This website uses cookies

Read our Privacy policy and Terms of use for more information.

Laura Frederick hosted this How to Contract webinar with Joanna Valencia, a fractional general counsel whose clients include Goodie AI, and Anya Ryjkova, in-house counsel at BNY Mellon. Joanna took the vendor seat and works on AI contracts constantly. Anya took the customer seat after a decade in corporate legal departments at Meta, Uber, and Toyota, and she was a computer scientist before she was a lawyer. Having both seats filled by people who work these deals kept the conversation out of the theoretical.

Want unlimited access to 110+ webinar replays? Our paid members get permanent access to webinar recordings from 2024 and 2025, plus 30+ hours of courses courses, certifications, and our massive expert library. If you just want an individual webinar, register in advance to get access to the recording for 14 days. You can sign up for our auto registration list so you are registered for every webinar we host. Learn more about our membership →

They worked through three sample provisions that Laura built for training purposes, each one flawed on purpose, covering bias testing obligations, fairness warranties and their disclaimers, and disclosure and reporting duties. Along the way they got into statutory damages, exclusive remedies that fail of their essential purpose, tort claims that sit outside the liability cap, insurance coverage for algorithmic discrimination claims, and what to do with legacy contracts that say nothing about any of this.

Here are our top ten takeaways from the speakers' comments during the webinar:

  1. Focus on outcomes rather than intent. Discrimination risk in an AI system shows up in two ways. Disparate treatment covers intentional acts. Disparate impact covers a facially neutral process that produces an unequal outcome for a protected group, and that is where AI systems tend to land, because a model can operate with no intent at all and still skew the result based on the inputs it was given. Draft for the second one, because it is the one your model can produce on its own.

  2. Remember that the regulator's questions come to you. When you buy an AI product, your end customers do not care who your vendor is. That relationship means nothing to them. The company facing the public absorbs the wrath of individual clients, class action lawyers, and regulators, and the company facing the public is the one answering questions about how the algorithm works. Whatever your vendor promised in a contract nobody outside the deal will read, the exposure still lands on you.

  3. Press your vendor on testing before the signature line. Leverage disappears the moment the contract gets signed, so use the window while there is still no ink on that final line. Ask to see the testing methodology. Ask for the numbers. Ask for proof that bias testing actually runs. Then make sure the testing covers the population you serve, because the risk profile in real estate looks nothing like lending or healthcare.

  4. Tie retesting to the events that matter. Vendor forms usually offer annual bias testing, which sounds responsive and does very little. Most of the AI laws want retesting connected to an event, like a broken threshold or a failed metric. Push for testing triggered by any material change in model logic and by any material finding in model performance. A vendor testing once a year can run light data through the process and call the obligation satisfied.

  1. Borrow your metrics and definitions from the regulations. You are not writing this standard from scratch. The CCPA and CPRA, the Colorado AI Act, and the EU AI Act and its interpreting regulations all give you material to work from. Design a metric with your product team, such as a disparate impact ratio, and set the thresholds that send the vendor back to retest. That work pushes you into deep conversations with engineers, and it hedges a huge piece of the risk.

  1. Anchor fairness warranties to methodology and thresholds. Customers often ask for a warranty that a model is unbiased or fair. Neither term has a fixed legal meaning, and both look backward. Tie the warranty to something the vendor actually did, like a required methodology and a threshold met at the time of testing, so both sides have something measurable when they need to decide whether the warranty broke. A warranty that the model does not unlawfully discriminate warrants a legal conclusion a court reaches after the fact.

  1. Watch for exclusions and disclaimers that swallow the warranty. Vendors often carve out bias that results from customer data, prompts, or configuration, which sounds fair until you notice that everything relates to the customer. A model you buy is designed to work with your data, so an exclusion that broad voids the promise you paid for. Narrow it to inputs the vendor did not supply, and only where the vendor can prove the bias came from those inputs. Then check whether a closing sentence quietly wipes out every other bias promise in the contract.

  1. Look hard at any sole remedy before you rely on it. A corrective action plan mutually agreed by the parties, with no deadline and no fallback when they never agree, is not a remedy. A remedy has to do something to be enforceable, and when it fails of its essential purpose the customer walks back into ordinary damages. Some jurisdictions have held that the associated liability cap falls with it, because the two were an interdependent bargain. The same trap sits in a sole remedy that cross-references indemnification, since indemnification needs a third-party claim.

  1. Replace vague timing language with a fixed deadline. Commercially reasonable notice and commercially reasonable remediation efforts give the vendor room to sit on a problem while your compliance clock runs. Pick a number of days for notice and list what the notice has to contain, the way a cyber insurance policy tells you exactly what to include to get coverage. Add a remediation timeline with regular reporting. Give yourself a termination right for failure to remediate instead of routing everything to an indemnity that may never mention bias.

  1. Ask whether the vendor can actually pay. We spend our energy allocating fairness risk through warranties, remedies, and disclosure duties, and none of it is worth much when the risk materializes and the vendor cannot cover it. Affirmative AI endorsements are still immature, and the market for AI liability coverage is new and inconsistent. Require the vendor to represent that its policy does not exclude indemnified bias risk. Where you want to push harder, ask for confirmation that algorithmic discrimination claims fall expressly within coverage.

Subscribe to Stay in the Loop

Our weekly newsletter tells you what is coming up on the How to Contract calendar and brings you recaps like this one when you cannot make the live session. Subscribe now and get the practical pieces without having to block the hour.