MEMO · TO readers evaluating a workshop or a speaker · RE Governance
What your AI vendor contract is probably missing
Standard SaaS contract templates miss protections that matter specifically for AI vendor relationships, and the contract itself, not regulation, is currently an organisation's primary protection.
Terence Kok, Enterprise AI Strategist, Author, Keynote Speaker
Most organisations sign AI vendor agreements built on the same SaaS templates that governed conventional software procurement, and those templates were never written for how AI systems actually behave: probabilistic output that degrades over time without any code change, training data whose provenance carries legal exposure the client rarely controls, and a live question of whether the vendor is using client data, queries or outputs to improve its own platform without separate consent. Regulation has not caught up to any of this yet. Until it does, the contract itself is the organisation's primary protection, which means the terms have to be negotiated explicitly rather than inherited from a template.
Ten clauses are missing from most agreements currently in force. Data rights and ownership should explicitly prohibit the vendor from using input data, queries or outputs to train its own models without separate, revocable consent. Confidentiality and security should align to ISO/IEC 27001 and specify a breach notification window, seventy-two hours is a reasonable standard, not left to the vendor's discretion. Service-level and performance terms should set an uptime minimum, 99.9 percent for anything in production, with defined remedies when it is missed.
Performance and accuracy warranties should set a minimum quality threshold with an obligation on the vendor to retrain when the system falls below it, not merely a best-efforts clause. Liability allocation should include indemnification for IP infringement, data breaches and regulatory violations, with liability for confidentiality breaches specifically uncapped. Regulatory compliance should have the vendor warrant compliance with every jurisdiction the client operates in, PDPA, the EU AI Act, and any sector-specific regime that applies.
Transparency and audit rights should guarantee access to training data disclosure, model cards and third-party fairness audits on request, not only at the vendor's convenience. IP rights in any custom development should vest in the client, not the vendor, by default. Termination and exit terms should guarantee data export rights, verifiable evidence of data destruction, and a minimum ninety-day transition assistance period. And dispute resolution should specify governing law and confidential proceedings before a dispute ever arises, not be negotiated for the first time in the middle of one.
Exhibit · The missing clauses
Ten terms most AI vendor agreements don't have
Until regulation catches up, the contract itself is the organisation's primary protection.
| # | Clause | What it should require |
|---|---|---|
| 01 | Data rights & ownership | Prohibits the vendor from training on client input, queries or outputs without separate, revocable consent. |
| 02 | Confidentiality & security | Aligned to ISO/IEC 27001, with a 72-hour breach notification window. |
| 03 | Service-level & performance | A 99.9% uptime minimum for anything in production, with defined remedies when missed. |
| 04 | Performance & accuracy warranties | A minimum quality threshold with an obligation to retrain when the system falls below it. |
| 05 | Liability allocation | Indemnification for IP infringement, data breaches and regulatory violations; uncapped for confidentiality breaches. |
| 06 | Regulatory compliance | Vendor warrants compliance in every jurisdiction the client operates in — PDPA, EU AI Act, sector-specific regimes. |
| 07 | Transparency & audit rights | Guaranteed access to training data disclosure, model cards and third-party fairness audits on request. |
| 08 | IP rights in custom development | Vests in the client, not the vendor, by default. |
| 09 | Termination & exit terms | Data export rights, verifiable evidence of destruction, and a minimum 90-day transition assistance period. |
| 10 | Dispute resolution | Governing law and confidential proceedings specified before a dispute ever arises. |
Reference
This piece is adapted for Praxora Lab from the original. Originally published at terencekok.com ›
More in Governance
- Beginning your journey: identifying tasks for quality, traceable, auditable AI agents
The TRACE framework that structures how to evaluate whether a task is right for autonomous agent deployment, and how much oversight it needs.
- Foundations of dependable agentic AI
Why engineering reliability into agentic systems depends on bounded task specifications and trajectory-level observability in production, not on how capable the underlying model is.
- From human-in-the-loop to AI-on-the-loop: redesigning oversight architectures
How oversight structures need to change as AI systems take on more decision-making without a person approving every step, and why that shift is a design choice regulators already permit.