AI contract clauses: 20 terms every enterprise buyer must demand.
Standard AI vendor agreements are drafted by vendor legal teams to minimise the vendor's obligations and maximise its rights. This note isolates the 20 clauses that separate a commercially defensible AI agreement from a vendor template — grouped across IP, data, model stability, service levels, and exit — with the rationale and what to demand for each.
The AI agreement your vendor sends is engineered to protect the vendor. Across 200+ enterprise AI agreements the same gaps recur: weak IP assignment, training-data reuse, no model-change notice, and no exit rights. You will not win all 20 clauses — but entering negotiation knowing what to request, and what each omission costs, is the difference between a defensible contract and a vendor template.
01 Key findings
The default AI agreement is a vendor instrument. It is drafted to minimise vendor obligations and maximise vendor rights; most buyers sign because they lack the commercial framework to see what they are conceding.
Training-data reuse is the single most important data provision. An opt-out is insufficient — enterprise agreements require explicit, written opt-in consent before your inputs, prompts, outputs, or logs train the vendor's models.
Model instability is an uncosted operational risk. Without a 90-day-minimum change notice, legacy-model access, and regression commitments, a silent model update can break production workflows overnight.
Standard SLAs are commercially unacceptable. A 99.5% API SLA permits 43+ hours of annual downtime; production enterprise deployments should target 99.95% with meaningful, spend-linked credits.
No exit right locks you into obsolete technology. AI evolves faster than contract cycles; without termination for convenience, audit rights, and data-export obligations, buyers are trapped in commitments that are stale before they expire.
02 IP ownership clauses (1–4)
Who owns the outputs, prompts, and fine-tuned models is the foundation of a defensible AI agreement. Weak language grants a licence; a proper clause assigns the IP. For deeper context see our AI IP ownership guide.
| # | Clause | Why it matters | What to demand |
|---|---|---|---|
| 1 | Output ownership assignment | Weak versions only say "you may use outputs," leaving IP with the vendor. | Unconditional assignment of all IP (copyright, database and other rights) in outputs to the customer, surviving termination, with no reservation of derivative rights. |
| 2 | Prompt & system-prompt ownership | Prompt engineering is a real investment; vendors can mine or reuse it. | Explicit acknowledgement that your prompts and templates are your IP, with no training, competitive analysis, or third-party disclosure. |
| 3 | Fine-tuned model ownership & portability | Vendors claim fine-tuned weights are locked into their infrastructure. | Fine-tuned adaptor weights treated as your IP, exported in a portable, industry-standard format on request and at termination — or equivalent behaviour portability if export is genuinely impossible. |
| 4 | No IP indemnification carve-outs for AI outputs | Many agreements carve out AI-generated content, leaving you exposed to third-party infringement claims. | Meaningful IP indemnification for AI outputs, or at minimum a clear risk allocation that avoids unlimited third-party exposure without vendor contribution. |
03 Data rights clauses (5–9)
Data rights decide whether your proprietary information stays yours. See our enterprise AI data rights guide for the full treatment.
| # | Clause | Why it matters | What to demand |
|---|---|---|---|
| 5 | Training-data prohibition | The single most commercially important data provision; opt-out mechanisms are insufficient. | Explicit, specific, written opt-in consent before inputs, prompts, outputs, logs, or metadata are used to train, fine-tune, evaluate, or improve models. |
| 6 | Data residency & processing locations | Regulated and EU workloads carry jurisdiction-specific obligations. | Precise processing/storage locations with regional restriction; GDPR Article 46 transfer mechanisms for processing outside the EEA; explicit FCA, BaFin, SEC, and HIPAA coverage where relevant. |
| 7 | Data retention limits | Vendors often retain data via separate safety-filtering layers. | Explicitly defined, minimised retention with zero-retention options for sensitive deployments, verified to cover all pipeline components including safety filters. |
| 8 | Data subject rights & GDPR processor terms | Vendor DPA templates are frequently inadequate for enterprise needs. | Executed DPAs and support for access, erasure, and portability requests within statutory timescales — negotiated, not merely signed. |
| 9 | Competitive intelligence restriction | Absence signals vendor intent and leaves harmful reuse unconstrained. | Commitment that aggregate insights from your usage (workflow types, query categories, industry patterns) will not inform vendor strategy, pricing, or competitor intelligence. |
04 Model stability clauses (10–13)
A silent model change can degrade or break production workflows. These clauses convert model volatility into managed, contractual change. For lock-in dynamics see our AI vendor lock-in guide.
| # | Clause | Why it matters | What to demand |
|---|---|---|---|
| 10 | Model change notification | Undated deprecations break dependent production workflows without warning. | Minimum 90 days' advance written notice before deprecation or material behaviour change (180 days for major transitions), with "material change" defined to capture capability regressions. |
| 11 | Legacy model access | You need a stable target while assessing a new model version. | Access to the previous model version for at least the notification period, or equivalent transition-assistance funding where legacy access is impossible. |
| 12 | Benchmark regression commitments | Quality regressions directly affect customer-facing and automated-decision use cases. | Agreed test-set benchmarks with contractual commitments that future versions will not regress below defined thresholds without notice and remediation. |
| 13 | Safety & content-policy change notification | Policy updates can silently stop applications functioning as designed. | Advance notice, on the same terms as model changes, for safety and content-policy changes that materially affect your use case. |
05 SLA & service commitments (14–16)
Service-level terms decide whether production stays up and performant under load. Standard AI API SLAs are written for hobbyists, not enterprises.
| # | Clause | Why it matters | What to demand |
|---|---|---|---|
| 14 | Uptime SLA | A 99.5% SLA allows 43+ hours of annual downtime — unacceptable for production. | 99.95% availability (4.4 hours annual downtime) with credits set as a meaningful percentage of affected monthly charges, not nominal service credits. |
| 15 | Latency SLA commitments | Real-time use cases fail on unpredictable response times. | P99 latency commitments for real-time applications, or at minimum defined "degraded service" thresholds and remediation for sustained latency exceedances. |
| 16 | Rate-limit commitments | Unilateral rate-limit changes disrupt production during peak demand. | Committed throughput (requests and tokens per minute) with guaranteed capacity that cannot be reduced without notice and compensation. |
06 Commercial & exit clauses (17–20)
Consumption-based AI billing is opaque and multi-year commitments age quickly. These clauses protect price, verifiability, and the right to leave. See our OpenAI Enterprise pricing guide and AI usage pricing analysis.
| # | Clause | Why it matters | What to demand |
|---|---|---|---|
| 17 | Audit rights over billing & usage | Token-based billing is complex and hard to verify independently. | Access to detailed, machine-readable usage logs for you or a nominated auditor, covering a rolling 24-month lookback, with vendor cooperation within 30 days of a request. |
| 18 | Price protection & discount preservation | List-price rises can quietly erode a committed discount's value. | Committed rates that preserve at least the same percentage discount from any new list price — or a penalty-free right to exit the commitment. |
| 19 | Termination for convenience with proportional refund | AI evolves faster than most contract cycles, risking obsolescence mid-term. | Termination for convenience after an initial period (typically 12 months of a multi-year deal) with proportional refund of upfront amounts, minus a reasonable break fee. |
| 20 | Data export & transition assistance at termination | Without export and transition help, exit becomes captivity. | Complete export of data, outputs, fine-tuned parameters, logs, and configurations in documented formats within 30 days, plus 90–180 days of transition assistance at maintenance-level pricing. |
07 The biggest traps
Three provisions cause the most commercial damage when they slip through. Treat their absence as a red flag, not a rounding error.
"We won't train on your data unless you opt out." This inverts the burden and depends on you policing a setting the vendor controls. Insist on opt-in: no training on inputs, prompts, outputs, logs, or metadata without specific written consent for each use. This is the single highest-value data clause in the agreement.
No committed change notice. Vendors deprecate models and shift safety policies on their own schedule. Without a 90-day-minimum notice, legacy-model access, and regression thresholds, a routine vendor update can break customer-facing workflows with no recourse.
Multi-year lock-in without termination for convenience. Combined with weak audit and export rights, this traps you in obsolete technology and unverifiable billing. Pair a termination-for-convenience right with 24-month audit rights and a 30-day export obligation.
08 Prioritisation framework
You will not obtain all 20 clauses from every vendor. Weight your asks by these four factors before you sit down to negotiate. For the strategic backdrop see our Enterprise AI Procurement Guide.
Data sensitivity
The more regulated or proprietary your inputs, the higher you weight training prohibition, residency, retention, and DPA terms (clauses 5–8).
Production dependency
If AI sits in customer-facing or automated-decision paths, prioritise model-stability and SLA clauses (10–16) — a regression or outage is a business incident, not an inconvenience.
IP value creation
Heavy investment in prompts, fine-tuning, or generated assets pushes output, prompt, and model-ownership clauses (1–3) to the top of the list.
Commitment size & horizon
Large multi-year spend raises the stakes on price protection, audit, and exit rights (17–20); model these before signing any volume commitment.
09 Our recommendation
Opt-in training prohibition (5), output ownership (1), 90-day model-change notice (10), and data export at termination (20). Walk if these cannot be secured — their absence is uninsurable.
Fine-tuned model portability (3), IP indemnification (4), 99.95% uptime (14), audit rights (17), price protection (18), and termination for convenience (19). Trade concessions here deliberately, not by default.
Residency, retention, DPA, latency, rate limits, benchmarks, and legacy access. Prioritise by data sensitivity and production dependency — essential for some deployments, optional for others.
Have your AI agreement reviewed before you sign
Our AI procurement practice reviews vendor agreements clause by clause and negotiates the terms that matter against every major AI vendor.
The Licensing Edge
Weekly AI procurement intelligence, contract clause updates, and vendor pricing movements for enterprise buyers. 3,000+ subscribers.