Contract clauses that actually matter

Lesson 2 of 5 in Third-Party AI, Generative AI, Agentic AI, and Frontier Governance.

Due diligence tells you what the vendor is today. The contract is the only control you have over what the vendor becomes. Every clause below exists because someone, somewhere, needed it and did not have it. The eating-disorder helpline NEDA learned about model-change notification when its vendor upgraded a scripted chatbot with generative AI without telling it — the bot then gave dieting advice to people with eating disorders. Air Canada learned about output accountability when a court held it to the bereavement-fare policy its chatbot invented. Both cases get the full post-mortem treatment in the next module; here, they are exhibits for the clauses.

The AI procurement clause set — what each clause buys you, and what its absence costs
ClauseWhat it buys youThe failure it prevents

No training on customer data

Your prompts, documents, and outputs are excluded from the vendor’s model training (or require opt-in)

Your confidential data resurfacing in someone else’s completions; regulator questions about onward processing you never authorized

Model-change notification

Advance notice of model swaps, retraining, and capability additions, with a re-validation window before changes hit production

The NEDA/Tessa pattern: the product you validated silently becomes a different product with different failure modes

Audit and evaluation rights

The right to test the system on your own data, run bias audits, and (for high tiers) inspect documentation or commission third-party audits

Discovering at enforcement time that you certified compliance for a system you were contractually barred from examining

Bias-testing representations

Warranties that the system has been tested for disparate impact, with methodology and results as contract deliverables

Carrying full discrimination liability for a vendor’s untested tool — the fact pattern in Mobley v. Workday

IP / output indemnification

The vendor stands behind output infringement claims (scope and caps vary widely — read the exclusions)

Your marketing team publishes generated content; a rights-holder sues you, not the vendor

Documentation deliverables

Model card, system card, or EU AI Act Art 13 instructions-for-use as named deliverables, updated per release

Being unable to complete your own conformity, FRIA, or DPIA work because the vendor’s paperwork does not exist

Performance warranties + SLAs

Measurable accuracy/latency floors on defined benchmarks, with remedies

"Best-efforts AI" that degrades below usability with no recourse

Exit and portability

Data return in usable formats, deletion certification, transition assistance, and (where relevant) model or configuration portability

A hostage negotiation disguised as a renewal conversation

The clause set has a statutory backstop in the EU. The AI Act’s value-chain rules (taught in full in the EU value-chain module) make contracting a compliance mechanism, not just risk allocation: providers of high-risk systems owe downstream deployers the information they need to comply, and Art 25(4) requires written agreements from suppliers of tools and components. More dangerous in practice is the reverse flow — you can become the provider without noticing. Put your brand on the vendor’s system, substantially modify it, or repurpose it into a high-risk use, and Art 25 hands you the full provider duty stack. Your contract should therefore also police you: internal sign-off before rebranding, fine-tuning, or repurposing any procured system.

What did you just become? A value-chain role check for procured AI

Interactive decision tree — outcomes:

  • You are now the provider

    Under Art 25, white-labeling a high-risk system or substantially modifying one transfers the full provider obligations to you: risk management, technical documentation, conformity assessment, post-market monitoring. The original provider must hand over documentation — which is exactly why your contract needed cooperation duties. Very few procurement teams price this in.

  • You are the deployer

    You carry the deployer duty set — use per instructions, human oversight, input data relevance, monitoring, log retention, and (where applicable) a fundamental rights impact assessment — but not the provider stack. Keep your configuration inside the vendor’s documented envelope to stay here.

  • Deployer — but document the analysis

    Outside the high-risk categories the Art 25 role-switch has less bite, but record why your modification does not change the classification, and re-run the analysis whenever the use case shifts. Repurposing is a re-triage trigger in your own intake process.

Key terms: indemnification, audit rights, model change notification, liability cap, substantial modification, white labeling

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.