What to Put in an AI Vendor Contract
AI vendor contracts in the Philippines often skip what matters: data return, audit logs, model changes, and exit protection.

Most AI vendor contracts signed by companies operating in the Philippines are written for the start of the relationship. They describe what the vendor will build, when it will be delivered, and how much it will cost.
Very few of them describe what happens at the end.
That is the part that decides whether your operation keeps running when the vendor changes its pricing, changes its model, or simply stops answering your emails. Below are the clauses that actually protect a Philippine operation, and why the usual ones fall short.
The Problem: The Contract Ends, But the Work Does Not
Three things usually go missing at the same time.
| What goes missing | What it is | Where it sits |
|---|---|---|
| The data | Prompts, fine-tuning examples, correction history | Inside the vendor system |
| The configuration | Settings, rules and thresholds that fit your business | Inside the vendor system |
| The knowledge | The reasons behind those settings | Nowhere, because nobody wrote it down |
When an AI vendor relationship ends, the work does not stop. Your team still needs to process invoices, answer customer messages, and produce reports. Only now the tool that did half of it is gone.
Three things usually go missing at the same time:
- The data. Your prompts, your fine-tuning examples, your correction history. All of it may sit inside the vendor's system.
- The configuration. The settings, rules and thresholds that made the tool fit your business.
- The knowledge. The reasons behind those settings, which nobody wrote down.
I learned this lesson the expensive way, and not with an AI vendor. When Google changed its AdSense rules, I could not respond in time, and advertising income across all my sites stopped in a single night. The structure depended on an external service, there was no mechanism to receive notice of rule changes, and human monitoring was not enough. The dependency itself was not the mistake. Having no clause and no process for the day the other side changed the rules was the mistake.
An AI vendor can change its rules the same way. Models are retired. Pricing tiers are restructured. Default models are swapped for newer ones. None of these events require your agreement, and none of them are covered by a standard delivery contract.
Why Standard Contract Templates Fall Short
Four assumptions in the usual templates do not hold for AI services.
| Assumption in the template | Why it fails for AI |
|---|---|
| The product stays the same | The vendor may change the underlying model; six-month-old test results stop applying |
| Data is a single item | Prompts, labelled examples, rejection history and audit logs are different assets |
| Delivering a working service is enough | Without logs you cannot investigate an error or prove compliance |
| 30 days notice is balanced | It protects the right to leave, not the ability to leave |
Most companies in the Philippines adapt a software development or BPO service agreement when they buy AI services. Those templates were written for a different kind of risk.
Related: How to Spot a Real AI Development Company in the Philippines explains this in detail.
They assume the product stays the same
A traditional software contract assumes the version you bought is the version you keep. AI services do not work that way. The vendor may change the underlying model, and the output your team reviewed and approved during testing may not be the output you get six months later.
They treat data as a single item
Templates usually say something like "all data shall be returned upon termination." That sentence is too small for the problem. Your prompts, your labelled examples, your rejection history and your audit logs are different assets with different formats. If the contract does not name them separately, you will receive a database export and nothing else.
Related: When the Product Changes Without You Choosing It: What to Decide Before Your Tool's Default Model Is Swapped|Case Study for Japanese Companies in the Philippines explains this in detail.
They have no visibility requirement
Standard agreements say the vendor must deliver a working service. They rarely say the vendor must show you how it worked. Without logs, you cannot answer a customer complaint, you cannot investigate an error, and you cannot prove compliance to a regulator.
They ignore the exit period
A termination clause that says "either party may terminate with 30 days notice" sounds balanced. In practice, 30 days is not enough to export data, rebuild a workflow, retrain staff and run a parallel test. The clause protects the right to leave, not the ability to leave.
Related: Why Your AI Vendor's Legal Form Changes the Deal: SEC-Registered Corporations vs DTI Sole Proprietors in the Philippines explains this in detail.
The Clauses That Actually Protect You
The terms worth adding before you sign.
| Clause | What to specify |
|---|---|
| Data return in a named format | Which data, in which format (CSV or JSON), by when, usable without the vendor's software |
| Audit logs you can read | Timestamp, input reference, model or version, output; retained for a defined period |
| Notice before change | Advance notice of model retirement, pricing changes and default-model swaps |
| A workable exit period | Long enough to export, rebuild, retrain and run a parallel test |
Here are the terms worth adding before you sign. None of them require unusual legal language, and most vendors will accept them if you raise them during negotiation rather than after.
1. Data return in a named format
Do not write "return all data." Write which data, in which format, and by when.
State that on termination the vendor shall provide, within a defined number of days, the prompt library, configuration settings, labelled training examples, correction history and processing logs, in a machine-readable format such as CSV or JSON. Add that the export must be usable without the vendor's own software.
Under the Data Privacy Act of 2012 and its Implementing Rules, processing by a personal information processor must be governed by a contract that sets out the subject matter, duration, nature and purpose of the processing, the types of personal data involved, and the security measures in place. If your AI vendor touches customer data, this is not optional. It is also a good place to attach your data return terms.
2. Audit logs you can read
Require that the vendor keeps a log of each processing request and its result, retained for a defined period, and made available to you on request.
Specify what a log entry contains: timestamp, the input reference, which model or version handled it, and the output. Without the model version, a log tells you almost nothing when you are investigating why last quarter's results differ from this quarter's.
3. Notice before the model changes
This is the clause most companies never think of, and the one that causes the most trouble.
Add a term requiring written notice a defined number of days before the vendor changes the underlying model, the default model, or any parameter that affects output. Add the right to test the new configuration in a staging environment before it reaches production.
Vendors do announce these changes. The problem is that announcements go to a developer mailing list, not to your operations manager. A contractual notice requirement puts the message where someone will act on it.
4. A handover period with real scope
Replace a bare notice period with a defined transition period. State that during this period the vendor will provide documentation, answer questions from your team or your new vendor, and support a parallel run.
Sixty to ninety days is realistic for an operation of any size. Thirty days is a formality.
5. Named points of contact and escalation
For Philippine operations this matters more than people expect. Verbal agreements carry real weight in local business culture, and a change agreed in a phone call can be treated as settled by one side and unknown by the other.
Write down who is authorised to approve changes on each side, and require that scope changes are confirmed in writing. In my own project work in the Philippines I made it a rule that specification changes are documented in the weekly progress meeting, precisely because "we agreed on this last week" comes up so often.
Putting It Into Practice
You do not need to renegotiate every contract at once. Work in this order.
Step 1 — List your AI dependencies. Write down every AI service your operation uses, including the ones bought on a company credit card by a single department. Shadow subscriptions are common and are the ones with no contract at all.
Step 2 — Check each contract for the five clauses above. Mark each as present, weak or missing. Most will have gaps in model change notice and audit logs.
Step 3 — Rank by damage. Ask one question for each service: if this stopped tomorrow, what stops with it? A tool that drafts internal summaries is a nuisance. A tool that screens customer applications is an operational failure.
Step 4 — Fix the top two at renewal. Contract renewal is when you have leverage. Raise the clauses then, not during an incident.
Step 5 — Export your data now, once. Do not wait for termination to find out whether the export works. Request a full export while the relationship is healthy, and check that you can actually open and use it.
That last step is the one people skip. A right to receive data is not the same as a tested process for receiving it.
What This Is Worth
The value of these clauses is not measured in savings. It is measured in the cost you avoid.
Consider a mid-sized operation in Metro Manila where an AI service handles first-line customer messages. If the vendor relationship ends without a proper handover, the team goes back to manual handling. That means additional staff hours, slower response times, and a period where service quality is visibly worse to customers.
Now consider the same operation with a 90-day transition, a tested data export and a documented prompt library. The switch is a project, not a crisis. The same work moves to a new vendor or in-house over two months, with no gap in service.
The clauses cost nothing to add. The negotiation takes an hour. The difference shows up on the one day you needed them.
There is a second benefit that is easy to miss. Writing these terms forces your own team to document how the AI service is actually used. In my experience, that documentation turns out to be useful long before any contract ends.
FAQ
Q: Our vendor is a large international provider. Can we really change their standard terms?
Often not on the main agreement, but you can usually add an addendum or a data processing agreement covering export format, log retention and notice. Large providers are used to these requests from regulated industries. If they refuse all of them, that refusal is itself useful information about the risk you are taking.
Q: We use AI tools on a monthly subscription with no contract at all. What should we do?
Treat the terms of service as your contract and read the sections on data retention and account termination. Then reduce your exposure: keep your prompt library and configuration in your own storage rather than only inside the tool. If the tool disappears, you still hold the part that took the longest to build.
Q: How long should audit logs be kept?
It depends on what the AI touches. For services that process personal data, align the retention period with your own data retention policy and applicable regulatory requirements. For internal productivity tools, twelve months is usually enough to investigate a dispute. Whatever you choose, put the number in the contract rather than leaving it to the vendor's default.
Q: Who should own the prompts we developed?
Your company should. Prompts developed by your staff for your processes are your work product, and the contract should say so explicitly. This is worth checking, because some standard terms grant the vendor broad rights over content submitted to the service.
Q: Does this apply to AI features inside software we already use?
Yes, and these are the easiest to overlook. When an existing vendor adds AI features to a product you already licensed, the original contract rarely covers them. Ask for an amendment that addresses model changes and data use for the new features.
Sign for the Ending, Not Only the Beginning
An AI vendor contract should assume the relationship will end. Not because vendors are unreliable, but because in a market this fast, endings are normal.
The five clauses in this article — data return in a named format, readable audit logs, notice before model changes, a real handover period, and named points of contact — turn an ending into a scheduled project.
If you are reviewing an AI vendor agreement for a Philippine operation and want a second pair of eyes on the operational terms, we work with Japanese and local companies on exactly this kind of review.
References
About the author

Founder / AI Engineer (36+ years in IT)
- ●From Tokyo · based in Manila for 13+ years
- ●36+ years in IT (development, SEO, AI)
- ●IBM Certified Generative AI Engineer
- ●AI chatbots, RAG & AI agent development
A Japanese AI engineer with 36+ years in IT and 13+ years on the ground in the Philippines. I write from hands-on experience to help Japanese companies adopt AI that actually delivers results — chatbots, workflow automation, AI agents, and AI-driven marketing. Feel free to reach out in Japanese or English.
Your Competitors Are Already Using AI!
Is your business keeping up?
Related Articles

Competitor Research With AI in One Hour a Week
A four-step weekly routine that collects and compares competitor information, so pricing decisions rest on current data.
8/10/2026

When Not to Use AI: Tasks to Keep Human
An honest look at the five tasks Philippine businesses should keep human — consequential decisions among them.
8/9/2026

Turning Full-Stack Developers Into Agent Specialists
Hiring an AI agent specialist in the Philippines is slow and costly. Retraining the developers you have is usually faster.
8/7/2026

Keeping AI Running Through Brownouts and Typhoons
Cloud AI does not stop when the office loses power — your access does. A continuity plan for Philippine operations.
8/5/2026

Your AI Vendor's Legal Form Changes the Deal
SEC-registered corporation or DTI sole proprietor — in the Philippines the difference changes contracts, banking, and recourse.
8/3/2026

How to Measure ROI on AI in a Philippine Business
Most businesses cannot say whether their AI project paid back, because nothing was measured first. The four things to count.
8/1/2026
