Research Note · AI · Contracts

AI audit rights: what enterprise contracts must include.

Most enterprise AI contracts grant no meaningful audit rights. Usage is measured by the vendor, billed by the vendor, and verified against vendor logs — and the model can change under you without notice. This note sets out the five audit-right categories to demand, the exact contract mechanisms that make them enforceable, and how to win them from vendors who resist.

By James Hill-WoodUpdated Sep 20239 min readAI research cluster
Bottom line

In a review of 40+ enterprise AI contracts, fewer than 15% carried meaningful usage audit rights and none carried model change rights by default. Treat five categories — usage/billing, data processing, security, model change, and outcome attribution — as a single package, framed by the risk each mitigates, and negotiate them before signature when your leverage is highest.

01 Key findings

  1. The absence is systematic, not accidental. AI vendors measure usage on their own infrastructure, bill from their own systems, and control model behaviour by their own decisions. Standard terms leave buyers fully dependent on vendor-provided data for every material question.

  2. AI audit rights are not SaaS audit rights. Traditional audits policed seat and module compliance. AI audits must verify opaque token consumption, data-handling practices, model-version consistency, and regulatory documentation — none of which is observable without contractual access to raw logs.

  3. Data handling is the highest-stakes category. Several enterprises have discovered their data was used in general model training despite marketing representations to the contrary — with no means of detection absent an explicit audit right and a defined verification mechanism.

  4. Model change is a genuinely new risk class. A deployment validated against one model version can behave differently after a silent vendor update, with no notification obligation triggered. Change logs and pinning rights are the only contractual defence.

  5. Most rights are winnable. Usage logs, data attestations and security certifications track provisions vendors already offer cloud customers. Model change logs and training-exclusion verification need persistence; outcome-attribution rights need the most effort but are increasingly standard.

02 Five audit-right categories

A complete framework addresses five distinct areas, each requiring specific, enforceable contract language. Vague grants — audit of “relevant documentation” on “reasonable notice” — are not enforceable in practice; specify the artefact, the timeline, and the remedy.

CategoryWhat to demandContract mechanismVendor resistance
Usage & billingMachine-readable logs: API records, timestamps, token counts by call type, model version IDs, billing line items12+ month history; 10 business-day response; third-party billing audit at vendor cost above 3–5% discrepancyLow
Data processingStorage location, tenant segregation, and training-exclusion verificationInspection right; updated evidence within 30 days of any material change; machine-readable logs, not attestations aloneMedium–High
Security & complianceCurrent SOC 2 Type II, ISO 27001, sector-specific certificationsAnnual + post-incident reports; substitutes where direct access is refused: CSA CAIQ, pen-test summariesLow
Model change & versionChange log for weights, safety filters, output formats, context window, rate limits24-month retention; 60-day notice of material change; model-pinning right for a transition periodMedium
Outcome attributionMethodology and underlying data behind each billed outcomeDefined attribution method; per-outcome dispute window; supporting data on requestHigh
The audit-rights gap

In our review of more than 40 enterprise AI contracts signed in 2024–2025, fewer than 15% contained any meaningful usage audit rights, fewer than 10% contained data processing audit rights, and none contained model change audit rights as a default term. These are standard governance requirements that AI vendors have simply not yet normalised into their commercial terms.

03 EU AI Act compliance

The EU AI Act imposes obligations on enterprises deploying AI systems in the EU — “deployers” — that create a direct need for vendor audit access. High-risk applications (HR decisions, credit scoring, consequential customer-facing services, various public-sector uses) require deployers to hold documentation that can only be produced with vendor cooperation.

Required recordWhat it containsWhy vendor access is unavoidable
Conformity assessmentDocumentation demonstrating the AI system meets EU AI Act requirementsHeld and maintained by the vendor building the system
Technical documentationModel architecture, training data, performance characteristicsProprietary to the vendor; not observable from outputs
Operation & oversight logsRecords of human oversight and any reviewed or overridden AI decisionsPartly generated within vendor infrastructure
Change & incident recordsSignificant changes affecting risk classification; failures; harmful outputsOnly the vendor knows when the system materially changes

Require vendors to contractually commit to supplying all documentation necessary for your compliance obligations, retaining it for the contract term plus three years, and notifying you of any change that may affect the system’s risk classification. A vendor unwilling to commit is, in effect, making your EU AI Act compliance impossible — a point worth stating explicitly at the table.

04 Billing verification & disputes

Billing errors are more common in AI services than in traditional SaaS because measurement operates at a lower level of abstraction — individual API calls and token counts rather than user seats — creating more room for discrepancy. Enterprises analysing detailed logs consistently find anomalies, from rounding differences to systematic overcharges for failed calls counted as billable events.

Provision 01

Detailed logs on demand

Vendor supplies API-level usage logs within a defined timeframe — 10 business days is the cloud-contract standard and the right baseline here.

Provision 02

Defined dispute window

Typically 90 days from invoice date to formally contest charges, without waiving payment on undisputed amounts.

Provision 03

Escrow, not suspension

Disputed amounts held pending resolution, barring the vendor from suspending service over a charge under formal review.

Provision 04

Escalation to arbitration

A binding path if the dispute is not resolved within a defined period, plus vendor-funded audit for repeated errors above a 3–5% threshold.

05 Data handling audit rights

Of all categories, data handling carries the highest commercial and regulatory stakes. Whether enterprise data is used to train or improve models — historically a vendor default unless the customer opted out — has direct implications for competitive intelligence, privacy regulation, and IP exposure. The right must be explicit, specific, and backed by defined remedies for breach.

Verify three things: that data is stored in geographically appropriate locations (EU residency for EU-regulated businesses); that it is segregated from other customers and from the vendor’s general infrastructure; and that it has not entered any training, fine-tuning, or evaluation dataset without explicit written consent.

Trap to avoid

“Relevant documentation on reasonable notice” is not an audit right. Vendors define “relevant” narrowly and “reasonable” generously. Specify instead: the exact artefacts (data-flow diagrams, training-pipeline logs, data-residency certificates), a fixed notice period of five to ten business days, machine-readable evidence rather than certifications alone, and a remedy for confirmed breach — termination at your option without early-termination penalty.

06 Model change audit logs

Model change rights have no precedent in traditional software contracting, because traditional software does not silently and continuously alter its core behaviour mid-term. AI systems do — foundation model vendors push updates, sometimes weekly, that can change output quality, safety filters, context handling, and format in ways invisible until production behaviour shifts.

A customer-service AI that passes every quality assessment against one model version may produce meaningfully different outputs after a silent update to the next — creating quality-control failures, regulatory exposure, and inconsistencies that are hard to trace without version logs.

Two protections to secure

Detection and reproduction. Access to model-version logs lets you detect that a change occurred; model-pinning rights or version-history access let you reproduce historical behaviour for analysis. Both are available for negotiation with major vendors and should be standard for any deployment where AI output quality has been formally validated. Require a documented change log with 24-month retention and 60 days’ notice of material changes.

07 Negotiating resistant vendors

Vendors resist comprehensive audit rights for two legitimate reasons: commercial concern about exposing proprietary infrastructure, and operational concern about supporting frequent requests across a large customer base. Acknowledge both — while holding the substance. Four moves carry most of the leverage.

Move 01

Propose a package

Present audit rights as a single coherent package rather than a list of individual demands the vendor can pick apart clause by clause.

Move 02

Frame by risk

Justify each provision by the specific risk it mitigates — billing exposure, data-training leakage, silent model drift — not as generic governance.

Move 03

Trade accommodations

Offer advance-notice requirements and annual (not ad hoc) audit schedules in exchange for broader substantive coverage.

Move 04

Sequence by resistance

Bank the easy wins — usage logs, data attestations, security certifications — then spend capital on model change logs, training exclusion, and outcome attribution.

Advisory note

Firms including Atonement Licensing, which has negotiated AI audit-rights provisions for more than 60 enterprise clients, report that most vendors accept usage-log access, data-handling attestations and annual certifications without significant resistance. Model change logs and training-exclusion verification require more persistence but are achievable with meaningful commitments.

08 Our recommendation

Regulated deployer
When the EU AI Act applies

Lead with compliance and data-processing rights. Secure conformity and technical documentation, oversight logs, retention for term plus three years, and risk-reclassification notice — without them, compliance is impossible.

High-consumption buyer
When spend is API-metered

Prioritise usage and billing rights: 12+ months of machine-readable logs, a 90-day dispute window with escrow, and a vendor-funded third-party audit above a 3–5% error threshold.

Outcome-priced buyer
When you pay per result

Force outcome-attribution rights: a defined methodology for what counts as a billed outcome, a per-outcome dispute window, and underlying supporting data on request. Pair with model-change logs to keep results reproducible.

Does your AI contract include audit rights?

Our AI procurement practice reviews agreements for missing provisions and negotiates comprehensive access rights — typically within two rounds.

Request a contract review →

The Licensing Edge

Weekly vendor intelligence for enterprise software buyers. AI contract analysis, audit-rights frameworks and negotiation tactics.