The growth of artificial intelligence systems makes it necessary to regulate their use contractually. Since the adoption of the European AI Regulation (AI Act) on 13 June 2024, precise obligations apply to providers and deployers, particularly for high-risk systems. Without suitable clauses, a business faces non-compliance, intellectual property disputes, data leaks and, ultimately, significant administrative penalties under the AI Act, available on EUR-Lex, and under the GDPR, according to the CNIL.
1) Map the use and classify the AI system
Before drafting, classify the project and each party’s role (provider, integrator, deployer and processor). This step determines the obligations arising from the AI Act and GDPR.
AI Act classification and key obligations
- High-risk AI: a system subject to risk-management, data-governance, technical-documentation, logging, human-oversight, robustness and accuracy requirements, conformity assessment and CE marking, post-market monitoring and incident reporting (see AI Act).
- General-purpose AI (GPAI) and models with systemic risk: documentation, transparency and value-chain management obligations.
- Prohibited practices and specific transparency requirements (e.g. labelling synthetic content/deepfakes).
For personal data processing, GDPR compliance remains mandatory (legal basis, minimisation, information, DPIA and processor governance), as reiterated by the CNIL and its controller–processor standard contractual clauses.
2) The 12 essential clauses for regulating AI
1. Purpose, scope and definitions
- Define “AI System”, “Training/Validation Data”, “Outputs”, “Deployer” and “Provider” within the meaning of the AI Act.
- Specify objectives, permitted and prohibited use cases (e.g. no use for unlawful sensitive profiling).
2. AI Act roles and responsibilities
- Identify who is the “provider” (responsible for compliance, CE marking and technical documentation) and who is the “deployer” (putting into service, oversight and user information), in accordance with the AI Act.
- Contractually allocate tasks: risk management, log maintenance, updates and post-market monitoring.
3. Regulatory compliance (AI Act, GDPR and national law)
- Ongoing AI Act compliance clause, including in the event of reclassification.
- GDPR compliance: legal basis, information, DPIA and processor safeguards under the CNIL standard clauses.
- Cooperation during authority audits/inspections (CNIL and market authorities) and notification of serious AI incidents under the AI Act.
4. Training data and governance
- Warranty of lawful and fair collection, no infringement of third-party rights, source traceability and dataset documentation.
- Quality/bias: cleaning procedures, representativeness and drift assessment. Require “datasheets” and technical logs.
The CNIL provides useful guidance on data quality, minimisation and security requirements in AI projects (CNIL — AI).
5. Intellectual property (IP) and rights in outputs
- Warranty of ownership/licences for components, datasets and models used; indemnification for infringement.
- Output regime: usage/exploitation rights, restrictions and reassignment. Regulate text and data mining and protected databases.
To secure your rights (trademarks, designs, patents and copyright), refer to good practices from INPI. General contract and liability rules are available on Légifrance (Code civil, trade secrets, etc.).
6. Transparency, labelling and human oversight
- Clear information to end users on AI use, its limitations and when a human is involved.
- Labelling generated content where required (deepfakes) and logging critical interactions.
7. Performance, bias, SLA and acceptance
- Measurable performance thresholds (accuracy, error rate and latency), acceptance-testing and retraining procedures.
- AI-adapted SLAs: availability, response time, false-positive/negative rates and financial penalties.
8. Security, cybersecurity and incidents
- Enhanced technical and organisational measures (encryption, access control, defence against data poisoning, exfiltration and jailbreaks).
- Mandatory annual cyber insurance for the service provider and an incident-response plan aligned with CNIL recommendations.
9. Confidentiality, location and transfers
- Confidentiality and trade secrets (reference to French law available on Légifrance), segregation of training and inference environments.
- EU location for sensitive data; safeguards for transfers outside the EU; consideration of extraterritorial legislation.
10. Balanced liability, caps and exclusions
- Dual cap: general contractual liability vs data/IP liability, with carve-outs (infringement of fundamental rights, GDPR breaches, fraud and wilful misconduct).
- Proportionate indemnification mechanism and compliance with general principles of French contract law (see Code civil).
11. Exit arrangements, portability and escrow
- Return/export of data, prompts, logs and training artefacts; open format; assistance without undue additional charges.
- Escrow of the model or weights where relevant (critical SaaS, on-premises).
12. Audit, penalties and termination
- Right to audit relevant environments (including critical subcontractors) and remediation within contractual deadlines.
- Termination for serious AI Act/GDPR breach; penalties for repeated non-compliance.
For public-sector bodies, the European Commission published voluntary model clauses for procuring AI solutions in 2025. Their inclusion must be coordinated with the Code de la commande publique, available through Légifrance, and procedures on the Service Public Pro portal.
3) Model AI contract clause: ready-to-use excerpt
Purpose. The Provider makes available to the Customer an artificial intelligence system “[AI System Name]” for [Objectives], in compliance with the EU AI Regulation and GDPR.
Roles. The Provider acts as a “provider” within the meaning of the AI Act and, where relevant, as a processor under the GDPR. The Customer acts as a “deployer” and, where applicable, as a controller.
Compliance. The Provider warrants that the AI System complies with applicable obligations (risk management, data governance, documentation, logging, human oversight, CE marking and post-market monitoring). The Customer undertakes to use the AI System in accordance with permitted uses and to provide the required information to end users.
Data and traceability. The Provider represents that training data was lawfully collected and used and provides, on request, documentation on sources, annotation methodology, bias tests and performance metrics.
Transparency. Generated content is identified where required by regulation. The Customer maintains effective human oversight for significant decisions.
IP. The Provider warrants that it holds the necessary rights in components (models, datasets and libraries) and indemnifies the Customer against any third-party claim. Outputs are licensed to the Customer for [exploitation/other], subject to third-party rights and the law.
Security. The Provider implements appropriate security measures (access control, encryption and defence against adversarial attacks) and notifies any security incident or serious incident under the AI Act without undue delay.
Location and transfers. Customer data is processed and hosted in [country], with no transfers outside the EU unless adequate legal safeguards and prior information are provided.
Liability. The Provider’s aggregate liability under this Agreement is capped at [x]% of amounts billed over the last [12] months, excluding personal data breaches, infringements of fundamental rights, infringement and fraud.
Audit. The Customer may audit compliance and security measures, directly or through an independent third party, under reasonable notice and confidentiality conditions.
Exit arrangements. At expiry, the Provider assists the Customer in exporting data, prompts, logs and training artefacts in an open format, without unjustified additional charges.
Termination. Either Party may terminate for a serious breach not remedied within [30] days, particularly for AI Act/GDPR non-compliance.
Adapt this excerpt to your context, system classification and allocation of roles in the value chain. GDPR clauses between controller and processor must reflect the requirements published by the CNIL.
4) Specific features by contract type
AI SaaS
- Emphasise portability, exit arrangements without additional charges, model-quality-oriented SLAs, regular updates and notification of version changes.
- Provide an acceptable-use policy (AUP) prohibiting unlawful/discriminatory uses and an incident-reporting mechanism.
On-premises/edge integration
- Specify the target environment, hardware requirements, retraining cycles, escrow access to code/weights and enhanced audit obligations.
Public procurement
- Coordinate AI clauses with the Code de la commande publique (see Légifrance) and EU model clauses published in 2025 for AI procurement.
- Require enhanced traceability, accessible logs and cooperation with inspections.
5) “AI-first” contracting process and governance
- Pre-contractual NDA, detailed specification (input data, integrations, quality criteria and hidden costs), and a scoped POC.
- Selection criteria: AI Act/GDPR compliance, provider transparency, cyber insurance, server location and exit arrangements.
- Ethics and risk steering committee, registers of processing activities and AI systems, DPIA where necessary.
Need end-to-end support and ready-to-use contract templates? Explore AI and law resources and Discover the Initial journey.
6) Operational checklist
- Classify the system (high-risk/GPAI/other) and roles (provider/deployer).
- Document training data (sources, licences and bias) and tests.
- Clauses: AI Act/GDPR compliance, IP, transparency, security, location, liability, audit, exit arrangements, SLA and penalties.
- Provide cyber insurance, audit rights at critical subcontractors and incident-reporting mechanisms.
For further guidance on business obligations, consult Service Public Pro. On contractual principles and liability, refer to Légifrance. Practical guidance is also offered by legal practitioners, for example Avocats Mathias and AGN Avocats.
7) Risks and penalties
Failure to comply with AI Act requirements may lead to significant administrative fines (up to €35 million or 7% of worldwide turnover for certain serious breaches), as set out in the text available on EUR-Lex. GDPR breaches are also penalised by authorities under the framework detailed by the CNIL.
Further reading
See our related guides: GDPR and artificial intelligence: legal obligations, European AI Act: complete guide and Automating contract drafting with AI.
Quick FAQ
Is an AI clause necessary if I already have SaaS terms of sale/use?
Yes. AI introduces specific risks (training data, bias, transparency and human oversight) absent from conventional SaaS. Dedicated clauses are essential.
Who is liable for incorrect AI outputs?
Liability depends on roles (provider/deployer), performance commitments, human oversight and permitted uses. Provide balanced caps and carve-outs.
Must I prohibit data transfers outside the EU?
Not necessarily, but they must have legal safeguards (adequate guarantees) and be proportionate. EU location is recommended for sensitive data.
For more, read other AI and law analyses or discuss AI transformation with Initial.
Further reading
Related resources
Frequently asked questions
FAQ
Which clauses are essential in an AI contract?
Purpose and definitions, provider–deployer roles, AI Act/GDPR compliance, data governance, IP, transparency/oversight, performance and SLA, security, confidentiality/location, liability, exit arrangements, audit and termination.
How should intellectual property in data and outputs be addressed?
Warrant the lawfulness and ownership of datasets and components, define output usage rights, provide indemnification for infringement of third-party rights and coordinate everything with French IP rules (INPI) and the Code civil.
How can the AI Act and GDPR be reconciled in the same contract?
Allocate obligations according to roles (provider/deployer), incorporate AI Act requirements (risks, documentation, logs and CE) and include CNIL GDPR clauses for personal data processing (legal basis, processing, transfers and DPIA).
Should specific insurance be required from the AI provider?
Yes, annual cyber insurance with a limit suited to the risk and scope (sensitive data, business criticality) is recommended, together with security obligations and an incident-response plan.
What penalties apply for AI Act non-compliance?
Administrative fines of up to €35 million or 7% of worldwide turnover for certain serious breaches (under the AI Act text published on EUR-Lex), in addition to GDPR penalties where applicable.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.