From Shubhi K | Product & Market Analysis

What CFOs Actually Negotiate in AI Contracts, and Why Discount Ranks Last

On this page

46% of large-company CFOs name cost uncertainty as their biggest internal concern about AI. The answer they have arrived at is not a harder push on rate. AI contract negotiation in 2026 turns on six clauses that decide what a deal costs after signature: data rights, model change notice, price protection, exit, compliance flow-down and incident terms. Discount is the one the vendor most wants you to fight about.

Key takeaways

  • The US federal government has published the first standard AI contract clause, and it is a buyer's document. The GSA draft requires 72-hour incident notice and a flat ban on training any other customer's model on your data. It also requires 30 days of concurrent access to a new major model version before the old one is withdrawn.
  • Model change notice is the clause with the shortest fuse. Anthropic publishes a 60-day minimum before retiring a model. Its four most recent retirements ran 60, 62, 62 and 61 days, down from 189 days for Claude Opus 3 a year earlier.
  • Discount is worth least on exactly the contracts that are growing fastest. Vertice's benchmark data, drawn from its own negotiation dataset, puts consumption-based discounts 42% below seat-based ones, on plans that overshoot budget by around 40%.
  • Exit terms are won at signature or not at all. Morgan Lewis recommends treating termination assistance as a contractual obligation with pre-agreed rates, covering four separate classes of artefact rather than the single word "data".
72 hoursIncident notice window in the first US federal AI contract clause. Source: Holland & Knight analysis of the GSA proposed rule, March 2026.
46%of CFOs name cost uncertainty as their biggest internal AI concern. Source: Deloitte CFO Signals, Q2 2026, n=200.
60 daysAnthropic's published minimum notice before a model is retired. Source: Anthropic model deprecations, August 2026.

What "AI contract negotiation" covers in 2026

An AI agreement is not a software licence with a different logo on it. Three things about it behave differently, and each one has produced a clause.

The product changes underneath you without your consent. The vendor's economics change too, because inference is a variable cost rather than a fixed one, which is the reason AI gross margins keep getting rewritten. And your own data is an input to the vendor's product in a way it never was for a CRM seat.

So the negotiation has moved. The rate card is still there. It is no longer where the money is.

Why the discount conversation moved

Pricing models shifted first. Vertice reports that the share of software plans sold on a per-seat basis fell from about half to about a third inside twelve months, with the remainder consumption-based or hybrid. That is the same compression covered in the piece on what seat-based pricing is losing.

The consequence is commercial, not philosophical. On the same dataset, consumption plans carry discounts 42% below seat-based ones, cost about 37% more per user, and overshoot budget by roughly 40% against about 5% for seat plans. Treat those as directional. They are a vendor's own numbers, published to sell a cost-control product, and no methodology note accompanies them.

The direction is still the point. If a discount on a consumption contract is both smaller and applied to a number you cannot predict, then negotiating it hard is effort spent on the least controllable line in the deal.

Clause 1: data rights, and the training prohibition

This is the clause that has moved furthest in eighteen months, and the federal draft shows how far.

GSA's proposed clause, designated GSAR 552.239-7001 and released on 6 March 2026, gives the government ownership of all government data, inputs and outputs both, plus custom developments. It then bars the contractor from using that data to train, fine-tune or otherwise improve any model for another customer or for any commercial purpose.

That is not a negotiating position. It is a published default that a very large buyer intends to impose, which makes it the most useful redline text available to a much smaller one.

The default you inherit if you say nothing

Commercial defaults vary by product tier inside the same vendor. Consumer and free tiers commonly permit training on your content. Enterprise tiers commonly do not. The gap between those two positions sits inside one company and is decided by which order form you signed.

Ask for three things in writing. No training on your inputs or outputs for any purpose beyond serving you. Deletion obligations that cover derivatives, meaning embeddings, vector indexes and caches, not only the source files. And written certification that deletion happened, extended to subcontractors.

The derivative point is where most agreements are silent. A vendor can delete every document you uploaded and still hold a vector index built from them. If the clause says "customer data" and defines that term as files, the index is outside it. This is the mechanism behind the argument that workflow data, not raw data, is what actually holds a customer in place.

Clause 2: model change notice and version continuity

Every other clause on this list protects you from something that might happen. This one protects you from something that is scheduled.

Anthropic publishes its full deprecation history, which makes it the only lab whose actual notice behaviour can be measured rather than asserted. Its stated policy is at least 60 days' notice before retiring a publicly released model. Counting from each announcement to each retirement date gives the record below.

Days between deprecation announcement and retirement, Claude models
ModelAnnouncedRetiredDays of notice
Claude Opus 330 June 20255 January 2026189
Claude Sonnet 3.513 August 202528 October 202576
Claude Sonnet 3.728 October 202519 February 2026114
Claude Haiku 3.519 December 202519 February 202662
Claude Haiku 319 February 202620 April 202660
Claude Sonnet 4 and Opus 414 April 202615 June 202662
Claude Opus 4.15 June 20265 August 202661

Dates are from Anthropic's published deprecation history, accessed 20 August 2026. Day counts are calculated from the announcement date to the retirement date. Anthropic appears here because it publishes the record in one place, not because its practice is worse than a competitor's. Comparable histories for other labs are harder to reconstruct, which is itself a finding.

Notice periods are converging on the published floor Days between deprecation announcement and retirement, by announcement date 60-day published minimum Opus 3, Jun 2025189 Sonnet 3.5, Aug 202576 Sonnet 3.7, Oct 2025114 Haiku 3.5, Dec 202562 Haiku 3, Feb 202660 Sonnet 4, Opus 4, Apr 202662 Opus 4.1, Jun 202661
The shaded band is the published minimum. Four consecutive retirements have landed inside 2 days of it, so treat the floor as the plan rather than the worst case.

What 60 days actually buys you

Sixty days is enough to swap an API string. It is not enough to re-run an evaluation suite, retune prompts, requalify outputs with a risk function and get a change through a release board.

Three asks are winnable here. Notice measured in months rather than days for any model your production workload depends on. Concurrent access to the replacement while the incumbent still runs, which is exactly what the federal draft specifies at 30 days for a major version and 15 for a minor one. And no price change on a forced migration, because a deprecation you did not choose should not reset the commercial terms.

The third one is the sleeper. If your rate is tied to a named model, retirement of that model reopens pricing at a moment when you have no ability to walk. Tie the rate to a capability tier instead.

Clause 3: price protection and benchmark rights

A discount is a number. Price protection is a mechanism, and mechanisms survive the account manager who granted them.

Three mechanisms are worth more than a point or two of headline rate. A cap on renewal uplift, expressed as a fixed percentage or an index. Price holds on expansion, so that seats or units added in month 9 carry the same unit price as those bought at signature. And a benchmarking right that lets you test your pricing against comparable deals, with an obligation on the vendor to meet the benchmark or let you exit.

Tie the rate to a capability tier, not a model name

Here is the public case for why the price line moves. Federal agencies bought ChatGPT Enterprise, Claude and Gemini through GSA's OneGov arrangements at $0.47 to $1 per agency. More than 120 orders were placed, covering roughly 3.4 million workers. Those offers expire at the end of September 2026.

GSA's own official, Birgit Smeltzer, told FedScoop on 13 August 2026 that some vendors have agreed to extend and others are preparing new offers, while confirming that prices will eventually increase. The largest buyer in the world, holding 3.4 million users, has a renewal it cannot fully price. Your position is not stronger than that.

My view is that a renewal cap is the single highest-value clause on this list for a company under 500 people, because it is the only one that compounds. Everything else protects a single event. A cap protects every year of the relationship, and it is cheap for a vendor to grant in year one when they are trying to land you.

Clause 4: exit rights and portability

Switching an AI vendor in 2026 is limited by contract, not by engineering. The migration is a week of work. The agreement is three years long.

Morgan Lewis put the practical version of this in writing in February 2026. Treat exit as a formal workstream during negotiation, when leverage is highest. Make transition assistance a contractual obligation with pre-agreed rates rather than an informal expectation. The same note recommends run-off support for a limited period so the business keeps running while a replacement is stood up.

The four artefact classes

The reason exit clauses fail is that they name one thing and you own four. Separate them explicitly.

Customer data and inputs. Customer-developed artefacts, meaning prompt libraries, system instructions, workflows, evaluation datasets and guardrail configurations. Outputs, including the rights you hold to reuse them. And deletion obligations covering the vendor and every subcontractor, with written certification.

The second class is the one buyers forget and the one that actually costs money to rebuild. An evaluation set that took your team four months to assemble is not "our data" in most standard definitions. If the contract does not name it, you are rebuilding it at the exact moment you are also migrating. That is the practical switching cost behind the build-versus-buy question on coding agents, and it is contractual rather than technical.

Ask for export in documented, standard formats within a defined window, plus a change-of-control right that lets you exit at original pricing if the vendor is acquired. In a market where point tools are being absorbed into larger agent platforms, change-of-control is not a hypothetical.

Clause 5: compliance flow-down that survives a moving deadline

Most AI contracts written in 2025 flow down regulatory obligations by naming a statute and a date. That drafting choice has just aged badly.

The date moved in July

The EU AI Act's high-risk obligations were originally enforceable from 2 August 2026. The Digital Omnibus deferred them. Following political agreement in May 2026, obligations for standalone Annex III systems now apply from 2 December 2027, and systems embedded in regulated products from 2 August 2028.

The important part for a contract is what did not move. Article 50 transparency obligations remain on the original schedule, and 2 August 2026 stayed an active compliance date. A clause drafted as "the supplier shall comply with the high-risk requirements from 2 August 2026" is now either unenforceable or accidentally stricter than the law, depending on how it was worded.

Draft the obligation, not the date. Require compliance with applicable AI regulation as amended, require notice of any change that alters the system's regulatory classification, and require the documentation you would need to satisfy a regulator yourself. The European Commission's model contractual clauses for AI procurement, published for public buyers and reusable by private ones, are a reasonable starting text.

Clause 6: incident notice, audit and the transparency gap

The federal draft is most useful here because it puts numbers on things that commercial agreements leave to judgement.

It requires notice of a confirmed or suspected security incident within 72 hours, daily updates until resolution, and preservation of forensic artefacts for at least 90 days. It requires 30 days' written notice before a new service provider is added or substantially modified. And it requires notice of changes that materially increase bias or decrease safety guardrails, which is a disclosure obligation almost no commercial contract currently carries.

The notice windows the federal draft puts in writing GSAR 552.239-7001, proposed 6 March 2026. Not final. 72 hrs Security incident 15 days Minor model version access 30 days Major version access, new subprocessor 90 days Forensic artefact retention Ownership of inputs and outputs sits with the buyer. Training on buyer data for any other customer is prohibited outright. These are the numbers to quote back when a vendor says a window is not standard.
Every figure here is a published government position, which changes what "market standard" means in a negotiation.

Audit rights are the weakest of the six in practice. Most vendors will offer a third-party attestation report and refuse a direct audit, and for a buyer spending five figures a year that is a reasonable place to land. Push instead for a verification right you can actually exercise: named evaluation metrics, disclosure of material model changes, and access to the logs of your own usage.

Where this argument is weakest

Four honest problems with everything above.

The case for taking the discount instead

Clause negotiation has a cost. Legal time, elapsed weeks, and a finite amount of goodwill you can spend with a vendor before they stop returning calls. A 20% discount on a $120,000 contract is $24,000 in year one, banked, with no execution risk.

Every clause on this list is a contingent claim. It pays out only if the risk it covers materialises, and you have to enforce it. If your AI spend is small, your data is not sensitive and your switching cost is genuinely low, take the money. I would, and the analysis in the piece on where measurable AI return has actually appeared is the better use of that afternoon.

What this post cannot show you

There is no public dataset on what share of commercial AI contracts contain any of these clauses. The federal draft tells you what one buyer intends to require. The law firm guidance tells you what experienced counsel recommend. Neither tells you the win rate, and I am not going to invent one.

Two of the seven sources here also deserve a flag. The GSA clause is a proposed rule that has not been finalised, so it may change or lapse. The Vertice figures are a vendor's own benchmark, published alongside a product that sells cost control, with no sample-size note attached to the specific percentages. I have used them for direction only, and you should discount them the same way.

The last weakness is structural. Small buyers get paper, not negotiation. If you are signing a self-serve order form, none of this is available to you, and the honest advice is to keep contracts short and annual instead. That is a real limit on who this post is useful for.

The six clauses, ranked by what you are likely to actually get
ClauseWhat to ask forRealistic outcome
Data and training rightsNo training on your data, deletion of derivatives, certified deletionUsually granted at enterprise tier. Derivatives are the part that needs pushing.
Incident notice72 hours, daily updates, 90-day artefact retentionOften granted. Cheap for the vendor and now has a federal precedent.
Renewal capFixed percentage ceiling on uplift, price hold on expansionWinnable in year one. Very hard to add at first renewal.
Model change noticeMonths not days, concurrent access to the replacement, no price resetConcurrent access is achievable. Long notice periods are resisted hard.
Exit and portabilityExport in standard formats, four artefact classes named, transition rates agreedPartially winnable. Termination for convenience after 12 months is the common landing point.
Direct audit rightOn-site or third-party audit of the vendor's controlsRarely granted below very large spend. Take the attestation report.
What 200 CFOs say is actually hard about AI Deloitte CFO Signals, Q2 2026. Companies with at least $1bn revenue. Surveyed 22 May to 7 June 2026. GOVERNANCE CHALLENGES Speed versus risk59% No governance authority51% No visibility into AI tools43% TOP CONCERNS Cost uncertainty (internal)46% Content litigation (external)43% Regulatory complexity36%
Cost uncertainty outranks security and regulation as an internal worry. That is a contract problem before it is a technology problem.

One structural note before the questions. Every clause here assumes you know what you have bought. Most companies do not, and the application-sprawl numbers explain why 43% of these CFOs report no visibility into which AI tools their organisation is using.

Frequently asked questions

What should be in an AI vendor contract?

Six things beyond price. A prohibition on training the vendor's models on your data, including derivatives such as embeddings and indexes. Notice before a model version is changed or retired, with concurrent access to the replacement. A cap on renewal price increases. Exit rights covering data, prompts, evaluation sets and outputs. Compliance obligations drafted to the law as amended rather than to a fixed date. And a defined incident notification window.

Can AI vendors train on our company data?

It depends entirely on which tier you signed. Consumer and free tiers commonly permit it. Enterprise tiers commonly prohibit it, but you should confirm the prohibition covers model improvement generally, not only training a model used by other customers. Ask separately about derivatives. Deleting your files does not delete a vector index built from them unless the contract says so explicitly.

How much notice do AI vendors give before retiring a model?

Anthropic publishes a minimum of 60 days for publicly released models, and its recent practice sits very close to that floor. Its four most recent retirements ran 60, 62, 62 and 61 days from announcement, compared with 189 days for Claude Opus 3 in 2025. Treat the published minimum as the plan rather than the worst case, and negotiate for longer notice on anything in production.

What is a termination for convenience clause in a SaaS contract?

It is a right to end the agreement before the term expires without being in breach. Vendors rarely grant it outright on multi-year deals. The common landing point is a partial version: termination on 90 days' notice after the first 12 months, sometimes with a break fee that declines over the term. On AI contracts it matters more than usual, because the product you bought may not exist in the same form in 18 months.

Does the EU AI Act still apply from August 2026?

Partly. The Digital Omnibus deferred high-risk obligations for standalone Annex III systems to 2 December 2027, and to 2 August 2028 for AI embedded in regulated products. Article 50 transparency obligations and enforcement powers over general-purpose AI remained on the original schedule, so 2 August 2026 stayed an active compliance date. Contracts naming the old date need rewording to reference applicable law as amended.

Is it better to negotiate discount or contract terms with an AI vendor?

Terms, on any contract you expect to renew. A discount is a one-year benefit that resets at renewal, and on consumption-based plans it is applied to a quantity you cannot forecast. A renewal cap, a price hold on expansion and an exit right compound across the whole relationship. The exception is a small annual contract with low switching cost, where the cash is worth more than the paper.

Where to start this week

Pull your three largest AI contracts and search each one for four strings: "train", "terminate", "increase" and "delete". The absence of a hit is the finding.

Then pick the one renewing soonest and ask for exactly two things. A ceiling on renewal uplift, and written confirmation that your inputs, outputs and any derivatives are excluded from model training. Both are cheap for the vendor to grant and both keep paying after the account manager who granted them has moved on.

If you are told a request is not standard, quote the federal numbers back. A 72-hour incident window and 30 days of concurrent model access are now a published government position, which makes them a great deal harder to describe as unusual.

Related analysis

Contract terms are downstream of vendor economics. For why the price line keeps moving, read what inference costs are doing to AI margins, and for the pricing-model shift behind the discount squeeze, read the case on seat compression.

References

  1. Holland & Knight, GSA's Proposed AI Clause: A Deep Dive into New Requirements for Government Contractors, March 2026. Used for GSAR 552.239-7001 data rights, incident and model version notice windows.
  2. Anthropic, Model deprecations, accessed 20 August 2026. Used for the 60-day policy and every date in the notice-period table.
  3. Deloitte, Q2 2026 CFO Signals Survey, 2026. Used for all CFO percentages. Sample of 200 North American CFOs at companies with at least $1bn revenue, surveyed 22 May to 7 June 2026.
  4. Morgan Lewis, Building Exit Rights and Portability into AI Deals, 25 February 2026. Used for transition assistance and the four artefact classes.
  5. Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes, 2026. Used for the deferred compliance dates.
  6. FedScoop, GSA official on OneGov AI deals: Some extensions, some new offers coming, 13 August 2026. Used for OneGov pricing, order volume and the Smeltzer comment.
  7. Vertice, Vertice Launches AI Cost Optimization to Tackle Unchecked AI Spend, 2026. Used for the pricing-model and discount comparisons, treated as directional.

The weakest thing about this source base is its status. Reference 1 is a proposed rule that has not been finalised and may change. Reference 7 is a vendor's own benchmark published to support a product, with no sample-size note attached to the individual percentages. No public dataset exists on how often any of these clauses is actually agreed in commercial contracts, so this post describes the terms being asked for, not a measured win rate.

SK
Shubhi K
Founding Member, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading