Contracting with AI: The Clauses an Indian AI Vendor Agreement Needs

There is no dedicated comprehensive AI statute in India as of now. Rather, current laws and sectoral regulations, and developing government policy and governance programs are currently used to address AI-related risks. The contract is, therefore, the place where the risks associated with the use of AI are allocated, and a generic software contract might not provide much detail on training with customer data, inaccurate output or model changes.
Why the contract carries weight
Section 8(1) of the Digital Personal Data Protection Act, 2023 (DPDP Act) keeps a Data Fiduciary responsible for processing undertaken on its behalf, including by a Data Processor. Section 8(2) requires a valid contract with a Data Processor, while the Digital Personal Data Protection Rules, 2025 require contracts to provide for reasonable security safeguards. If reasonable security precautions are not taken, there is a risk of penalty of up to ₹250 crore. Contractual allocation of responsibility and costs is especially significant as the liability to the regulator cannot be contracted away.
The relevant DPDP provisions and Rules will be implemented in stages, with Rules 3, 5-16, 22 and 23 to be implemented 18 months after notification of the Rules. The 18-month period is currently being counted down to 13 May 2027. Until the relevant provisions take effect, existing obligations under the Information Technology Act, 2000 and the SPDI Rules, 2011 remain relevant where applicable, particularly where SPDI is handled. Contracts signed today should therefore be drafted with both regimes in mind.
The clauses
- Scope and service levels. Define the use case, model or version, support obligations and measurable uptime or response targets. Require notice of material model changes, degradation or withdrawal or replacement, so the customer can assess the effect on accuracy and compliance.
- Data ownership and training restrictions. Treat inputs, prompts, personal data, logs, outputs and derived data separately rather than as one block of “customer data”. State whether each may be retained, used to improve models or combined with other customers’ data. If training is not permitted, say so expressly.
- Processing terms. Identify the vendor as a Data Processor on the basis of documented instructions. Identify security controls, sub-processors, processing locations and a breach-notice period that allows the customer to meet its statutory obligations. Under Rule 7 of the DPDP Rules, the Data Fiduciary must intimate the Data Protection Board without delay and provide updated and detailed information within 72 hours, or such longer period as may be permitted.
- IP and training-data warranty. Allocate ownership or licensing rights in outputs, custom models and fine-tuned weights. Consider warranties regarding the lawful use of training data and indemnities for infringement claims. The legal position on AI training and copyright remains evolving. In ANI Media Pvt. Ltd. v. OpenAI, the Delhi High Court in its 24 July 2026 decision, declined to grant ANI interim injunctive relief and held, on a prima facie basis, that storing copyrighted material for AI training fell within Section 52(1)(a) of the Copyright Act, 1957. ANI has challenged the decision in appeal, and the broader issue remains subject to further judicial and policy developments.
- Output risk and human review. AI outputs can be inaccurate, biased or fabricated. Thus, include testing or performance commitments and specify when human review is mandatory, particularly for hiring, credit or clinical decisions. A blanket “as is” disclaimer rarely allocates these risks adequately.
- Audit and transparency. Tailor audit rights to the AI system rather than copying SaaS terms. Look for relevant certifications, security reports, logs and audit rights, including those mandated by sector-specific regulators like RBI.
- Indemnity and liability cap. Handle data breaches, IP claims, unauthorized use of training data, and, when legally allowed, regulatory liability resulting from the vendor. Where vendors offer a cap of fees paid, consider higher caps or carve-outs for confidentiality, data misuse and IP infringement.
- Exit and deletion. Section 8(7) of the DPDP Act requires a Data Fiduciary to cause its Data Processor to erase personal data once the purpose is no longer being served, subject to applicable requirements. Agreements must include return and/or deletion of customer data, prompts, logs and contractually defined derived data (embeddings, if applicable), as well as a deletion certificate and transition support.
- Compliance and change in law. The vendor should warrant compliance with applicable Indian law. In the context of AI tools creating synthetic media or other regulated content, applicable provisions of the Information Technology Rules and subsequent amendments should be taken into account. A change-in-law clause may enable the parties to review contractual obligations as the DPDP framework fully takes effect and the law on AI and copyright evolves.
AI agreements must move beyond standard software terms. The right protections depend on the data involved, the sector and whether the tool influences decisions about individuals, but clear allocation of responsibility for data use, model changes, liability and exit is the practical starting point.




