AI Vendor Contract Review Checklist: 32 Things to Verify Before Signing
Signing an AI vendor contract without a thorough review is one of the most expensive mistakes a business can make — and one of the most common. AI agreements differ from standard SaaS contracts in important ways: they often include terms about how your data is used to train models, who owns outputs generated from your prompts, what happens when the model changes behavior, and whether you can leave the platform with your data intact. This checklist covers 32 items across six categories. Work through it before signing any AI vendor agreement, whether you are evaluating a standalone AI tool, a platform with embedded AI, or a custom AI development contract. Flag any item you cannot confirm with the vendor before you sign.
Category 1: Data Ownership and Usage Rights (Items 1–7)
1. **Who owns your input data?** Confirm that all data you provide to the system — prompts, documents, files, customer records — remains your property. The contract should state this explicitly, not rely on an implied understanding.
2. **Is your data used to train the vendor's models?** Many AI vendors include opt-out provisions, but the default is often opt-in. Ask specifically whether prompts, completions, feedback signals, or fine-tuning data you provide will be used to train shared models. Get the answer in writing, not just from a sales rep.
3. **Is your data isolated from other customers?** For sensitive workloads, confirm whether your data lives in a dedicated tenant or a shared data environment. Multi-tenant environments that are properly isolated are often fine; shared training pipelines are a different matter.
4. **What is the data retention and deletion policy?** The contract should specify how long your data is retained after the engagement ends, and confirm you can request deletion. Verify that deletion requests cover backups and fine-tuning checkpoints, not just production databases.
5. **Who owns AI-generated outputs?** Outputs generated from your prompts using your data are generally treated as yours, but some contracts include carve-outs for model improvement or vendor marketing. Confirm there are no output usage rights the vendor is retaining.
6. **Are there data localization restrictions you need?** If your business operates under GDPR, HIPAA, or other data sovereignty requirements, confirm that data processing and storage complies. Ask specifically which regions data transits through and where it is stored at rest.
7. **What data does the vendor collect about your usage patterns?** Usage metadata — query volumes, error rates, user counts — is often retained and can constitute sensitive competitive information. Understand what telemetry the vendor collects and how it is used.
Category 2: Intellectual Property and Output Rights (Items 8–12)
8. **Who owns intellectual property derived from AI outputs?** If your team uses the AI to generate code, product designs, marketing copy, or other potentially protectable work product, the contract should not impose any IP encumbrance on outputs.
9. **Are there output restrictions that would affect your use case?** Some AI vendors restrict use of outputs for training competing models, in certain industries, or in specific commercial contexts. Read the acceptable use policy as carefully as the contract.
10. **Does the vendor indemnify you against IP claims from third parties?** Generative AI output can reproduce copyrighted material. A strong enterprise contract includes IP indemnification provisions protecting you if a third party claims your AI-generated content infringes their IP. Understand the scope, caps, and exclusions.
11. **What are the restrictions on reverse engineering or model extraction?** These are standard vendor protections and generally reasonable, but confirm they do not inadvertently restrict your ability to use outputs in ways that are legitimate for your business.
12. **Is fine-tuned model IP clearly defined?** If you are paying to fine-tune a model on your proprietary data, confirm who owns the fine-tuned weights, whether you can export them, and what happens to them when the contract ends.
Category 3: Service Level Agreements and Reliability (Items 13–18)
13. **What uptime SLA is guaranteed, and what constitutes a violation?** AI API vendors typically guarantee 99.5–99.9% uptime. Understand how downtime is measured, whether scheduled maintenance windows count, and whether partial degradation counts toward SLA calculations.
14. **What are the remedies when SLAs are missed?** SLA credits should be meaningful relative to the impact of downtime on your operations. Credits of 5–10% of monthly fees for extended outages are common; understand the trigger thresholds and claim process.
15. **Are there latency commitments?** For real-time use cases — customer-facing chat, real-time document analysis — latency matters as much as uptime. Confirm whether the vendor provides latency SLAs and how they are measured (P50, P95, P99).
16. **What is the vendor's incident communication process?** Understand how you will be notified of outages, what the SLA is for communication during incidents, and whether a status page is available. 'We post to our status page' is a weaker commitment than 'we will notify your designated contacts within 15 minutes of a Sev-1 incident.'
17. **Are there rate limits or throttling provisions?** Most AI APIs have rate limits. Understand the tier you are purchasing, whether limits can be exceeded at a cost or are hard caps, and what happens to in-flight requests when you hit a limit.
18. **Is there a disaster recovery and backup commitment?** For AI applications managing business-critical workflows, understand the vendor's DR capabilities, RTO/RPO commitments, and whether customer data is included in backup and recovery scope.
Category 4: Pricing, Cost Controls, and Contract Terms (Items 19–23)
19. **Is pricing based on tokens, requests, users, or a flat fee — and is that structure stable?** AI pricing models vary widely. Token-based pricing (per thousand input/output tokens) can be highly variable under production workloads. Request for a usage estimate or simulation based on your expected workload before signing.
20. **Are there minimum commit requirements or true-up provisions?** Enterprise AI contracts often include annual minimum commits with true-up charges if you underconsume. Understand the structure and negotiate minimums that reflect realistic first-year usage, not optimistic projections.
21. **What are the price escalation terms for multi-year agreements?** Some AI vendors include CPI or discretionary escalation clauses. Cap these at a specific percentage; resist 'at vendor's discretion' language.
22. **Are there penalty-free exit provisions if the product changes materially?** If the vendor changes the underlying model, degrades performance, or alters functionality in ways that affect your use case, you should have exit rights without penalty. This is particularly important for AI products where model changes can materially affect output quality.
23. **What is the auto-renewal and cancellation notice requirement?** SaaS contracts with annual auto-renewal and 60–90 day cancellation windows are common. Build a calendar reminder 120 days before renewal if the negotiation window is shorter than you expect to need.
Category 5: Compliance and Regulatory Obligations (Items 24–28)
24. **Does the vendor offer a Data Processing Agreement (DPA) that satisfies your regulatory obligations?** For GDPR, CCPA, HIPAA, SOC 2, and similar frameworks, a DPA is required in most enterprise AI deployments. Confirm the DPA covers your specific regulatory requirements, not just general GDPR language.
25. **Is the vendor SOC 2 Type II certified, and is the report available to you?** SOC 2 Type II certification is the baseline security assurance for enterprise SaaS. Ask for the audit report and review any listed exceptions before signing.
26. **What HIPAA-specific protections apply if you are processing PHI?** If your use case involves protected health information, you need a signed Business Associate Agreement (BAA) before any data enters the system. Some AI vendors will not sign BAAs; understand this before you invest in evaluation.
27. **How does the vendor handle subprocessors?** AI systems often rely on third-party infrastructure (cloud providers, monitoring tools). The contract should list known subprocessors and require notification of changes, particularly for regulated data types.
28. **What are the vendor's AI-specific transparency and explainability commitments?** Emerging regulations in the EU (AI Act) and emerging state-level rules in the US require documentation of AI system behavior for certain use cases. Confirm the vendor can provide required disclosures for your regulatory environment.
Category 6: Model Changes, Support, and Exit Provisions (Items 29–32)
29. **Does the vendor guarantee model stability, or can the model change without notice?** AI model providers routinely update models to improve capability or safety. For business-critical applications, understand whether you are pinned to a specific model version, whether notice is required before changes, and how long deprecated versions remain available.
30. **What is the support SLA and escalation path for production issues?** For enterprise deployments, understand whether a named customer success contact or dedicated support tier is available, what the SLA is for initial response and resolution, and who the escalation path reaches when standard support cannot resolve an issue.
31. **Can you migrate your data and configurations if you leave?** Vendor lock-in risk is real in AI deployments. Confirm you can export your data, fine-tuned models, prompt templates, and integration configurations in a portable format. Understand whether the vendor will provide migration assistance.
32. **What is the contract termination process and timeline?** Understand the notice period, what happens to your data and access during the notice period, what cleanup obligations fall on you, and what the vendor's obligations are after termination. Specifically confirm whether fine-tuned models, stored embeddings, or custom configurations are deleted on a schedule you agree to.
How to Use This Checklist in Practice
This checklist is most valuable as a vendor evaluation tool, not just a contract review tool. Run through it when you are comparing vendors, before you invest significant time in technical evaluation. Items 1–7 (data usage) and 29 (model stability) are the areas where AI contracts most commonly differ from standard SaaS agreements and where surprises are most costly.
**Red flags to watch for in any AI vendor contract:**
- Data usage language that does not explicitly exclude your data from shared model training
- Output ownership clauses that grant the vendor any license to your generated content
- 'Discretionary' pricing escalation with no cap
- No DPA offered, or a DPA that covers only GDPR without your applicable framework
- No model stability commitment, particularly for a production use case where output consistency matters
- Minimum commits set above 150% of your realistic first-year projection
**Engage an attorney who understands AI contracts for high-value deployments.** For enterprise SaaS deals under $50K annually, a thorough review against this checklist typically suffices. For larger engagements, custom development contracts, or deployments involving sensitive data categories, attorney review is the right call. Many technology attorneys now specialize in AI contracts and can redline a standard vendor agreement in 4–8 hours.
Negotiating From a Position of Strength
AI vendors — particularly mid-tier and enterprise vendors — expect negotiation. Vendors who tell you 'take it or leave it' on data usage rights, IP ownership, or model stability are telling you something important about how they will treat you as a customer.
High-leverage negotiation items that vendors most commonly accept when asked:
- Adding an explicit statement that your data will not be used to train shared models
- Limiting the vendor's right to use your outputs for marketing without specific written consent
- Adding a termination-for-cause right if the vendor changes the underlying model materially
- Including a data deletion schedule with a confirmation process
- Removing vague language like 'we may update the terms at our discretion' in favor of notice and consent provisions
Low-leverage items that vendors rarely move on:
- IP indemnification caps are usually fixed at a multiple of fees paid
- Uptime SLA percentages are usually standardized by tier
- Subprocessor lists are often treated as non-negotiable by large vendors
Understanding which items are actually negotiable lets you focus energy where it pays off. Use this checklist to identify your non-negotiables upfront, so the negotiation conversation moves efficiently.
Special Considerations for Custom AI Development Contracts
If you are contracting for custom AI development — not just an API subscription — additional items matter:
**Scope definition:** AI development projects are particularly prone to scope creep because what is 'done' can be ambiguous. Insist on specific performance benchmarks (accuracy thresholds, latency targets, error rate ceilings) as acceptance criteria, not just 'the model will be trained and delivered.'
**Training data ownership:** If the vendor is generating training data on your behalf or using your proprietary data for fine-tuning, confirm the trained model and the training dataset remain your property, are not retained by the vendor, and are delivered to you at project close.
**Ongoing maintenance model:** Custom AI systems require maintenance as their domain data evolves and as underlying model infrastructure changes. Confirm whether the engagement includes post-launch support, on what terms, and what happens if the underlying model the custom system depends on is deprecated.
**Code and model deliverables:** For custom development, specify exactly what deliverables transfer at project completion: model weights, source code, documentation, test suites, infrastructure configuration. 'We'll deliver the trained model' can mean very different things to different vendors.
Frequently Asked Questions
Frequently Asked Questions
Data usage rights — specifically, whether your data will be used to train the vendor's shared models. Many AI vendors default to using customer data for model improvement unless you explicitly opt out. This is the term that most commonly surprises businesses after signing, and it is also typically negotiable. Get written confirmation, not just a verbal assurance, before signing.
For standard SaaS-tier AI tools under $25K annually, a thorough self-review against this checklist is usually sufficient. For enterprise-scale deployments, custom AI development contracts, any deployment involving protected health information or other sensitive data categories, or deals over $50K annually, engage an attorney with AI/SaaS contract experience. The cost of 4–8 hours of attorney time is minor relative to the cost of a poorly negotiated enterprise AI agreement.
Your outputs — the content, code, analysis, or decisions generated by the AI while using the platform — belong to you and are not affected by contract cancellation. What you need to plan for is whether any data, fine-tuned models, stored embeddings, or configurations that live in the vendor's infrastructure can be exported before your access ends. Many vendors have short windows (30–60 days after termination) to retrieve your assets. Build your exit plan before you need it.
You must obtain a signed Business Associate Agreement (BAA) before any protected health information (PHI) enters an AI system. This is non-negotiable under HIPAA. Many consumer-grade and mid-market AI tools will not sign a BAA — if the vendor declines, you cannot use their system for PHI workloads, period. HIPAA-eligible AI vendors (AWS, Azure, Google Cloud, and a growing set of specialized health AI vendors) have established BAA processes. Budget additional time for BAA negotiation and never assume a tool is HIPAA-compliant because it is 'secure.'