AI clauses in enterprise contracts
Contracts cannot move a regulatory obligation. What they can do is guarantee the information flow each party needs to meet its own, and allocate the financial consequence when someone fails. Most AI contracts currently do neither.
Five terms that earn their place
- Role allocation. State who is provider and who is deployer for each system, and what happens if Art. 25 triggers. Ambiguity here is expensive later.
- Information supply. Annex IV inputs, declared accuracy metrics and the population measured, the pre-determined change envelope, and Art. 13 instructions for use — as a deliverable, with a format and a refresh obligation.
- Log control and access. Who holds which logs, retention period, and a retrieval mechanism that works inside two days. Arts. 19 and 26(6) each bite for logs “under their control”, which in SaaS commonly leaves the deployer holding none.
- Incident notification timing. Aligned to Art. 73’s 15 / 10 / 2-day clocks rather than a generic SLA. Your clock and theirs are different clocks.
- Modification restrictions. Where a provider clearly specifies the system is not to be changed into a high-risk one, their duty to supply information to a new provider changes. Choose that deliberately in both directions.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What an indemnity does and does not do
It allocates money. It does not move a duty.
A regulatory obligation attaches to the person the Regulation names. An indemnity can shift the financial consequence of failure between commercial parties. It is no answer to a market surveillance authority, and it does not stop the obligation being yours.
Practical consequence. Negotiating hard on the indemnity while leaving the information-supply clause vague is the wrong trade. Without Annex IV inputs and log access you cannot comply at all, and an indemnity for a fine does not restore a withdrawn product.
Terms worth asking for, in order of leverage
| Term | Realistic to obtain? |
|---|---|
| Notification of material change to the AI system or its intended purpose | Usually yes |
| Log access mechanism with a defined turnaround | Usually yes |
| Declared accuracy metrics and the population measured | Usually yes |
| Incident notification aligned to Art. 73 clocks | Negotiable |
| Annex IV inputs on request | Negotiable, easier at Tier 1 spend |
| Sub-processor notification extended to model providers | Negotiable |
| Right to audit the AI system | Rarely, and rarely exercised |
| Training data disclosure for a foundation model | Effectively never |
Expert analysis based on what we see in negotiations, not a survey.
Status labels on this page
Verified fact: Article references and dates cited above, checked against the consolidated Regulation.
Expert analysis: The tables, tiering and assessments on this page are our practice, not a standard.
Unsettled: Procurement practice is not codified and varies by buyer. Verify specific programme requirements against the buyer's own published materials.
Contract at Tier 1, standardise below
Bespoke AI terms on every supplier is unaffordable. Reserve negotiation for suppliers whose AI touches decisions about people, and standardise the rest into your base terms.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
Can a contract transfer EU AI Act obligations?
No. Regulatory obligations attach to the person the Regulation names as provider, deployer, importer or distributor. A contract can allocate the financial consequence of failure between commercial parties through indemnities and liability caps, and should guarantee the information flow each party needs, but it does not transfer a duty owed to a regulator.
What AI clauses should be in a supplier contract?
Role allocation per system with a mechanism for Article 25 shifts; information supply covering Annex IV inputs, declared accuracy metrics, the pre-determined change envelope and Article 13 instructions for use; log control and an access mechanism that works within two days; incident notification timing aligned to the Article 73 clocks rather than a generic SLA; and a deliberate position on whether the buyer may modify the intended purpose.