AI vendor terms should address material model changes, changes in data use and changes in hosting or sub-Processors. Define what requires notice, reassessment or consent under the contract. Preserve a workable suspension or exit route where a change creates unacceptable legal or operational exposure.
The business situation
A business approves an AI service for internal document summaries. The vendor later routes some requests to a new model provider and changes retention settings. The original diligence report still describes the old architecture, while the service has already changed.
AI governance starts with a use case and a responsible legal entity. A model is not itself a Data Fiduciary. The organisation determining the purpose and means of personal-data processing may be one. Contract, intellectual-property, consumer, employment and sector rules can apply alongside data-protection law; the relevant obligations depend on the deployment.
What needs examining
01. Define materiality by consequence
Avoid relying solely on a version number. A change can be material because it affects data location, permitted training use, output reliability, security or the ability to reproduce a decision. Identify what the business needs to know in advance, what can be notified afterwards and what should trigger a fresh assessment. The thresholds should fit the actual use case.
02. Coordinate notice with internal reassessment
The vendor's notice needs to reach an accountable owner with time to respond. Define the evidence needed to assess the change, such as revised sub-Processor lists, evaluation results or retention configurations. Where the customer has its own client commitments, consider whether the change also affects those obligations. A procurement inbox without an escalation process is not a functioning change control.
03. Preserve a realistic alternative
Suspension, rollback and termination rights matter only if the business can use them. Assess data export, workflow portability, transition support and fees. Do not assume the supplier can keep an old model running indefinitely. A negotiated migration period may be more useful than a broad right that is technically impossible to exercise.
Law, contract and recommended practice
Applicable Indian statutes and sector directions are mandatory where their scope is met. NIST AI RMF is a voluntary governance framework, unless particular commitments become binding through a contract or another applicable requirement. Its GOVERN, MAP, MEASURE and MANAGE functions can organise evidence without creating a new Indian legal obligation.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Contractual control Receive notice of defined material changes | Versioned change-notice schedule | Notice and assessment record |
| Law, where applicable Maintain lawful processing and sector compliance | Reassess affected data flows and use | Updated legal-basis and scope analysis |
| Recommended practice Avoid untested deployment changes | Release review and fallback procedure | Evaluation result and release decision |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Does every model update need a new contract?
Not necessarily. A well-drafted change mechanism can cover ordinary updates. Material departures from agreed data use, risk limits or service commitments may require an amendment or another contractual response.
Is a general right to update the service sufficient?
It may protect vendor flexibility but leave the customer without information or an effective remedy. Assess the right against the customer's regulatory obligations, use case and operational dependence.
Review one vendor update against the original approval file. Any gap between the approved service and the current service should lead to a recorded decision, not silent acceptance.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- NIST AI Risk Management FrameworkNational Institute of Standards and Technology · Voluntary governance framework. It does not, by itself, create an Indian statutory duty.
- Indian Contract Act, 1872Government of Uttar Pradesh · Commercial Tax Department · Government-hosted statutory reference. Read with applicable amendments, special law and judicial interpretation.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS ai governance practice