AP · LAWYERS
0%

Review and negotiation of contracts with AI vendors

An AI vendor's standard terms are written for the vendor: they reserve the right to use your data, cap their liability and say nothing about what happens the day you want to leave. We review and negotiate that contract before it is signed, or renegotiate it at renewal, and hand over replacement wording clause by clause, together with a list of what is worth conceding and what is not.

Why the standard contract does not work as it arrives

An AI vendor's contract usually arrives as a link to terms and conditions nobody read in full, with annexes and policies the vendor can change at will and which the contract incorporates by reference. The problem is not that they are abusive. It is that they resolve every question in favour of whoever drafted them and leave the company with no answer the day its own customer complains. The review consists in giving the company back the decisions that belong to it.

The clauses we negotiate

  • Ownership of inputs and outputs. Who owns what the company loads into the system and who owns what the system produces, including the right to exploit it commercially without hidden restrictions.
  • Use of data for training. Whether the vendor may retrain its models on client information, on what scope, and how that option is switched off in writing rather than only in a settings panel.
  • Personal data. The vendor's role as processor, documented instructions, subprocessors, international transfers and the real location of the infrastructure, under Law 1581 of 2012 and Decree 1377 of 2013.
  • Confidentiality and trade secrets. What company and customer information may enter the system, and what duty of secrecy is assumed by whoever receives it.
  • Service levels. Availability, support, response times and consequences of failure, which in many contracts simply do not exist.
  • Security and incidents. Minimum controls, the duty to notify a breach, who inside the company is notified and what information comes with that notice.
  • Liability and indemnities. Caps, exclusions and cover against third party claims for infringement of intellectual property rights.
  • Audit and evidence. What the company may verify, how often, and which reports or certifications the vendor must deliver without being chased for them.
  • Unilateral changes. Limits on amending the terms, the underlying model and the price during the term.
  • Continuity and exit. Portability of data and configurations, return, certified deletion and what happens if the vendor discontinues the service.

The other end: what you promise your own client

Many companies have already built AI into a service they sell. That is where a costly asymmetry appears: the contract with the end client promises results, timings and confidentiality that the vendor contract does not support. We review both ends together.

  • Whether the company may process in a third party system the information its client handed over, and on what authorisation.
  • Whether the client has to be told that part of the service relies on an automated system, and how that disclosure is documented.
  • What liability the company takes on for a defective output, and how far it can pass it on.
  • Consistency between the terms, exclusions and termination grounds of both contracts.

How we run the review

  1. We understand the use case. What the system will do, on what data and which decision it supports. Without that the review comes out generic and is useless for negotiating.
  2. We read the whole contract. Including annexes and documents incorporated by reference, which are almost never opened and usually hold what matters.
  3. Clause-by-clause matrix. The vendor's position, the client's defensible position and the alternative wording proposed.
  4. Prioritisation. What cannot be conceded, what can be traded for another concession, and what is better accepted and offset with an internal control.
  5. Negotiation. We support in writing or at the table, as the client prefers, and record what the vendor accepted and what it refused.

What the client receives

  • The clause-by-clause review, with the risk of each one explained in business language.
  • The replacement wording proposed, ready to send to the vendor.
  • A list of non-negotiable points and another of tradable ones, so whoever negotiates knows where to give ground.
  • The personal data processing annex where the contract lacks one or brings an incomplete version.
  • Where the vendor refuses changes, a written opinion on the risk that remains live and the internal control that offsets it, so the decision to sign is an informed one.

Let's solve your legal matter

Every case starts with an honest conversation. Book 30 minutes, no commitment.

Send the contract for review