AI Planning for Contracting
- Paul Peter Nicolai

- Aug 25
- 2 min read
In AI, where complexity and uncertainty are common, clear contractual terms are vital for businesses buying AI systems. These should cover data ownership, security, vendor warranties, indemnity, bias mitigation, and liability. Including these in pro-buyer contracts is essential.
Data Ownership: Understanding who owns the data, both input and output, of an AI system is crucial. These provisions help ensure that the business has the right to use, access, and manage the data just as it needs to.
Data Security: Adding these provisions is crucial for safeguarding a business’s sensitive information—such as personally identifiable details and other personal data—that an AI system processes. This way, we can better prevent unauthorized access, use, disclosure, breaches, or misuse.
Vendor Representations and Warranties: These include the vendor’s assurances regarding the AI system’s functionality, performance, accuracy, and that it does not infringe on third-party rights. They also cover compliance with laws and regulations and adherence to high ethical standards. Having these provisions in place gives a business peace of mind, offering remedies in case the AI system doesn't meet the promised standards or if the business reasonably believes it should.
Vendor Indemnity Obligations: When a vendor agrees to indemnify a business against certain liabilities related to its AI system, it provides important protection. This setup helps shield the business from unexpected costs and expenses, especially since the business often has limited control over the AI; mainly regarding its usage and the data it handles.
Bias Mitigation: Ensuring that a vendor has taken appropriate steps to prevent the AI system from generating biased results is genuinely important. It helps ensure that everyone is treated fairly, regardless of protected characteristics under the law, and significantly reduces the risk of causing unintended harm to anyone.
Vendor Liability: Having a vendor bear appropriate responsibility for their AI system really helps business customers. It ensures they aren’t held accountable if any issues come from the vendor, their affiliates, or subcontractors. So, it’s fair for the vendor’s liability to be as broad as possible, given the situation.
Questions to Ask
In addition to those contract provisions, you should approach its agreement with a vendor of an AI system with the same scrutiny and diligence as you apply to any other technology transaction. Key questions include:
Data Input and Protection: What types of data (confidential, PIN, sensitive, commercially critical information, etc.) will be entered into the AI system, and what additional protections are required?
Transparency and Ethics: How do you ensure that the vendor is as transparent as possible about the sources of training data and the use of data inputs and outputs? Are the AI system’s algorithms safe, effective, and ethically sound? How does the vendor mitigate the risk of producing biased output?
Security Standards: What are the vendor’s cybersecurity protocols and What are the vendor’s cybersecurity protocols and measures, and how do they align with your cybersecurity requirements?
Vendor Reputation: What feedback on the AI system have other clients of the vendor made publicly available, and what is the vendor’s code of ethics for the development and use of AI systems? Is the vendor currently under regulatory investigation or the subject of multiple lawsuits?




Comments