How Should In-House Counsel Review AI Vendor Terms?

October 22, 2025·Rikka AI Series·Part 13 of 16

As AI adoption accelerates, reviewing vendor agreements is no longer just about standard commercial terms. It's about understanding how data and models are governed, and how risks are allocated. In this episode, Rikka founder Charlyn Ho shares practical guidance for in-house counsel on what to watch for in AI vendor contracts, including data collection provisions, liability and indemnification for misuse or inaccuracies, and intellectual property protections.

Transcript

Why AI Vendor Terms Are Different

When you review AI company terms, like OpenAI's, Claude's, or Gemini's, you're looking at many of the same issues as any commercial agreement. But AI adds two things worth extra attention: the data involved, and the model itself.

That means looking closely at:

  • The data: its quality, ownership, and traceability
  • The model: how it learns, how autonomous it is, and where bias could creep in

Three Things to Review in Every AI Vendor Contract

  1. Data terms. How is the vendor collecting, storing, and using any data you input? Who owns it?
  2. Liability and indemnification. How are risks allocated if the AI is misused, or if it produces inaccurate results?
  3. Intellectual property. Does your organization keep ownership of both what you put in and what the model produces?

Enterprise Versions Often Offer Better Protections

Depending on your use case, it may be worth paying for the enterprise version of a generative AI tool. Enterprise contracts often include stronger protections: the vendor won't train its model on your data, confidentiality terms are tighter, and you may get indemnification for IP infringement.

This Isn't Entirely New, It Just Requires AI Fluency

Reviewing AI vendor terms doesn't have to be radically different from how you already review vendor contracts and manage third-party risk. Many of the same issues apply.

What's different is AI's ability to learn from and process huge amounts of data. To spot the issues that are unique to AI, alongside the ones common to any vendor, you need a working understanding of how the technology actually functions.

Look Beyond the Contract: Vendor Due Diligence

The contract isn't the whole picture. You also need real due diligence on the vendor, including their AI governance framework.

Confirm the vendor complies with the AI regulations that apply to you: the EU AI Act where relevant, plus any US state and federal laws, even if your company isn't the one building the model.

AI governance isn't just an internal matter. Evaluating a vendor's governance framework tells you about the ethical and compliance dimensions of their AI practices, which matters for managing your own legal risk. Monitoring vendor performance and revisiting contracts over time helps you keep up as the risks evolve.

A holistic approach to third-party AI risk isn't just about checking compliance boxes. It's about building a foundation for responsible AI use that supports real, sustainable growth.

If your team is negotiating AI vendor terms right now, Rikka's AI Governance Assessment can help you spot what's unique to AI in that contract, not just standard vendor risk.