AI clauses in B2B contracts: 20 questions for software vendors and retail partners
From model training on your data to logging and liability, the questions fashion brands should ask AI vendors and wholesale partners before signing, mapped to the AI Act.
KEY TAKEAWAYS Summary by the editors
- Under Article 25 of the EU AI Act, a company that rebrands, substantially modifies or repurposes a high-risk AI system can become its provider, so contracts should state who is the provider.
- Article 25(4) requires providers of high-risk AI systems and their third-party suppliers to agree in writing on the information, capabilities and technical access needed for compliance.
- Deployers of high-risk AI must keep automatically generated logs under their control for at least six months, which requires vendors to make logs accessible.
- The EU Model Contractual Clauses for AI, updated in March 2025 to align with the AI Act, offer high-risk and light versions that can serve as a drafting reference.
- Generative AI providers must mark synthetic output in a machine-readable way under Article 50, a capability buyers can ask vendors to confirm.
Before signing any contract for software with AI features, a fashion brand should establish who is the AI provider, whether its data will train the vendor's models, what documentation and logs it will receive, and how responsibilities and liability are allocated. The same questions now apply to wholesale relationships, where brands and retail partners increasingly exchange product data, order proposals and sell-out data through AI-enabled tools. The checklist below groups 20 questions into five areas.
Why do AI clauses matter in fashion B2B contracts?
The AI Act places obligations on whoever plays a given role, not on whoever signed the purchase order. A brand that licenses a B2B ordering platform, a PIM with generative copy or a demand-planning tool is usually a deployer. But under Article 25 a deployer becomes a provider of a high-risk system if it puts its own name or trademark on it, makes a substantial modification, or changes its intended purpose so it becomes high-risk. White-labelled tools offered to retail partners under the brand's name deserve particular care.
Data flows are the second reason. Wholesale relationships carry sensitive information in both directions: unreleased line sheets, wholesale prices and margins from the brand; sell-through, stock and customer insights from the retailer. Once that data passes through AI services, contracts need to say whether it can be used for training, shared with other clients or retained.
What should you ask about roles and classification?
- Who is the provider of each AI system or feature in the contract, and who is the deployer?
- What is the intended purpose of each AI feature, as stated in the provider's instructions for use?
- Does the vendor consider any feature high-risk under the AI Act, and on what reasoning?
- Which general-purpose AI models are used underneath, and from which providers?

What should you ask about data?
- Will our data, prompts or outputs be used to train or improve models for other customers? Can this be excluded by contract?
- Where is data processed and stored, and which sub-processors are involved?
- How long are prompts, outputs and logs retained, and can we request deletion?
- How is confidential partner data, such as a retailer's sell-out figures, separated from other clients' data?
What should you ask about transparency and documentation?
- Does generated content carry machine-readable marking as required of providers under Article 50, and will it survive our export and publishing pipeline?
- Does any customer-facing chatbot disclose that users are interacting with AI at the first interaction?
- What technical documentation and instructions for use will we receive, and in which language?
- Will logs be available to us for at least six months if the system is high-risk, as deployers must retain them?
What should you ask about performance, change, liability and exit?
- How is accuracy measured for our use case, and can we see results on data similar to ours?
- How are we notified before model changes that could alter outputs, such as a new underlying model version?
- How will the vendor inform us of risks or serious incidents, and how fast?
- Can we suspend or switch off AI features without losing the core service?
- Who bears liability if generated content infringes third-party intellectual property, and is there an indemnity?
- Who owns outputs, such as generated product descriptions or images, and can we use them freely across channels?
- How will costs change if AI usage grows, for example through usage-based pricing?
- On exit, can we export our data, configurations and generated assets in a usable format?
| Area | Main legal reference | Questions |
|---|---|---|
| Roles and classification | AI Act Articles 3, 6 and 25 | 1 to 4 |
| Data | GDPR, trade secrets, contract | 5 to 8 |
| Transparency and documentation | AI Act Articles 26 and 50 | 9 to 12 |
| Performance, change, incidents | AI Act Article 26 monitoring duties; contract | 13 to 16 |
| Liability and exit | Contract, IP law | 17 to 20 |
How does this apply between brands and retail partners?
Wholesale contracts rarely mention AI today, yet AI increasingly sits between the parties: automated replenishment proposals, AI-generated product content syndicated to retailers' webshops, and analytics on shared sell-out data. Useful clauses for terms of trade or data-sharing agreements include:
- Permitted use of shared data, including whether either party may use it to train models.
- Responsibility for AI-generated product content that a retailer publishes, including disclosure of synthetic imagery.
- Human review of automated order proposals before they become binding.
- Notification if either side changes how AI processes shared data.
Partners also differ in maturity. A department store group may already run its own AI governance and send suppliers questionnaires; a small specialty retailer may not know which of its tools use AI. Agreeing a short, shared set of principles at account level, rather than negotiating each tool separately, tends to work better for both sides.

What are the practical limits?
Large AI vendors often offer standard terms with little room for negotiation, and smaller fashion companies have limited leverage. Where clauses cannot be changed, the questionnaire still has value: written answers document due diligence, inform the AI inventory and risk register, and identify tools that should not receive sensitive data. Answers should be refreshed at renewal, because AI features and underlying models change faster than typical contract cycles. Contracts allocate responsibility between parties, but they do not transfer legal duties that the AI Act or GDPR place on a deployer.
Frequently asked questions
What AI clauses should be in a software contract?
Key clauses cover provider and deployer roles, use of customer data for training, data location and retention, transparency features such as output marking, access to documentation and logs, change notification, IP liability and exit rights.
Can a software vendor train AI on my company's data?
Only if the contract and, for personal data, data protection law allow it. Many vendors offer opt-outs or enterprise terms excluding training, so the point should be settled in writing before signing.
When does a brand become an AI provider under the AI Act?
Under Article 25, a deployer becomes the provider of a high-risk AI system if it puts its own name or trademark on it, substantially modifies it, or changes its intended purpose so it becomes high-risk.
Are there model contract clauses for AI?
Yes. The EU Model Contractual Clauses for AI, updated in March 2025 for alignment with the AI Act, exist in a high-risk and a light version. They target public buyers but can guide private contracts.
One edition every weekday morning. Read in five minutes. Free for industry professionals.
SOURCES
- artificialintelligenceact.eu: Article 25, Responsibilities along the AI value chain
- artificialintelligenceact.eu: Article 26, Obligations of deployers of high-risk AI systems
- artificialintelligenceact.eu: Article 50, Transparency obligations
- European Commission Public Buyers Community: Updated EU AI model contractual clauses




