The 38-item AI MSA red-team checklist organises the contractual review around seven clause families (training-data carve-outs, output ownership + IP indemnification, model-deprecation rights, sub-processor expansion, kill-switch SLA, exit-data portability, regulatory + EU AI Act flow-through) where 2025-2026 enterprise AI MSA failures cluster; vendors scoring yes on 30+ items are contractually serious, 20-29 items are treatable through negotiation, and below 20 signals that the vendor's commercial position depends on retaining the rights the checklist is designed to constrain.
Premise: most enterprise AI MSAs in 2026 are recycled SaaS MSAs with an AI addendum bolted on, and the failure modes cluster in the addendum where standard cloud-procurement legal review is weakest. The 38-item structure is built for a working session between procurement and legal, complementing the operational AI Vendor Security Questionnaire (RES-001). Anchored to AM-121 (IT operations reality), GPT-4 base deprecation 2024, the EU AI Act Article 26 + Annex IV flow-through, and observable 2024-2025 procurement disputes. 60-day review cadence because contract language patterns evolve faster than the regulatory surface.
/holding/RES-005/Embed this claimiframe + oEmbed
The card auto-updates when the claim's status, last-reviewed date, or correction log changes. Embedders never need to refresh — the card is rendered live from the canonical record.
About this register
The Resources register tracks claims attached to long-lived tools, checklists, and templates. Each claim carries its own review cadence tied to the tool it accompanies, and corrections are appended whenever the underlying tool changes.
Reviews coming up in Resources
- RES-003 · Holding · next +50d (3 Jul 2026)
The four-phase agent incident runbook (detect within 4h, contain within 30s, roll back per action class, post-mortem wi…
- RES-004 · Holding · next +80d (2 Aug 2026)
The Works Council AI Notification Packet covers three EU jurisdictions (German BetrVG §87(1) point 6, Dutch WOR Article…
- RES-002 · Holding · next +80d (2 Aug 2026)
The pre-deployment AI DPIA template fuses GDPR Article 35 obligations with EU AI Act Article 26 (deployer) and Article…