The clauses that decide what you can govern.
When you deploy a model you did not build, the contract or licence sets the limits of your control: what you may test, what you are told when it changes, where your data goes and how you leave. Each row names a clause, the red flag to look for, a fallback position and the evidence to keep. The reasoning is in chapter 15.
Contract clauses
18 clauses for AI services, APIs and embedded AI. Read each row as a check: find the clause, test it against the red flag, negotiate towards the fallback, and file the evidence against the system's registry entry.
Cross-reference: Vendor / Model Due-Diligence Gate · frameworks and obligations.
| Clause | What it governs | Risk | Red flag | Fallback position | Evidence to keep | Maps to |
|---|---|---|---|---|---|---|
| Use of your data for training | Whether the supplier may use your inputs, outputs or logs to train or improve its models. | Confidential or personal data absorbed into a model you do not control; loss of trade secrets. | Training use is on by default, allowed for "service improvement", or controlled by a setting the supplier can change. | An express no-training commitment covering inputs, outputs and logs, surviving termination, with any opt-in in writing. | The clause, the account or API setting captured at go-live, and a periodic re-check of that setting. | |
| Rights in inputs and outputs | Who owns, and who may use, what you send and what the system returns. | You cannot use or protect outputs you depend on; the supplier claims rights in your content. | The supplier takes a licence to your inputs beyond providing the service, or reserves rights in outputs. | You keep your inputs; outputs are assigned or licensed to you; the supplier's licence is limited to running the service. | The clause, referenced from the registry entry of each system that uses the supplier. | |
| Retention and deletion | How long prompts, outputs, files and logs are kept by the supplier, and how deletion is proven. | Data kept longer than your lawful basis allows; logs you need for your own duties are deleted too early. | Retention "as long as necessary" with no number, or abuse-monitoring retention you cannot shorten or see. | Stated retention per data type, deletion on request and at exit, and a deletion confirmation you can file. | Retention terms per data type; deletion confirmations; your own log-retention schedule that meets Art. 26(6). | |
| Sub-processors and upstream model providers | Which third parties (hosting, model providers, labelling services) touch your data. | An unvetted party in the chain; the model behind the service changes supplier without notice. | A sub-processor list that is not published, or changes with no notice and no right to object. | A published list, advance notice of changes, a right to object, and flow-down of the same terms. | Dated snapshots of the sub-processor list; objection decisions. | |
| Data residency and transfers | Where inference, storage and support access happen. | Unlawful transfer of personal data; inference routed outside the permitted region. | A region commitment for storage only, while inference or support may run anywhere. | Region commitments for inference, storage and support access, with a transfer mechanism where needed. | Residency policy verdicts from the inference path; the transfer assessment. | |
| Documentation and instructions for use | The model card, instructions for use, known limitations and evaluation results the supplier provides. | You cannot meet your own deployer duties (use per instructions, oversight, monitoring) without them. | Documentation "available on request" or limited to marketing material. | A named documentation set at signature, updated with each material version, including limitations and failure modes. | Versioned copies attached to the registry entry. | |
| Audit and evaluation access | Your right to assess the supplier and to test the system. | No way to verify claims; evaluation or red-teaming of the service is a breach of terms. | Audit only by reading the supplier's own summary; testing, benchmarking or security research prohibited. | Independent reports on a set cadence, a right to run boundary evals and agreed red-team windows. | Reports received; your boundary eval results; the agreed test windows. | |
| Change notice, version pinning and deprecation | How the supplier changes, replaces or retires the model you depend on. | Behaviour changes in production without a release on your side; forced migration on short notice. | Models may be "updated or improved at any time"; deprecation notice shorter than your re-validation cycle. | Pinnable versions, advance notice of material change, and a deprecation window longer than your re-validation cycle. | Change notices filed against the registry entry; re-validation results per version. | |
| Incident and vulnerability notification | When and how the supplier tells you about security incidents, data breaches and model failures. | You miss your own clocks (GDPR Art. 33, AI Act serious-incident duties) because the supplier told you late. | Notice "without undue delay" with no hours, or limited to personal-data breaches. | A notice window in hours that fits your own clocks, covering security, privacy and serious model failures. | The SLA; notices received and their timestamps; your incident records that cite them. | |
| Availability, latency and rate limits | Uptime, response time, throughput and the remedies when they fail. | The business process stops when the model does; rate limits cap you at peak. | Service credits as the only remedy for an outage that halts a critical process. | SLAs sized to the process, capacity commitments, and termination rights on repeated breach. | SLA reports; your own availability monitoring; continuity tests. | |
| IP indemnity | Who defends and pays if outputs or the model infringe third-party rights. | Infringement claims over generated content or training data land on you. | Indemnity excluded when you modify prompts, use filters differently or combine outputs. | Indemnity for outputs used as documented, with conditions you can meet and evidence you can produce. | Proof that you met the indemnity conditions (filters on, documented use), kept as logs. | |
| Performance warranties and output disclaimers | What the supplier promises about accuracy, safety and fitness. | All output risk sits with you, whatever the marketing said. | Blanket disclaimers of accuracy with no documented performance at all. | Documented performance on stated tasks, and an obligation to disclose known material degradations. | The documented performance, compared with your own evals. | |
| Liability caps and exclusions | The ceiling on what the supplier pays and what it excludes. | A cap far below the harm a failure can cause; exclusions that swallow the AI risk. | A cap set at a few months of fees, with data, IP and regulatory losses all excluded. | Carve-outs from the cap for data protection, confidentiality and IP; a cap sized to the risk tier. | The cap and carve-outs, recorded as residual risk in the risk register. | |
| Supplier acceptable-use policy | Uses the supplier forbids, which bind you and your users. | Your intended use, or a downstream user's, breaches the supplier's terms and the service is cut. | A policy incorporated by reference that the supplier can change unilaterally. | A frozen copy at signature, notice of changes, and confirmation that your intended use is permitted. | The policy version checked at go-live, mapped to your own prohibited-use list. | |
| Role allocation and regulatory cooperation | Who is provider and who is deployer, and what information, access and help flows between them. | Duties fall between the parties; you become provider by rebranding or modifying without knowing it. | Silence on AI Act roles, or a clause that shifts provider duties to you without the access to meet them. | Roles stated per system, and the information, technical access and assistance Art. 25(4) contemplates. | The role decision recorded in the registry entry, with the clause that supports it. | |
| Security controls and certifications | The supplier's security programme, certifications and AI-specific protections. | Your data and your users are exposed through the supplier's weaknesses, including prompt injection in shared components. | Certifications that exclude the AI service from their scope. | Certifications that name the service in scope, plus disclosure of AI-specific tests (red team, injection). | Certificates with their scope statements; red-team summaries. | |
| Termination assistance, portability and exit | How you leave: data return, transition help, format of what you get back. | Lock-in: you cannot move prompts, fine-tunes, embeddings or logs to another supplier. | No transition period; fine-tuned weights or adapters belong to the supplier; export only in proprietary formats. | A transition period, return of your data and tuning artefacts in open formats, and deletion afterwards. | An exit plan and the record of an exit drill. | |
| Insurance | The cover the supplier must carry, and the evidence it must show. | An indemnity the supplier cannot pay; AI losses excluded from the supplier's policies. | No insurance clause, or cover that excludes AI-related claims. | Named cover types and limits, with certificates on request and notice of cancellation. | Certificates of insurance, dated and filed with the contract. |
Licence families for models and datasets
Open weights are not one licence. Each family asks something different of a deployer, and each leaves a record that belongs in the AIBOM entry of the system that uses it.
| Family | Examples | What it asks of you | Watch for | AIBOM fields |
|---|---|---|---|---|
| Permissive | Apache 2.0, MIT, BSD | Keep notices and the licence text; Apache 2.0 adds an express patent grant. | The model licence may be permissive while its training data or a dataset licence is not. | Licence id, notice file, source URL, file hash. |
| Copyleft | GPL family | Distributing a derivative requires releasing it under the same licence. | Applies to code in the serving stack as much as to the model; distribution is the trigger. | Licence id, what is distributed, where the source offer lives. |
| Network copyleft | AGPL 3.0 | Users interacting over a network with a modified version must be offered its source. | Serving a modified component behind an API can trigger the source offer. | Licence id, modification status, source-offer location. |
| Responsible-AI licence (use-restricted) | OpenRAIL family | Open access with listed prohibited uses that must be passed on to every downstream user and derivative. | Use restrictions travel with the model: your terms of use must carry them. | Licence id, restriction list version, where the restrictions are flowed down. |
| Custom community licence | Vendor "community" licences for open-weight models | Acceptable-use policy incorporated by reference; attribution or naming duties; scale thresholds above which a separate licence is needed. | Thresholds and policies differ per model version; naming rules can apply to derivatives you publish. | Licence id and version, AUP version, threshold check result, attribution duty. |
| Non-commercial or research-only | CC BY-NC family; research licences | No commercial use. | A research-only dataset or model inside a commercial product is a breach, whoever added it. | Licence id; a policy verdict that blocks it from production builds. |