Research Note · AI · Contracts

AI contract clauses: 20 terms every enterprise buyer must demand.

Standard AI vendor agreements are drafted by vendor legal teams to minimise the vendor's obligations and maximise its rights. This note isolates the 20 clauses that separate a commercially defensible AI agreement from a vendor template — grouped across IP, data, model stability, service levels, and exit — with the rationale and what to demand for each.

By James Hill-WoodUpdated Dec 20199 min readAI research cluster
Bottom line

The AI agreement your vendor sends is engineered to protect the vendor. Across 200+ enterprise AI agreements the same gaps recur: weak IP assignment, training-data reuse, no model-change notice, and no exit rights. You will not win all 20 clauses — but entering negotiation knowing what to request, and what each omission costs, is the difference between a defensible contract and a vendor template.

01 Key findings

  1. The default AI agreement is a vendor instrument. It is drafted to minimise vendor obligations and maximise vendor rights; most buyers sign because they lack the commercial framework to see what they are conceding.

  2. Training-data reuse is the single most important data provision. An opt-out is insufficient — enterprise agreements require explicit, written opt-in consent before your inputs, prompts, outputs, or logs train the vendor's models.

  3. Model instability is an uncosted operational risk. Without a 90-day-minimum change notice, legacy-model access, and regression commitments, a silent model update can break production workflows overnight.

  4. Standard SLAs are commercially unacceptable. A 99.5% API SLA permits 43+ hours of annual downtime; production enterprise deployments should target 99.95% with meaningful, spend-linked credits.

  5. No exit right locks you into obsolete technology. AI evolves faster than contract cycles; without termination for convenience, audit rights, and data-export obligations, buyers are trapped in commitments that are stale before they expire.

02 IP ownership clauses (1–4)

Who owns the outputs, prompts, and fine-tuned models is the foundation of a defensible AI agreement. Weak language grants a licence; a proper clause assigns the IP. For deeper context see our AI IP ownership guide.

#ClauseWhy it mattersWhat to demand
1Output ownership assignmentWeak versions only say "you may use outputs," leaving IP with the vendor.Unconditional assignment of all IP (copyright, database and other rights) in outputs to the customer, surviving termination, with no reservation of derivative rights.
2Prompt & system-prompt ownershipPrompt engineering is a real investment; vendors can mine or reuse it.Explicit acknowledgement that your prompts and templates are your IP, with no training, competitive analysis, or third-party disclosure.
3Fine-tuned model ownership & portabilityVendors claim fine-tuned weights are locked into their infrastructure.Fine-tuned adaptor weights treated as your IP, exported in a portable, industry-standard format on request and at termination — or equivalent behaviour portability if export is genuinely impossible.
4No IP indemnification carve-outs for AI outputsMany agreements carve out AI-generated content, leaving you exposed to third-party infringement claims.Meaningful IP indemnification for AI outputs, or at minimum a clear risk allocation that avoids unlimited third-party exposure without vendor contribution.

03 Data rights clauses (5–9)

Data rights decide whether your proprietary information stays yours. See our enterprise AI data rights guide for the full treatment.

#ClauseWhy it mattersWhat to demand
5Training-data prohibitionThe single most commercially important data provision; opt-out mechanisms are insufficient.Explicit, specific, written opt-in consent before inputs, prompts, outputs, logs, or metadata are used to train, fine-tune, evaluate, or improve models.
6Data residency & processing locationsRegulated and EU workloads carry jurisdiction-specific obligations.Precise processing/storage locations with regional restriction; GDPR Article 46 transfer mechanisms for processing outside the EEA; explicit FCA, BaFin, SEC, and HIPAA coverage where relevant.
7Data retention limitsVendors often retain data via separate safety-filtering layers.Explicitly defined, minimised retention with zero-retention options for sensitive deployments, verified to cover all pipeline components including safety filters.
8Data subject rights & GDPR processor termsVendor DPA templates are frequently inadequate for enterprise needs.Executed DPAs and support for access, erasure, and portability requests within statutory timescales — negotiated, not merely signed.
9Competitive intelligence restrictionAbsence signals vendor intent and leaves harmful reuse unconstrained.Commitment that aggregate insights from your usage (workflow types, query categories, industry patterns) will not inform vendor strategy, pricing, or competitor intelligence.

04 Model stability clauses (10–13)

A silent model change can degrade or break production workflows. These clauses convert model volatility into managed, contractual change. For lock-in dynamics see our AI vendor lock-in guide.

#ClauseWhy it mattersWhat to demand
10Model change notificationUndated deprecations break dependent production workflows without warning.Minimum 90 days' advance written notice before deprecation or material behaviour change (180 days for major transitions), with "material change" defined to capture capability regressions.
11Legacy model accessYou need a stable target while assessing a new model version.Access to the previous model version for at least the notification period, or equivalent transition-assistance funding where legacy access is impossible.
12Benchmark regression commitmentsQuality regressions directly affect customer-facing and automated-decision use cases.Agreed test-set benchmarks with contractual commitments that future versions will not regress below defined thresholds without notice and remediation.
13Safety & content-policy change notificationPolicy updates can silently stop applications functioning as designed.Advance notice, on the same terms as model changes, for safety and content-policy changes that materially affect your use case.

05 SLA & service commitments (14–16)

Service-level terms decide whether production stays up and performant under load. Standard AI API SLAs are written for hobbyists, not enterprises.

#ClauseWhy it mattersWhat to demand
14Uptime SLAA 99.5% SLA allows 43+ hours of annual downtime — unacceptable for production.99.95% availability (4.4 hours annual downtime) with credits set as a meaningful percentage of affected monthly charges, not nominal service credits.
15Latency SLA commitmentsReal-time use cases fail on unpredictable response times.P99 latency commitments for real-time applications, or at minimum defined "degraded service" thresholds and remediation for sustained latency exceedances.
16Rate-limit commitmentsUnilateral rate-limit changes disrupt production during peak demand.Committed throughput (requests and tokens per minute) with guaranteed capacity that cannot be reduced without notice and compensation.

06 Commercial & exit clauses (17–20)

Consumption-based AI billing is opaque and multi-year commitments age quickly. These clauses protect price, verifiability, and the right to leave. See our OpenAI Enterprise pricing guide and AI usage pricing analysis.

#ClauseWhy it mattersWhat to demand
17Audit rights over billing & usageToken-based billing is complex and hard to verify independently.Access to detailed, machine-readable usage logs for you or a nominated auditor, covering a rolling 24-month lookback, with vendor cooperation within 30 days of a request.
18Price protection & discount preservationList-price rises can quietly erode a committed discount's value.Committed rates that preserve at least the same percentage discount from any new list price — or a penalty-free right to exit the commitment.
19Termination for convenience with proportional refundAI evolves faster than most contract cycles, risking obsolescence mid-term.Termination for convenience after an initial period (typically 12 months of a multi-year deal) with proportional refund of upfront amounts, minus a reasonable break fee.
20Data export & transition assistance at terminationWithout export and transition help, exit becomes captivity.Complete export of data, outputs, fine-tuned parameters, logs, and configurations in documented formats within 30 days, plus 90–180 days of transition assistance at maintenance-level pricing.

07 The biggest traps

Three provisions cause the most commercial damage when they slip through. Treat their absence as a red flag, not a rounding error.

Trap 01 · Opt-out training

"We won't train on your data unless you opt out." This inverts the burden and depends on you policing a setting the vendor controls. Insist on opt-in: no training on inputs, prompts, outputs, logs, or metadata without specific written consent for each use. This is the single highest-value data clause in the agreement.

Trap 02 · Silent model changes

No committed change notice. Vendors deprecate models and shift safety policies on their own schedule. Without a 90-day-minimum notice, legacy-model access, and regression thresholds, a routine vendor update can break customer-facing workflows with no recourse.

Trap 03 · No exit

Multi-year lock-in without termination for convenience. Combined with weak audit and export rights, this traps you in obsolete technology and unverifiable billing. Pair a termination-for-convenience right with 24-month audit rights and a 30-day export obligation.

08 Prioritisation framework

You will not obtain all 20 clauses from every vendor. Weight your asks by these four factors before you sit down to negotiate. For the strategic backdrop see our Enterprise AI Procurement Guide.

Factor 01

Data sensitivity

The more regulated or proprietary your inputs, the higher you weight training prohibition, residency, retention, and DPA terms (clauses 5–8).

Factor 02

Production dependency

If AI sits in customer-facing or automated-decision paths, prioritise model-stability and SLA clauses (10–16) — a regression or outage is a business incident, not an inconvenience.

Factor 03

IP value creation

Heavy investment in prompts, fine-tuning, or generated assets pushes output, prompt, and model-ownership clauses (1–3) to the top of the list.

Factor 04

Commitment size & horizon

Large multi-year spend raises the stakes on price protection, audit, and exit rights (17–20); model these before signing any volume commitment.

09 Our recommendation

Must-win
Non-negotiable

Opt-in training prohibition (5), output ownership (1), 90-day model-change notice (10), and data export at termination (20). Walk if these cannot be secured — their absence is uninsurable.

High-value
Push hard

Fine-tuned model portability (3), IP indemnification (4), 99.95% uptime (14), audit rights (17), price protection (18), and termination for convenience (19). Trade concessions here deliberately, not by default.

Position-dependent
Weight to context

Residency, retention, DPA, latency, rate limits, benchmarks, and legacy access. Prioritise by data sensitivity and production dependency — essential for some deployments, optional for others.

Have your AI agreement reviewed before you sign

Our AI procurement practice reviews vendor agreements clause by clause and negotiates the terms that matter against every major AI vendor.

Request AI advisory →

The Licensing Edge

Weekly AI procurement intelligence, contract clause updates, and vendor pricing movements for enterprise buyers. 3,000+ subscribers.