Under active development Content is continuously updated and improved

GV-6.2-007Review vendor contracts and avoid arbitrary or capricious termination of critical GAI technologies

>Control Description

Review vendor contracts and avoid arbitrary or capricious termination of critical GAI technologies or vendor services and non-standard terms that may amplify or defer liability in unexpected ways and/or contribute to unauthorized data collection by vendors or third-parties (e.g., secondary data use). Consider Clear assignment of liability and responsibility for incidents, GAI system changes over time (e.g., fine-tuning, drift, decay); RequestNotification and disclosure for serious incidents arising from third-party data and systems; Service Level Agreements (SLAs) in vendor contracts that address incident response, response times, and availability of critical support.

>Cross-Framework Mappings

Ask AI

Configure your API key to use AI features.