90 Days Gen AI Risk Trial -Start Now
Book a demo
Free Template · Legal / Procurement

AI Vendor Contract Clauses

Use these clauses as a starting point when negotiating contracts with AI vendors. They cover AI-specific risks that standard vendor contracts often miss - especially around training on your data, retention, audit evidence, and incident notification.

The Clauses

1) Data usage and training restriction

Vendor must not use Customer Data (including prompts, inputs, outputs, logs, or telemetry) to train, fine-tune, or improve any model without explicit written consent. Vendor must provide a clear opt-out by default.

2) Data retention and deletion

Vendor must disclose retention periods for Customer Data and provide deletion within a defined SLA (e.g. 30 days) upon request or contract termination.

3) Subprocessors and data residency

Vendor must maintain an up-to-date subprocessor list, notify Customer of changes in advance, and support data residency requirements where applicable.

4) Security controls

Vendor must maintain SOC 2 Type II (or equivalent), encrypt data in transit and at rest, enforce MFA, and implement least-privilege controls for internal access.

5) Audit rights and evidence

Customer must have the right to audit Vendor controls (or receive independent evidence such as SOC 2 reports) and to request additional attestations for AI-specific controls.

6) Incident notification

Vendor must notify Customer within a defined window (e.g. 24-72 hours) of any security incident involving Customer Data, including AI-specific incidents (prompt injection exploit, model misconfiguration causing data exposure).

7) Model changes and change management

Vendor must provide advance notice of material model changes that impact security, privacy, or performance; include rollback options; and document changes.

8) Liability and indemnity

Contract must address AI-specific risks (data leakage, hallucination-driven actions, misuse) and include appropriate liability limits and indemnities.

Complete AI governance library

Download every AI security and governance template

Every policy, checklist, and playbook a security or GRC team needs to build a defensible AI governance program. One email, one ZIP, ready to adapt.

  • 29 .docx files
  • 1.1 MB total
  • Updated June 2026
  • NIST AI RMF · ISO 42001 · EU AI Act aligned

Work email only. We'll email them to you.

Get started

Need vendor risk governance at scale?

A clause library helps in procurement. Aona AI gives you continuous visibility into AI usage, vendor exposure, and audit-ready evidence.