Most AI procurement still runs on SaaS templates written before anyone asked who the provider is when a customer fine-tunes the vendor’s model. When something fails; a discriminatory score, a leaked training record, a hallucinated contract term; the contract decides who pays. These are the twelve clauses we negotiate hardest.
Role and compliance allocation
1. AI Act role clause. Say explicitly who is provider and who is deployer for each component, including what happens if the customer’s configuration or fine-tuning would flip the roles (substantial modification). Silence here is how a buyer becomes a provider by accident.
2. Regulatory cooperation. The party facing the authority needs the other’s file: technical documentation, conformity evidence, logs; delivered within fixed deadlines, matching the 15-day serious-incident clock.
3. Transparency artifacts. For generative features: who implements Article 50 marking and disclosure; with acceptance criteria, not intentions.
Data and IP
4. Training rights on customer data. The single most negotiated clause of 2026: may the vendor train on your prompts, outputs, documents? Default should be no; any yes should be scoped, aggregated/de-identified, and priced.
5. Data protection annex. KVKK/GDPR processor terms tuned for AI: sub-processor lists including model hosts, transfer mechanics (2024 KVKK standard contracts for Türkiye), deletion covering derived artifacts and fine-tunes.
6. Output ownership and freedom to use. Assignment or broad licence of outputs, plus a warranty that outputs do not incorporate third-party trained content in a way that restricts use.
7. IP indemnity for training-data claims. Copyright suits over training data are live worldwide; the vendor (who chose the corpus) should indemnify, without the “you prompted it” carve-out swallowing the promise. Check alignment with the vendor’s TDM opt-out and copyright policy.
Performance and change
8. Model identification and change control. Pin model/version; require notice (and for regulated uses, consent) before swaps, deprecations or “silent upgrades” that change behaviour; with rollback and parallel-run windows.
9. Accuracy SLAs and evaluation. Replace “commercially reasonable efforts” with measurable evals on agreed test sets, drift thresholds tied to remedies, and (for high-risk uses) the vendor’s post-market monitoring outputs shared with you.
10. Human-oversight enablement. The product must expose what Article 14 requires you to have: confidence signals, logs, override and stop controls.
When it goes wrong
11. Liability architecture. Carve-outs from the cap for data breaches, IP indemnity, regulatory fines caused by the vendor’s non-compliance, and prohibited-practice violations; think in multiples of fees, not fee refunds.
12. Incident and exit. Joint incident playbook (who notifies whom, KVKK 72-hour and AI Act 15-day clocks), plus exit: model weights or equivalent continuity for fine-tunes, data export in usable form, and post-termination inference for a wind-down period.
Use this with our AI due-diligence questions and the AI Act Readiness Checklist; the same twelve headings work as a review grid for contracts you receive.
This article is for general information only and does not constitute legal advice. For advice on your specific situation, contact us.
Author
-
View all postsMümtaz is the Managing Partner of Vircon Legal, which he founded in 2016. He advises founders, investors and operators on financing rounds, M&A, cross-border incorporations and regulated verticals such as crypto-asset infrastructure, fintech and games, bringing a former startup founder's perspective to every engagement. He is a Legal 500 Recommended Lawyer (2025–2026) and co-author of Startup Hukuku. Canonical profile: https://mumtazhacipasaoglu.com · Open-access legal guides: https://github.com/mumtazhpo
If this is on your desk
Templates and checklists are free in the Founder Academy; for a specific situation, book a 30-minute intro call.
Founder AcademyBook an intro callMore from Vircon Insights
Down Rounds and Pay-to-Play: The Founder's Legal Position When Valuation Falls
September 7, 2026Venture Debt: When It Makes Sense for a Turkish Startup and What to Read in the Documents
September 4, 2026Ten Critical Points When Negotiating a Shareholders' Agreement
September 3, 2026The Family Member on the Payroll: Employment Contract, Arm’s-Length Pay and Disguised Profit Distribution
August 31, 2026When a Family Company Invests in Startups: Structure, Conflicts and the Rights That Break the Next Round
August 28, 2026Who Enforces the EU AI Act, and What Do the Fines Actually Look Like for an SME?
August 11, 2026Related Practice Areas
Privacy & Cybersecurity
KVKK and GDPR compliance, breach response, cybersecurity governance.
View service →Mergers & Acquisitions
End-to-end M&A: due diligence, structuring, documentation, negotiation.
View service →Intellectual Property
Trademark, patent, copyright and trade secret advisory.
View service →