What to Put in an AI Vendor Contract Before You Sign

Oct, 2026
A business owner reviewing an AI vendor contract with a lawyer before signing

Summary

Explains why AI vendor contracts need scrutiny beyond price and login terms, since AI tools produce new output, models change, and data may pass through subprocessors. Lists six clauses to negotiate: a training ban, notice of model changes, indemnification reaching outputs, audit rights, data-handling disclosure, and a data return/deletion process. Includes a composite risk example, guidance on raising the clauses with vendors, and an FAQ.

By: Jordan Gerheim, CEO – Outside Chief Legal LLC

An AI vendor contract decides who controls what you put into the tool, who answers when the tool gets something wrong, and how you get out. It is easy to read the price and the login terms and skip the rest. If the agreement is silent on the points below, the vendor’s standard terms may end up answering them for you.

Quick answer: Before you sign, ask for six things in writing. A ban on training on your data. Notice before the model changes. Indemnification that covers what the tool produces. Audit rights. Disclosure of where your data goes and who else touches it. A clear process to get your data back and confirmed deleted when you leave. Which of these you can get depends on the vendor and the deal.

Why an AI vendor contract is different from ordinary software terms

Ordinary software often does the same thing every time you click. An AI tool may not. It produces new output from what you give it. The model behind it can change. It may also rely on other companies’ models and on servers you never see.

That raises questions that ordinary software terms often leave open. Does the vendor keep what you type in? Can it use your inputs to improve its own product? If the tool produces something that infringes someone else’s rights, who pays? If the vendor swaps the underlying model next month, will anyone tell you?

A recent compliance commentary by attorney Michael Volkov (linked below) lays out clauses aimed at exactly these gaps. The six below follow that framework, written in plain words for a growing business.

These are contract terms. They exist only if you and the vendor agree to them in writing. The governing-law clause in the vendor’s form is worth a look too. If it picks a state other than yours, ask why.

Six clauses to negotiate in an AI vendor contract

1. A ban on training on your data. Ask for a ban unless you agree in writing: the vendor may not use your inputs, the outputs, or any other data you submit to train, retrain, fine-tune, or otherwise improve any model. Ask that it reach the vendor’s own models and any underlying models it builds on. Why it matters: a customer list or a draft contract pasted in for a quick summary is your data. A general privacy statement may not say what happens to it.

2. Notice when the model changes. Ask for advance notice before any material model change that could affect output quality, behavior, or how your data is handled. Why it matters: you may test and approve a tool in the spring and be relying on a different model by summer. Notice gives you time to retest, adjust, or leave.

3. Indemnification that reaches the outputs. Some vendors offer to defend you if the software itself infringes someone’s rights. Ask that the indemnification extend explicitly to model outputs and predictions, not only to the platform. If the model may have been built on improperly sourced material, ask about a separate indemnity for the origin of the training data. Why it matters: the risk you carry may come as much from what the tool writes or decides as from the platform, and your business puts its name on the result. Vendors may push back or cap their exposure. The cap matters as much as the promise.

4. Audit rights. Ask for the right to audit. If the vendor will not agree, ask for the right to request compliance documentation and evidence of its technical controls, such as proof that training is switched off for your account and a list of who has access. Why it matters: a promise you cannot check is hard to rely on.

5. Disclosure of where your data goes and who touches it. Ask the vendor to disclose where your data is stored and processed, and to name its subprocessors and any underlying model providers. Ask that the list stay current for as long as the contract runs. Why it matters: your data can pass through several companies. If a customer contract or your industry expects your data to stay in certain places or with approved parties, you cannot make that promise without knowing the chain.

6. A way to get your data back and confirm it is deleted. Ask for a defined process to retrieve your data when the contract ends, and to confirm deletion from the vendor’s systems, including its subprocessors. Why it matters: closing an account may not delete the data. Without a clause, your data may stay wherever the vendor’s default settings leave it.

A composite example

Here is an illustration, not a real client and not a prediction. A small company near Mobile signs up for an AI tool that summarizes customer calls. The sales page calls the service secure. Months later, someone reads the contract. It has no limit on training, no duty to announce model changes, an indemnity that covers only the software, and no deletion process.

Nothing has gone wrong. But when a customer asks where its call recordings went, the owner has no contract answer to give.

How to raise these clauses with a vendor

Ask early, before the price is settled. Your room to negotiate may shrink once the deal feels done.

Expect a different answer from different vendors. Larger providers may use standard forms and may not change them. Smaller ones may agree to an addendum.

Get it in the contract. A promise in a sales call or an email may not be part of the signed agreement. The signed document, and whatever it incorporates, may be what counts.

Clauses 5 and 6 build on the data-handling and vendor-breach points in our September 22 Cybersecurity Awareness Month piece on data handling and vendor contracts, so read that one for the detail on subprocessors and deletion. For a tool that touches customer or employee information, start with the first four clauses.

The NIST AI Risk Management Framework is a useful voluntary resource if you want a broader way to think about AI risk inside your business.

When to have a lawyer read the AI vendor contract

Bring in a lawyer when the tool will see customer, employee, or confidential business information, or when you plan to put its output in front of customers. A review can help you see which gaps matter for your business and your industry, and which asks are realistic for that vendor.

That is the point of having legal at the table before the decision, not after it. At Outside Chief Legal, we look at the agreement alongside the business decision, so the practical question gets answered too: how do you use the tool and manage the risk?

If you have an AI vendor contract on your desk, book a Risk-Free Strategy Session and we will go through it with you.

FAQ

What should an AI vendor contract say about my data?
At a minimum, it should say whether the vendor can use your data to train or improve models, where the data is stored and processed, who else handles it, and how it is returned and deleted when the contract ends.

Can I negotiate an AI vendor contract with a large provider?
Sometimes, and sometimes not much. Large providers may use standard forms. You can still ask for an addendum, compare tiers that come with different data terms, and decide whether the tool is worth the gaps that remain.

Does a training ban mean the vendor cannot see my data?
No. A training ban addresses whether your data may be used to build or improve models. The vendor may still need to process your data to deliver the service. That is why the storage, subprocessor, and deletion clauses matter alongside it.

General information only. This article is not legal advice.

Our Corporate/Business Counsel Services

Our Litigation Services

Meet Our Team  | Contact Us

Outside Chief Legal LLC is a modern, forward-thinking law firm serving as fractional chief legal officers and outside general counsel for businesses and their owners. With over 200 years of combined litigation, in-house, general counsel, and administrative legal experience, the firm delivers approachable, comprehensive counsel that blends legal expertise with practical business insight to help clients navigate ownership complexities with confidence. OCL is a trusted partner for founders, business owners, and leadership teams nationwide. Learn more about our firm, meet our team, or schedule a Risk-Free Strategy Session to talk with an attorney about how we can help your company.