Most AI vendor contracts are still written for software that does not make decisions. That mismatch is the subject of a recent piece of thinking from Dr. Jonah Tebaa, an AI governance advisor who works with banks, retailers, and insurers across the Gulf and international mid-market. His argument is narrow and practical: a handful of clauses, usually buried past the pricing and the service-level basics, determine whether a buyer actually controls the AI system it is purchasing or merely rents access to a black box with an invoice attached.
The Case He Uses to Make the Point
Tebaa's illustration is a $340,000 annual contract between a Gulf retail bank and a vendor supplying a credit-scoring and fraud-detection platform. On paper, the deal was sound. Fair pricing, a workable implementation schedule, standard uptime commitments. His point is that none of those terms address what happens once the model is live and making decisions about real customers. That gap, he argues, is where most procurement reviews stop looking, and where most of the actual risk sits.
Six Clauses, Not One Contract Review
Rather than treating AI procurement as a single negotiation, Tebaa breaks it into six specific, checkable clauses. He is explicit that none of them require the buyer to understand the underlying technology. They require reading the contract with different questions in mind.
- Model change notification — 30 days' written notice before a new model version enters production, so oversight bodies are approving what is actually running, not a system that has since been swapped out underneath them.
- Training-data opt-out — an explicit written opt-in requirement before a vendor can use the buyer's customer data to train models serving other clients.
- Standing audit rights — quarterly decision logs and bias audit results as a contractual default, not something available only "upon reasonable request."
- An uncapped liability carve-out for discriminatory or erroneous automated decisions and any regulatory fines that follow, separate from the standard damages cap.
- A drift-based performance SLA — an accuracy floor of 92%, service credits triggered below 95%, and termination rights opening below 85%, measured quarterly rather than judged on uptime alone.
- Portability on exit — the buyer's data and the model weights, or an equivalent retrained model, delivered within 30 days of termination, rather than a raw data export that leaves the buyer starting over.
Why the Reframing Matters
The significance of Tebaa's framework, in his own account, is less about any single clause and more about what the list collectively does to the procurement conversation. Legal and risk teams are well practiced at reviewing indemnities, termination-for-convenience windows, and data-protection boilerplate. Almost none of that language was designed with a self-updating decision engine in mind. An uptime SLA, for instance, tells a buyer the system is running. It says nothing about whether it is still making correct decisions, which is the actual business risk in a credit-scoring or fraud-detection context.
Tebaa's broader claim is that this is a template problem, not a bad-actor problem. Vendor contracts for AI platforms are frequently adaptations of master service agreements originally built for static software licensing. The clauses he flags are rarely absent out of an intent to disadvantage the buyer; they are absent because nobody rewrote the document for a product category that learns, drifts, and changes after deployment. That distinction matters for how procurement and risk teams should approach the negotiation. It is not adversarial by default. In his experience, vendors will often agree to these terms once asked directly, because the request is unfamiliar rather than unreasonable.
The exit clause draws particular attention in his framing, because it is the one buyers are least likely to negotiate before signature and least able to negotiate after. Once a model has spent months tuned to an organization's specific data, the buyer's leverage to demand its weights back collapses. Tebaa's position is that portability terms belong at the start of the relationship, priced in like any other deliverable, not treated as an afterthought to be resolved during a difficult termination.
Taken together, his six clauses function less as a checklist and more as a test: whether a contract lets an organization see inside the system, correct it, hold someone accountable when it fails, and leave with what it built. For buyers moving quickly to adopt AI systems that touch lending, pricing, or claims decisions, that test is arguably the more consequential part of the contract than the price on the cover page.