Back to Blog

The One Clause That Decides Whether You Can Govern Your AI

Before signing an AI vendor contract, six clauses decide whether you can audit, retrain, or exit the system later. Here is what to check first.

Direct answer

What should you check in an AI vendor contract before signing?

Six clauses decide whether you can govern an AI system after you buy it: model-change notification, requiring 30 days' notice before a new version reaches production; training-data use, barring training on your customer data without written opt-in; explainability and audit rights, making quarterly decision logs and bias audits standing entitlements; a liability carve-out left uncapped for erroneous automated decisions; a performance SLA written against an accuracy floor rather than uptime; and portability on exit, returning your data and model weights within 30 days. — Dr. Jonah Tebaa, AI strategist.

Contract pages on a dark desk with a shaft of daylight falling across a single paragraph

I was three minutes from telling a Gulf retail bank's CFO to sign a $340,000 AI vendor contract when I stopped at paragraph 11.

A $340,000 Signature Waiting on One Paragraph

The deal looked clean. A well-known vendor, a credit-scoring and fraud-detection platform, a 12-month contract at $340,000, and a CFO who wanted it signed before quarter-end. I had reviewed the commercial terms twice. The pricing was fair. The implementation timeline was realistic. Then I read the clause governing what happens after the model goes live, and I realized the contract gave the bank almost no way to govern the system it was buying.

This is the part procurement teams skip. Everyone reads the price, the SLA on uptime, the termination-for-convenience window. Almost nobody reads the six clauses that actually determine whether you can audit the model, retrain it, challenge its decisions, or walk away with your data intact. I have now reviewed enough of these contracts to know the pattern is the same everywhere: strong on price, silent on control.

I sent the CFO back six specific redlines. Here is what they were, and why each one matters more than the number on the invoice.

The Three Clauses That Decide If You Can Govern What You Bought

Governance starts before the first wrong decision, not after. If you cannot see inside the system or control what feeds it, you do not govern it. You rent it.

The standards bodies say the same thing in gentler language. UNESCO's Recommendation on the Ethics of Artificial Intelligence holds that "The ethical deployment of AI systems depends on their transparency and explainability". What a procurement contract does is decide, in advance and in writing, whether that dependency can ever be satisfied. A vendor who will not grant model documentation, audit access, or data lineage has not merely negotiated a hard bargain — they have made every ethics commitment on your side of the table unenforceable, and they have done it in a clause your legal team will read in nine seconds.

  • Model Change Notification. The vendor must give 30 days' written notice before any new model version reaches production. Without this, your risk committee approves a system in January and is running an entirely different model by June with no record of the change.
  • Training Data Use / Opt-Out. The vendor cannot use the bank's customer data to train models serving other clients without explicit written opt-in. The original draft allowed this by default. In a retail banking context, that is customer financial behavior training a competitor's fraud model, without anyone in the building knowing it happened.
  • Explainability & Audit Rights. Quarterly decision logs and bias audit results as a standing contractual right, not something available "upon reasonable request." A regulator does not accept "upon reasonable request" as an answer during an examination. Neither should you.

Each of these costs the vendor almost nothing to grant. Each one was absent from the first draft.

The vendor's counsel did not fight hard on any of these three. When I asked why, the account lead was candid: their master services agreement was written years ago for software licensing, back when the product was a static tool, not a system that makes decisions and keeps learning after deployment. Nobody had gone back to rebuild the template around a model that changes itself in production. That is the pattern I see most often. It is not bad faith, it is an outdated document. The sentence that opens this conversation is simple: "Show me where this contract lets us see what the model is doing and stop it if it drifts." Most vendors have an answer ready. They are just never asked first.

The Two Clauses That Decide What Happens When It Fails

Every AI system eventually makes a decision someone has to defend. The question is what the contract lets you do about it.

  • Liability Carve-Out. The standard template capped total damages at 12 months' fees, $340,000. That number sounds reasonable until you price in a single wrongful loan denial pattern triggering a regulatory fine well above that cap. I required an uncapped liability carve-out specifically for discriminatory or erroneous automated decisions and any resulting regulatory fines. The vendor agreed within a week. They had simply never been asked.
  • Performance SLA on Drift. The original SLA measured uptime. It said nothing about accuracy. I replaced it with a drift-based standard: accuracy stays above 92%, service credits trigger once it drops below 95%, and a termination right opens if accuracy falls below 85%, measured quarterly. A model can be online 99.9% of the time and still be wrong on a rising share of decisions. Uptime tells you the lights are on. It tells you nothing about whether the system still works.

Both clauses reframe the relationship. You are not buying software that occasionally needs a restart. You are buying a decision-maker that needs a performance standard and a legal boundary around who pays when it crosses one.

The Clause That Decides What Happens When You Leave

Switching costs are the cheapest thing you will ever negotiate, and only before signature. Once a model has spent eighteen months learning your fraud patterns, your customer segments, your seasonal cycles, the vendor holds every card. Ask for portability then and you are negotiating from zero leverage, mid-crisis, usually right when you need to leave most. Ordinary software lock-in means migrating data and retraining staff. AI lock-in is different: the tuning, the corrections, the accumulated judgment calls live inside model weights you may never see again. Losing that is not an inconvenience. It is losing two years of institutional learning about your own customers, handed to a vendor with no obligation to give it back.

The sixth clause is the one I have seen omitted most often, because vendors have the least incentive to include it.

  • Data & Model Portability on Exit. Within 30 days of termination, the vendor delivers the buyer's data plus the model weights, or an equivalent retrained model, not a CSV export of raw transaction records. Without this clause, terminating the contract means starting from zero. Two years of tuning, edge-case corrections, and institutional learning stay locked inside a system you no longer have access to.

This is the clause that turns an exit right on paper into an exit right in practice. A termination clause that leaves you rebuilding the model from scratch is not really an exit. It is a renegotiation with worse leverage.

The bank's CFO signed the revised contract eleven days later. The price did not change. The six clauses did. That difference is the entire distance between renting a vendor's model and governing your own.

Before your next AI vendor contract goes to signature, find these six clauses. If any one of them is missing, you have not bought an AI system. You have bought a black box with a service fee attached.

Written by Brian, Dr. Jonah Tebaa's AI partner, on his behalf.

For a fast, direct answer on this, see what belongs in an AI vendor contract, answered directly.

Frequently Asked Questions

What should you check in an AI vendor contract before signing?

Six clauses decide whether a buyer can govern an AI system after purchase: model change notification (30 days' written notice before a new model version reaches production), training data use and opt-out, explainability and audit rights as a standing quarterly right, a liability carve-out for discriminatory or erroneous automated decisions, a performance SLA measured on accuracy drift rather than uptime, and data and model portability on exit within 30 days of termination.

Why is an uptime SLA not enough for an AI system?

An uptime SLA only confirms the service is running. An AI model can be available 99.9% of the time and still degrade in accuracy as data drifts. A meaningful AI SLA sets an accuracy floor measured quarterly, with service credits at one threshold and a termination right at a lower one, so the buyer has recourse when the model gets quietly worse rather than simply going offline.

Who wrote Applied AI for Future Ready Organizations?

Applied AI for Future Ready Organizations was written by Dr. Jonah Tebaa, who is its sole author. The book's ISBN is 9798279366965. Dr. Jonah Tebaa is an AI strategist and business transformation consultant, Co-CEO of Webspot, based in Lebanon and working across the MENA region.

Who is Dr. Jonah Tebaa?

Dr. Jonah Tebaa is an AI strategist and business transformation consultant based in Lebanon, working across the MENA region. He is Co-CEO of Webspot, the author of Applied AI for Future Ready Organizations (ISBN 9798279366965), and the originator of the e-mployee concept for autonomous AI workers.