AI Contract Clause Library
In brief
The AI Contract Clause Library is a free DOCX and XLSX policy for EU AI Act. Nine contract clauses for buying or supplying AI: documentation, data use, testing, incidents, changes, oversight, audit and the allocation of regulatory roles, each tied to the duty it allocates. It is written for provider / developer, deployer / user organisation and importer.
- Format
- DOCX and XLSX · Policy
- Version
- v1, built 28 Sep 2026
- Duties cited
- 3 from 2 instruments
- Rows from the records
- 12
- Frameworks
- EU AI Act
- Written for
- Provider / developer, Deployer / user organisation, Importer
- Price and licence
- Free · CC BY 4.0
What's inside
- Document: nine clauses with placeholders for counsel
- Vendor duties sheet: the duties a supplier contract should allocate
- Each clause cites the recorded duty behind it
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Vendor duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Provide contestability, supply-chain transparency and records (guardrails 7 to 9) | Vendor and supply-chain governance | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 7, 8 and 9 | Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, model | AI system register and supplier disclosures | GOVERN 6.x | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records | ||
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Developers must supply deployers with documentation of the technology | Technical documentation | Colorado ADMT law (SB 26-189) | Colorado (United States) | Provider / developer | Legal requirement | 2027-01-01 | Developers of automated decision-making technology must provide deployers with the documentation the statute lists, so that deployers can meet their notice, dis | Source-linked | https://aipolicytracker.org/obligations/us-colorado-admt-developer-documentation | ||||
| Draw up technical documentation before placing a high-risk system on the market | Technical documentation | EU AI Act | European Union | Provider / developer | Legal requirement | Article 11 and Annex IV | 2027-12-02 | Technical documentation must be drawn up before a high-risk system is placed on the market or put into service and kept up to date. It must demonstrate complian | Annex IV technical file | Clause 7.5 Documented information; Annex A control on system documentation | GOVERN 1.4, MAP 3.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-technical-documentation |
| Report serious incidents to market surveillance authorities | Incident reporting and handling | EU AI Act | European Union | Provider / developer, Deployer / user organisation | Legal requirement | Article 73 | 2027-12-02 | Providers of high-risk AI systems must report serious incidents to the market-surveillance authority of the Member State where the incident occurred, immediatel | AI incident response procedure; Incident log and authority notifications | Clause 10 Improvement; Annex A control on incident handling | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-serious-incident-reporting |
| Verify conformity before importing or distributing high-risk AI | Vendor and supply-chain governance | EU AI Act | European Union | Importer, Distributor | Legal requirement | Articles 23 and 24 | 2027-12-02 | Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised represe | Supplier due-diligence checklist | Annex A controls on third parties and suppliers | GOVERN 6.1, GOVERN 6.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations |
Duties a contract with an AI supplier should allocate.
Document outline (DOCX)
- AI contract clause library
- 1. Description of the AI system
- 2. Documentation and cooperation
- 3. Data use
- 4. Testing and performance
- 5. Incidents
- 6. Changes
- 7. Human oversight
- 8. Audit
- 9. Allocation of regulatory roles
- The duties these clauses allocate
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
- Verify conformity before importing or distributing high-risk AI
- Providers of high-risk AI must have written agreements with suppliers of components, tools and services
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The DOCX and XLSX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Check the duties against your situation. The "Vendor duties" sheet lists the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 4Complete the document. Work through the DOCX sections (AI contract clause library, The duties these clauses allocate) and replace each placeholder with your organisation's answer.
- 5Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (3)
Each is cited in the file with its source reference and a link back to the record.
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | bb068ecd9dad | First version, built from dataset bb068ecd9dad. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Contract Clause Library?
Document: nine clauses with placeholders for counsel. Vendor duties sheet: the duties a supplier contract should allocate. Each clause cites the recorded duty behind it.
Which duties does it cite?
3 recorded duties from Australian Voluntary AI Safety Standard and EU AI Act, including Guardrails 7, 8 and 9, Articles 23 and 24 and Article 25(4). Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and importer. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the DOCX and XLSX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.