Contract clauses that actually matter
Lesson 2 of 5 in Third-Party AI, Generative AI, Agentic AI, and Frontier Governance.
Due diligence tells you what the vendor is today. The contract is the only control you have over what the vendor becomes. Every clause below exists because someone, somewhere, needed it and did not have it. The eating-disorder helpline NEDA learned about model-change notification when its vendor upgraded a scripted chatbot with generative AI without telling it — the bot then gave dieting advice to people with eating disorders. Air Canada learned about output accountability when a court held it to the bereavement-fare policy its chatbot invented. Both cases get the full post-mortem treatment in the next module; here, they are exhibits for the clauses.
| Clause | What it buys you | The failure it prevents |
|---|---|---|
No training on customer data | Your prompts, documents, and outputs are excluded from the vendor’s model training (or require opt-in) | Your confidential data resurfacing in someone else’s completions; regulator questions about onward processing you never authorized |
Model-change notification | Advance notice of model swaps, retraining, and capability additions, with a re-validation window before changes hit production | The NEDA/Tessa pattern: the product you validated silently becomes a different product with different failure modes |
Audit and evaluation rights | The right to test the system on your own data, run bias audits, and (for high tiers) inspect documentation or commission third-party audits | Discovering at enforcement time that you certified compliance for a system you were contractually barred from examining |
Bias-testing representations | Warranties that the system has been tested for disparate impact, with methodology and results as contract deliverables | Carrying full discrimination liability for a vendor’s untested tool — the fact pattern in Mobley v. Workday |
IP / output indemnification | The vendor stands behind output infringement claims (scope and caps vary widely — read the exclusions) | Your marketing team publishes generated content; a rights-holder sues you, not the vendor |
Documentation deliverables | Model card, system card, or EU AI Act Art 13 instructions-for-use as named deliverables, updated per release | Being unable to complete your own conformity, FRIA, or DPIA work because the vendor’s paperwork does not exist |
Performance warranties + SLAs | Measurable accuracy/latency floors on defined benchmarks, with remedies | "Best-efforts AI" that degrades below usability with no recourse |
Exit and portability | Data return in usable formats, deletion certification, transition assistance, and (where relevant) model or configuration portability | A hostage negotiation disguised as a renewal conversation |
The clause set has a statutory backstop in the EU. The AI Act’s value-chain rules (taught in full in the EU value-chain module) make contracting a compliance mechanism, not just risk allocation: providers of high-risk systems owe downstream deployers the information they need to comply, and Art 25(4) requires written agreements from suppliers of tools and components. More dangerous in practice is the reverse flow — you can become the provider without noticing. Put your brand on the vendor’s system, substantially modify it, or repurpose it into a high-risk use, and Art 25 hands you the full provider duty stack. Your contract should therefore also police you: internal sign-off before rebranding, fine-tuning, or repurposing any procured system.
What did you just become? A value-chain role check for procured AI
Interactive decision tree — outcomes:
- You are now the provider
Under Art 25, white-labeling a high-risk system or substantially modifying one transfers the full provider obligations to you: risk management, technical documentation, conformity assessment, post-market monitoring. The original provider must hand over documentation — which is exactly why your contract needed cooperation duties. Very few procurement teams price this in.
- You are the deployer
You carry the deployer duty set — use per instructions, human oversight, input data relevance, monitoring, log retention, and (where applicable) a fundamental rights impact assessment — but not the provider stack. Keep your configuration inside the vendor’s documented envelope to stay here.
- Deployer — but document the analysis
Outside the high-risk categories the Art 25 role-switch has less bite, but record why your modification does not change the classification, and re-run the analysis whenever the use case shifts. Repurposing is a re-triage trigger in your own intake process.
Key terms: indemnification, audit rights, model change notification, liability cap, substantial modification, white labeling
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.