Contracting for AI Vendors in India: The Clauses to Add When You Buy AI Tools

India has no single AI law; the MeitY India AI Governance Guidelines (2025) rely on the IT Act, the DPDP Act, and sectoral regulators. So the AI vendor contract is the main tool for allocating AI risk, through clauses on training-data rights, output ownership, liability, and indemnity.

Contracting for AI Vendors in India: The Clauses to Add When You Buy AI Tools

Contracting for AI Vendors in India: The Clauses to Add When You Buy AI Tools

When There Is No AI Law, the Contract Is the Law

Most discussions about AI risk ask what the law requires. In India, the more useful question for a business buying AI tools is what your contract requires, because that is where the real protection sits.

In November 2025, the Ministry of Electronics and Information Technology released the India AI Governance Guidelines, the country's first comprehensive framework for AI. The deliberate policy choice was not to pass a separate AI law. Instead, India relies on existing laws such as the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, with sectoral regulators such as the RBI and SEBI overseeing AI use in their domains. The framework favours innovation with accountability layered in over time.

The practical consequence for buyers is direct. When there is no single statute to point to, the agreement with your AI vendor becomes the main instrument that decides who carries the risk. A standard software contract was not written for tools that learn from your data, generate content, and occasionally get things wrong with confidence. The clauses have to be added.

Contracting for AI Vendors in India: The Clauses to Add When You Buy AI Tools

Why AI Vendor Contracts Need New Clauses in 2026

1. India governs AI through existing laws and the contract

Because the governance framework leans on current laws and sectoral oversight rather than a dedicated AI act, the contract is where general principles become specific, enforceable obligations between you and your vendor. What the statute leaves open, the agreement has to close.

The Digital Personal Data Protection Act, 2023 governs the use of personal data, including its use to train AI models. If your inputs contain personal data, whether and how a vendor may use that data to train or improve its models is not a technical detail. It is a consent and purpose question that belongs in the contract.

3. AI risk does not fit standard SaaS terms

Traditional software contracts assume deterministic behaviour and lean on broad disclaimers and tight liability caps. AI introduces different risks: inaccurate or fabricated outputs, intellectual-property exposure from training data, and outputs whose ownership is unclear. Those risks need terms written for them, not inherited from a generic template.

4. Accountability has to be allocated explicitly

A recurring theme of responsible-AI frameworks, including India's, is clear allocation of responsibility. In a buyer-vendor relationship, that allocation happens in the contract through ownership, liability, indemnity, and audit terms, not by assumption.

The Clauses to Add When You Buy AI Tools

  1. Training-data rights. State clearly whether the vendor may use your inputs, prompts, and data to train or improve its models, and restrict or prohibit it where appropriate, with specific attention to any personal data covered by the DPDP framework.
  2. Output ownership and intellectual property. Define who owns the outputs generated through your use of the tool, and address licensing and reuse so there is no ambiguity later.
  3. Accuracy, performance, and error liability. Set expectations for accuracy and reliability, and address responsibility for inaccurate or fabricated outputs rather than accepting blanket disclaimers.
  4. Confidentiality, data protection, and sub-processors. Carry data-protection obligations into the agreement or a linked data processing addendum, including sub-processor approval, breach notification, and deletion, consistent with DPDP duties.
  5. Security and incident response. Require defined security standards, incident notification timelines, and cooperation, recognising that AI services can introduce new threat surfaces.
  6. Indemnity. Allocate indemnity for third-party claims, including intellectual-property infringement arising from training data or outputs.
  7. Transparency and AI disclosure. Where relevant, require the vendor to disclose where and how AI is used in the deliverables or service, so you are not unknowingly exposed.
  8. Human oversight. Reflect the principle of meaningful human oversight for consequential decisions, in line with people-first governance expectations.
  9. Audit and standards alignment. Reserve audit or information rights and reference recognized standards or frameworks the vendor should align with, so claims can be verified rather than assumed.
  10. Exit, deletion, and transition. Provide for return or deletion of your data on exit, including confirmation, and for a transition that does not strand you.

How to Operationalize This Across Your AI Vendors

1. Build a reusable AI clause set or addendum

Rather than negotiating each AI deal from scratch, create a controlled set of AI clauses, or an AI addendum, that captures the terms above and can be applied consistently across vendors.

2. Standardize, then control deviations

Make the AI clause set the default, and route any weakening of key terms, such as training-data use or indemnity, through approval so exceptions are recorded with who approved them and why.

3. Connect AI contracting to data protection and third-party risk

Treat AI vendor agreements as part of your wider data-protection and third-party-risk governance, since an AI vendor is also a processor and a third party, not a separate category.

4. Keep an audit-ready trail

Hold executed AI agreements, addenda, and approvals in a central, permissioned repository with version history, so you can show what was agreed, by whom, and when.

India Guardrails for AI Vendor Contracting in 2026

  • Use the governance framework as your map. The India AI Governance Guidelines point to existing laws and sectoral regulators, so align AI contracting with the IT Act, the DPDP framework, and any rules from your sector's regulator.
  • Treat training data as personal data where it is. If your inputs include personal data, consent and purpose limitations under the DPDP framework apply, and the contract should reflect that.
  • Keep execution legally sound. Electronic signatures and records are recognized under the IT Act, 2000, which supports audit-ready execution of AI agreements and addenda.
  • Watch the moving parts. AI governance in India is phased and evolving, including proposals around labelling of AI-generated content. So build contracts you can update as expectations mature.

Disclaimer: This blog is general information and not legal advice. Have qualified counsel review AI vendor agreements against your specific risk profile and sector obligations.

Conclusion

Summing up, India has chosen to govern AI through existing laws and institutional oversight rather than a single statute, which puts the contract at the center of how AI risk is managed when you buy AI tools. Training-data rights, output ownership, accuracy and liability, data protection, indemnity, transparency, human oversight, audit, and clean exit are the terms that turn a generic software agreement into one built for AI.

The businesses that get this right will not treat each AI purchase as a one-off negotiation. They will standardize an AI clause set, control deviations through approvals, connect it to their data-protection and third-party-risk programmes, and keep an audit-ready record of what was agreed.

When the statute leaves room, the contract should not. That is what makes AI adoption fast and defensible at the same time.

Explore audit-ready AI vendor contracting with Doqfy today!

Sources and References