Skip to content
Holding·last review7 May 2026

SMBs without legal teams sign AI vendor MSAs that lock them in via seven recurring clause patterns: (1) data-portability narrowness (prompts/embeddings/agent state excluded from 'your data' definitions), (2) auto-renewal with short notice windows, (3) model-deprecation rights without credit, (4) sub-processor expansion without consent, (5) output-IP ambiguity, (6) pricing escalator without cap, (7) termination-data export window too short. Pattern recognition + a 1-page checklist applied before signature is the practical defence. Five questions emailed to the vendor sales rep before signing — and their willingness to answer in writing — is itself a signal.

SMB-specific procurement piece. Lead-magnet pair with RES-005 (AI MSA Red-Team Checklist downloadable). Cadence 45-day (vendor MSA template revisions + EU AI Act enforcement guidance both move at this cadence). Trigger conditions: major AI vendor MSA template revision (Microsoft, OpenAI, Anthropic, Google all publish public MSAs); new EU AI Act Article 16 implementation guidance affecting deployer obligations; SMB-tier consumer protection rulings on auto-renewal / data-portability. Sister claims: AM-145 (enterprise-tier exit clauses), OPS-014 (vendor due diligence small business), RES-005 (MSA red-team checklist).

Published
7 May 2026
Last reviewed
7 May 2026
Next review
+44d· 21 Jun 2026
Cohort
SMB without legal team
Cadence
45-day
Sibling claim
AM-145AI vendor exit clauses: the 2026 procurement red-flag checklist
Embed this claimiframe + oEmbed
HTML iframe
Paste-the-URL (Substack, Medium, Notion, WordPress)

The card auto-updates when the claim's status, last-reviewed date, or correction log changes. Embedders never need to refresh — the card is rendered live from the canonical record.