Use this AI vendor contract checklist to organize review of the agreement, data-processing terms, service description, and referenced policies together. Define the product edition and intended use first. These are discussion points and examples for qualified counsel to adapt; they are not a ready-made contract or legal advice.
Map the agreement and service boundary
Check that the main agreement, order form, data-processing terms, security exhibit, and online terms describe one consistent service. Identify which document governs if terms conflict and which product, model features, regions, and subprocessors are included. For each obligation, note the operational owner and evidence or process that would show it is being met. Keep unresolved terms open for counsel rather than treating a vendor policy as an agreed commitment.
Review service scope, permitted use, customer configuration duties, support, availability, and change management. Document data roles, purposes and instructions, confidentiality, disclosures, retention, return, and deletion. Review security commitments, evidence access, incident coordination, subprocessor controls, and continuity obligations. Address intellectual property, input and output treatment, third-party materials, indemnity, limitation of liability, and claims process. Check term, renewal, suspension, termination, export, transition support, and post-termination handling.
Data processing, training, and deletion
Define covered data by type: prompts, files, outputs, feedback, telemetry, account records, and support content. Ask whether the vendor or downstream provider may retain, analyze, or use each type to train or improve models. Specify which settings can change, whose action changes them, whether the contract overrides a default, and what notice applies if model-provider terms change.
For return and deletion, ask about production copies, logs, backups, abuse-monitoring records, support systems, legal holds, and the event that ends retention. Define export format and transition assistance. Do not assume a dashboard setting changes every copy or overrides the contract. Where GDPR Article 28 applies to a controller-processor relationship, the processor contract must cover specified processing particulars and obligations. Ask counsel to determine whether the actual roles and facts bring the arrangement within those provisions; see the official GDPR text.
An AI data processing agreement should identify the processing that is actually contemplated, not rely on a generic label. A discussion draft for an AI DPA template can organize questions about subject matter, duration, data types, purposes, instructions, security, subprocessors, assistance, deletion, and audit evidence. Counsel must adapt it to the parties, service, and applicable law.
Intellectual property, indemnity, and service levels
Define separately customer inputs and supplied materials, vendor software and documentation, generated outputs, third-party models or content, and feedback or fine-tuning contributions. Review each license’s purpose, duration, transfer rights, restrictions, and survival after termination. Do not assume that either party owns every AI-generated output or has cleared every training source.
For AI vendor IP indemnity, ask counsel to examine covered claims, exclusions, notice, defense control, cooperation, settlement approval, remedies, and how the indemnity interacts with liability caps. Scope depends on product, jurisdiction, facts, and negotiated language. The U.S. Copyright Office’s Part 2 report addresses copyrightability of AI-generated outputs. Its Part 3 training report is explicitly a pre-publication version. These reports are background, not a legal conclusion about a particular vendor, output, or claim.
An AI vendor SLA template should define the measured service and boundary: availability window, measurement source, treatment of planned maintenance, support channel, severity definitions, initial-response target, update cadence, restoration objective, incident notice, and any credit or termination remedy. State exclusions and dependencies, including customer networks and named upstream providers. A percentage without a measurement window, exclusions, and remedy is incomplete. Have counsel and the service owner adapt it to the product and agreement.
Security, incident notification, and audit
Tie security commitments to the actual service schedule or exhibit rather than a broad marketing statement. Review access controls, tenant boundaries, encryption, logging, vulnerability handling, backup and recovery, support access, and customer responsibilities. For assurance, define how current evidence will be provided with its boundary, period, exceptions, remediation status, and complementary customer controls. A SOC report has a defined scope; request the report and system description. NIST’s supply-chain guidance and the FTC’s vendor security guidance are references for tailoring supplier review, not standards automatically incorporated into an agreement.
An AI vendor incident notification clause should define the event that triggers notice, recipient and contact path, initial notice timing, facts available at that point, update cadence, cooperation, evidence preservation, and authority for external communications. Clarify how suspected events are reported while facts develop and how later findings and remediation status are shared. If GDPR Article 33(2) applies to a processor, it requires notification to the controller without undue delay after awareness of a personal data breach. That statutory wording does not settle every contractual trigger or workflow. Counsel should reconcile contract terms with applicable law and the parties’ roles.
For audit rights, match verification to service, data sensitivity, and applicable duties. A practical evidence sequence may start with a current independent report and scope statement, then written answers and remediation updates, with targeted additional review if a material gap remains. State who pays, notice, frequency, confidentiality protections, and how findings are addressed. Where GDPR Article 28 applies, confirm with counsel how required information and audit cooperation can be provided in practice; do not assume a report alone satisfies every right.
Worked example: meeting-summary service
Hypothetical only: A company considers a meeting-summary service for internal product discussions. It would process participant names, audio, transcripts, and summaries. The vendor’s FAQ says prompts are retained for 30 days, while the draft data schedule names the service but leaves the model subprocessor and training-use answer blank. The reviewer records both as unknown, requests a service-specific schedule and subprocessor list, and asks the privacy lead to confirm data roles. The business allows evaluation only with synthetic meeting content until contract terms and security evidence are reviewed. No production recording is approved in this example. It is not a real legal review or vendor test.
For upstream selection prompts, see the AI RFP and Procurement Checklist, the AI Vendor Security Review Checklist, and the EU AI Act Vendor Due Diligence guide.
Frequently asked questions
What should an AI vendor agreement template cover?
Use it to identify service scope, data use, security, subprocessors, incident handling, outputs and third-party materials, service levels, liability, evidence, and exit terms. Have counsel draft or adapt binding language.
Is an AI DPA template ready to sign?
No. It can help organize processing particulars and open questions. Counsel should verify the parties’ roles, actual data flows, service terms, and applicable legal requirements.
What belongs in an AI SaaS contract review?
Compare the order form, main terms, data-processing terms, security exhibit, and referenced policies. Confirm they cover the same product configuration and identify which document controls if they conflict.
Does an AI vendor SLA template guarantee service availability?
No. The negotiated contract creates any commitment. Define the measurement, period, exclusions, dependencies, support response, and remedy, then confirm the terms with counsel and the service owner.
Updated 2026-10-08. Sources are linked on this page.