What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Governments should define the public need and permitted use first, assess the consequences of error, then make the supplier’s obligations specific enough to test, monitor and enforce. A sound AI procurement contract covers data rights and privacy, security, performance, documentation, human oversight, incidents, system changes, supplier accountability, and a safe way to leave. The exact terms depend on the jurisdiction, procurement rules and use case; no model clause set is a complete contract.

Start with the public need, not a product label

Before specifying a model or tool, describe the service problem the agency is trying to solve. A contract built around a product name alone can leave unclear what the system is allowed to do, how success will be judged, and who is responsible when it fails.

  • Identify intended users, affected people, the service context and the outcomes the agency expects.
  • Describe permitted uses, prohibited uses and foreseeable adjacent uses. State whether the supplier or subcontractors may use AI to deliver any broader contracted service.
  • Identify relevant data, its sources and quality assumptions, and whether the agency has the people and processes needed to operate and oversee the system.
  • Require disclosure of AI components and material subcontractors, including relevant changes. UK procurement guidance offers optional tender questions about supplier AI use and advises considering disclosure where AI will be used to deliver a service.
  • Name the agency decision owner and specify required approvals before deployment. For relevant US federal agency information systems, GAO’s summary of federal guidance says authorization to operate is required before deployment.

Scale safeguards to the system’s impact

Risk is about the system in its actual use, not just the technology category. Consider the consequences of an error, the rights or essential services involved, the sensitivity of data, the security setting and how much the system automates. A tool that informs a decision may require different controls from one that makes or executes it.

Use that assessment to set the depth of testing, human review, monitoring, audit access and incident response. Higher-impact uses call for stronger evidence and controls. Record the assessment and make it a contract input, so it can be revisited if the use, data, model or operating context changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Put data rights, privacy and security in writing

Specify exactly what government information the supplier may access, process, retain, disclose or transfer, and for what purpose. In particular, do not leave implied whether the supplier may use government information to train, fine-tune or otherwise improve models.

  • Set access controls, security safeguards, retention periods, permitted transfers, breach-notice duties and deletion requirements.
  • Define ownership and license scope for government data, supplier materials, outputs and derived materials. Say what the government may continue to use after the contract ends.
  • Require documentation and traceability sufficient for government review, including information about relevant data handling and system changes.
  • Set rules for subcontractors that handle government data or provide material AI functions, including disclosure and controls on their access and use.

AI-specific clauses do not necessarily settle privacy or intellectual-property questions. The European Commission Public Buyers Community says its proposed clauses are not a full contract and do not cover matters such as intellectual property, acceptance, payment, delivery times, applicable law or liability. Those terms need to be handled in the wider agreement and under the applicable law.

Make performance claims measurable before deployment

Translate supplier claims into requirements tied to the agency’s task and operating conditions. A general accuracy claim is not enough if it does not say what was measured, for whom, on what data or in what workflow.

  • Define the task, operating context, agreed baseline, acceptance criteria and error thresholds.
  • Use evaluation data representative of the population, language, workflow and environment in which the system will operate.
  • Require evidence of capabilities and known limitations. Where practicable, test the proposed solution before award or launch.
  • Set service levels relevant to the use, such as availability and response times, and define remedies, correction and retest procedures if the system fails acceptance.
  • Specify ongoing evaluation frequency, reporting responsibilities and who performs and pays for retesting after material changes.

GAO’s summary of US federal guidance calls for testing proposed solutions where practicable and contract terms for continuing testing, monitoring and performance. The contract should therefore treat evaluation as an ongoing duty, not a one-time gate at launch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Require documentation, transparency and audit cooperation

The agency needs enough information to oversee the system, investigate failures and explain decisions to affected people where appropriate. Specify what the supplier must deliver and maintain: system and data documentation, limitations, relevant change records, logs and access to evidence.

Set a reasonable audit and review process, including cooperation with independent review where justified. Confidentiality and security protections can be appropriate, but should not prevent the government from verifying compliance or investigating a serious failure. OECD analysis warns that limited transparency can undermine independent maintenance and monitoring capability. UK government guidance recommends transparency about the project, tools, data and algorithms, and encourages explainability and interpretability as design criteria.

Define human oversight and incident response

Assign day-to-day responsibilities between the agency and supplier for monitoring, escalation and corrective action. Match human review and intervention provisions to the decision being supported and the consequences of error; a nominal human approval step is not meaningful if the reviewer lacks time, information or authority to act.

  • Set processes for reporting security incidents, harmful or discriminatory outcomes, data issues, unauthorized use and significant performance changes.
  • State when the agency may pause, restrict or suspend the system, and require supplier support for investigation, remediation and safe resumption.
  • Define how complaints, appeals and requests for review are routed when appropriate to the service.
  • Require monitoring of performance, privacy, civil-rights, security and other risks relevant to the use case.

EU model-clause materials for non-high-risk systems list human oversight, risk management, robustness and cybersecurity among the subjects they address. The contract still needs to assign operational roles and specify what happens when a safeguard fails.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Control changes to models and services

A deployed service may change through updates to its model, data, hosting, functionality or subcontractors. Require advance notice and a review process for changes that could affect performance, risk or government data.

  • Identify which changes require notice, agency approval, retesting or an updated impact assessment.
  • Give the agency a right to reject a material change or suspend or terminate the affected service under defined conditions.
  • Require updated documentation and evidence after changes that alter performance characteristics, data handling or security posture.
  • Include applicable agency policy, security authorization and legal compliance duties in the contract.

For relevant federal agency information-system cases, US federal rules summarized by GAO require pre-deployment authorization and contract oversight for emerging risks. The precise requirement is jurisdiction- and system-dependent; it should not be treated as a rule for every government buyer.

Allocate accountability and make remedies usable

Separate responsibilities for supplier-controlled components, agency configuration and use, data quality, human decisions and third-party dependencies. Avoid terms that leave responsibility indeterminate merely because several parties contribute to an outcome.

Connect obligations to practical remedies: correction, retesting, agreed service credits or other remedies, suspension, termination, transition assistance and access to records needed to continue the service. Address liability and other ordinary contract terms in the context of governing law and the full agreement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Plan portability and a safe exit

Set the exit requirements before award, while the agency still has leverage to negotiate them. Define export formats, interfaces, documentation, continuing licenses, transition assistance, cooperation duties, wind-down roles and costs. Specify how government data and derived materials are returned or deleted, and what evidence of deletion the supplier must provide.

UK guidance recommends defining end-of-life roles and processes and using auditable methods for data cleaning and collection. A workable exit plan should make it possible to preserve records, move the service or discontinue it without losing access to information needed for public accountability.

Use model clauses as a drafting aid, not a substitute for review

Model clauses can provide a starting point, but they are not universal rules or complete contract forms. The European Commission Public Buyers Community describes its proposed clauses as voluntary and calls for a case-by-case judgment about sufficiency and proportionality. It distinguishes fuller clauses for high-risk systems from a lighter approach for non-high-risk systems.

A separate record for MCC-AI-Light describes a February 2025 working document for non-high-risk procurement. Its listed topics include risk management, data governance, transparency, human oversight, accuracy, robustness, cybersecurity and data-set rights. The record says it does not reflect an official European Commission position, so buyers should check the current applicable source and status before adopting language.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Guidance also has jurisdictional limits. The UK policy note applies to specified central government bodies, while the US provisions summarized by GAO concern federal agencies. Neither should be presented as binding on all governments. Adapt any clause package to the buyer’s procurement regime, sector rules, current agency policy and applicable law, with legal review.

Compare bids against the same criteria

Use a consistent set of use-case criteria when comparing proposals, systems or clause packages. These dimensions reflect themes in UK, EU, OECD and US federal guidance; the sources do not establish a universal scoring formula.

  • Impact on individuals, rights and essential services.
  • Data sensitivity, provenance, quality and permitted reuse.
  • Performance in the actual operating context and disclosure of limitations.
  • Transparency, documentation and auditability.
  • Human review and intervention options.
  • Security, resilience and subcontractor exposure.
  • Frequency and governance of model or service changes.
  • Portability, transition time, data disposition and exit cost.
  • Whole-life cost, including integration, maintenance, monitoring and retirement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.