An AI consulting contract should pin down nine things: deliverables with acceptance tests, price and change control, ownership of what's built, whose accounts it runs in, data handling, third-party tool costs and commissions, warranties and liability, handover documentation, and exit and support terms. Have a lawyer read it when personal data, large sums or customer-facing AI are involved.
AI projects need more than a generic consulting template because what you're buying is unusual: automations living inside your accounts, prompts and settings rather than a report, all resting on third-party tools that change their terms and prices, with outputs that are never perfectly predictable. The wording below is illustrative, not legal advice. Use it to know what to look for, what to ask for, and which gaps to raise before you sign.
Clause 1: deliverables and a test for "done"
This is the clause everything else depends on. It should list what will be delivered in terms you can check, and define an acceptance test: which real cases will be run, what counts as a pass, who tests, how long they have, and what happens on a fail.
"The Consultant will deliver the Order Intake Workflow described in Schedule 1. The Workflow is accepted when it processes the 50 test orders in Schedule 2 with no incorrect product, quantity or delivery date, and sends any order it cannot read to the Client's nominated inbox. The Client will complete testing within 10 working days of being told the Workflow is ready. If it fails, the Consultant will correct it and resubmit it at no extra charge."
Why it matters: "an AI-powered solution to streamline operations" can't fail, so it can't be enforced. A test with a number can. Build the test from your own past cases, including the awkward ones. How to scope an AI project covers writing deliverables and acceptance criteria in more depth.
Clause 2: price, payment stages and change requests
State whether the price is fixed or an estimate with a cap, what it includes, and when each payment falls due. Tie payments to things you can check, and keep a real sum back until acceptance and handover. Then describe how changes work, because AI projects attract "while you're at it" requests.
"The fixed fee is $X, payable 30% on signing, 40% when the Workflow is delivered for testing and 30% on acceptance and completion of the handover in clause 8. Either party may request a change in writing. The Consultant will state the cost and effect on timing of each change before starting it, and no change is chargeable unless the Client has approved that statement in writing."
Why it matters: without a written change process, every small addition becomes an argument at invoice time. Handling scope creep and change requests in AI projects goes further.
Clause 3: who owns the workflows, prompts and documents
You should own what was made for you: the workflows, prompts, configurations and documentation. Consultants often reuse their own templates and methods across clients, which is reasonable, as long as you get a permanent right to keep using whatever sits inside your system.
"All deliverables created for the Client under this agreement, including workflows, prompts, configurations and documentation, belong to the Client on payment. Where deliverables include the Consultant's pre-existing materials, the Consultant grants the Client a perpetual, royalty-free, non-exclusive licence to use, copy and modify them for the Client's business."
AI outputs add a wrinkle. OpenAI's and Anthropic's terms assign you their rights in outputs "if any", and Microsoft says it doesn't claim ownership of Copilot output but doesn't decide whether a given output is protected by copyright. Whether purely AI-generated material attracts copyright at all is unsettled and varies between countries. That's why the licence wording matters: it lets you use everything regardless of how the ownership question is eventually answered. Who owns the AI workflows a consultant builds covers the traps.
Clause 4: accounts, credentials and where things run
Everything should be built in accounts your business owns, on your payment card, with the consultant given their own user access that you can remove at any time. That includes API keys for AI models, which should be issued from, and billed to, your own developer account.
"All software accounts, subscriptions and API keys used for the deliverables will be held in the Client's name. The Consultant will use individual user access provided by the Client, will not share or store Client passwords, and will keep two-factor authentication enabled. On completion or termination, the Client will remove the Consultant's access and the Consultant will confirm in writing that it holds no remaining credentials."
Why it matters: an automation running in a consultant's own account stops working, or becomes a bargaining chip, the day the relationship ends. It's the single most common reason a small business ends up paying for the same build twice.
Clause 5: confidentiality and personal data
Two things belong here. First, confidentiality of your business information, including anything shared before the contract was signed. Second, if the consultant will handle personal data on your behalf, such as customer names, addresses or order histories, data-protection law such as the GDPR requires a written contract with particular terms. Article 28 of the GDPR lists them: the consultant processes the data only on your documented instructions, keeps it confidential, keeps it secure, uses other processors only on agreed conditions, helps you respond to people's requests about their data, deletes or returns it at the end, and gives you what you need to show compliance, including audits.
"The Consultant will process Client personal data only on the Client's documented instructions and only for the Services, using the tools and plans listed in Schedule 3, none of which use Client data to train AI models. The Consultant will not use personal or consumer AI accounts for Client data. At the end of the Services the Consultant will delete or return all Client personal data and confirm this in writing."
Why it matters: the tool list is the practical heart of it. Business plans such as ChatGPT Business, Claude Team and Gemini in Workspace don't train on business content by default; a consultant pasting your customer list into a personal account is a different matter. If you'll share data during scoping, before the contract exists, read whether to sign an NDA before sharing data with an AI consultant.
Clause 6: third-party tools, running costs and commissions
List every third-party tool the deliverables depend on, who pays for each, and the estimated monthly running cost at your stated volumes. Ask the consultant to disclose any commission, referral fee or partner benefit linked to tools they recommend, and to tell you about known price or product changes.
"Schedule 4 lists each third-party service used, its plan, and the Consultant's estimate of monthly running costs at the volumes in Schedule 1. The Consultant has disclosed in Schedule 4 any commission or referral fee it receives from these providers. The Consultant is not responsible for providers' price or product changes but will notify the Client of any it becomes aware of during the Services."
Why it matters: tools change under you. OpenAI's custom GPTs stop running on 11 December 2026, so anything built on one needs moving. A running-cost estimate in writing also stops the "it'll cost pennies" answer turning into a platform bill three times the size.
Clause 7: warranties, AI accuracy and limits on liability
No honest consultant will warrant that AI output is always right, and you shouldn't ask them to. What they can warrant is how they work: with reasonable skill and care, within the tools' terms of use, and to the standard set by the acceptance test. Then read the liability cap carefully. Caps are often tied to the fees paid; the question is whether that's enough compared with the worst plausible loss.
"The Consultant will perform the Services with reasonable skill and care and in line with the terms of use of the tools in Schedule 4. The Client acknowledges that AI-generated outputs may contain errors and that the review steps in Schedule 1 form part of the Workflow. The Consultant's total liability is limited to [amount], except for breach of confidentiality or data-protection obligations. The Consultant holds professional indemnity insurance of [amount] and will provide evidence on request."
If the project includes something customers talk to directly and you sell to customers in the EU, add who is responsible for the EU AI Act's transparency duties, such as telling people they're talking to an AI, which have applied since 2 August 2026. The practical step, a clear notice and a route to a person, belongs in the deliverables in clause 1.
Clause 8: handover and documentation
Handover should be a deliverable with a list, and the final payment should depend on it. Without that, documentation is the first thing dropped when a project runs late.
"Handover comprises: (a) a written description of each workflow, its triggers, steps and failure alerts; (b) a list of every account, connection and API key used; (c) all prompts in a document held by the Client; (d) the acceptance test results; (e) a recorded walkthrough; and (f) a session showing the Client's nominated staff member how to make the changes listed in Schedule 5. The final payment is due when handover is complete."
Why it matters: the day something breaks is usually the day you find out whether handover happened. The AI consultant handover checklist has the full list to attach as a schedule.
Clause 9: fixes, support and a clean exit
Three things to settle: a period after acceptance when defects are fixed free; what support costs after that; and how either side can end the contract, including what happens to work in progress and which clauses survive.
"For 30 days after acceptance, the Consultant will correct any defect in the deliverables at no charge. After that, support is available at the rates in Schedule 6. Either party may end this agreement on 14 days' written notice. On termination the Client will pay for work completed to date, and the Consultant will hand over all work in progress in its current state, with notes, within 7 days. Clauses 3, 4, 5 and 8 survive termination."
Why it matters: automations fail after launch for reasons nobody caused, such as a supplier changing an email format or a platform pausing a flow after repeated errors. Knowing in advance who fixes what, and at what price, turns a crisis into a routine email.
A weak proposal clause, rewritten
Here's a sentence of the kind that often appears in proposals, followed by what's wrong with it and a rewrite.
Before: "The Consultant will implement AI solutions to streamline the Client's operations, with ongoing optimisation as required."
- "AI solutions" names no deliverable.
- "Streamline" can't be tested.
- "Ongoing optimisation as required" is open-ended work with no price or end.
After: "The Consultant will deliver the Box Change Workflow in Schedule 1, accepted when it applies the 40 test emails in Schedule 2 with no incorrect change and sends unclear requests to the shop manager. Improvements after acceptance are outside this agreement and may be requested under clause 2."
The rewrite is less exciting and far more useful. It says what you get, how you'll know, and where the work stops.
A farm shop's contract, clause by clause
An illustrative farm shop hires a consultant to automate veg box changes (skips, swaps and address changes arriving by email) and to set up AI-drafted replies to common customer questions for staff to approve. Here's how its contract settles each clause.
| Clause | What the shop agreed |
|---|---|
| 1. Deliverables and test | Two workflows; accepted when 40 past change emails are applied with no wrong change, and 30 past questions get drafts the manager rates usable |
| 2. Price and changes | Fixed fee of $4,800 (illustrative): $1,440 on signing, $1,920 on delivery for testing, $1,440 on acceptance and handover; changes priced in writing first |
| 3. Ownership | Shop owns workflows, prompts and documents; consultant's templates licensed permanently |
| 4. Accounts | Built in the shop's Zapier and Google Workspace accounts; consultant access removed at handover |
| 5. Data | Customer data only in the shop's business accounts; no consumer AI tools; deletion confirmed at the end |
| 6. Tools and costs | Zapier Professional, estimated at the annual rate of $19.99 a month for current volumes; Gemini already included in Workspace; no commissions |
| 7. Warranties and liability | Reasonable skill and care; cap raised from the fee to 1.5 times the fee (see below) |
| 8. Handover | Written notes, prompt document, test results, recorded walkthrough, session with the shop manager |
| 9. Support and exit | 30 days of free fixes; then an hourly rate stated in the schedule; 14 days' notice either way |
The liability discussion is worth following. The draft capped liability at the fee, $4,800. The shop asked what the worst plausible failure would cost: a week of wrong boxes for all 220 customers, refunded at about $25 each, is $5,500, more than the cap. Rather than argue for an unlimited cap, the shop did two things: negotiated the cap up to 1.5 times the fee, and added a manager's review of every change for the first four weeks, which makes a week-long failure unlikely to go unnoticed. That's the practical way to handle liability in a small contract: compare the cap with a realistic worst case, then reduce the worst case as well as raising the cap.
When to have a lawyer read it
For a small, internal project with no personal data, careful reading against the nine clauses may be enough. Pay a solicitor or lawyer who handles commercial contracts to review the draft when any of these apply:
- The consultant will handle customers' or staff members' personal data.
- The system will talk to customers directly, or make or influence decisions about people.
- The fee, or the worst plausible loss, is more than you could comfortably absorb.
- The draft includes indemnities, unusual liability terms or exclusions you don't understand.
- You plan to sell or license what's built, so ownership really matters.
- It's a long retainer with automatic renewal or a long notice period.
- The consultant's standard terms say they override anything else you've agreed.
To keep the review affordable, send the lawyer the draft with a one-page note: what's being built, what data it touches, the figures involved, and which of the nine clauses you're unsure about. A focused question gets a faster, cheaper answer than "please check this contract".
Questions about signing an AI consulting contract
Should I sign the consultant's contract or use my own?
Most small businesses sign the consultant's standard terms plus a statement of work describing the job. That's fine, as long as you read the terms against the nine clauses here and ask in writing for anything missing. If you hire consultants often, a standard agreement of your own, drafted once by a lawyer, saves time and keeps terms consistent.
Is a statement of work the same as a contract?
Not quite. The statement of work describes this particular job: deliverables, acceptance tests, price, timing. The main terms cover the rules that apply to every job: ownership, confidentiality, liability, termination. You need both, either as two documents that refer to each other or as one document with both parts. Deliverables and tests belong in the statement of work.
What payment schedule is reasonable for an AI project?
Tie payments to stages you can check, and keep a meaningful final payment until the work passes its acceptance test and the handover is complete. Paying everything up front removes your bargaining power if the build stalls. For retainers, monthly payment with a short notice period is common. Whatever you agree, write down what triggers each payment.
Do I need a separate NDA as well?
Not if the contract's confidentiality clause covers information you shared before signing. If you need to share real business data during scoping, before the contract is agreed, sign a short non-disclosure agreement first, and share anonymised or made-up examples wherever you can until then.
What if the consultant uses subcontractors?
The contract should say whether they may, require your agreement before they do, name who they are, pass the same confidentiality and data terms down to them, and keep the consultant responsible for their work. Ask where subcontractors will access your data from and on which accounts, since that affects how your data-protection obligations apply.
Further reads
- Is Your AI Consultant Independent? Checking for Tool Commissions — How to check for commissions before clause 6 is agreed.
- Should You Pay an AI Consultant on Results? Success Fees Explained — If the proposal ties fees to results, what to watch.
- Fixed-Scope vs Hourly AI Consulting: Which Protects Your Budget? — Choose the pricing model before drafting clause 2.
- AI Software Contracts: Auto-Renewals, Price Rises, Notice Periods — The separate contracts for the software itself.
- AI Clauses for Agency Contracts: Disclosure, Ownership, Approvals — The other side: AI clauses when you're the supplier.
- What If Your AI Vendor Shuts Down? Checks Before You Commit — Checks for when a tool in clause 6 disappears.
- How to Evaluate an AI Implementation Proposal or Quote — A 22-point checklist for any AI implementation quote, with the phrases to pin down, a scoring sheet and two quotes compared over three years.
- What an AI Consultant Does for a Law Firm, and What It Costs — The five phases of a law-firm AI engagement, what each should hand over, how fees are built from consultant days, and proposal red flags.
- AI Contract Review for Small Firms: What It Catches and Misses — What AI contract review reliably catches, what it misses and why, with a worked review, a test method and a prompt that demands evidence.
- Can AI Review a Contract? What Small Business Owners Should Know — What an AI first read of a contract catches and misses, when to pay a lawyer, a clause-by-clause prompt and a tour operator's hotel contract read end to end.
- How to Choose an AI Consultant: 20 Questions to Ask First — Twenty questions to put to any AI consultant, what strong and weak answers sound like, and a scoring sheet filled in for a farm shop.
- What Is a Fractional Chief AI Officer and Do You Need One? — What a fractional chief AI officer does each month, what providers publish as prices, and cheaper set-ups that suit most small businesses.
- How to Vet an AI Consultant's Case Studies and References — A grouped vetting checklist, a case study taken apart claim by claim, a reference-call script with sample notes, and a church office choosing a consultant.
- How to Write a Request for Proposal for an AI Project — Eight sections every AI project RFP needs, a members' club's RFP filled in, a pricing table that makes replies comparable, and a scoring matrix.
- How to Judge Whether Your AI Consultant Delivered Value — A weighted scorecard for judging an AI consultant: scope delivered, results against baseline, adoption at 90 days, team independence and advice quality.
- AI Consultant Red Flags: 12 Warning Signs to Walk Away From — Twelve warning signs when hiring an AI consultant, each with an example, the question to ask, its innocent version and a scored two-proposal comparison.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: GDPR Article 28 (processor contracts); OpenAI and Anthropic terms on output ownership; Microsoft Learn, 'Data, privacy and security for Microsoft Copilot'; EU AI Act Article 50; OpenAI help pages on custom GPT retirement (checked September 2026). Clause wording is illustrative and not legal advice.