AI Governance Library

Contracting for Generative AI and mitigating Generative AI supply chain risks

Deloitte Legal white paper on contractual issues and mitigations for organisations procuring generative AI systems and for GenAI use by suppliers and service providers, including EU AI Act implications.
Cover of Contracting for Generative AI and mitigating Generative AI supply chain risks

⚡ Quick Summary

Published by Deloitte LLP, this white paper of December 2024 sets out contractual issues and risks to consider when procuring generative AI systems and when generative AI is used by suppliers and service providers. It states that it explains these matters on a largely jurisdiction-neutral basis and focuses on GenAI provided as a service, whether private or public cloud. It opens with adoption evidence, citing a 2024 Deloitte survey in which over 79% of CEOs expect GenAI to transform their organisations within three years.

The paper's central argument is that vendor terms for GenAI often do not fully address a purchasing organisation's interests and legal requirements, because contractual market practice has not yet been established, so organisations should evaluate vendor terms against their own minimum requirements and address risks explicitly in the contract. It works through legal issues including data privacy, intellectual property rights, confidential information, AI regulation, inaccuracy or “hallucinations”, opacity, liability and redress, bias and ESG, then offers contractual mitigations, four supply chain scenarios, EU AI Act role analysis, and four implementation pillars: contract templates and playbooks, due diligence, governance and procurement processes.

🧩 What’s Covered

The document is organised in five numbered sections, preceded by an introduction and followed by a contacts page.

  • Introduction and scope: defines GenAI as a subset of AI that uses training data to produce new content such as text, images, audio, video and software code, distinguishes direct procurement from indirect use of GenAI in the supply chain, and states the paper's purpose, scope and structure.
  • Section 1 – Key legal issues: catalogues data privacy (including automated decision-making rules under EU and UK law), intellectual property rights, confidential information, AI regulation described as “vertical” or “horizontal”, inaccuracy, opacity or the “black box”, liability and redress, bias, and ESG.
  • Section 2 – Procuring a GenAI system: addresses vendor terms versus the customer's minimum requirements, controller and processor roles, lawfulness of training data, misappropriation of inputs, ownership of and usage rights in outputs, sector regulation, pricing mechanisms (per token or output, per user, per interaction), liability caps, lock-in, ESG and cybersecurity under NIS2 and DORA, closing with eleven key questions to ask.
  • Section 3 – Supply chain risks: four scenarios – supplier-generated materials the customer wants to own, service provider decisions impacting individuals, confidential information shared with suppliers, and GenAI-assisted code development – plus eleven points for GenAI-specific clauses.
  • Section 4 – EU AI Act: its risk-based approach and the provider, deployer, importer and distributor roles, citing Regulation (EU) 2024/1689.
  • Section 5 – Putting theory into practice: four pillars – contract templates and playbooks, due diligence, governance, and procurement processes.
  • Get in touch: four named Deloitte Legal contacts.

💡 Why it matters?

The paper is aimed at organisations that buy GenAI rather than build it. It translates legal exposure – possible intellectual property infringement in training data, loss of confidentiality through vendor reuse of inputs, unclear ownership of outputs, bias in automated decisions – into contract-level questions about warranties, indemnities, usage rights, audit and exit. Its role analysis under the EU AI Act helps an organisation work out whether it acts as a deployer and what information and support it must obtain from a provider to meet its own obligations. The question lists and clause points are written to be used in negotiation and in procurement templates.

❓ What’s Missing

No model clause wording is provided; the mitigations appear as suggestions and checklists, so drafting still requires legal input. The EU AI Act discussion is presented as a brief introduction and does not map obligations to specific risk categories, timelines or penalties. The stated jurisdiction-neutral approach leaves country-by-country detail on intellectual property ownership and automated decision-making open, and the document describes those requirements as evolving. Pricing, ESG and cybersecurity are treated briefly, and coverage is limited to cloud-based, as-a-service GenAI. The authors state that remedying all procurement risks is close to impossible.

👥 Best For

Legal, commercial and procurement teams negotiating GenAI contracts on vendor terms; privacy and compliance officers reviewing controller and processor roles and automated decision-making; third-party risk and supply chain managers assessing indirect GenAI use; and governance teams building GenAI clauses, playbooks, due diligence questionnaires and audit rights.

📄 Source Details

The document is Contracting for Generative AI and mitigating Generative AI supply chain risks, dated December 2024 and issued by Deloitte LLP (Deloitte Legal), whose contacts are Dr Till Contzen, Paul O'Hare, Elizabeth Lumb and Louis Wihl. It runs to 25 pages in English. No series name, edition or reference number is printed, and no URL for the paper itself appears; the only web address is www.deloitte.com/about in the imprint. The full text of all 25 pages was available for this review.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.