AI Contract Addendum Template

Model contract addendum for AI-specific terms with existing vendors.

DRAFT — Adapt for your institution

AI ADDENDUM TO [Product/Service Agreement]

Between: [Institution full legal name] ("Institution")

And: [Vendor full legal name] ("Vendor")

Regarding: [Product/Service Name]

Effective date of this Addendum: [Date]

Reference agreement: [Agreement name and date]

Article 1: Definitions

For the purposes of this Addendum, the following terms shall have the meanings set forth below:

"AI System" — Any machine learning model, algorithm, neural network, or automated decision-making system that relies on machine learning or statistical modeling, provided by Vendor as part of or in connection with the Product/Service, including features embedded in platform updates.

"Training Data" — Data used to train, fine-tune, validate, or evaluate AI Systems, including data from Institution and data from other sources.

"Model Outputs" — Scores, predictions, classifications, recommendations, generated content, or other results produced by AI Systems using Institution Data.

"Institution Data" — All data provided by Institution to Vendor or generated through Institution's use of the Product/Service, including constituent records, giving histories, engagement data, and all associated metadata.

"Personal Information" — Any information that identifies or could reasonably be used to identify a natural person, as defined by applicable law.

"AI Processing" — Any processing of Institution Data by or through an AI System, including inference, training, fine-tuning, evaluation, and quality assurance.

Article 2: Data Use Restrictions

2.1 Vendor shall not use Institution Data for training, fine-tuning, or improving AI Systems without prior written consent from Institution.

2.2 Vendor shall provide a documented mechanism for Institution to opt out of data use for AI model training, including training of general-purpose or multi-client models.

2.3 If Institution consents to data use for model training, Vendor shall apply industry-standard techniques (such as differential privacy, data aggregation, or equivalent safeguards) to minimize the risk that Institution Data is identifiable or reconstructable from trained models, and shall document the techniques applied.

2.4 Vendor shall not share Institution Data or Model Outputs with third parties for AI development purposes without prior written consent.

2.5 Vendor shall document all uses of Institution Data in AI processing, including but not limited to inference, training, evaluation, and quality assurance.

2.6 Model Outputs generated from Institution Data are the property of Institution. Vendor acquires no ownership interest in Model Outputs. Institution may retain, export, and use Model Outputs without restriction during and after the term of the Reference Agreement.

Review against institutional data governance policy. Confirm opt-out mechanism is technically implemented, not just contractually stated.

Article 3: Data Residency

3.1 Vendor shall process and store Institution Data only in [Country/Region].

3.2 Vendor shall notify Institution in writing [Number] days before any change in data processing or storage location.

3.3 AI processing of Institution Data shall not occur in jurisdictions that do not provide adequate data protection as determined by [governing framework].

3.4 Unauthorized transfer of Institution Data to a jurisdiction not meeting the requirements of Section 3.3 shall constitute a material breach. Upon discovery, Vendor shall immediately cease processing in the unauthorized jurisdiction, return or delete affected data, and notify Institution within [Number] hours.

Article 4: Transparency

4.1 Vendor shall provide documentation of AI System methodology, including model type and intended use cases, sufficient for Institution's governance committee to evaluate. Documentation of training data sources and data use is addressed in Section 2.5.

4.2 Where the model architecture supports it, Vendor shall make available, on Institution's request, feature importance data or model explanations for individual predictions generated from Institution Data. For model architectures that do not support individual-level explanations, Vendor shall provide the most granular explanation technically feasible and document why individual explanations are unavailable.

4.3 Vendor shall provide performance metrics specific to Institution's instance, including accuracy, precision, recall, or equivalent business-relevant metrics, on a [frequency] basis.

4.4 Vendor shall publish and maintain model cards or equivalent documentation for each AI System that processes Institution Data.

4.5 Vendor shall notify Institution in writing at least [Number] days before deploying changes to AI Systems that materially affect Model Outputs, including model retraining, architecture changes, or changes to training data composition.

Article 5: Bias Testing and Fairness

5.1 Vendor shall conduct bias testing on AI Systems at least annually and share methodology and results with Institution on request.

5.2 Vendor shall document whether protected class attributes (as defined by applicable federal law and the laws of [Institution's state and states in which Institution's constituents reside]) are used as model inputs, and if so, describe the safeguards in place.

5.3 Vendor shall provide Institution with sufficient data or tools to conduct independent fairness evaluation of Model Outputs against Institution's own constituent base.

5.4 Upon identification of bias in Model Outputs, Vendor shall document corrective actions and provide a timeline for remediation not to exceed [Number] days. Vendor shall implement the corrective actions within that timeline and notify Institution upon completion.

Determine which protected attributes are relevant under your state law exposure.

Article 6: Incident Response

6.1 Vendor shall notify Institution within [24/48/72 hours] of discovering any AI-specific incident, including but not limited to: unauthorized data exposure through model outputs, discriminatory model behavior, material model errors, and security breaches affecting AI infrastructure.

6.2 Notification shall include: description of the incident, data and systems affected, estimated scope, and initial containment measures taken.

6.3 Vendor shall provide a full incident report within [Number] business days of initial notification, including root cause analysis, complete scope assessment, and a remediation plan with implementation timeline.

6.4 Vendor shall cooperate with Institution's investigation of AI-related incidents, including providing access to logs, model documentation, and technical personnel.

Align notification timeline with your institutional incident response policy and any state breach notification requirements.

Article 7: Data Portability

7.1 Vendor shall provide Model Outputs (scores, predictions, segments, classifications) in a portable, machine-readable format on Institution's request.

7.2 Export format shall be documented and include field definitions, scoring methodology summary, and data dictionary.

7.3 Vendor shall provide Model Outputs within [Number] business days of request.

7.4 Export shall not incur additional fees beyond those specified in the Reference Agreement.

Article 8: Termination and Data Handling

8.1 On termination or expiration of the Reference Agreement, Vendor shall delete all Institution Data from systems under Vendor's control, including training datasets, evaluation sets, derived datasets, and cached or retained prompts and outputs, within [Number] days. For model weights trained on multi-client data where selective deletion is technically infeasible, Vendor shall certify that Institution Data cannot be extracted or reconstructed from retained models using commercially available techniques, and shall document the technical basis for that certification. For single-client fine-tuned models, Vendor shall delete or retrain the model within [Number] days.

8.2 Vendor shall provide written certification of data deletion.

8.3 Following the procedures in Section 8.1, Institution Data in raw or derived form shall not persist in systems under Vendor's direct control after termination, except as technically limited for multi-client model weights as described above.

8.4 Vendor shall return all Model Outputs to Institution in the format specified in Article 7 prior to data deletion.

The distinction between raw data deletion and model weight decontamination is intentional. For shared/foundation models, selective removal of one client's contribution from model weights is technically infeasible without full retraining. The certification requirement in 8.1 addresses this limitation.

Article 9: Audit Rights

9.1 Institution may audit Vendor's AI processing of Institution Data at least annually, with [Number] days' written notice.

9.2 Audit scope includes: data handling practices for AI processing, training data management, model performance, bias testing results, security controls for AI infrastructure, and compliance with this Addendum.

9.3 Vendor shall cooperate with audit activities and provide access to relevant documentation, personnel, and systems.

9.4 Audit findings shall be addressed by Vendor with a documented remediation plan within [Number] days. Vendor shall implement the remediation plan within [Number] days of its delivery, or within a timeline mutually agreed for findings requiring structural changes. Failure to implement remediation within the agreed timeline shall constitute a material breach.

9.5 Costs of audit shall be borne by Institution, except that if audit reveals material non-compliance with this Addendum, Vendor shall bear the reasonable costs of the audit.

Article 10: Liability

10.1 Vendor shall be liable for direct damages arising from Vendor's material breach of this Addendum, including but not limited to unauthorized use of Institution Data for AI training, failure to notify of AI-related incidents within the agreed timeline, and data exposure through AI System vulnerabilities.

10.2 Vendor shall maintain [type and amount] insurance coverage for AI-related liabilities.

10.3 Vendor shall indemnify Institution against third-party claims, regulatory investigations, enforcement actions, fines, and penalties arising from Vendor's AI Processing of Institution Data in violation of this Addendum or applicable law.

10.4 Nothing in this Addendum limits Institution's right to seek injunctive relief for Vendor's unauthorized use of Institution Data.

Liability provisions should be reviewed by counsel in the context of your overall contract liability cap.

Article 11: General Provisions

11.1 This Addendum is incorporated into and forms part of the Reference Agreement. In the event of conflict between this Addendum and the Reference Agreement regarding AI processing, this Addendum governs.

11.2 Capitalized terms not defined in this Addendum have the meanings assigned in the Reference Agreement.

11.3 This Addendum may be amended only by written agreement signed by authorized representatives of both parties.

11.4 If any provision of this Addendum is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect, and the invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable.

11.5 Articles 8, 9, and 10, and any provisions that by their nature should survive, shall survive termination or expiration of the Reference Agreement and this Addendum.

11.6 All notices under this Addendum shall be delivered in accordance with the notice provisions of the Reference Agreement. If the Reference Agreement does not contain notice provisions, notices shall be in writing and delivered to the addresses specified in the Reference Agreement.

Signatures

For Institution

Name: [Name]
Title: [Title]
Date: [Date]
Signature:

For Vendor

Name: [Name]
Title: [Title]
Date: [Date]
Signature: