The questions behind the vendor contract
An AI contract review should connect the words on the page with the way the tool will be used.
Which documents control?
Identify the order form, online terms, data terms, acceptable-use rules and any incorporated policies. Understand how changes are communicated and when they take effect.
What does the provider promise?
Compare security, accuracy and privacy representations with the actual contractual commitments. Identify exclusions and evidence you need before relying on a claim.
Who is responsible when something goes wrong?
Consider incident notice, cooperation, rights in inputs and outputs, indemnities and liability limits in the context of the intended use. The importance of each provision depends on the facts.
What happens at exit?
Check access to records, deletion commitments, transition assistance and termination rights. An exit plan is part of choosing a provider.
ILLUSTRATIVE EXAMPLE
Compare the promise with the commitment.
A hypothetical provider says customer data is not used for training. The proposed agreement, however, incorporates a policy allowing some information to improve its services. The meaning and scope of that permission are not clear.
Compare the sales statement with the applicable contract, policy, product tier and settings. Request a specific explanation or commitment covering the information the business intends to supply.
The business decision: resolve the gap before relying on the promise. If the provider cannot give an acceptable commitment, consider restricting the information supplied or choosing a different deployment. The contract review changes how the tool may be used.
Further reading: NIST AI Risk Management Framework. These questions are a general starting point, not a complete compliance checklist or legal advice for a particular matter.