AI vendor contracts often contain hidden traps: auto-renewal clauses, data lock-in provisions, vague SLA terms, and unreasonable IP assignments. Before signing, know what you're agreeing to.
Insist on a DPA that covers: encryption at rest and in transit, no training your data for model improvement, deletion of data upon request, compliance with GDPR/CCPA, and incident notification within 24 hours.
Standard terms: You own input data and output, vendor owns their technology. Watch for: clauses granting vendor ownership of your data, restrictions on how you use the output, or claims on derivative works.
Demand specific SLAs: 99.9% uptime, response time <4 hours for critical issues, remedies for breaches. Avoid vague language like "best efforts" or "as available."
Negotiate: 30-60 day termination notice (not 90+), no auto-renewal without explicit consent, ability to terminate for convenience, transition assistance period.
Ensure vendor provides: full data export in standard formats, reasonable time for transition (30-90 days), no penalty fees for switching.