Contracting with AI Vendors
Updated: 6 days ago
In this guide, I give lawyers a structured framework for negotiating AI vendor agreements, starting with the service’s intended use, the information it handles, and the actions it may take. I cover data use, ownership, outside providers, performance evidence, human review, privacy, privilege, security, indemnities, liability, insurance, product changes, and exit rights. The guide also includes sample clauses and checklists for higher-risk uses, AI agents, and customer-specific artifacts, with current references to the EU AI Act, EU Data Act, Colorado law, and related guidance.
I address data, privacy, and privilege in depth, unpacking what “training on your data” really means, why embeddings and vector databases matter, what AI-specific DPAs must include, and how to protect privilege and confidentiality across sensitive practice areas while contracting with AI vendors. I then tackle liability, performance standards, and SLAs, arguing for output-level indemnification, hallucination-aware liability allocations, and accuracy and bias thresholds instead of “as is” disclaimers, along with exit terms that prevent lock-in and align with the EU Data Act.
The guide closes with practical negotiation tactics and risk-transfer strategies tailored to AI and artificial intelligence deals, including using industry templates and competitive intelligence, navigating new regulatory regimes like the EU AI Act and Colorado AI Act, and tying vendor liability caps to real insurance coverage so that contracting with AI vendors fairly allocates AI-specific risks while keeping human legal judgment at the center.