The regulatory backdrop is tightening, not loosening
While industry leaders debate self-regulation, regulators in major markets are moving ahead with binding rules. The EU AI Act, for example, imposes obligations on providers of high-risk AI systems, including conformity assessments and post-market monitoring. In the United States, sectoral regulators and the Federal Trade Commission have signalled that existing consumer protection and anti-discrimination laws apply to AI. The UK has taken a more principles-based approach, but its regulators have published expectations for AI governance. This means that even if vendors argue against new AI-specific regulation, they already operate within a patchwork of enforceable rules. For enterprise buyers, the relevant question is not whether regulation is desirable but whether their contracts allocate compliance risk clearly. A vendor that claims 'we don't need regulation' may still be subject to it, and may still pass on the cost of non-compliance to customers through indemnity gaps or service interruptions.What vendors are saying, and what it means for buyers
OpenAI's Sam Altman told the BBC that the world is 'right to be afraid' but 'should trust' AI firms. The statement acknowledges public concern while asking for confidence in corporate stewardship. Nvidia's Jensen Huang went further, arguing that AI safety should be left to industry rather than regulation. Both positions rely on the premise that vendors will act responsibly without external enforcement. For procurement leaders, such assurances are not sufficient diligence. They are marketing claims. The appropriate response is to demand evidence: independent safety evaluations, red-teaming results, model cards, incident logs and clear escalation paths. Where vendors refuse to provide these, buyers should treat the refusal as a risk signal.A diligence checklist for AI contracts
Enterprise buyers should embed specific requirements into AI contracts. First, demand auditable safety testing. This means the right to commission or receive third-party evaluations of the model or system, not just internal reports. Second, require incident reporting. Vendors should be obligated to notify customers of safety failures, data breaches or model drift within a defined period. Third, clarify liability. Indemnities should cover not only intellectual property infringement but also harms arising from safety failures, with caps that reflect the potential impact. Fourth, insist on transparency about training data and model limitations. Buyers need to know what the system cannot do, not just what it can. Fifth, build in audit rights. Contracts should allow customers or their designated auditors to inspect safety controls and compliance records. Sixth, include termination rights for material safety breaches. Without these, buyers are locked into multi-year commitments even if the vendor's safety posture deteriorates.The cost of inaction
The risk of not addressing the trust gap is twofold. Operationally, a safety failure can disrupt services, harm customers and trigger regulatory action. Reputationally, boards and investors are increasingly attentive to AI governance. A company that cannot demonstrate it asked hard questions of its AI vendors may face scrutiny from its own stakeholders. Moreover, the trust gap is not static. As AI systems become more capable and more embedded in critical workflows, the consequences of failure grow. Procurement teams that treat safety as a checkbox today may find themselves renegotiating contracts under duress tomorrow.How to structure the negotiation
Buyers should separate the conversation into three tracks: technical, legal and commercial. Technically, ask for evidence of safety testing and continuous monitoring. Legally, negotiate liability, indemnity and audit clauses. Commercially, link payment milestones to safety deliverables and consider shorter initial terms with renewal options contingent on performance. It also helps to benchmark vendors against each other. If one vendor accepts independent testing and another refuses, that difference should be reflected in pricing and risk allocation. The market is still forming, but early movers can set a precedent that raises standards across the sector.What to watch next
Regulatory developments will continue to shape the trust gap. The EU's implementation of the AI Act, the UK's approach to AI governance and US enforcement actions will all provide signals. Vendor behaviour will also matter: whether OpenAI, Nvidia and others translate their public statements into contractual commitments. For now, the burden of diligence falls on buyers. The evidence supports a cautious approach: treat self-regulation claims as a starting point for negotiation, not a substitute for it.Sources and References
- BBC News (bbc.co.uk)
- TechCrunch (techcrunch.com)
Why It Matters
The trust gap between vendor assurances and regulatory pressure creates a material risk for enterprise buyers. Without contractual safeguards, companies may bear the cost of safety failures they cannot control. This brief provides a framework for procurement and risk leaders to demand evidence and allocate liability before signing multi-year AI contracts.FY Outlook
Expect continued divergence between industry self-regulation claims and regulatory action. The EU AI Act's implementation and US enforcement will set precedents. Vendors that offer auditable safety testing and clear liability terms may gain a competitive advantage. Buyers should monitor vendor behaviour and be prepared to renegotiate contracts as standards evolve.The reporting and evidence for this briefing were checked against bbc.co.uk (bbc.co.uk) and techcrunch.com (techcrunch.com).



