Samsung banned generative AI for 3 years rather than accept the data terms. Air Canada argued its chatbot was a separate legal entity. Both lost the same argument about who answers for an AI system.
Derek Mobley applied for more than 100 jobs and was rejected by everyone. When he sued in February 2023, he didn’t sue the employers. He sued Workday, whose AI screening tools had evaluated, ranked, and rejected the applications on their behalf. That decision is what turned a hiring dispute into a question about AI vendor management.
The rejections arrived within minutes, sometimes in the middle of the night. Across more than 100 applications since 2017, not one appeared to have been read by a person.
Three years on, the case is one of the most closely watched tests of who answers for an AI system. On June 22, 2026, US District Judge Rita F. Lin refused to dismiss the California Fair Employment and Housing Act claims and allowed a disability claim to proceed under the Americans with Disabilities Act (ADA).
The allegation is that the screening tools relied on proxy indicators of illness, like medical-related leave and patterns consistent with treatment and recovery, and flagged applicants on inferred health status rather than job qualifications. Nobody had to enter that information.
What kept Workday in the case was where the model lived. Plaintiffs allege the tools were built, trained, and operated from Pleasanton, so the screening originated in California regardless of where the applicant sat.
Workday says the buyer holds the controls. A spokesperson said customers maintain full control of their hiring processes and the tools are designed around human oversight.
"It's hard to incorporate humans into the process if the platform does the weeding out before humans have the ability to intervene."
—Valence Howden, Advisory Fellow, Info-Tech Research Group
Lin's order decides Workday's exposure, not the buyer's. In other words, holding a vendor liable doesn't move your obligations. It adds parties who may share them.
No customer agreement appears anywhere in the order. That leaves every CIO signing an AI vendor agreement this year with one question.
What is AI vendor management when you can't dictate the terms? It is the practice of controlling data use, output accountability, and compliance exposure across AI suppliers, and in Mobley's case, none of it came from a contract term.
In this article, we'll break down the 3 contract provisions where AI vendor management has the least leverage and what enterprises build when the terms don't cover them.
Mobley's case shows where AI vendor management fails first. The terms that decide who answers for a model's output are the ones buyers have the least room to change. In fact, AI agreements take more from the buyer than ordinary software agreements do.
Much of that comes from boilerplate written before generative AI existed, which now reaches things it was never drafted to cover. A clause letting a vendor "improve, build, or enhance" its products can extend to training and fine-tuning unless the buyer negotiates explicit limits.
The numbers show how wide that gap runs. Stanford Law School's CodeX center found that 92% of AI contracts claim data-usage rights beyond what service delivery requires, against a 63% market average. Liability runs the same way. 88% of AI vendors cap their own exposure, but only 38% cap the customer's.

So what are buyers doing about it? There is no settled playbook for AI vendor management yet, so enterprises are improvising. Some refuse the terms and ban the tools outright. Others treat AI vendor management as an internal build and scale AI across the organization with their own controls. A third group deploys first and contests liability for the output afterward.
Only the second builds a control. Refusing the terms isn’t a solution, and disowning the output isn’t a defense that holds up with a regulator. That is what changes for the CIO. A SaaS agreement is negotiated on uptime and support. An AI vendor agreement decides who may train on your inputs, who answers when the model is wrong, and who the regulator comes to after deployment.
Next, we'll walk through the 3 provisions where AI vendor risk management has the least leverage and what each one costs when it goes unaddressed.
AI vendor management rarely fails because legal missed something in the contract. More often, it fails because the terms that decide control were never on the table.
The problem isn't awareness either. Deloitte's State of AI in the Enterprise survey asked 3,199 leaders which AI risks concerned them most. Data privacy and security came first at 73%. Legal, intellectual property, or regulatory compliance followed at 50%, ahead of governance and model quality at 46% each.
So enterprises are worried about the right things, then sign contracts that don't cover them. An AI vendor risk assessment will surface every one of these. Surfacing is not the same as solving.

Here's an overview of the 3 places AI vendor management loses control:

Next, we'll walk through how 3 leading enterprises each ran into one of these provisions and what they built in response.
In early 2023, employees in Samsung Electronics' semiconductor unit entered source code and a recorded meeting into a consumer AI interface on 3 occasions. To handle this, Samsung first capped uploads at 1024 bytes per prompt.
The cap was a control Samsung could enforce on its own side, but it only solved part of the issue. It limited how much proprietary data could leave in a single prompt. It did nothing about the code and the meeting that had already gone out, because on the consumer tier, inputs trained the AI model by default. Samsung couldn’t retrieve that data, delete it, or get a commitment that it wouldn’t be used.
AI vendor management starts with a fence around your data. When a vendor won't write that fence into the contract, it has to come from somewhere else. Samsung tried a couple of substitutes before it found one that held. The byte cap was the first.
Removing the tool was next. In 2023, it banned generative AI on company devices and networks across its DX division, which covers smartphones and home appliances. The concern was that data sat on external servers, was hard to retrieve or delete, and might surface for other users.
That same year, Samsung started building an alternative. It partnered with a domestic technology company on an in-house model specifically to prevent the leak of business secrets that could occur on platforms developed by others. Samsung Gauss, developed by Samsung Research, was unveiled that November and put to work on employee productivity first.
Three years later, Samsung reopened the door. In June 2026, the DX division introduced 3 external generative AI services, chosen after testing with roughly 2,500 employees, alongside a dedicated security framework and new AI divisions across its affiliates.
"The adoption of external generative AI is not simply providing AI as a work tool, but rather a starting point for fundamentally transforming how we work and our execution speed."
—Roh Tae-moon, President and Representative, Samsung Electronics
Samsung tried to solve a vendor problem with its own settings, then by removing the vendor. Neither worked. The cap couldn't reach data the vendor already held, and the ban held only until the business needed the tools back.
What changed the answer was building its own model, a fence Samsung owned rather than one it had to ask for. When it returned to external services 3 years later, the fence was already standing, and it brought a security framework and 2,500 employees of testing, not better contract terms. That is what AI vendor management looks like when the terms won't move.
Air Canada found out where output accountability lands in a small claims tribunal. The Civil Resolution Tribunal of British Columbia found negligent misrepresentation in February 2024 and ordered Air Canada to pay $812.02 in damages, interest, and fees. A survey of the Canadian Legal Information Institute database found no earlier case on bad chatbot advice, making this apparently the first.
The award barely covers a single fare, but the finding behind it reaches much further.
None of it started as a legal question. On the day Jake Moffatt's grandmother died in November 2022, he asked the chatbot on Air Canada's website about bereavement fares. It told him he could submit a ticket for a reduced rate within 90 days of issue, even after the trip had happened. The words "bereavement fares" linked to Air Canada's own policy page, which said the opposite. Moffatt booked full fare to and from Toronto for $1,630.36.
The airline knew the chatbot was wrong. A representative admitted in writing months later that it had used misleading words and said the issue had been noted for updating, then offered a $200 voucher. Moffatt refused it and sued.
Then came the argument that drew the tribunal's attention. Air Canada said it couldn’t be held liable for information provided by its agents, servants, or representatives, including a chatbot. Tribunal member Christopher Rivers called it a remarkable submission and rejected it. He also rejected the argument that Moffatt should have clicked the link. Air Canada never explained why one page of its website was inherently more trustworthy than another.
"It establishes a common sense principle: If you are handing over part of your business to AI, you are responsible for what it does."
—Gabor Lukacs, President, Air Passenger Rights
In this case, there was no vendor at all, and that is where the insight sits. With a supplier in the picture, a buyer can point to indemnities and disclaimers and believe the exposure has moved. Air Canada had none of that and tried the next best thing, arguing its own software was a separate party.
The tribunal rejected it and required reasonable care to ensure the output was accurate. That is the standard every deployer faces, whether the system was bought or built, and human review inside the workflow is what meets it.
Home Depot put Flock Safety license plate cameras at the entrances and exits of its 233 California store parking lots. They capture the plate, make, model, and color of every vehicle that enters, log it with a timestamp and location, and feed it into a database law enforcement can search nationwide.
That network is now under pressure everywhere it operates. More than 90 cities have moved to cancel or reject Flock cameras, and an August 2026 investigation documented at least 50 officers charged with or accused of using plate readers to track partners and ex-partners without a case.
The cameras are Flock Safety's, but the obligation isn’t. Compliance is the one part of AI vendor management a buyer can’t hand off, even when the system belongs to someone else.
Five California residents filed a proposed class action on 1 May 2026 in the US District Court for the Northern District of California, alleging the retailer runs a covert surveillance operation in its parking lots. The case hasn't been decided.
California's ALPR Privacy Act doesn’t stop at the provider. It binds operators and end users, and requires a published policy carrying 7 mandatory elements.
Home Depot published one. Even so, the complaint alleges it omits at least 3 elements. It has no named custodian, no defined retention period, and a sharing clause with no limit on federal, out-of-state, or immigration access.
So pointing at the vendor doesn’t help. The statute makes the operator answerable for its own policy, sharing restrictions, and audit logs.
The vendor's record doesn’t make that easier either. The complaint cites two California audits from early 2026. Mountain View Police found Flock had set a camera to nationwide sharing without permission. A Ventura County audit found out-of-state agencies had run more than 364,000 searches after the department believed National Lookup had been off since 2023.
"The existence of access by out-of-state agencies, without the City's awareness, that circumvented the protections we purposefully built and believed were in place is frankly unacceptable."
—Michael Canfield, Chief, Mountain View Police Department
For its part, Flock says its products don’t use facial recognition, and none is in development. None of it shifts the exposure.
Nor does the argument that no harm was done. Three months before the filing, the First District held in Bartholomew v. Parking Concepts that collecting plate data without publishing the required policy is harm in itself, at a minimum of $2,500 per person.
That defendant had no policy at all. Home Depot has one, and whether a policy missing mandatory elements causes the same harm is a question the court expressly left open. Home Depot has announced no change since.
Plaintiffs want the court to make Home Depot monitor the system itself, allow independent audits for 3 years, and change or end any vendor relationship it can't verify. Each is a compliance obligation Home Depot couldn’t delegate to Flock, and each could have been written into the vendor contract at signature.
The Mobley case is still active, and no customer agreement appears anywhere in the order. What kept the vendor in it was where the model was built and how it behaved.
The same pattern holds across all three companies. Samsung couldn’t get its fence written in. Air Canada had no vendor to disown the output to. Home Depot holds the compliance obligation on cameras it did not install. In each case, the exposure was visible at signature, but the control wasn’t.
That gap is expensive. More than 40% of agentic AI projects are expected to be canceled by the end of 2027, with inadequate risk controls among the reasons.
So the question for any CIO signing on an AI vendor this year isn’t whether legal read the agreement closely enough. It is what you build when the agreement doesn’t cover you.
.avif)
AI reads contracts at volume and flags terms that fall outside market norms, which matters because AI agreements take more from the buyer than ordinary software agreements do. It finds the gaps, but it can’t close them.
Zero data retention processing means the vendor handles your inputs without storing them, so prompts, documents, and logs are never retained or used for training. It matters most when a vendor does not make training opt-in by default.
Ask whether your inputs train the model, who answers when an output is wrong, and who a regulator will approach after deployment. Then ask what happens if the vendor changes a setting on its own side. Vendors will often adjust terms or configurations on request, but a configuration isn’t a commitment, and the vendor can change it back. Any assurance that matters should be written into the agreement.
AI risk management is the practice of identifying and reducing the risks created by deploying AI, which fall into three categories: how your data is used, what happens when an output is wrong, and where regulatory exposure lands. Those risks are growing. The AI Incident Database logged 362 documented incidents in 2025, up from 233 the year before, while the share of organizations rating their incident response as excellent fell from 28% to 18%.
AI processes large datasets to flag threats and score exposure faster than manual review can. Applying it to your own vendors is harder, because the risk sits in the contract terms rather than in the data.
The four stages are selection, contracting and onboarding, performance management, and renewal or offboarding. AI shifts the weight to the second stage, because the terms agreed there govern training rights, output accountability, and compliance exposure for the entire deployment.