Skip to main content
AI & Digital · AI Vendor Agreement

AI Vendor Agreement Template

The contract that governs the AI software or services you buy: who owns the inputs and outputs, whether the vendor may train on your data, who pays when an output infringes someone's copyright, and how the EU AI Act and GDPR obligations get allocated. Attorney drafted, with a data processing addendum, indemnity, and service levels built in.

4.9rating
1,761+created this week
Ready in 5-10 min
Free to create and preview. Download as PDF or Word.
Attorney drafted
State-specific law built in
Cites the controlling statutes
PDF + Word formats ready
Portrait of Suna Gol

Written by

Suna Gol
Portrait of Anderson Hill

Fact-checked by

Anderson Hill
Portrait of Jonathan Alfonso

Legally reviewed by

Jonathan Alfonso

Last updated March 30, 2026

Key Takeaways

  • An AI vendor agreement allocates the risks a normal software contract was never written for: model training on your data, hallucinated or infringing output, and shifting regulatory duties under the EU AI Act and GDPR.
  • Get the data clause in writing. Many AI tools reserve the right to use your inputs to improve their models. A clause that says the vendor will not train on your data, and will keep it segregated, is the line most buyers wish they had insisted on.
  • Output ownership does not happen automatically. Vendors often grant you rights to outputs by contract, but purely machine-generated material may not qualify for copyright at all after Thaler v. Perlmutter, so the agreement should address both the license and the gap.
  • IP indemnity is where AI vendors hedge. Many indemnities exclude claims arising from your prompts, your fine-tuning data, or modified output, and cap recovery low. Read the carve-outs, not the headline promise.
  • The EU AI Act assigns duties by role. If you only use a vendor's system you are usually a deployer. Fine-tune it for a high-risk purpose and you can become a provider, with the heavier compliance load. The contract should say who is which.
  • If the vendor processes personal data on your behalf, GDPR Article 28 requires a written data processing agreement with specific terms. The agreement folds that addendum in rather than leaving it to a separate negotiation.

Reviewed for accuracy by the document.com legal team. Educational information, not legal advice.

What Is AI Vendor Agreement Template?

An AI vendor agreement is the contract that governs your purchase or license of an artificial intelligence product or service, whether that is access to a large language model API, an AI-powered SaaS application, a custom model the vendor builds for you, or a managed service that runs AI on your behalf. It sets the commercial terms, but more importantly it allocates the risks that generative AI introduces and that a generic software license does not touch: whether the vendor may use your data to train its models, who owns the prompts you send and the outputs the system returns, who is liable when an output infringes a third party's copyright or produces a discriminatory result, and how the parties divide the compliance duties that the EU AI Act, GDPR, and a growing list of state laws impose.

Think of it as a software or services contract with three extra layers bolted on. A data layer controls what the vendor may do with the information you feed the system. An intellectual property layer licenses inputs and outputs and addresses the uncertain copyright status of machine-generated work. A regulatory layer names which party carries which obligation as AI law continues to change. A well-drafted agreement makes those allocations explicit instead of leaving them to the vendor's standard terms, which are almost always written to protect the vendor.

This is a different instrument from your internal AI rules. A workplace AI use policy governs how your own employees use these tools. An AI vendor agreement governs your relationship with the company selling you the tool. You usually need both: the policy to control conduct inside your walls, and the vendor agreement to hold the supplier to account for the technology it provides.

Why This Matters Now

AI procurement outran AI contracting. Companies signed up for chatbots, copilots, and model APIs at speed during 2023 and 2024, frequently clicking through the vendor's standard online terms without negotiating a word. Those default terms tend to grant the vendor broad rights to use customer data, disclaim warranties on accuracy and non-infringement, and cap liability at a few months of fees. The bill for that haste is now arriving.

Copyright litigation made the output risk concrete. In Thomson Reuters v. ROSS Intelligence, a Delaware federal court in 2025 rejected an AI company's fair-use defense for training on copyrighted material, the first major ruling of its kind. Authors, publishers, artists, and software developers have filed a wave of suits targeting both training data and generated outputs that allegedly reproduce protected work. If your vendor loses one of those cases, the question of who indemnifies you is no longer academic.

Regulators arrived in force. The EU Artificial Intelligence Act (Regulation 2024/1689) became law in 2024, with obligations on general-purpose AI model providers applying from August 2, 2025 and the high-risk system rules applying from August 2, 2026. The U.S. Federal Trade Commission launched Operation AI Comply in September 2024 and has continued enforcement against deceptive AI claims under a new administration. Between the AI Act deadlines and FTC enforcement, those duties land on someone, and the contract decides whether that someone is you or the vendor.

Vendors are quietly shifting risk to buyers. Industry reporting through 2025 and 2026 shows AI agreements increasingly excluding claims arising from customer prompts or fine-tuning data, denying indemnity when outputs are modified, pushing responsibility for high-risk uses onto the customer, and capping liability while disclaiming warranties on accuracy, infringement, and regulatory compliance. The headline 'we indemnify you' often dissolves once you read the carve-outs. A negotiated agreement is how you push back before signing, not after a problem lands.

What an AI Vendor Agreement Actually Covers

At the commercial core, the agreement does what any technology contract does. It identifies the parties, describes the AI product or service, sets the term, the fees, and the renewal mechanics, and names the conditions for termination. None of that is unusual. What sets an AI vendor agreement apart is everything stacked on top of those ordinary terms, because artificial intelligence breaks several assumptions that conventional software licensing took for granted.

Start with the data clause, because it is the one buyers most often get wrong. A traditional SaaS contract rarely worried about the vendor learning from your usage. With AI, your inputs can become training fuel that improves a model your competitors also pay to use. The agreement has to state, in operative language, whether the vendor may train on your data at all, and if the answer is no, it has to back that up with segregation, retention limits, and deletion duties. A vague 'we respect your privacy' line in a marketing page is not a contractual restriction. The buyer who insists on 'Vendor shall not use Customer Data to train, fine-tune, or improve any model' has done more to protect the company than ten pages of boilerplate.

Ownership comes next, and it has two halves that people conflate. The contractual half is straightforward to draft: you want ownership or a broad, perpetual, royalty-free license to the inputs you provide and the outputs the system returns, plus a clear statement that the vendor claims nothing in your outputs. The statutory half is where it gets uncomfortable. After Thaler v. Perlmutter, purely machine-generated output may have no copyright owner at all, which means a competitor could copy it freely. The vendor cannot fix that by contract; it can only license you whatever rights exist. So the agreement should grant you the broadest available license and, separately, your own internal process should ensure a human contributes enough creative judgment that the final work is protectable when protection matters.

Then comes the risk-shifting machinery: indemnification, warranties, and limitation of liability. This is where vendors fight hardest and where buyers concede the most without realizing it. The IP indemnity is the prize. You want the vendor to defend and pay if its model infringes someone's copyright, and you want that promise to survive the carve-outs vendors routinely insert for prompts, fine-tuning data, and modified output. Watch the limitation of liability clause. A vendor that caps all liability, including the IP indemnity, at a few months of fees has effectively neutered the indemnity it just gave you. Carve the IP indemnity and any data-breach liability out from under the general cap, or raise the cap to a number that would actually matter against a real judgment.

Layered over all of it is the regulatory allocation. The EU AI Act decides who is a provider and who is a deployer, and that classification drives real obligations. GDPR Article 28 dictates the data processing terms whenever personal data is involved. State privacy laws add their own service-provider contract requirements. The FTC polices deceptive AI claims under the FTC Act. A serious agreement does not pretend these duties do not exist. It names which party bears each one and requires the vendor to hand over the documentation you need to satisfy your share. The job of the document is to convert a fast-moving, uncertain legal environment into a fixed set of allocations both parties can plan around.

One practical note on scope. The right document depends on what you are actually buying. A click-through API for occasional use may only justify a careful review of the vendor's standard terms and a short addendum on data and indemnity. A mission-critical AI platform that touches customer personal data and feeds consequential decisions warrants a fully negotiated agreement with a data processing addendum, service levels, and an uncapped IP indemnity. Match the contracting effort to the stakes, and never assume the vendor's defaults are neutral. They are drafted by the vendor's lawyers, for the vendor.

When You Need This

You are licensing access to a large language model or AI API and will send it your own data or your customers' data.

You are buying an AI-powered SaaS application, a copilot, or an analytics tool that processes information you consider confidential or regulated.

You are engaging a vendor to build or fine-tune a custom AI model for your business, where ownership of the model, weights, and outputs needs to be settled.

The AI tool will process personal data of EU or UK residents, triggering a GDPR Article 28 data processing agreement, or personal data of state residents under laws like the CCPA.

You will use the AI system for a consequential or high-risk purpose such as hiring, lending, insurance, or healthcare, where EU AI Act provider or deployer duties attach.

You want to replace a vendor's click-through standard terms with a negotiated agreement that restricts training on your data and gives you a real IP indemnity.

You are a managed-service provider or agency reselling AI capabilities to your own clients and need to flow vendor obligations downstream.

How to Fill Out AI Vendor Agreement Template

  1. 1. Identify the parties and the exact deliverable

    Name the buyer and the vendor, and describe precisely what you are getting: API access, a SaaS subscription, a custom-built model, or a managed service. Vague scope language is where disputes start. Attach an order form or statement of work that lists the specific models, features, usage limits, and any fine-tuning the vendor will perform, so 'the AI service' is never left to interpretation.

  2. 2. Lock down the data and training clause

    This step protects you most. State whether the vendor may use your inputs and outputs to train, fine-tune, or improve any model. For most business buyers the answer should be a flat no. Add data segregation, a retention period, deletion on termination, and confidentiality. If you permit any training use, make it narrow, specific, and opt-in, never a buried default.

  3. 3. Assign ownership of inputs and outputs

    Grant the buyer ownership of, or a broad perpetual royalty-free license to, the inputs supplied and outputs generated, and confirm the vendor claims no ownership in buyer outputs. Acknowledge the copyright gap from Thaler v. Perlmutter in your own planning: if you need the output to be protectable, build in a step where a human contributes meaningful creative judgment. For custom model work, settle who owns the model, the weights, and the fine-tuned derivatives explicitly.

  4. 4. Negotiate the IP indemnity and read the carve-outs

    Require the vendor to defend and indemnify you against claims that its training data or output infringes third-party rights. Then scrutinize the exclusions for prompts, fine-tuning data, and modified output, and the cap. Push to carve the IP indemnity out from under the general liability cap, secure a duty to defend, and confirm you can participate in the defense. An indemnity capped at three months of fees will not survive a real copyright judgment.

  5. 5. Set warranties, accuracy disclaimers, and liability limits

    Do not expect an accuracy warranty; you will not get one and the technology cannot reliably support it. Do negotiate warranties that the vendor has the rights to license the model, will perform materially as documented, and complies with applicable law. Then fix the limitation of liability so that data breaches and the IP indemnity sit outside or above the general cap, which is the number that actually decides who pays when something goes wrong.

  6. 6. Attach the data processing addendum and transfer terms

    If the vendor processes personal data on your behalf, incorporate a GDPR Article 28 data processing addendum covering documented instructions, confidentiality, Article 32 security, sub-processor authorization, breach notification, audit, and deletion. For EU or UK personal data crossing borders, add the appropriate transfer mechanism such as the Standard Contractual Clauses. For U.S. state data, include the CCPA service-provider terms. Bar the vendor from training on personal data unless the addendum expressly allows it.

  7. 7. Allocate EU AI Act and regulatory roles

    State which party is the provider and which is the deployer under the EU AI Act for each use of the system, and require the vendor to supply the technical documentation you need to meet your own obligations. If you fine-tune the system for a high-risk purpose, recognize that you may become the provider and price that responsibility in. Add a compliance-cooperation clause so each side helps the other satisfy duties as AI law continues to change.

  8. 8. Add service levels, security, term, and exit

    Set service-level commitments with uptime targets and remedies for failure, a security schedule with concrete controls, and audit or certification rights. Define the term, renewal, and termination triggers, including termination for a vendor security failure or a material change to its data-use terms. Specify what happens to your data on exit: export in a usable format, then certified deletion. Sign with authorized signatories and keep the executed version on file.

Key Terms Defined

Training data
The body of text, images, code, or other material an AI model learns from. The central question in an AI vendor agreement is whether your inputs may be added to it. Once your data trains a model, you can lose control of it permanently, which is why a no-training clause matters.
Provider (EU AI Act)
Under Article 3 of the EU AI Act, an entity that develops an AI system or general-purpose model and places it on the market or puts it into service under its own name. The provider carries the heaviest compliance duties. You can become a provider yourself by fine-tuning a model for a high-risk purpose.
Deployer (EU AI Act)
Under the EU AI Act, a natural or legal person using an AI system under its own authority in a professional context. If you simply use a vendor's system as delivered, you are usually a deployer rather than a provider, with lighter but still real obligations for high-risk systems.
Data processing agreement (DPA)
The written contract GDPR Article 28 requires whenever a vendor processes personal data on your behalf. It must cover documented instructions, confidentiality, security, sub-processors, breach notification, data-subject assistance, audit, and deletion. An AI vendor agreement should fold the DPA in rather than leave it to a separate fight.
IP indemnification
A vendor's promise to defend and pay if its model's training data or output infringes a third party's intellectual property. The value lives in the fine print: watch for exclusions covering your prompts, fine-tuning data, and modified outputs, and for a liability cap that quietly guts the promise.
Hallucination
An AI output that is fluent and confident but factually wrong or fabricated. Vendors disclaim accuracy warranties largely because of it. The agreement cannot eliminate hallucination, so it should assign responsibility for verifying output and keep the vendor's overblown sales claims on the hook under the FTC Act.

Related Documents

Vendor Agreement (general)

A general vendor agreement governs the supply of goods or services and works for most procurement. An AI vendor agreement is the specialized version: it keeps the commercial backbone but adds the data, IP, and regulatory clauses that AI requires. If you are buying anything AI-specific, start from the AI version rather than the generic one.

Workplace AI Use Policy

A workplace AI use policy governs how your own employees use AI tools internally. An AI vendor agreement governs your relationship with the company selling you the tool. They solve different problems and most organizations need both: the policy to control conduct inside the company, and the vendor agreement to hold the supplier accountable for the technology.

Non-Disclosure Agreement

An NDA creates the confidentiality duty between you and the vendor. The AI vendor agreement operationalizes and extends it, restricting how the vendor may use the data you disclose, barring training on it, and adding the GDPR and security terms an NDA alone does not reach. The two work together; the NDA is often signed first, during diligence.

Computer Services Agreement

A computer services agreement covers traditional IT and software services. It is a sensible base layer, but it predates the questions AI raises about training data, output ownership, and model-specific indemnities. Use it as a starting structure and layer the AI-specific terms on top, or move to the AI vendor agreement directly.

End User License Agreement

An EULA is the vendor's standard, non-negotiated license for using its software, written to protect the vendor. An AI vendor agreement is the negotiated alternative for buyers with leverage or sensitive data. If all you have is the vendor's EULA, read it for the data-use, warranty, indemnity, and liability-cap terms before you click accept.

Legal Authorities & Sources

This page is grounded in primary law. The statutes and official resources below are the authorities behind the guidance above. Verify the current text of any statute before relying on it.

Frequently Asked Questions

Ready when you are

Create your AI Vendor Agreement Template in minutes.

Answer a few questions and download a clear, attorney-drafted document that cites the controlling law and is ready to sign.

Create AI Vendor Agreement Template
No account · Free to preview