The clauses that decide what you can govern.

When you deploy a model you did not build, the contract or licence sets the limits of your control: what you may test, what you are told when it changes, where your data goes and how you leave. Each row names a clause, the red flag to look for, a fallback position and the evidence to keep. The reasoning is in chapter 15.

Contract clauses

18 clauses for AI services, APIs and embedded AI. Read each row as a check: find the clause, test it against the red flag, negotiate towards the fallback, and file the evidence against the system's registry entry.

Cross-reference: Vendor / Model Due-Diligence Gate · frameworks and obligations.

AI contract clauses: what each governs, the risk, the red flag, the fallback position, the evidence to keep and the instruments it maps to
Clause What it governs Risk Red flag Fallback position Evidence to keep Maps to
Use of your data for training Whether the supplier may use your inputs, outputs or logs to train or improve its models. Confidential or personal data absorbed into a model you do not control; loss of trade secrets. Training use is on by default, allowed for "service improvement", or controlled by a setting the supplier can change. An express no-training commitment covering inputs, outputs and logs, surviving termination, with any opt-in in writing. The clause, the account or API setting captured at go-live, and a periodic re-check of that setting.
Rights in inputs and outputs Who owns, and who may use, what you send and what the system returns. You cannot use or protect outputs you depend on; the supplier claims rights in your content. The supplier takes a licence to your inputs beyond providing the service, or reserves rights in outputs. You keep your inputs; outputs are assigned or licensed to you; the supplier's licence is limited to running the service. The clause, referenced from the registry entry of each system that uses the supplier.
Retention and deletion How long prompts, outputs, files and logs are kept by the supplier, and how deletion is proven. Data kept longer than your lawful basis allows; logs you need for your own duties are deleted too early. Retention "as long as necessary" with no number, or abuse-monitoring retention you cannot shorten or see. Stated retention per data type, deletion on request and at exit, and a deletion confirmation you can file. Retention terms per data type; deletion confirmations; your own log-retention schedule that meets Art. 26(6).
Sub-processors and upstream model providers Which third parties (hosting, model providers, labelling services) touch your data. An unvetted party in the chain; the model behind the service changes supplier without notice. A sub-processor list that is not published, or changes with no notice and no right to object. A published list, advance notice of changes, a right to object, and flow-down of the same terms. Dated snapshots of the sub-processor list; objection decisions.
Data residency and transfers Where inference, storage and support access happen. Unlawful transfer of personal data; inference routed outside the permitted region. A region commitment for storage only, while inference or support may run anywhere. Region commitments for inference, storage and support access, with a transfer mechanism where needed. Residency policy verdicts from the inference path; the transfer assessment.
Documentation and instructions for use The model card, instructions for use, known limitations and evaluation results the supplier provides. You cannot meet your own deployer duties (use per instructions, oversight, monitoring) without them. Documentation "available on request" or limited to marketing material. A named documentation set at signature, updated with each material version, including limitations and failure modes. Versioned copies attached to the registry entry.
Audit and evaluation access Your right to assess the supplier and to test the system. No way to verify claims; evaluation or red-teaming of the service is a breach of terms. Audit only by reading the supplier's own summary; testing, benchmarking or security research prohibited. Independent reports on a set cadence, a right to run boundary evals and agreed red-team windows. Reports received; your boundary eval results; the agreed test windows.
Change notice, version pinning and deprecation How the supplier changes, replaces or retires the model you depend on. Behaviour changes in production without a release on your side; forced migration on short notice. Models may be "updated or improved at any time"; deprecation notice shorter than your re-validation cycle. Pinnable versions, advance notice of material change, and a deprecation window longer than your re-validation cycle. Change notices filed against the registry entry; re-validation results per version.
Incident and vulnerability notification When and how the supplier tells you about security incidents, data breaches and model failures. You miss your own clocks (GDPR Art. 33, AI Act serious-incident duties) because the supplier told you late. Notice "without undue delay" with no hours, or limited to personal-data breaches. A notice window in hours that fits your own clocks, covering security, privacy and serious model failures. The SLA; notices received and their timestamps; your incident records that cite them.
Availability, latency and rate limits Uptime, response time, throughput and the remedies when they fail. The business process stops when the model does; rate limits cap you at peak. Service credits as the only remedy for an outage that halts a critical process. SLAs sized to the process, capacity commitments, and termination rights on repeated breach. SLA reports; your own availability monitoring; continuity tests.
IP indemnity Who defends and pays if outputs or the model infringe third-party rights. Infringement claims over generated content or training data land on you. Indemnity excluded when you modify prompts, use filters differently or combine outputs. Indemnity for outputs used as documented, with conditions you can meet and evidence you can produce. Proof that you met the indemnity conditions (filters on, documented use), kept as logs.
Performance warranties and output disclaimers What the supplier promises about accuracy, safety and fitness. All output risk sits with you, whatever the marketing said. Blanket disclaimers of accuracy with no documented performance at all. Documented performance on stated tasks, and an obligation to disclose known material degradations. The documented performance, compared with your own evals.
Liability caps and exclusions The ceiling on what the supplier pays and what it excludes. A cap far below the harm a failure can cause; exclusions that swallow the AI risk. A cap set at a few months of fees, with data, IP and regulatory losses all excluded. Carve-outs from the cap for data protection, confidentiality and IP; a cap sized to the risk tier. The cap and carve-outs, recorded as residual risk in the risk register.
Supplier acceptable-use policy Uses the supplier forbids, which bind you and your users. Your intended use, or a downstream user's, breaches the supplier's terms and the service is cut. A policy incorporated by reference that the supplier can change unilaterally. A frozen copy at signature, notice of changes, and confirmation that your intended use is permitted. The policy version checked at go-live, mapped to your own prohibited-use list.
Role allocation and regulatory cooperation Who is provider and who is deployer, and what information, access and help flows between them. Duties fall between the parties; you become provider by rebranding or modifying without knowing it. Silence on AI Act roles, or a clause that shifts provider duties to you without the access to meet them. Roles stated per system, and the information, technical access and assistance Art. 25(4) contemplates. The role decision recorded in the registry entry, with the clause that supports it.
Security controls and certifications The supplier's security programme, certifications and AI-specific protections. Your data and your users are exposed through the supplier's weaknesses, including prompt injection in shared components. Certifications that exclude the AI service from their scope. Certifications that name the service in scope, plus disclosure of AI-specific tests (red team, injection). Certificates with their scope statements; red-team summaries.
Termination assistance, portability and exit How you leave: data return, transition help, format of what you get back. Lock-in: you cannot move prompts, fine-tunes, embeddings or logs to another supplier. No transition period; fine-tuned weights or adapters belong to the supplier; export only in proprietary formats. A transition period, return of your data and tuning artefacts in open formats, and deletion afterwards. An exit plan and the record of an exit drill.
Insurance The cover the supplier must carry, and the evidence it must show. An indemnity the supplier cannot pay; AI losses excluded from the supplier's policies. No insurance clause, or cover that excludes AI-related claims. Named cover types and limits, with certificates on request and notice of cancellation. Certificates of insurance, dated and filed with the contract.

Licence families for models and datasets

Open weights are not one licence. Each family asks something different of a deployer, and each leaves a record that belongs in the AIBOM entry of the system that uses it.

Licence families: examples, obligations, what to watch in AI use and the AIBOM fields to capture
Family Examples What it asks of you Watch for AIBOM fields
Permissive Apache 2.0, MIT, BSD Keep notices and the licence text; Apache 2.0 adds an express patent grant. The model licence may be permissive while its training data or a dataset licence is not. Licence id, notice file, source URL, file hash.
Copyleft GPL family Distributing a derivative requires releasing it under the same licence. Applies to code in the serving stack as much as to the model; distribution is the trigger. Licence id, what is distributed, where the source offer lives.
Network copyleft AGPL 3.0 Users interacting over a network with a modified version must be offered its source. Serving a modified component behind an API can trigger the source offer. Licence id, modification status, source-offer location.
Responsible-AI licence (use-restricted) OpenRAIL family Open access with listed prohibited uses that must be passed on to every downstream user and derivative. Use restrictions travel with the model: your terms of use must carry them. Licence id, restriction list version, where the restrictions are flowed down.
Custom community licence Vendor "community" licences for open-weight models Acceptable-use policy incorporated by reference; attribution or naming duties; scale thresholds above which a separate licence is needed. Thresholds and policies differ per model version; naming rules can apply to derivatives you publish. Licence id and version, AUP version, threshold check result, attribution duty.
Non-commercial or research-only CC BY-NC family; research licences No commercial use. A research-only dataset or model inside a commercial product is a breach, whoever added it. Licence id; a policy verdict that blocks it from production builds.