MEMO · TO readers evaluating a workshop or a speaker · RE Governance

Insights Governance

What your AI vendor contract is probably missing

Standard SaaS contract templates miss protections that matter specifically for AI vendor relationships, and the contract itself, not regulation, is currently an organisation's primary protection.

Terence Kok

About the author

Terence Kok

Enterprise AI Strategist, Author, Keynote Speaker

Enterprise AI strategist with twenty-five years leading transformation programmes across Asia and the Middle East, specialising in impact assessment, governance and deployment methodology.

Read the full profile ›

Most organisations sign AI vendor agreements built on the same SaaS templates that governed conventional software procurement, and those templates were never written for how AI systems actually behave: probabilistic output that degrades over time without any code change, training data whose provenance carries legal exposure the client rarely controls, and a live question of whether the vendor is using client data, queries or outputs to improve its own platform without separate consent. Regulation has not caught up to any of this yet. Until it does, the contract itself is the organisation's primary protection, which means the terms have to be negotiated explicitly rather than inherited from a template.

Ten clauses are missing from most agreements currently in force. Data rights and ownership should explicitly prohibit the vendor from using input data, queries or outputs to train its own models without separate, revocable consent. Confidentiality and security should align to ISO/IEC 27001 and specify a breach notification window, seventy-two hours is a reasonable standard, not left to the vendor's discretion. Service-level and performance terms should set an uptime minimum, 99.9 percent for anything in production, with defined remedies when it is missed.

Performance and accuracy warranties should set a minimum quality threshold with an obligation on the vendor to retrain when the system falls below it, not merely a best-efforts clause. Liability allocation should include indemnification for IP infringement, data breaches and regulatory violations, with liability for confidentiality breaches specifically uncapped. Regulatory compliance should have the vendor warrant compliance with every jurisdiction the client operates in, PDPA, the EU AI Act, and any sector-specific regime that applies.

Transparency and audit rights should guarantee access to training data disclosure, model cards and third-party fairness audits on request, not only at the vendor's convenience. IP rights in any custom development should vest in the client, not the vendor, by default. Termination and exit terms should guarantee data export rights, verifiable evidence of data destruction, and a minimum ninety-day transition assistance period. And dispute resolution should specify governing law and confidential proceedings before a dispute ever arises, not be negotiated for the first time in the middle of one.

Reference

This piece is adapted for Praxora Lab from the original. Originally published at terencekok.com ›

More in Governance