our customers’ users are employees or agents of our customers or independent consultants rather than employees of LivePerson. As a result, we are not able to control the actions of these operators and the impression that any such operator leaves the user with whom they interact. A user may not know that the operator is not a LivePerson employee. If a user were to have a negative experience in a LivePerson-powered real-time dialogue, it is possible that this experience could be attributed to us, which could diminish our brand and harm our business. Additionally, we have no control over the content of our customers’ websites on which our website chat icon appears.

Increased regulatory uncertainty and conflicting stakeholder views regarding environmental, social and governance (“ESG”) matters may increase our costs, harm our reputation, or otherwise adversely impact our business.

Governmental authorities, non-governmental organizations, rating agencies, customers, investors, employees, and other stakeholders remain focused on ESG concerns, such as diversity and inclusion, climate change, sustainability, social responsibility, and corporate governance and transparency. However, stakeholder expectations on ESG matters continue to evolve and are not uniform. This focus on ESG concerns and efforts to comply with shifting and sometimes conflicting expectations could result in increased compliance costs and other complexities, including with respect to collecting, measuring, and reporting ESG-related information in connection with expanding mandatory and voluntary reporting, diligence and disclosure requirements. Responding to ESG considerations and implementation of our ESG goals and initiatives involves risks and uncertainties, requires investments, may subject us to governmental and political scrutiny, and depends in part on third-party performance or data that is outside of our control. In addition, some stakeholders may disagree with our ESG goals and initiatives, and we could be criticized for the timing, scope or nature of our ESG goals or initiatives. If we fail to meet our goals and initiatives or otherwise do not act responsibly, or if we are perceived to not be acting responsibly, or if we become subject to regulatory scrutiny in key ESG areas, we risk negative stockholder reaction, including from proxy advisory services, as well as damage to our reputation, loss of customers or business partners, inability to attract and retain employee talent, and other material adverse effects on our business, results of operations and cash flows.

Risks Related to our Financial Condition and Operating Results

Our quarterly revenue and operating results may fluctuate significantly, which may cause a substantial decline in the trading price of our securities.

Our quarterly revenue and operating results may fluctuate significantly as a result of a variety of factors, many of which are outside of our control. Some of the important factors that may cause our revenue and operating results to fluctuate include:

•our ability to attract and retain new customers;

•our ability to retain and increase sales to existing customers;

•demand from customers for our services;

•our ability to innovate and provide new services to current and future customers;

•our ability to add AI, machine learning, and automation into our services;

•the introduction of new services by us or our competitors;

•our ability to avoid and/or manage service interruptions, disruptions, or security incidents;

•changes in our pricing models or policies or in those of our competitors;

•our ability to maintain and add integrations with third-party consumer messaging platforms and endpoints;

•levels of adoption by companies of mobile and cloud-based messaging solutions;

14

•investments in growing our sales and marketing programs;

•levels of adoption by users of conversational AI and web and mobile-based conversation technology;

•exposure to foreign currency exchange rate fluctuations; and

•the amount and timing of capital expenditures and other costs related to operation and expansion of our business, including those related to acquisitions.

Our revenue and operating results may also fluctuate significantly in the future due to the following factors that are entirely outside of our control:

•new laws, regulations, or regulatory or law enforcement initiatives;

•economic conditions specific to the web, mobile technology, electronic commerce, and cloud computing; consequences of unexpected geopolitical events, natural disasters, acts of war or terrorism, outbreaks of contagious disease, or climate change; and

•general, regional, and/or global economic and political conditions.

As a result, comparing our operating results on a period-to-period basis may not be meaningful. You should not rely upon these comparisons or our past results as indicators of our future performance. Due to the foregoing factors, it is possible that our operating results in one or more future quarters may fall below the expectations of securities analysts and investors or below any guidance we may provide to the market. If this occurs, the trading price of our securities could decline significantly.

In the past we have experienced losses, we had an accumulated deficit of $991.3 million as of December 31, 2024 and we may incur losses in the future.

We have in the past experienced, and we may in the future experience, losses and negative cash flow, either or both of which may be significant. We recorded a net loss of $134.3 million for the year ended December 31, 2024, and as of December 31, 2024, our accumulated deficit was $991.3 million. We cannot assure you that we can sustain or increase profitability on a quarterly or annual basis in the future. Failure to achieve or maintain profitability may materially and adversely affect the market price of our securities.

The non-payment or late payment of amounts due to us from a significant number of customers may negatively impact our financial condition or make it difficult to forecast our revenues accurately.

For the years ended December 31, 2024, 2023 and 2022, our allowance for credit losses was $8.6 million,$9.3 million and$9.2 million, respectively. We base our allowance for credit losses on specifically identified credit risks of customers, historical trends, and other information that we believe to be reasonable. A large proportion of receivables is due from larger corporate customers that typically have longer payment cycles. We adjust our allowance for credit losses when accounts previously reserved have been collected. As a result of increasingly long payment cycles, we have experienced unanticipated fluctuations in our revenues from period to period. Any failure to achieve anticipated revenues in a period could cause the market price of our securities to decline.

There are inherent limitations on the effectiveness of our controls.

We do not expect that our disclosure controls or our internal control over financial reporting will prevent or detect all errors and all fraud. A control system, no matter how well-designed and operated, can provide only reasonable, not absolute, assurance that the control system’s objectives will be met. The design of a control system must reflect the fact that resource constraints exist, and the benefits of controls must be considered relative to their costs. Further, because of the inherent limitations in all control systems, no evaluation of controls can provide absolute assurance that misstatements due to error or fraud will not occur or that all control issues and instances of fraud, if any, have been detected. The design of any system of controls is based in part on certain assumptions about the likelihood of future events, and there can be no assurance that any design will succeed in achieving its stated goals under all potential future conditions. Projections of any evaluation of the effectiveness of controls to future periods are subject to risks. Over time, controls may become inadequate due to changes in conditions or deterioration in the degree of compliance with policies or procedures.

15

As a non-accelerated filer, we are no longer required to include, and have not included in this Annual Report, an attestation report from our independent registered public accounting firm as to the effectiveness of our internal control over financial reporting pursuant to Section 404(b) of the Sarbanes-Oxley Act. If and when we again become subject to the auditor attestation requirements under Section 404(b) of the Sarbanes Oxley Act, our independent registered public accounting firm may issue a report that is adverse in the event it is not satisfied with the level at which our internal control over financial reporting is documented, designed or operating. Including such an attestation report would also cause us to incur additional expenses, which may be significant.

There can be no assurance that control issues will not be identified in the future. If we cannot remediate future material weaknesses or significant deficiencies in a timely manner, or if we identify additional control deficiencies that individually or together constitute significant deficiencies or material weaknesses, our ability to accurately record, process, and report financial information and our ability to prepare financial statements within required time periods, could be adversely affected. Failure to maintain effective internal controls could result in violations of applicable securities laws, stock exchange listing requirements, subject us to litigation and investigations, negatively affect investor confidence in our financial statements, and adversely impact our stock price and our ability to access capital markets.

As a “smaller reporting company,” we may comply with certain reduced reporting and disclosure requirements which could make our common stock less attractive to investors.

As a smaller reporting company, we are permitted to comply with scaled-back disclosure obligations in our SEC filings compared to other issuers, including with respect to disclosure obligations regarding executive compensation in our periodic reports and proxy statements. In addition, we are only required to provide two years of audited financial statements in our SEC reports. If we rely on these exemptions, less information will be available in our SEC reports than SEC reports filed by other public companies. We cannot predict if investors will find our common stock less attractive because we may rely on these exemptions. If some investors find our common stock less attractive as a result, there may be a less active trading market for our common stock and our stock price may be more volatile

Because we recognize revenue from subscriptions for our service over the term of the subscription, declines in our business may not be immediately reflected in our operating results.

We generally recognize revenue from customers ratably over the terms of their subscription agreements, which are typically 12 or more months. As a result, much of the revenue we report in each quarter is the result of subscription agreements entered into during previous quarters. Consequently, a decline in new or renewed subscriptions or cancellations of existing subscriptions in any one quarter may not be reflected in our revenue results for that quarter. Any such decline, however, could negatively affect our revenue in future quarters. Our subscription model also makes it difficult for us to rapidly increase our revenue through additional sales in any period, because revenue from new customers and additional revenue from existing customers is generally recognized over the applicable subscription term, rather than immediately.

If our goodwill or long-lived assets become impaired, we may be required to record a significant charge to earnings.

We review our goodwill for impairment at least annually and when events or changes in circumstances indicate that the carrying value may not be recoverable. Factors that may be considered a change in circumstances indicating that the carrying value of our goodwill or amortizable intangible assets may not be recoverable include a decline in stock price and market capitalization, reduced future cash flow estimates, and slower growth rates in our industry. As discussed in Note 5 – Goodwill and Intangible Assets, Net in the Notes to the Consolidated Financial Statements under Item 8 of this Annual Report on Form 10-K, we have experienced impairments in the past, and from time to time, we may be required to record a significant charge to earnings in our consolidated financial statements during the period in which any impairment of our goodwill or amortizable intangible assets is determined, resulting in a negative impact on our results of operations.

Risks Related to Industry Dynamics and Competition

If we are unable to develop and maintain successful relationships with partners, service partners, social media, and other third-party consumer messaging platforms and endpoints, our business, results of operations, and financial condition could be adversely affected.

We believe that continued growth for companies in our industry depends, in part, on enabling brands to connect with consumers across consumers’ preferred conversational channels and messaging endpoints, such as SMS, Facebook Messenger,

16

WhatsApp, Apple Business Chat, Google Rich Business Messenger, Line, Kakao Talk, Instagram, and WeChat. Accordingly, we have identified and developed, and maintain, strategic relationships with many key technology partners. As part of our growth strategy, we plan to further develop partnerships and specific solution areas with additional technology partners. We typically rely on our strategic partners and third-party service providers to supplement our own subject matter expertise and to leverage industry best practice, provide enhanced products and services, and reduce costs. If we fail to establish these relationships in a timely and cost-effective manner or at all, if these strategic partners or third-party service providers fail to provide the services expected, or if we lose any or all of our current relationships, then our business, results of operations, and financial condition could be adversely affected. Replacing a strategic relationship could also take a long time and result in increased expenses. Additionally, even if we are successful at developing these relationships, but there are problems or issues with the integrations, or our ability to scale and onboard our customers onto new endpoints, our reputation and our prospects may be adversely affected.

We have begun the process of migrating our technology infrastructure to the public cloud and may in the future be unable to secure additional cloud hosting capacity on commercially reasonable terms or at all. If any of our public cloud providers increases pricing terms, terminates or seeks to terminate our contractual relationship, establishes more favorable relationships with our competitors, or changes or interprets their terms of service or policies in a manner that is unfavorable to us, we may be required to transfer to another provider and may incur significant costs and experience service interruptions.

If we are unable to effectively operate on mobile devices, our business could be adversely affected.

We have extended our products and services to support messaging on mobile phone and tablet applications (together, “mobile solutions”) belonging to our company and our customers. If the mobile solutions we have developed do not meet our customers’ needs or the needs of their website visitors, we may fail to retain existing customers and we may have difficulty attracting new customers. Such solutions also present risks related to privacy and security, which could subject us to investigations, litigation, or reputational harm. If we are unable to rapidly innovate and grow mobile revenue, or if we incur excessive expenses in this effort, our financial performance and prospects may be negatively affected.

Additionally, our mobile phone and tablet applications and those of our customers depend on their interoperability with popular mobile operating systems, networks, and standards that we and they do not control, such as Android and iOS operating systems, and any changes in such systems and terms of service that degrade the functionality of our solutions or give preferential treatment to competitive products could adversely affect our revenue. We may not be successful in developing products that operate effectively with these technologies, systems, networks, or standards. As new devices and platforms are released, it is difficult to predict the challenges we may encounter in developing versions of our solutions for use on these alternative devices.

The markets in which we participate are highly competitive, and we may lose customers and revenue if we are not able to innovate or effectively compete.

The markets for mobile and online business messaging, digital engagement and AI technology are intensely competitive, rapidly changing, and characterized by aggressive marketing, pricing pressure, evolving industry standards, rapid technology developments, and frequent new product introductions. We believe that competition will continue to increase as our current competitors increase the sophistication of their offerings and as new participants enter the market, which may cause additional pressure. If we are unable to accurately anticipate technology developments and to innovate in the markets in which we compete and develop successful integrations with third-party consumer messaging platforms, AI providers, and endpoints, or our competitors are more successful than us at developing compelling new products, services, and integrations, or at attracting and retaining customers, we may lose revenue and market share and our operating results could be adversely affected.

We have current and potential competition from providers of messaging and digital engagement solutions that enable companies to engage and connect with their consumer customers, as well as technology providers that offer customer relationship management and contact center solutions. We have current and potential competitors in many different industries, including:

•technology or service providers offering or powering competing digital engagement, contact center, communications, or customer relationship management solutions, such as eGain, Genesys, Nuance, Oracle, Salesforce.com and Twilio;

•service providers that offer basic messaging products or services with limited functionality free of charge or at significantly reduced entry level prices;

17

•social media, social listening, messaging, AI, bots, e-commerce, and/or data and data analytics companies, such as Meta Platforms, Google and WeChat, which may leverage their existing or future capabilities and consumer relationships to offer competing B2B solutions; and

•customers that develop and manage their messaging solutions in-house.

In addition, many of our current and potential competitors have substantial competitive advantages, such as greater brand recognition, significantly larger financial, marketing, and resource and development budgets, access to larger customer bases, larger and more established marketing and distribution relationships, and/or more diverse product and service offerings. As a result, these competitors may be able to respond more quickly and effectively than we can to any change in the general market acceptance of messaging services or any new or changing opportunities, technologies, standards, pricing strategies, or customer requirements. Also, because of these advantages, potential customers may select a competitor’s products and services, even if our services are more effective. For all of these reasons, we may not be able to compete successfully against our current and future competitors.

We may be unable to respond to rapid technological change and changing customer preferences in the online sales, marketing, customer service, and/or online e-commerce industries and this may harm our business.

If we are unable, for technological, legal, financial, or other reasons, to adapt in a timely manner to changing market conditions in the online sales, marketing, customer service, and/or e-commerce industries or our customers’ requirements or preferences, our business, results of operations, and financial condition would be materially and adversely affected. Online business is characterized by rapid technological change. Sudden changes in customer and consumer requirements and preferences, frequent new product and service introductions embodying new technologies, and the emergence of new industry and regulatory standards and practices including without limitation data privacy, security, and AI standards, could render the LivePerson services and our proprietary technology and systems obsolete. The rapid evolution of these products and services requires that we continually improve the performance, features and reliability of our services. Our success depends, in part, on our ability to:

•enhance the features and performance of our services;

•develop and offer new services that are valuable to companies doing business online; and

•respond to technological advances and emerging industry and regulatory standards and practices in a cost-effective and timely manner.

If any of our new services, including upgrades to our current services, do not meet our customers’ or consumers’ expectations, we could lose customers and our business may be harmed. Updating our technology may require significant additional capital expenditures.

Our failure to update our technology or expand our operations in an efficient manner could cause our expenses to grow, our revenue to decline and could otherwise have a material adverse effect on our business, results of operations, and financial condition.

Downturns in the global economic environment or in particular industries in which our sales are concentrated may adversely affect our business and results of operations.

The U.S. and other global economies have experienced in the past and could in the future experience economic downturn that affects all sectors of the economy, resulting in declines in economic growth and consumer confidence, increases in unemployment rates and uncertainty about economic stability. Further, there is increased uncertainty regarding social, political, immigration and trade policies in the U.S. (including implementation of tariffs on U.S. imports and retaliatory tariffs), which could impact our global operations and our business. Global credit and financial markets have in the past experienced extreme disruptions, including diminished liquidity and credit availability and rapid fluctuations in market valuations. Our business has been affected by these conditions in the past and could be similarly impacted in the future by any downturn in global economic conditions.

Our business is, and will continue to be, dependent on sales to customers in the telecommunications, financial services, retail, travel, consumer/retail, automotive, and technology industries. A downturn in one or more of these industries could have a material adverse effect on our business, liquidity, results of operations, financial condition and cash flows. In the event that industry conditions deteriorate in one or more of these industries, we could experience, among other things, cancellation or non-renewal of existing contracts, reduced demand for our products and reduced sales. Weak economic conditions may cause our customers to experience difficulty in supporting their current operations and implementing their business plans. Our customers

18

may reduce their spending on our services, may not be able to discharge their payment and other obligations to us, may experience difficulty raising capital, or may elect to scale back the resources they devote to customer service and/or sales and marketing technology, including services such as ours. Economic conditions may also lead consumers and businesses to postpone spending, which may cause our customers to decrease or delay their purchases of our products and services.

It could be difficult to predict the timing, strength or duration of any economic slowdown or subsequent economic recovery, either relating to the global economic environment or to any particular industry in which our sales are concentrated, which, in turn, could make it more challenging for us to forecast our operating results, make business decisions and identify risks that may adversely affect our business, sources and uses of cash, financial condition and results of operations. If economic conditions deteriorate for us or our customers, we could be required to record charges relating to restructuring costs or the impairment of assets, may not be able to collect receivables on a timely basis, and our business, financial condition, and results of operations could be materially adversely affected.

Risks Related to Security Vulnerabilities and Service Reliability

Failures or security breaches in our services or systems, those of our third-party service providers, customers or partners, including those resulting from cyber-attacks, security vulnerabilities, defects, or errors, could harm our business.

Our products and services involve the storage and transmission of proprietary information and personal data related to our customers and their users, employees and consumers. Theft and security breaches expose us to a risk of improper use, disclosure or loss of such information, which could result in litigation, regulatory investigation, and potential liability.

In the period prior to the completion of our public cloud migration, we are exposed to risks inherent in maintaining the stability and security of our legacy infrastructure due to prior customization, aging and obsolescence of related legacy systems and third-party technologies. Because our customers are, and may continue to be, dependent upon these legacy systems, we also face an increased level of embedded risk in maintaining the legacy systems. Moreover, our ability to timely mitigate, manage and patch vulnerabilities related to legacy systems and related legacy third-party technologies could impact our system security as well as our day-to-day operations, and the deployment of technology enhancements and innovation. In addition, we face risks related to recently acquired businesses and in-process integration of related technologies and platforms. If our operational systems, or those of external parties on which our business depends, are unable to meet our or our customers’ business and operations requirements, or if they fail, have other significant shortcomings or are impacted by cyber-attacks, we could be materially and adversely affected.

We experience cyber-attacks of varying degrees on a regular basis in the ordinary course of our business. Our security measures may also be breached and such breach may be difficult to contain—due to employee or other error, lack of appropriately restricted technical and administrative or privileged access controls, intentional malfeasance and other third-party acts, and system errors or vulnerabilities, including vulnerabilities of our third-party service providers, our customers, partners, or otherwise. We have announced plans to move our technology infrastructure to the public cloud, which will require us to rely on third-party cloud providers to maintain appropriate safeguards.

Additionally, following the COVID-19 pandemic, we elected to maintain a globally distributed, substantially remote workforce. Remote working arrangements may increase the risk of cybersecurity incidents or data breaches. Our use of employees and contractors from countries with higher rates of cybercrime and whose privacy laws reduce our ability to perform full background checks may increase risk of a cybersecurity incident or data breach, including insider risk.

A breach or unauthorized access, or attempts by outside parties to fraudulently induce employees, users, vendors, or customers to disclose sensitive information in order to gain access to our data or data of our customers, users, experts, or consumers, including, but not limited to, individual personal information and financial credit or debit card data that is protected by law or contract, could result in significant legal and financial exposure, damage to our reputation, and a loss of confidence in the security of our products and services that could potentially have an adverse effect on our business.

While we continue to take measures to enhance our information security program and safeguard our products and services, cybersecurity threats and vulnerabilities in desktop computers, mobile phones, smartphones and handheld devices, as well as cyber-attacks, cybersecurity threats, malicious actors and other security incidents continue to evolve in sophistication and frequency industry-wide, and there can be no assurance that we can prevent all security risks. Furthermore, while the Company has designed an information security program to protect our information systems from cybersecurity threats, and to ensure the confidentiality, integrity and availability of systems and information used, owned or managed by the Company related to our

19

employees, our customers and their users, implementation of the supporting controls has coverage gaps and weaknesses and potential for human error that could provide threat actors a window of time to exploit such weaknesses before they are identified and/or addressed. The goal of the information security program is to manage risks in a prioritized fashion; however, control gaps and/or effectiveness, resource constraints, and execution failure can pose cybersecurity risk to LivePerson. In addition, although we work to continuously improve our internal controls and procedures on cybersecurity incident management, prevention, detection, mitigation, response, and recovery, we may be unsuccessful in detecting, reporting or responding to these events in a timely manner, accurately assessing the severity of an event, or sufficiently preventing, limiting, or containing harm arising out of an event.

Because the techniques used to obtain unauthorized access, disable or degrade service, or sabotage systems are constantly evolving in sophisticated ways to avoid detection and often are not recognized until launched against a target, it may be difficult or impossible for us to anticipate or identify these techniques or to implement adequate preventative measures. And while technological advancements enable more data and processes, such as mobile computing and mobile payments, they also increase the risk that cyber-attacks and other security incidents will occur. Additionally, the global threat of cyber-attacks has increased in response to the Russia-Ukraine war and the Israel-Hamas war. An advanced threat actor of high sophistication, such as a nation state, with essentially unlimited resources, poses a significant risk to LivePerson and arguably all similarly situated firms with LivePerson’s size and resources. A significant cyber-attack, or a security incident of any magnitude that is profiled in the media, involving our, our third-party service providers’ or our customers’ systems, could result in material harm to our brand and reputation, and our ability to deliver our services or retain customers, and expose us to lawsuits, regulatory investigations, and significant damages, fines or penalties.

Moreover, our customers may authorize third-party access to their customer data located in our cloud environment. Because we do not control the transmissions to customer-authorized third parties, or the processing of such data by customer-authorized third parties, we cannot ensure the integrity or security of such transmissions or processing. Because our services are responsible for critical communication between our customers and consumers, any security failures, defects or errors in our components, materials or software or those used by our customers could have an adverse impact on us, on our customers and on the end users of their websites and applications. Such adverse impact could include a decrease in demand for our services, damage to our reputation and to our customer relationships, legal exposure, and other financial liability or harm to our business.

We may be liable if third parties access or misappropriate confidential or personal data from our systems or services.

The dialogue transcripts of the text-based chats, email interactions and other interactions between our customers and their users may include sensitive and/or personally identifiable information such as personal contact and demographic information, financial information, personal health matters, and account numbers. Although we employ and continually test and update our security measures to protect this information from unauthorized access, it is still possible that our security measures could be breached and such a breach could result in unauthorized access to our customers’ data or our data, including our intellectual property and other confidential business information. These risks could arise from acts of external parties or from acts or omissions of employees or third-party service provider personnel to whom we have granted access to our systems, including if the information systems used by such third parties are penetrated or compromised by an insider or by external third parties. Because the techniques employed by hackers to obtain unauthorized access or to sabotage systems change frequently and are becoming more sophisticated in circumventing security measures and avoiding detection, we may be unable to anticipate all techniques or to implement adequate preventative measures. A security breach could result in disclosure of our trade secrets or disclosure of confidential customer, supplier or employee data. If third parties were able to penetrate our network security or otherwise copy and/or misappropriate personal data relating to our customers’ users or the text of customer service inquiries, our competitive position may be harmed and we could be subject to liability. In the event of a security incident, we could be required to comply with a myriad of breach notification laws at the state, federal and international level, which may cause business disruption and extensive notification costs, and could lead to penalties, government investigations and lawsuits for compliance failures. We may as a result of a security incident be deemed out of compliance with U.S. federal and state laws, international laws, securities laws or contractual commitments, and we may be subject to government investigations, lawsuits, fines, criminal penalties, statutory damages, and other costs to respond to breach or security incidents, which could have a material adverse effect on our business, results of operations, and financial condition. We may incur significant costs to protect against the threat of security breaches or to mitigate the harm and alleviate problems caused by such breaches. While we currently maintain insurance coverage that may cover certain cybersecurity risks, such insurance coverage is subject to certain exclusions and exceptions and may be insufficient to cover all losses.

Furthermore, certain software and services that we use to operate our business are hosted and/or operated by third parties or integrated with our systems. As we expand our use of cloud-based services, we will increasingly rely on third-party cloud

20

providers to maintain appropriate safeguards to protect confidential or personal data we receive. While we have conducted initial due diligence on these cloud providers with respect to their security and business controls, we may not have the visibility to effectively monitor the implementation, configuration, and efficacy of these controls. If third-party services do not have adequate security measures in place, experience service interruptions, or have their security breached, our business operations could be similarly disrupted and we could be exposed to liability and costly investigations or litigation. The risk of circumvention of our security measures or those of third parties on which we rely has been heightened by advances in computer and software capabilities and the increasingly complex techniques employed by, bad actors. In particular, supply-chain attacks have increased in frequency and severity, and there can be no assurance that third parties’ infrastructure in our supply chain or our third-party service providers’ supply chains have not been compromised.

The need to properly secure, and securely transmit and store, confidential information online requires caution and has shaped the e-commerce and online communications landscape, and increasingly has become an area of consumer and regulatory focus and concern. Any publicized compromise of security could deter people from using online services such as the ones we offer or from using them to conduct transactions, which involve transmitting confidential information. Because our success depends on the general acceptance and reputation of our services and electronic commerce, we may incur significant costs to protect against the threat of security breaches or to alleviate problems caused by these breaches.

We provide service-level commitments to certain customers. If we do not meet these contractual commitments, or if we suffer significant outages, we could be obligated to provide credits or refunds or face contract terminations, which could adversely affect our revenue and harm our reputation.

We offer service-level commitments in certain of our customer contracts, primarily related to uptime of our service. If we are unable to meet the stated service-level commitments or suffer periods of downtime that exceed the periods allowed under our customer contracts, whether due to downtime caused by us or our third-party service providers, which has occurred on several occasions in the past and could occur in the future (including in connection with the migration of our technology infrastructure to the public cloud), we may be contractually obligated to provide these customers with service credits and/or pay financial penalties, which could significantly impact our revenue. In addition, even if our contracts provide otherwise, these customers may attempt to terminate or reduce their contracts, which has occurred from time to time, and/or pursue other legal remedies. Recurring or extended service outages and the inability to recover our services and systems in a timely fashion could also cause damage to our reputation and result in substantial customer dissatisfaction or loss, could cause significant interruptions to our business operations, and could cause us to incur significant costs or divert the attention of our technical or other personnel to recover, all of which could adversely affect our current and future revenue and operating results.

We are dependent on technology systems and third-party content that are beyond our control.

The success of our services depends in part on our customers’ online services as well as the internet and mobile connectivity of consumers, both of which are outside of our control. As a result, it may be difficult to identify the source of problems if they occur. In the past, we have experienced problems related to connectivity, which has resulted in slower than normal response times to user messaging requests and interruptions in service. Our services rely both on the internet and on our connectivity vendors for data transmission. Therefore, even when connectivity problems are not caused by our services, our customers or their consumers may attribute the problem to us. This could diminish our brand and harm our business, divert the attention of our technical personnel or cause significant customer relations problems.

In addition, we outsource certain critical business activities to third parties and plan to continue to do so. We rely in part on service providers and other third parties for various services, including, but not limited to, internet connectivity, network infrastructure hosting, security and maintenance, and utilize software and hardware from a variety of vendors. As a result, we rely upon the successful implementation and execution of the business continuity and repopulation planning of these providers. These providers may experience problems that result in slower than normal response times, interruptions in service or other operational failures. If we are unable to continue utilizing the third-party services that support our web hosting and infrastructure or if our services experience interruptions or delays due to existing third-party service providers, new third-party service providers or a transition between third-party service providers, our reputation and business could be harmed, and we may be exposed to legal and reputational risk, and significant remediation costs.

We also rely on the security of our third-party service providers to protect our proprietary information and information of our customers and their end users. IT system failures, including a breach of our or our third-party service providers’ data security, could disrupt our ability to function in the normal course of business by potentially causing, among other things, an unintentional disclosure of customer information or loss of information. Additionally, despite our security procedures or those of our third-party

21

service providers, information systems may be vulnerable to threats such as computer hacking, ransomware, cyber-terrorism or other unauthorized attempts by third parties to access, obtain, modify or delete our or our customers’ data. Any such breach could have a material adverse effect on our operating results and our reputation as a provider of business collaboration and communications solutions and could subject us to significant penalties and negative publicity, as well as government investigations and claims for damages or injunctive relief under state, federal and foreign laws or contractual agreements.

We also depend on third parties for hardware and software. Such products could contain errors, defects, software bugs, material vulnerabilities, or inaccurate information that may be difficult to detect and correct, and could require us to incur significant costs or divert the attention of our technical or other personnel from our product development efforts. To the extent any such problems require us to replace such hardware or software, we may not be able to do so on acceptable terms, if at all.

Technological or other defects could disrupt or negatively impact our services, which could harm our business and reputation.

We face risks related to the technological capabilities of our services. We expect the number of interactions between our customers’ operators and consumers over our system to increase significantly as we expand our customer base. Our network hardware and software may not be able to accommodate this additional volume. Additionally, we must continually upgrade our software to improve the features and functionality of our services in order to be competitive in our markets. If future versions of our software contain undetected errors, our business could be harmed. As a result of software upgrades at LivePerson, our customer sites have, from time to time, experienced slower than normal response times and interruptions in service. If we experience system failures or degraded response times, our reputation and brand could be harmed. We may also experience technical problems in the process of installing and initiating the LivePerson services on new web hosting services, including in connection with our plans to migrate our technology infrastructure to the public cloud. These problems, if not remedied, could harm our business.

Our services also depend on complex software which may contain defects, particularly when we introduce new versions. We may not discover software defects that affect our new or current services or enhancements until after they are deployed. It is possible that, despite testing by us, defects may occur in the software. These defects could result in:

•damage to our reputation;

•lost sales;

•contract terminations;

•loss of market share;

•delays in or loss of market acceptance of our products; and

•unexpected expenses and diversion of resources to remedy errors.

Our products are complex, and errors, failures, or “bugs” may be difficult to correct.

Our products are complex, integrating hardware, software and elements of a customer’s existing infrastructure. Despite quality assurance testing conducted prior to the release of our products, our software may contain “bugs” that are difficult to detect and fix. Any such issues could interfere with the expected operation of a solution, which might negatively impact customer satisfaction, reduce sales opportunities or affect gross margins. Depending upon the size and scope of any such issue, remediation may have a negative impact on our business. Our inability to cure an application or product defect, should one occur, could result in the failure of an application or product line, damage to our reputation, litigation, and/or product reengineering expenses. Our insurance may not cover, or may be insufficient to cover fully, expenses associated with such events.

Failure to license necessary third-party software for use in our products and services, or failure to successfully integrate third-party software, could cause delays or reductions in our sales, or errors or failures of our service.

We license third-party software that we incorporate into our products and services. In the future, we might need to license other software to enhance our products and meet evolving customer requirements. These licenses may not continue to be available on commercially reasonable terms or at all. Some of this technology could be difficult to replace once integrated. The loss of, or inability to obtain, these licenses could result in delays or reductions of our products and services until we identify, license and integrate or develop equivalent software, and new licenses could require us to pay higher royalties. If we are unable to

22

successfully license and integrate third-party technology, we could experience a reduction in functionality and/or errors or failures of our products, which may reduce demand for our products and services.

Third-party licenses may expose us to increased risks, including risks associated with the integration of new technology, the impact of new technology integration on our existing technology, open-source software disclosure requirements, the diversion of resources from the development of our own proprietary technology, and our inability to generate revenue from new technology sufficient to offset associated acquisition and maintenance costs.

Our business is subject to the risks of earthquakes, fires, floods, and other natural catastrophic events and to interruption by man-made problems such as terrorism or cyber-attacks.

Although we intend to migrate our technology infrastructure to the public cloud, a substantial majority of our computer and communications infrastructure is running in our private cloud on hardware that is located at a limited number of facilities in the United States, Europe, and Australia. Our systems, operations, and data centers are vulnerable to damage or interruption from earthquakes, fires, floods, hurricanes, other acts of nature, power losses, telecommunications failures, terrorist attacks, acts of war, human errors, break-ins, state-sponsored or other cyber-attacks or failures, pandemics or other public health crises, or similar events. For example, a significant natural disaster, such as an earthquake, fire or flood, could have a material adverse impact on our business, operating results and financial condition, and our insurance coverage may be insufficient to compensate us for losses that may occur. Our global data providers could be vulnerable to the physical effects of climate change, including increased frequency and duration of extreme weather events and natural disasters. In addition, acts of terrorism could cause disruptions in our business or the economy as a whole. Our servers may also be vulnerable to computer viruses, break-ins, cyber-attacks, such as coordinated denial-of-service attacks or ransomware, or other failures, and similar disruptions from unauthorized tampering with our computer systems, which could lead to interruptions, delays, loss of critical data or the unauthorized disclosure of confidential customer data. Although we have implemented security measures and data recovery capabilities, there can be no assurance that we will not suffer from business interruption, or unavailability or loss of data, as a result of any such events, or that data recovery would be complete or on a timeline expected by our customers. As we rely heavily on our servers, computer and communications systems and the internet to conduct our business and provide high quality service to our customers, such disruptions could negatively impact our ability to run our business, result in loss of existing or potential customers and increased expenses, and/or have an adverse effect on our reputation and the reputation of our products and services, any of which would adversely affect our operating results and financial condition.

Risks Related to Regulatory and Data Privacy Issues

Our business is subject to a variety of U.S. and international laws and regulations regarding privacy, data protection and AI, and increased public scrutiny of privacy, security and AI issues could result in increased government regulation, industry standards, and other legal obligations that could adversely affect our business.

We collect, process, store, and use personal data and other information generated during mobile and online messaging between brands and consumers and between experts and consumers. We post our privacy policies and practices on our websites and we also often include privacy commitments in our contracts. Our business is subject to numerous federal, state and international laws and regulations regarding privacy, data protection, personal information, security, data collection, storage, use and transfer, and the use of cookies and similar tracking technologies. To the extent that additional legislation regarding user privacy is enacted, such as legislation governing the collection and use of information regarding internet or mobile users through the use of cookies or similar technologies, the effectiveness of our services could be impaired by restricting us from collecting or using information that may be valuable to our customers and/or exposing us to lawsuits or regulatory investigations. The foregoing could have a material adverse effect on our business, results of operations, and financial condition.

U.S. and international privacy laws and regulations are evolving and changing, subject to differing interpretations, may be costly to comply with, and may be inconsistent among countries and jurisdictions or conflict with other rules. To the extent we expand our operations in other countries, our liability exposure and the complexity and cost of compliance with data and privacy requirements will likely increase. Any failure by us to comply with our posted privacy policies, applicable federal, state or international laws and regulations relating to data privacy, data protection and AI, or the privacy commitments contained in our contracts, could result in proceedings against us by governmental entities, customers, consumers, watchdog groups or others, which could have a material adverse effect on our business, financial condition and results of operations. In addition, the increased attention focused upon liability as a result of lawsuits and legislative proposals and enactments could harm our reputation or otherwise impact our business, results of operations and financial condition.

23

Laws and practices regarding handling and use of personal and other information by companies have come under increased public scrutiny, and governmental entities, consumer agencies and consumer advocacy groups have called for, and in many instances, enacted increased regulation and changes in industry practices. For example, we are subject to the European Union (“E.U.”) General Data Protection Regulation (“GDPR”), which imposes significantly greater compliance burdens on companies that control or process personal data of users primarily located in the E.U. and, for noncompliance, provides for considerable fines up to the higher of 20 million Euros or 4% of global annual revenue. Additionally, following the United Kingdom’s withdrawal from the E.U., we also are subject to the U.K. General Data Protection Regulation (“U.K. GDPR”), a version of the GDPR as implemented into the laws of the U.K. While the GDPR and U.K. GDPR remain substantially similar for the time being, the U.K. government has announced that it would seek to chart its own path on data protection and reform its relevant laws, including in ways that may differ from the GDPR in some respects. While these developments increase uncertainty with regard to data protection regulation in the U.K., even in their current, substantially similar form, the GDPR and U.K. GDPR can expose businesses to divergent parallel regimes that may be subject to potentially different interpretations and enforcement actions for certain violations and related uncertainty. The GDPR and U.K. GDPR also impose certain technological requirements that may, from time to time, require us to make changes to our services to enable LivePerson and/or our customers to meet legal requirements and may impact how data protection is addressed in our customer and vendor agreements. E.U. and U.K. regulators have issued numerous fines pursuant to the GDPR and U.K. GDPR, respectively. Ensuring compliance with the GDPR and U.K. GDPR is an ongoing commitment that involves substantial costs, and it is possible that despite our efforts, governmental authorities or third parties will assert that our services or business practices fail to comply. We also must require vendors that process personal data to take on additional privacy and security obligations, and some may refuse, causing us to incur potential disruption and expense related to our business processes. If our policies and practices, or those of our vendors, are, or are perceived to be, insufficient, we could be subject to enforcement actions or investigations by Data Protection Authorities (including in the E.U. and U.K.) or lawsuits by private parties, and our business could be negatively impacted.

The E.U. has also released a proposed Regulation on Privacy and Electronic Communications (“e-Privacy Regulation”) to replace the E.U.’s Privacy and Electronic Communications Directive (“e-Privacy Directive”) to, among other things, better align with the GDPR, to amend the current e-Privacy Directive’s rules on the use of cookies and other tracking technologies, and to harmonize across current E.U. member state e-privacy data protection laws. Compliance with changes in laws and regulations related to privacy may require significant cost, limit the use and adoption of our services, and require material changes in our business practices that result in reduced revenue. Noncompliance could result in material fines and penalties, litigation, regulatory investigation and/or governmental orders requiring us to change our data practices, which could damage our reputation and harm our business.

Additionally, complexity and regulatory compliance uncertainty under the GDPR regarding certain transfers of personal information from the European Economic Area (the “EEA”) to the United States and certain other third countries remains. For example, on October 7, 2022, President Biden signed an Executive Order on “Enhancing Safeguards for United States Intelligence Activities,” which introduced new redress mechanisms and binding safeguards to address concerns raised in 2020 by the Court of Justice of the European Union in relation to data transfers from the EEA to the United States and which formed the basis of the new E.U.-US Data Privacy Framework (“DPF”), as released on December 13, 2022. The European Commission adopted its Adequacy Decision in relation to the DPF on July 10, 2023, rendering the DPF effective as an E.U. GDPR transfer mechanism to U.S. entities self-certified under the DPF. On October 12, 2023, the U.K. Extension to the DPF came into effect (as approved by the U.K. Government), as a U.K. GDPR data transfer mechanism to U.S. entities self-certified under the U.K. Extension to the DPF. We currently rely on the DPF and on a similar Swiss-US Data Privacy Framework to transfer certain personal data from the EEA and Switzerland, respectively to the United States and on the U.K. Extension to the DPF to transfer certain personal data from the U.K. to the United States. In recent years, the UK government has introduced proposed legislation intended to create a more business-friendly regime in the UK through changes to the existing data protection legislation. At this stage it is unclear whether and when changes to the legislation will be adopted and whether such legislative reforms could potentially lead the European Commission not to extend or to revoke the UK adequacy decision. We also currently rely on the E.U. standard contractual clauses and the U.K. Addendum to the E.U. standard contractual clauses and the U.K. International Data Transfer Agreement as relevant to transfer personal data outside the EEA and the U.K. with respect to both intragroup and third-party transfers. We expect the existing legal complexity and uncertainty regarding international personal data transfers to continue. In particular, we expect the DPF Adequacy Decision to be challenged and international transfers to the United States and to other jurisdictions more generally to continue to be subject to enhanced scrutiny by regulators.

If the transfer mechanisms we rely on are not sufficient and we are unable to transfer personal data between and among countries and regions in which we operate, it could affect the manner in which we provide our services and could adversely affect our financial results, and, until the legal uncertainties regarding how to legally continue transfers pursuant to the standard contractual clauses and other mechanisms are settled, we will continue to face uncertainty as to whether our efforts to comply

24

with our obligations under the GDPR and U.K. GDPR will be sufficient. Failure to comply with existing or new rules may result in significant penalties or orders to stop the alleged noncompliant activity.

In addition to the changing regulatory landscape in the E.U. and the U.K., we are subject to U.S. laws and regulations, including at the state level, such as the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (“CPRA”), which took effect on January 1, 2023 (the “CCPA”). Among other things, the CCPA gives California residents expanded data privacy rights, allowing consumers to opt out of certain data sharing with third parties, provides a private cause of action for data breaches, imposes additional obligations such as data minimization and storage limitations; on covered businesses; and forms a dedicated privacy regulator in California, the California Privacy Protection Agency, to implement and enforce the law. The CCPA marked the beginning of a trend toward more stringent state data privacy legislation in the United States, which may result in significant costs to our business, damage our reputation, and require us to amend our business practices, and could adversely affect our business, especially to the extent the specific requirements vary from those and other existing laws. For example, comprehensive privacy laws in multiple U.S. states have gone, or will go, into effect between 2024 and 2026, and a number of other states are considering similar laws related to the protection of consumer personal information. Moreover, laws in all 50 U.S. states require businesses to provide notice under certain circumstances to consumers whose personal information has been disclosed as a result of a data breach. Many similar laws have been proposed at the federal and state level; accordingly, we also may be subject to additional compliance obligations as such legislation is considered and adopted, which may require us to modify our data processing practices and policies and incur substantial costs and expenses to comply.

In addition to government activity, privacy advocacy and other industry groups have established and may continue to establish new self-regulatory standards that may place additional burdens on us. If our privacy practices are deemed unacceptable by watchdog groups or privacy advocates, such groups may take measures that harm our business by, for example, disparaging our reputation and our business, which may have a material adverse effect on our results of operations, and financial condition. In addition, privacy concerns may cause consumers to avoid online sites that collect various forms of data or to resist providing the data necessary to allow our customers to use our services effectively. Even the perception of data security and data privacy concerns, whether or not valid, could inhibit sales and market acceptance of our products and services.

Our business is subject to a variety of U.S. and foreign laws, and existing, new and developing regulatory or other legal requirements could subject us to claims or materially impact our business.

We and our customers are subject to a number of laws and regulations in the United States and abroad, including laws related to conducting business on the internet and on mobile devices, such as laws regarding data privacy, data protection, information security, cybersecurity, restrictions or technological requirements regarding the collection, use, storage, protection, disposal, transfer or other processing of consumer data, content, consumer protection, internet (or net) neutrality, advertising, electronic contracts, taxation, provision of online payment services (including credit card processing), and intellectual property rights, which are continuously evolving and developing. Because our services are accessible worldwide, certain foreign jurisdictions may claim that we are required to comply with their laws, even if we do not have a local entity, employees or infrastructure. Foreign data protection, privacy, and other laws and regulations may often be more restrictive than those in the United States. The scope and interpretation of the laws and other obligations that apply to us, including those related to user privacy and data security, are often uncertain and may be conflicting, particularly laws and obligations outside the U.S. There is a risk that these laws may be interpreted and applied differently in any given jurisdiction in a manner that is not consistent with our current practices, which could cause us to incur substantial cost and could negatively impact our brand, reputation and business.

Businesses using our products and services may collect data from their users. Various federal, state and foreign government bodies and agencies impose laws regarding collection, use, storage, retention, disposal, transfer or other processing of data from website visitors. We offer our customers a variety of data security procedures and practices, such as encryption for data at rest and masking algorithms for sensitive data prior to transfer to our database, in an effort to protect information. Changes to applicable laws and how they are interpreted relating to privacy and data security could significantly increase the cost to us and our customers of regulatory compliance and could negatively impact our business.

For instance, some states in the U.S. have enacted legislation designed to protect consumer privacy by prohibiting the distribution of “spyware” over the internet. Such legislation typically focuses on restricting the proliferation of software that, when installed on an end user’s computer, is used to intentionally and deceptively take control of the end user’s machine. We do not believe that the data monitoring methods that we employ constitute “spyware” or are prohibited by applicable laws. However, federal, state and foreign laws and regulations, many of which can be enforced by government entities or private parties, are constantly evolving and can be subject to significant changes in application and interpretation. If, for example, the scope of the

25

previously mentioned “spyware” legislation were changed to include web analytics, such legislation could apply to the technology we use and potentially restrict our ability to conduct our business.

Similarly, some U.S. courts have interpreted certain two-party consent wiretap statutes, such as the California Invasion of Privacy Act, to require the collection of prior consent from consumers who engage in a dialogue with chatbots. If the scope of such laws or newly enacted legislation were interpreted to apply to our services, we and/or our customers may be required to obtain the express consent of web visitors in order for our technology to perform its intended functions. Requirements that a website must first obtain consent from its web visitors before using our technology could reduce the amount and value of the services we provide to customers, which might impede sales and/or cause some existing customers to discontinue using our services or could subject us to fines and/or proceedings by governmental agencies, regulatory bodies, and/or private litigation, which could materially and adversely affect our business, financial condition and results of operations.

There has been an increased focus in 2024 on laws and regulations related to AI. For example, states, regions and supranational bodies, including the European Union and the United States, have passed or proposed new rules and regulations related to the development and use of AI technology, which cover, among other things, consumer protection, algorithmic accountability, privacy and transparency. In the United States, there is uncertainty at the federal level regarding applicable regulations that will apply to the development and use of AI. In January 2025, the Trump administration rescinded an Executive Order implemented by the Biden administration in 2023 aimed at establishing new standards for AI safety and security, privacy, consumer and employee protection and innovation and competition associated with the use of AI. The Trump administration then issued a new Executive Order that, among other things, directed the heads of various federal governmental bodies to review actions taken under the Biden Executive Order and develop a new action plan with respect to AI-related matters. In Europe, the EU AI Act, enacted on August 1, 2024, began to apply in February 2025, with the remaining requirements to become effective on a staggered basis through August 2027. The EU AI Act establishes, among other things, a risk-based governance framework for regulating AI systems operating in the EU. This framework categorizes AI systems, based on the risks associated with such AI systems’ intended purposes, as creating unacceptable or high risks, with all other AI systems being considered low risk. The EU AI Act prohibits certain uses of AI systems and places numerous obligations on providers and deployers of permitted AI systems, with heightened requirements based on AI systems that are considered high risk. The EU AI Act establishes requirements for the provision and use of products that leverage AI, machine learning, and similar technologies, including chatbots, with potential fines reaching up to the greater of €35 million and 7% of global income. We may not be able to anticipate how to respond to these rapidly evolving frameworks, which could impact our ability to develop and deploy AI-powered features in a timely manner. Compliance with evolving regulatory requirements may increase our operational costs, and we may need to expend additional resources to adjust our operations or offerings in certain jurisdictions if the legal frameworks are inconsistent across jurisdictions. This could include requirements to retrain our algorithms, disclose or provide greater transparency regarding the nature of our AI systems and the data we have employed to train them, or prevent or limit our use of AI. Any failure to comply with these regulations or delays in adapting to new requirements could result in penalties, loss of market access, competitive disadvantages, or reputational harm. Furthermore, because AI technology itself is highly complex and rapidly developing, it is not possible to predict all of the legal, operational or technological risks that may arise relating to the use of AI. Additionally, other countries have proposed legal frameworks on AI, which is a trend that is expected to increase, and existing laws and regulations may be interpreted in ways that may affect our use of AI. Any failure or perceived failure by us to comply with such requirements could have an adverse impact on our business. Our competitors may be developing their own AI products and technologies, which may be superior in features, functionality, compliance readiness, or cost efficiency compared to our offerings, potentially impacting our competitive position. Any of these factors could adversely affect our business, reputation, or operating results.

Further, various federal, state and foreign government bodies and agencies are highly focused on consumer protection initiatives, particularly in light of the increase in new technologies and services that incorporate or use bots, AI and/or machine learning. For example, the California B.O.T. Act requires that companies using bots on platforms with more than ten million unique monthly visitors from the U.S. use clear and conspicuous disclosure to inform consumers that they are not speaking to a human. Similar bills have been introduced from time to time at the state and federal level in recent years. Further, the use of certain AI and machine learning may be subject to laws and evolving regulations, controlling for, among other things, data bias and antidiscrimination. For example, the Federal Trade Commission (“FTC”) enforces consumer protection laws such as Section 5 of the FTC Act, which prohibits unfair and deceptive practices, including use of biased algorithms in AI. The European Commission’s EU AI Act imposes additional restrictions and obligations on providers of AI systems, including increasing transparency so consumers know they are interacting with an AI system, requiring human oversight in AI, and prohibiting certain practices of AI that could lead to physical or psychological harm. Given the increased focus by the FTC and other regulators on the use of AI, it is likely that additional laws, regulations, and standards related to AI may be introduced in the future. Regulation in this area could impact how businesses use our products and services to interact with consumers and how we provide our

26

services to our customers. As regulatory scrutiny of AI continues to grow, we may need to modify or restrict certain AI-driven functionalities in our products or services, which could impact their adoption or effectiveness.

AI tools can also present unique technological and legal challenges, such as the possibility of insufficient data sets, or data sets that contain biased or inaccurate information, which can negatively impact the decisions, predictions or analyses that AI applications produce. AI algorithms or automated processing of data may be flawed, and datasets may be insufficient or contain inaccurate, incomplete, poor-quality or biased information, which can create discriminatory outcomes or reduce the effectiveness of AI-driven insights. Deficiencies such as these could cause us reputational harm and subject us to legal liability, including claims of product liability, breach of warranty, or negligence. Additionally, AI-generated content and AI-assisted decision-making may raise unresolved intellectual property concerns, including uncertainty regarding ownership, licensing rights, and third-party claims over training data. The scope of these laws and regulations is rapidly evolving, subject to differing interpretations, may be inconsistent among jurisdictions, or conflict with other rules and is likely to remain uncertain for the foreseeable future. Evolving regulations, legal uncertainties, and enforcement actions could increase our compliance burden, limit our ability to deploy AI-driven solutions, and create additional operational challenges. We also expect that there will continue to be new laws, regulations, and industry standards concerning AI and machine learning proposed and enacted in various jurisdictions. If we fail to stay ahead of these developments, we may face additional costs, disruptions in our product development roadmap, and potential competitive disadvantages.

In addition, regulatory authorities and governments around the world are considering a number of legislative and regulatory proposals concerning privacy, collection and use of website visitor data, data storage, data protection, the “right to be forgotten,” content regulation, cybersecurity, government access to personal information, online advertising, email and other categories of electronic spam, and other matters that may be applicable to our business. Compliance with these laws may require substantial investment or may be technologically challenging for us. For example, some jurisdictions, including in the United States, are considering whether the collection of anonymous data may invade the privacy of website visitors. If laws or regulations are enacted that limit data collection or use practices related to anonymous data, we and/or our customers may be required to obtain the express consent of web visitors in order for our technology to perform certain basic functions that are based on the collection and use of technical data. Requirements that a website must first obtain consent from its web visitors before using our technology could reduce the amount and value of the services we provide to customers, which might impede sales and/or cause some existing customers to discontinue using our services.

It is also likely that, as our business evolves, an increasing portion of our business shifts to mobile, and our solutions are offered and used in a greater number of countries, we will become subject to laws and regulations in additional jurisdictions. We may need to expend considerable effort and resources to develop new product features and/or procedures to comply with any such legal requirements. It is difficult to predict how existing laws will apply to our business and what new laws and legal obligations we may become subject to. If we are not able to comply with these laws or other legal obligations, or if we become liable under them, we may be forced to implement material changes to our business practices, delay release of new and enhanced services and expend substantial resources, which would negatively affect our business, financial condition and results of operations. In addition, any increased attention focused on liability issues, or as a result of regulatory fines or lawsuits, could harm our reputation or otherwise impact our business, results of operations and financial condition. Any costs incurred as a result of this potential liability could harm our business and operating results.

We monitor pending legislation and regulatory initiatives to ascertain relevance, analyze impact and develop strategic direction surrounding regulatory trends and developments. Due to shifting economic and political conditions, tax policies or rates in various jurisdictions may be subject to significant change. A range of other proposed or existing laws and new interpretations of existing laws could have an impact on our business. For example:

Government agencies and regulators have reviewed, are reviewing and will continue to review, the personal data handling practices of companies doing business online, including privacy and security policies and practices. This review may result in new laws or the promulgation of new regulations or guidelines that may apply to our products and services. For example, the State of California and other states have passed laws relating to disclosure of companies’ practices with regard to global opt-out signals from internet browsers, the ability to delete information of minors, age appropriate design obligations for companies that offer online services, products or features “likely to be accessed” by children,and new data breach notification requirements. Washington State recently enacted the “My Health, My Data Act,” which broadly protects the privacy of certain personal health information and generally requires consent for the collection, use, or sharing of any such information. Similarly, outside the E.U. and the U.S., a number of countries have adopted or are considering privacy laws and regulations that may result in significant greater compliance burdens. Existing and proposed laws and regulations regarding cybersecurity and monitoring of online behavioral data, such as proposed “Do Not Track” regulations, regulations aimed at restricting certain targeted advertising

27

practices and collection and use of data from mobile devices, new and existing tools that allow consumers to block online advertising and other content, and other proposed online privacy legislation could potentially apply to some of our current or planned products and services. Existing and proposed laws and regulations related to email and other categories of electronic spam could impact the delivery of commercial email and other electronic communications by us or on behalf of customers using our services.

Source: SEC EDGAR (public domain) · 10-K for the period ended 2024-12-31, filed 2025-03-14 · accession 0001102993-25-000018

Filing HTML rendered to line-structured narrative text by the shipped reducer (datafeeds.edgar_fulltext.visible_text, keep_table_headers=True): scripts and inline-XBRL headers are dropped, and table content is reduced to its short label cells — numeric table data is not rendered and is therefore not counted. The same rendering is used for every year, so a year-over-year comparison is like for like.

The text is our rendering of the filing, not a facsimile: original pagination, typography and tables are not reproduced, and the numbers live in the financial statements (FA).

The outline locates item HEADINGS in this document. Only Items 1A and 7 have certified boundaries elsewhere in the terminal (the redline and the narrative-overlap number); every span here runs from one heading found to the next heading found.

How the outline was chosen. It is the longest chain of item headings that runs forward through both the document and the standard item order: 23 headings are on that chain and 17 further heading-shaped lines are not — the table-of-contents echo of every item, cross-references and exhibit-list mentions. Each entry's length is measured from its heading to the next heading on the chain.