Skip to content
Artificial intelligence

Key clauses in contracts with AI model providers

Use of the data sent to the model, confidentiality, liability for failures and exit terms: what to negotiate before building an AI model into the business.

By Cesar Augusto Taborda Lima

Before putting an AI model to work in a product or internal process, a business should have in writing what the vendor may do with the data, who answers for failures and infringements, what happens when the model changes and how to leave with what it built. With large providers, the room to move lies in the plan chosen and the configuration documented; with smaller integrators, the clauses can be negotiated. For high-risk systems in the European Union, the written agreement will become a legal requirement.

The provider of a high-risk AI system and the third party that supplies an AI system, AI model, tools, services, components, or processes that are used or integrated in a high-risk AI system shall, by written agreement, specify the necessary information, capabilities, technical access and other assistance based on the generally acknowledged state of the art, in order to enable the provider of the high-risk AI system to fully comply with the obligations set out in this Regulation. (…)

Regulation (EU) 2024/1689 (AI Act), Article 25(4), first subparagraph, as amended by Regulation (EU) 2026/1744.

The EU AI Act and Brazilian law

The AI Act has been in force since 1 August 2024, with its original prohibitions applying from 2 February 2025 and the rules for general-purpose AI models from 2 August 2025. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk rules, Article 25 included, to 2 December 2027 for Annex III uses such as recruitment and the credit scoring of individuals, and to 2 August 2028 for products regulated under Annex I. It also added suppliers of an “AI model” to the written-agreement duty.

The Act reaches providers and deployers outside the Union where the system’s output is used in the Union (Article 2(1)(c)), and treats as a provider anyone who changes a system’s intended purpose, including a general-purpose one, so that it becomes high-risk (Article 25(1)(c)). A Brazilian company building a CV screening tool on a commercial model for European clients will depend on the model vendor for the documentation it must hold.

In Brazil, the AI bill (PL 2.338/2023) passed the Federal Senate in December 2024 and is awaiting the report of a special committee of the Chamber of Deputies, the lower house. The LGPD (Law 13,709/2018, Brazil’s General Data Protection Law) already applies, however: sending personal data to a model is processing (art. 5, X).

Data, confidentiality and the LGPD

On inputs and outputs, the terms on training, on retention for abuse monitoring and on human review by the vendor need to be read separately. Some providers will, for eligible customers and on approval, keep customer content out of abuse monitoring logs (known as zero data retention); whatever is contracted should be in writing.

Confidentiality should cover prompts, attachments and outputs, and survive termination. Brazil’s Industrial Property Law (Law 9,279/1996) makes the unauthorised use of confidential information obtained through a contract a crime of unfair competition (art. 195, XI); the contract helps prove the confidentiality.

Where personal data is involved, a vendor processing it on the company’s behalf is a processor (operador) bound by the controller’s instructions (LGPD, arts. 5, VII, and 39) and jointly liable if it departs from them (art. 42, para. 1, I). A vendor reserving the right to train on that data is choosing purposes of its own, which sits poorly with that role. Servers abroad mean an international transfer, permitted only on the grounds in art. 33; these include the standard contractual clauses approved by the ANPD, Brazil’s data protection authority, in Resolution CD/ANPD 19/2024, valid only if adopted in full and without alteration. The controller must report incidents that may cause relevant risk or harm to the ANPD and the individuals affected within three business days of learning that personal data was affected (Resolution CD/ANPD 15/2024, arts. 6 and 9). The contract should fix the vendor’s notice period and its duty to supply the information required, as the ANPD recommends.

Outputs, model changes and liability

Brazil’s Copyright Law (Law 9,610/1998) defines the author as the natural person who creates the work (art. 11). As I see it, copyright in an output generated without human creative contribution is hard to sustain, and no contract can create it. The contract can rule out vendor claims over outputs and provide an indemnity, under which the vendor defends and pays for third-party infringement claims over the model or its outputs.

Standard terms may let the vendor change the model unilaterally, and a new version can alter a process that relied on stable answers. Version pinning, advance notice of deprecation and an overlap period for testing are worth negotiating, with the notice in the contract rather than only on a web page.

Service levels should be measurable and security measures described (LGPD, art. 46). Confidentiality, personal data and the intellectual property indemnity call for liability caps of their own. Brazil’s Civil Code requires the parties’ allocation of risk to be respected (art. 421-A, II), but in adhesion contracts it voids any advance waiver by the adhering party of rights arising from the nature of the transaction (art. 424). This assumes Brazilian law governs, so the governing law and forum clause deserves its own reading.

Documentation, audit and exit

The company will have to show regulators and customers how it uses the model. The AI Act requires providers of general-purpose AI models to make documentation available to those who integrate them (Article 53(1)(b)), and deployers of high-risk systems will have to keep the automatically generated logs under their control for at least six months (Article 26(6)). If those logs sit with the vendor, the contract should guarantee access. Where on-site audit is not feasible, independent audit reports should be required.

Exit is planned at entry: return and deletion of data, confirmed in writing (LGPD, art. 16), portability of prompts, fine-tuning data, fine-tuned models and embeddings, and a transition period with the service running. If a fine-tuned model cannot be exported, the data needed to repeat the tuning elsewhere should be kept; and since embeddings from one model are generally incompatible with another’s, so should the source texts.

Standard terms and negotiated contracts

With large providers, whose terms are standard, the room to move lies in choosing an enterprise plan that excludes training on customer data and includes a data processing agreement, switching on the retention settings available, and recording what was contracted, when, and under which version of the terms. With smaller integrators the contract is negotiable, and the integrator should pass through the commitments it receives from the model vendor; it cannot promise more than it obtained.

An AI vendor deserves the scrutiny given to any outsourced provider with access to sensitive business information. The European dates of 2027 and 2028 leave time to negotiate calmly; the LGPD already applies to every prompt containing personal data.