Back to Blog
AI

Your AI Vendor's Security Page Is Marketing. The Contract Is the Control.

17 September, 2026
4 min read
Your AI Vendor's Security Page Is Marketing. The Contract Is the Control.

Ask a firm how it evaluated its AI tool and you usually get a version of the same answer. Somebody read the security page, confirmed the vendor was SOC 2 compliant, and signed.

The Training Clause Has to Reach Further Than You Think

Michael Volkov, writing on 17 September 2026, sets out what the agreement should actually say. Read as a diligence list it is uncomfortable, because most of it is absent from the contracts firms have already signed.

Start with the clause everyone thinks they have.

A prohibition on training needs to be an explicit, affirmative bar on using your inputs, your outputs and any data submitted through the tool to train, retrain, fine-tune or otherwise improve any commercial or publicly available model. The word doing the work there is any.

Most AI products sit on somebody else's foundation model. A vendor can honestly say it does not train on your data while the model underneath it operates on different terms, and a clause naming only the vendor's own models leaves that gap wide open. The clause has to cover the models beneath the product, not just the product.

For an accounting firm this is not a privacy abstraction. Client financial records moving into a training set is a confidentiality question, and the client never agreed to it.

The Clause Nobody Asks For

Here is the one that is almost never negotiated and costs nothing to ask for.

Audit rights. A contractual right to request compliance documentation and evidence of the technical controls the vendor claims to run: that training is actually disabled on your tenant, what the retention settings actually are, how access controls are actually configured. Without that, as Volkov puts it, the assurance rests entirely on the vendor's self-reporting.

That is worth sitting with. A firm that has no audit right has a promise, and a promise is what you have instead of evidence when a client or an underwriter asks how you know.

Alongside it, a requirement for advance notice before material model changes affecting data handling. Products get upgraded underneath you, and a change you were not told about is a change you cannot document.

Deletion Is Not a Setting

The exit terms are where the real exposure sits, and they are the most commonly skipped.

The contract should name data residency and processing locations, identify every subprocessor, and keep that disclosure current rather than treating it as a one-time schedule attached at signing. Retention should be the shortest period consistent with actual business need, with a defined deletion process at termination.

Then the part that makes it real: a contractually guaranteed process for retrieving your data and confirming deletion from the vendor's systems, including from any subprocessors. Deleting your account is not deletion. Confirming deletion is a different act, and only one of them is something you can show somebody.

Indemnification deserves one line too. It should extend to model outputs and predictions rather than only the underlying platform, and it should be read against the liability cap in the same agreement, because an indemnity sitting under a cap equal to three months of fees is decoration.

What This Costs to Fix

Not much, and that is the point.

None of these are exotic asks. They are standard in enterprise software negotiation and unusual only because professional services firms buying a per-seat AI tool rarely negotiate at all. A firm with ten staff has less bargaining power than a bank, but it also has a simple option nobody uses: ask, in writing, and keep the answer.

MetaWurks answers several of these in the product rather than leaving them to a negotiation. Documents ingested into the platform are not used to train models and are not exposed to other users. Role based access controls decide who can open which client's records. Audit logs record who opened what and when, which is the evidence layer the audit-rights clause exists to reach.

That does not remove the need to read your agreements. It removes one tool from the list of things you have to take on trust.

Pull the contracts for every AI product touching client data and find the training clause. If there is not one, you do not have a position. You have a security page.

Join the Conversation

For the AI tool your firm relies on most, can you point to the sentence in the contract that stops your client data reaching a model, or only to the page on the website that says it does not?

Subscribe now to Our Newsletter and get the Coupon code.

All your information is completely confidential