# AI Vendor Contract Clauses

**Organization:** [ORGANIZATION NAME]
**Counterparty:** [VENDOR NAME]
**Prepared by:** [NAME / ROLE]
**Date:** [DATE]
**Version:** 1.0

---

## Purpose

A library of pre-drafted contract language for AI and machine learning vendor agreements. These clauses are drafted to be inserted into a Master Services Agreement, Data Processing Agreement, or AI-specific rider. They cover the areas standard SaaS contracts typically leave ambiguous or silent: training data use, model change control, output IP, evaluation rights, and liability for AI-specific harms.

> **Legal disclaimer.** Contract language is highly context-dependent. Have these clauses reviewed by qualified counsel before use. Nothing in this document is legal advice.

---

## How to Use

1. Map each clause to the relevant section of your base agreement (MSA, DPA, SCCs, OST, or an AI Rider).
2. Strike or negotiate the square-bracketed options to match your risk tolerance.
3. Attach the AI Vendor Security Questionnaire and the AI Vendor Evaluation Scorecard outputs as schedules.
4. Keep a signed and countersigned copy in your vendor management system.

---

## Clause 1 — Definitions

> **"AI System"** means any software, model, API, or service provided by Vendor that uses machine learning, generative AI, foundation models, or other automated decision systems.
>
> **"Customer Data"** means data, prompts, files, logs, instructions, and outputs submitted to or returned by the AI System by or on behalf of Customer.
>
> **"Training"** means any activity that creates, updates, fine-tunes, pre-trains, post-trains, or otherwise modifies the weights or parameters of any model.
>
> **"Sub-processor"** means any third party engaged by Vendor to process Customer Data, including any third-party foundation model provider.

---

## Clause 2 — Training Data Use

> 2.1 Vendor shall **not** use Customer Data for Training of any model, foundation model, or system, whether general-purpose or customer-specific, without Customer's prior express written consent.
>
> 2.2 The prohibition in 2.1 applies to model weights, embeddings, fine-tunes, RLHF datasets, evaluations, and any derivative artifacts. De-identification or anonymization does **not** permit Training use.
>
> 2.3 Vendor represents that its sub-processors are contractually bound by the same prohibition and shall furnish evidence of such binding on Customer's request.
>
> 2.4 Breach of Sections 2.1–2.3 is a material breach and grants Customer immediate termination rights, full refund of prepaid fees, and no limitation of liability under the agreement.

---

## Clause 3 — Data Processing, Residency, and Retention

> 3.1 Vendor shall process Customer Data solely to provide the Services described in the Order Form.
>
> 3.2 Customer Data shall be stored and processed **only** in [APPROVED REGIONS]. Any processing outside the approved regions requires [30] days prior written notice and Customer's consent.
>
> 3.3 Prompt, output, and telemetry logs shall be retained for no more than [30 days] unless Customer configures a longer retention period.
>
> 3.4 On termination, Vendor shall return or irrevocably delete Customer Data within [30 days] and certify deletion in writing. Backup data shall be overwritten per Vendor's documented rotation, not to exceed [90 days].

---

## Clause 4 — Model Ownership and IP

> 4.1 Customer owns all right, title, and interest in Customer Data, prompts, and outputs generated by the AI System from Customer Data.
>
> 4.2 Vendor retains ownership of its pre-existing models, weights, and Vendor-developed software.
>
> 4.3 Vendor assigns to Customer all right, title, and interest in any custom model, fine-tune, or adapter produced from Customer Data, subject to Vendor's underlying foundation model rights.
>
> 4.4 Vendor represents that no output of the AI System knowingly infringes the IP rights of any third party, and Vendor provides indemnity for such claims per Clause 11.

---

## Clause 5 — Model Change Control and Transparency

> 5.1 Vendor shall publish and maintain a list of all models and model versions currently deployed to Customer (including any third-party foundation models).
>
> 5.2 Vendor shall provide [60] days prior written notice of any material change to a model version, prompt scaffolding, or system prompt that affects deterministic output, accuracy, safety filter behavior, or data handling.
>
> 5.3 Customer may pin a specific model version for up to [12 months] following release.
>
> 5.4 Vendor shall document material changes in the system card or release notes and provide re-evaluation results on request.

---

## Clause 6 — Evaluation, Testing, and Red-Team Rights

> 6.1 Customer may conduct its own evaluation, bias testing, red-teaming, and penetration testing of the AI System for its own use, subject to Vendor's published Acceptable Use Policy.
>
> 6.2 Testing rights include adversarial prompting, prompt-injection testing, jailbreak probing, and automated evaluation against public or private benchmark sets.
>
> 6.3 Vendor shall not restrict Customer from sharing evaluation results internally, with its auditors, or with its regulators.
>
> 6.4 Findings are confidential and will be disclosed to Vendor under responsible disclosure.

---

## Clause 7 — Security Requirements

> 7.1 Vendor shall maintain SOC 2 Type II [or ISO 27001] attestation for the duration of the agreement. Attestation reports shall be provided annually at no additional cost.
>
> 7.2 Vendor shall maintain ISO 42001 certification [or equivalent AI management system attestation] once generally available for the provided service tier.
>
> 7.3 Vendor shall encrypt Customer Data in transit (TLS 1.2+) and at rest (AES-256 or stronger).
>
> 7.4 Vendor shall maintain a documented Secure Software Development Lifecycle for all AI components, including threat modeling for prompt injection, data exfiltration, and model abuse.

---

## Clause 8 — Incident Notification

> 8.1 Vendor shall notify Customer within [24] hours of becoming aware of any Security Incident involving Customer Data.
>
> 8.2 Security Incident includes unauthorized access, accidental disclosure via model output, training-data leakage, prompt-log exfiltration, unauthorized sub-processor access, and any confirmed prompt-injection or model-abuse event affecting Customer.
>
> 8.3 Vendor shall provide, at no cost, forensic support, a written root-cause analysis within [30] days, and remediation plan approval rights for Customer.

---

## Clause 9 — Sub-processors

> 9.1 Vendor shall maintain a current list of sub-processors at [URL], including all foundation model providers.
>
> 9.2 Vendor shall provide [30] days prior written notice of new or replacement sub-processors and allow Customer a reasonable right to object.
>
> 9.3 Vendor shall pass through these AI-specific obligations to all sub-processors via written contract.

---

## Clause 10 — Compliance with AI-Specific Law

> 10.1 Vendor represents that the AI System, as delivered, is capable of being used in compliance with the EU AI Act, GDPR Article 22, applicable US state AI laws [list], and sector-specific regulations applicable to Customer.
>
> 10.2 On Customer's reasonable request, Vendor shall provide: conformity assessment documentation, data governance evidence per EU AI Act Article 10, system cards, model cards, and post-market monitoring reports.
>
> 10.3 Vendor shall promptly notify Customer of any regulatory finding, enforcement action, or material limitation issued against the AI System.

---

## Clause 11 — Indemnification

> 11.1 Vendor shall defend, indemnify, and hold harmless Customer from third-party claims that the AI System or its Outputs: (a) infringe IP rights; (b) violate applicable AI law; (c) result from the use of Customer Data in Training in breach of Clause 2; or (d) constitute a misrepresentation of fact caused by a Vendor-introduced hallucination.
>
> 11.2 This indemnity is **not** subject to the limitation of liability in the main agreement.

---

## Clause 12 — Audit Rights

> 12.1 No more than once per [12 months], or at any time following a Security Incident or material compliance finding, Customer or its designated auditor may audit Vendor's compliance with this agreement.
>
> 12.2 Audit includes reviewing controls documentation, sub-processor bindings, training-data handling evidence, and sample prompt-log access records.
>
> 12.3 Audit costs are borne by Customer unless the audit reveals a material breach.

---

## Clause 13 — Service Levels for AI Outputs

> 13.1 Vendor shall maintain [99.9%] availability for the API / Service as defined in the SLA.
>
> 13.2 Vendor shall maintain documented accuracy / refusal / safety metrics for the model as delivered and disclose changes under Clause 5.
>
> 13.3 SLA credits of [10 / 25 / 50]% of monthly fees apply for availability shortfalls per tier.

---

## Clause 14 — Termination for AI-Specific Cause

In addition to general termination rights, Customer may terminate for cause, without penalty and with full refund of unearned prepaid fees, if:

- Vendor breaches Clause 2 (Training Data Use);
- Vendor materially changes the model in breach of Clause 5 and cannot remediate within [30] days;
- Vendor suffers a Security Incident that Customer reasonably determines to be material;
- Vendor loses a required certification (SOC 2, ISO 27001, ISO 42001) for more than [60] consecutive days.

---

## Clause 15 — Post-Termination Obligations

> 15.1 Vendor shall return or delete Customer Data per Clause 3.4.
>
> 15.2 Vendor shall delete any derivative artifacts — fine-tunes, embeddings, caches, evaluation datasets — that contain or are derived from Customer Data.
>
> 15.3 Vendor shall provide a written certification of deletion within [30] days of termination.

---

## Appendix A — Schedule of Approved Sub-processors

| Sub-processor | Role | Region | SOC 2 / ISO / AI Cert | Notes |
|---------------|------|--------|-----------------------|-------|
| | | | | |
| | | | | |

## Appendix B — Approved Model Versions

| Model Name | Provider | Version | Pinned Until | Notes |
|------------|----------|---------|--------------|-------|
| | | | | |

---

*These clauses are provided free by Aona AI. Pair with the AI Vendor Security Questionnaire, the AI Vendor Evaluation Scorecard, and the AI/ML Data Processing Agreement at `/resources/templates`.*
