[codicts-css-switcher id=”346″]

Global Law Experts Logo
ai vendor contracts spain

Our Expert in Spain

How to Negotiate AI Vendor Contracts in Spain (2026): Clauses, Liability, IP & Compliance

By Global Law Experts
– posted 2 hours ago

Search intent at a glance

  • Audience: Startups, scale-ups, general counsel, procurement managers and investors negotiating AI vendor agreements in Spain.
  • Outcome: An actionable negotiation playbook, sample clause language, regulatory mapping (EU AI Act and GDPR), a liability matrix and a due diligence checklist tailored to Spanish practice.
  • Read time: approximately 14 minutes.

AI vendor contracts Spain has become one of the most pressing commercial concerns for founders, general counsel and procurement teams in 2026, as the phased application of the EU AI Act collides with established GDPR obligations and Spanish enforcement practice. This guide translates those regulatory duties into negotiable contract language, so that a startup buyer can allocate compliance responsibility, limit liability, and secure the intellectual property and usage rights it actually needs. The material below moves from regulatory context to a clause-level checklist, a liability comparison table, an IP and licensing framework, a procurement due diligence list, and a practical negotiation playbook.

Every sample clause is offered as drafting starting-point language to be adapted to the facts and reviewed by qualified counsel. Read it as a working document rather than a substitute for advice.

1. Executive AI Overview: what startups must know in 2026

By 2026, a Spanish company that buys or integrates artificial intelligence is operating inside three overlapping legal regimes at once. The first is the EU AI Act (Regulation (EU) 2024/1689), the European Union’s horizontal framework that classifies AI systems by risk and imposes obligations on both providers and deployers; its provisions apply on a staggered timeline, with different obligations becoming applicable at different dates following its entry into force. The second is the General Data Protection Regulation (GDPR), which governs any AI system that processes personal data.

The third is Spanish national practice, shaped by the Agencia Española de Protección de Datos (AEPD) as the country’s data protection regulator, by the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) as the designated national AI authority, and by domestic rules on public procurement and civil liability.

The practical takeaway is simple: contractual silence is now a risk in its own right. If your AI vendor agreement does not say who performs conformity assessments, who maintains technical documentation, who runs the data protection impact assessment, and who bears the cost when a regulator imposes a fine, then those questions will be answered after the fact, usually against the party with the weaker paper trail. Well-drafted ai vendor contracts Spain buyers rely on convert regulatory duties into enforceable covenants, warranties and indemnities.

The essentials every startup should internalise before entering negotiations:

  • Classify the system first. The obligations that must flow into your contract depend on how the AI system is categorised under the EU AI Act’s risk-based approach (for example, prohibited, high-risk, or subject to transparency obligations).
  • Map who is provider and who is deployer. Your role determines which statutory duties you must satisfy and which you can push onto the vendor.
  • Treat GDPR as inseparable from AI. Most commercial AI touches personal data, triggering data processing agreements, DPIAs and breach notification duties.
  • Do not assume fines are transferable. Regulatory penalties cannot always be shifted by contract; you need indemnities and insurance as backstops.
  • Secure exit and continuity. Model access, data portability and escrow protect you when the vendor relationship ends.

2. Regulatory and legal context in Spain (EU AI Act, GDPR, public procurement)

Understanding the regulatory architecture is the precondition for drafting sensible ai vendor contracts Spain teams can defend. This section maps the principal obligations onto the two contracting roles, provider and deployer, and explains where Spanish public procurement adds a further layer.

a) EU AI Act: obligations for providers and deployers

The EU AI Act, described by the European Commission’s regulatory framework for AI, adopts a risk-based approach. Systems classified as high-risk attract the heaviest set of duties, including conformity assessment, technical documentation, risk management, logging, human oversight and transparency toward affected users. Providers, the entities that develop an AI system or place it on the market under their own name or trademark, bear the primary compliance burden. Deployers, organisations that use an AI system under their authority in a professional capacity, carry their own, generally lighter duties, such as using the system in accordance with instructions, ensuring appropriate human oversight and, in some cases, informing affected persons.

For contracting purposes, the crucial point is that these roles are not fixed by the label on the invoice. A startup that substantially modifies a purchased high-risk AI system, or puts it on the market under its own name, can find itself reclassified as a provider, inheriting the more onerous obligations. Your contract should therefore fix the parties’ roles expressly, require the vendor to warrant its own provider-side compliance, and oblige it to deliver the documentation you need to satisfy your deployer duties.

b) GDPR and DPIAs for AI systems

Where an AI system processes personal data, the GDPR (Regulation (EU) 2016/679) applies in full. Two provisions dominate AI vendor relationships. Article 28 governs the controller–processor relationship and prescribes the mandatory content of a data processing agreement, including processing purpose, duration, security measures, subprocessor controls and audit rights. Article 35 requires a data protection impact assessment (DPIA) where processing is likely to result in a high risk to the rights and freedoms of individuals, a threshold that AI-driven profiling, large-scale processing and automated decision-making frequently cross.

Guidance from the European Data Protection Board (EDPB) assists in interpreting DPIA triggers and cross-border data flows, while the Agencia Española de Protección de Datos (AEPD) sets the national enforcement posture in Spain and publishes practical guidance on data protection in AI contexts. Your contract must therefore allocate DPIA responsibilities, define controller and processor roles, and require the vendor to support you with the information a DPIA demands.

c) Spanish public procurement and national guidance

Where the buyer is a public body, or a startup selling into the public sector, Spanish public procurement rules add constraints. Domestic public sector contracts legislation, published in the Boletín Oficial del Estado (BOE), governs tendering, transparency, equal treatment and technical specifications for public contracts, and these rules shape how AI systems can be procured and what terms may be imposed. Procurement red flags include specifications that lock in a single vendor’s proprietary model, the absence of audit and portability rights, and inadequate flow-down of AI Act and GDPR obligations to subcontractors.

International policy context is also useful when framing a negotiation stance. The OECD AI Principles articulate widely endorsed expectations around transparency, accountability and robustness that increasingly inform both regulator guidance and reasonable market practice.

How Spanish law compares to US law

For buyers accustomed to US agreements, several structural differences matter. Spain is a civil law jurisdiction with a comprehensive, statute-driven data protection regime under GDPR and AEPD enforcement, contrasting with the more fragmented, state-and-federal US privacy landscape. Spanish courts generally enforce reasonable contractual liability caps between commercial parties, but liability arising from wilful misconduct (dolo) typically cannot be excluded, and statutory penalties are not freely transferable by contract. IP assignment norms and the treatment of regulatory fines also diverge. These differences make Spain-specific drafting essential rather than optional.

3. Core contract clauses: a checklist and sample language for ai vendor contracts Spain

This is the operational heart of the guide. Each subsection below sets out what the clause must achieve, offers sample drafting language to adapt, and flags the buyer’s typical red lines. Treat every sample as starting-point text, sample language, adapt to the facts and review with counsel before use.

a) Definitions and scope of services

AI agreements fail most often at the definitions stage, because parties use the same words to mean different things. Distinguish clearly between the Software (the platform and interfaces), the Model (the trained weights and architecture), the Outputs (the content the system generates), and the Training Data and Input Data. Precise definitions determine who owns what and who is responsible when something breaks.

Sample, adapt: “‘AI System’ means the software, the Model, the associated APIs and documentation supplied by the Vendor under this Agreement. ‘Model’ means the trained parameters, weights and architecture underlying the AI System. ‘Outputs’ means any content, prediction, classification or recommendation generated by the AI System in response to Customer Input Data.”

b) Compliance and regulatory obligations

This clause converts the EU AI Act and GDPR into contractual covenants. It should fix each party’s regulatory role, require the vendor to maintain conformity where it acts as provider, and oblige it to furnish the documentation the buyer needs as deployer.

Sample, adapt: “The Vendor warrants that, in respect of any high-risk AI System supplied hereunder, it has completed the conformity assessment required under applicable EU law, maintains up-to-date technical documentation, and shall provide the Customer with such information as is reasonably necessary for the Customer to discharge its obligations as a deployer. The Vendor shall notify the Customer without undue delay of any material change affecting the AI System’s regulatory status.”

Buyer red line: the vendor should not be permitted to disclaim all responsibility for AI Act compliance while retaining control of the model and its documentation.

c) Performance, accuracy and explainability warranties

Generic “the software will perform materially in accordance with the documentation” language is inadequate for AI. Specify measurable performance metrics, accuracy thresholds appropriate to the use case, service levels with remedies, and, where the AI Act or the use case demands it, explainability commitments that let the buyer understand and, where necessary, contest outputs.

Sample, adapt: “The Vendor warrants that the AI System will achieve the accuracy metrics set out in Schedule [X] measured over each calendar month. Where measured accuracy falls below the agreed threshold, the Customer shall be entitled to service credits calculated per Schedule [Y] and, upon persistent failure, to terminate for cause. The Vendor shall on request provide a reasonable explanation of the principal factors influencing a given Output.”

d) Change management and model updates

AI models change constantly, and an update that improves aggregate performance can degrade behaviour on the buyer’s specific data. The contract must give the buyer notice of material model changes, the right to test before deployment, and a mechanism to roll back or reject changes that break agreed metrics.

Sample, adapt: “The Vendor shall give the Customer no less than [30] days’ prior written notice of any material change to the Model that may affect performance, accuracy or regulatory status. The Customer may test the updated Model in a staging environment and, where the updated Model fails to meet the agreed metrics, require the Vendor to maintain the prior version for a transition period of not less than [90] days.”

e) Transparency, logs and audit rights

The EU AI Act’s logging obligations and the GDPR’s accountability principle both push toward record-keeping. Secure the buyer’s right to access logs, to audit the vendor’s compliance, and to receive the documentation needed to demonstrate its own compliance to a regulator such as the AEPD.

Sample, adapt: “The Vendor shall maintain automatically generated logs of the AI System’s operation for the period required by applicable law and shall make such logs available to the Customer on reasonable request. The Customer, or its appointed auditor bound by confidentiality, may audit the Vendor’s compliance with this Agreement not more than once per year on [30] days’ notice, and additionally following any Security Incident.”

f) Security obligations and breach notification

Article 32 of the GDPR requires appropriate technical and organisational measures. The contract should specify a baseline security standard, oblige the vendor to notify the buyer of security incidents within a short, defined window that supports the buyer’s own regulatory notification duty (under Article 33 GDPR, without undue delay and where feasible within 72 hours of becoming aware), and require cooperation in remediation.

Sample, adapt: “The Vendor shall implement and maintain the technical and organisational measures set out in Schedule [Z], which shall meet or exceed the requirements of Article 32 GDPR. The Vendor shall notify the Customer of any Personal Data Breach without undue delay and in any event within [24] hours of becoming aware, providing sufficient information to enable the Customer to meet its obligations under Article 33 GDPR.”

g) Data processing, datasets and training data provenance

This is where GDPR and AI-specific risk meet. The buyer needs a compliant data processing agreement, clarity on whether its data may be used to train or improve the vendor’s models, and warranties on the provenance and lawfulness of the training data the vendor itself used.

Sample, adapt: “The Vendor shall process Customer Personal Data only on documented instructions from the Customer and shall not use Customer Data to train, retrain or improve any Model except with the Customer’s prior written consent. The Vendor warrants that the datasets used to train the Model were lawfully obtained and that their use does not infringe the intellectual property or data protection rights of any third party.”

Buyer red line: silent, default use of buyer data for model training. This should require explicit opt-in, not opt-out.

4. Liability, indemnities and insurance, who bears the risk?

Liability allocation is where ai liability clauses spain buyers most need discipline, because the default position in most vendor templates transfers as much risk as possible to the customer. The negotiation is about caps, carve-outs, indemnities and insurance working together.

a) Limits on liability and enforceability in Spain

Spanish courts generally uphold reasonable liability caps agreed between commercial parties. However, under Spanish civil law liability for wilful misconduct (dolo) cannot be excluded in advance, and liability for statutory penalties cannot simply be excluded by drafting. A well-structured clause therefore sets a headline cap for ordinary contractual breaches while carving out specific high-severity events, data breaches, IP infringement and breach of confidentiality, for a higher or uncapped ceiling.

b) Indemnities: data, IP and regulatory fines

Indemnities shift the cost of specific, identifiable events. The buyer should seek indemnities for third-party IP infringement claims arising from the model or its outputs, for losses flowing from the vendor’s breach of its data protection obligations, and, to the extent lawfully permissible, for losses attributable to the vendor’s non-compliance. Because statutory fines cannot always be transferred outright, the indemnity should be framed to cover losses and costs arising from the vendor’s breach that give rise to such fines, backed by insurance.

c) Insurance options and negotiation tips

Require the vendor to maintain, and evidence, appropriate insurance, typically professional indemnity and cyber cover, at limits proportionate to the deployment’s risk. Insurance is the practical backstop where contractual caps and indemnities reach their legal limits. Ask for certificates, name the buyer as an additional insured where feasible, and require notice of any material change in cover.

Liability allocation: vendor vs buyer vs insurer, practical comparison

Risk / event Vendor liability (typical contractual treatment) Buyer protection (contractual remedies) Insurance cover (typical product) Negotiation tips
Data breach caused by vendor Often capped; buyer should push for a higher or uncapped sub-limit Indemnity, breach notification support, termination for cause Cyber / data breach liability Carve breach out of the general cap; tie to insurance limits
Third-party IP infringement in model or outputs Vendor indemnity expected; vendors often try to limit or exclude Full indemnity, defence obligation, replacement or modification IP infringement / professional indemnity Resist output-based carve-outs; require defence and settlement control safeguards
Regulatory fine (GDPR / AI Act) from vendor breach Frequently excluded; not always lawfully transferable Indemnity for losses arising from breach where permitted Regulatory / cyber (where cover permits) Frame as loss-arising indemnity; rely on insurance backstop
Service failure / accuracy shortfall Service credits; capped direct damages SLA credits, escalation, termination for persistent failure Rarely insured Prioritise meaningful credits and clear termination triggers
Wilful misconduct (dolo) Cannot be lawfully excluded in advance under Spanish law Uncapped liability preserved Generally excluded from cover Confirm express carve-out from all liability caps

5. IP, licensing and model ownership

Intellectual property is where deals about ai software licensing spain buyers negotiate can quietly go wrong, because the “software” you license and the “model” and “outputs” you rely on are legally distinct assets that may sit with different owners.

a) Ownership of models and outputs

Establish who owns the model, who owns the outputs, and what rights the buyer has to use each. Vendors typically retain ownership of the model and grant a licence; the buyer usually needs, at minimum, ownership or a broad, perpetual, royalty-free licence over the outputs generated from its own data, together with confirmation that it may use those outputs for its intended commercial purpose without further restriction. Note that the legal protectability of AI-generated outputs is itself uncertain and evolving, so the contract should focus on securing usage rights rather than assuming copyright vests automatically.

b) Licences for models and components

Modern AI systems are assemblies of proprietary code, open-source components and third-party model APIs, including large language models accessed under upstream terms. The contract should require the vendor to disclose material open-source and third-party dependencies, warrant that their licences permit the intended use, and pass through, or shield the buyer from, any restrictive upstream terms. Undisclosed copyleft obligations or restrictive API terms can otherwise surface as compliance liabilities later.

c) Transfer and licensing on termination

Address what happens to the buyer’s rights when the agreement ends. The buyer should secure a defined wind-down period, the return or deletion of its data, and, where the deployment is business-critical, a continuing licence or export of the model version it depends on.

d) Escrow and reproducibility for critical models

For mission-critical AI, consider model escrow. Define precisely what is deposited, model weights, training data or its documented provenance, build scripts and configuration, the release triggers (vendor insolvency, material breach, discontinuation), and the confidentiality regime protecting the deposit. Reproducibility matters: a set of weights with no build instructions may be unusable in practice.

6. Vendor due diligence and procurement checklist for Spanish startups

Contract terms are only as good as the diligence behind them. Effective ai procurement spain teams run pairs each negotiated clause with documentary evidence that the vendor can actually meet it.

a) Document request list

  • Evidence of conformity assessment for any high-risk AI system, and the technical documentation.
  • Records of accuracy and performance testing, with methodology.
  • Data provenance documentation for training data and confirmation of lawful basis.
  • The vendor’s data processing agreement, subprocessor list and cross-border transfer mechanisms.
  • Security certifications, penetration test summaries and audit log samples.
  • Insurance certificates evidencing professional indemnity and cyber cover.
  • Open-source and third-party dependency inventory with associated licences.

b) Red flags and walk-aways

  • Refusal to warrant AI Act or GDPR compliance while retaining control of the model.
  • Default use of buyer data for model training without an opt-out.
  • No audit or log access rights.
  • Blanket exclusion of liability for data breaches or IP infringement.
  • Undisclosed reliance on third-party model APIs with restrictive or opaque upstream terms.

c) Public procurement add-ons for public sector buyers

Public sector buyers must layer procurement-law requirements onto commercial diligence: transparency of specifications, equal treatment of bidders, and flow-down of AI Act and GDPR obligations to subcontractors. Specifications should avoid inadvertently locking in a single proprietary model, and audit and portability rights should be non-negotiable.

7. Negotiation playbook: red lines, bargaining chips and timelines

Bargaining power shapes everything. A startup buying a standard SaaS AI product from a large vendor has limited leverage on core terms but can often win on the specifics that matter most, data-use restrictions, breach carve-outs and audit rights. A buyer commissioning a bespoke system has far more room to negotiate ownership, escrow and indemnities. Sequence the negotiation: agree definitions and roles first, then compliance and data terms, then liability and IP, leaving commercial concessions as trading chips.

Buyer priority (hold firm) Concession the buyer can offer in exchange
Uncapped liability for data breach and IP infringement Accept a moderately lower general liability cap
No use of buyer data for training without consent Agree to anonymised, aggregated telemetry for service improvement
Model escrow for critical systems Accept a longer contract term or committed minimum spend
Meaningful SLA credits and termination triggers Extend the cure period before termination applies
Full audit and log access Accept reasonable notice periods and frequency limits

Choosing counsel and practicalities

Buyers frequently ask whether a US lawyer can work in Spain. A US-qualified lawyer can advise on US and international matters, but representation before Spanish courts and formal advice on Spanish law generally require a lawyer admitted to a Spanish bar (colegio de abogados). For AI vendor negotiations, the practical answer is a bilingual team or Spain-based technology counsel who can drive drafting in both languages. On cost, legal fees in Spain vary by firm size, region and seniority, with large Madrid and Barcelona firms at the top of the range; startups can manage budget through fixed-fee project work or retainers with boutique specialists.

Major national firms such as Garrigues are frequently named among the largest in Spain, but for AI vendor negotiation many startups prefer specialised boutique or mid-market technology teams that combine regulatory depth with commercial pragmatism.

8. Clause bank summary and next steps

The essential clauses to secure in any AI vendor agreement are: precise definitions separating software, model and outputs; compliance covenants mapping AI Act and GDPR duties; measurable performance and explainability warranties; change management and rollback rights; transparency, log and audit rights; robust security and breach notification; a compliant data processing agreement with training-data restrictions; carefully structured liability caps and carve-outs; indemnities for data, IP and regulatory exposure; clear IP and licensing terms; and escrow for critical systems. A model clause bank for AI vendor contracts and an AI procurement due diligence checklist are the natural companions to this guide. For a bespoke clause review tailored to your deployment, seek qualified Spanish technology counsel before signing.

9. Practical examples: two short negotiation scenarios

Scenario one, startup buys a SaaS LLM-based API where the vendor uses a third-party model. The vendor’s template disclaims all liability for outputs and permits use of customer prompts to improve the service. The buyer negotiates: an express warranty that the third-party model’s licence permits the intended commercial use; an indemnity for IP infringement in the outputs; and a rewrite of the data clause so that customer data is used to train nothing without written consent, with anonymised telemetry offered as a compromise. Result: the general cap stays, but breach and IP risk is carved out and data use is controlled.

Scenario two, enterprise integrates an on-premise model trained with client data. Here the buyer has more leverage. The negotiation secures ownership of, or a broad licence over, the fine-tuned model derived from the buyer’s data, a model escrow arrangement covering weights, provenance documentation and build scripts, and a continuing licence on termination. The vendor accepts these in exchange for a longer committed term. The before-and-after difference is stark: from a licence that would have stranded the buyer on exit, to a resilient arrangement with continuity and IP control.

10. Conclusion and next steps

Getting ai vendor contracts Spain right in 2026 is no longer a matter of borrowing a generic software template; it is a discipline that fuses EU AI Act obligations, GDPR compliance, Spanish liability norms and sharp commercial drafting. Start by classifying the AI system and fixing the provider and deployer roles, then run a DPIA where the processing warrants one, open a structured procurement dialogue backed by documentary diligence, subject the draft to Spain-specific legal review, and confirm that insurance sits behind your indemnities. Buyers who treat the contract as the instrument that operationalises compliance, rather than an afterthought, will move faster, litigate less and protect the value of their AI investment.

Adapt the sample language here to your facts, and have qualified counsel finalise the agreement before signing.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. GDPR (Regulation (EU) 2016/679), EUR-Lex
  2. European Commission, Regulatory framework for AI
  3. European Data Protection Board (EDPB)
  4. Agencia Española de Protección de Datos (AEPD)
  5. Boletín Oficial del Estado (BOE)
  6. OECD.AI Policy Observatory, AI Principles

FAQs

Can a US lawyer work in Spain?
Yes, but with limits. A US-qualified lawyer can advise on US law and international matters, but representation before Spanish courts and formal advice on Spanish law generally require a lawyer admitted to a Spanish bar. For negotiating AI vendor contracts Spain deals, the practical solution is a bilingual team or Spain-based technology counsel with AI and data protection experience.
Fees and compensation vary by firm size, region and seniority. Large Madrid and Barcelona firms generally sit at the top of the range, while boutiques and mid-market teams tend to be lower. For startups, this matters mainly for budgeting: fixed-fee project work or a retainer with a specialist technology boutique is often more cost-effective than large-firm hourly rates for a focused contract negotiation.
Major national firms such as Garrigues are consistently ranked among the largest in Spain by size and revenue. For AI vendor negotiations, however, startups often prefer specialised boutique or mid-market technology teams that combine regulatory depth with commercial pragmatism, engaging large-firm resources only where scale or cross-border complexity demands it.
Spain is a civil law jurisdiction with a comprehensive, statute-driven data protection regime under GDPR and AEPD enforcement. US privacy law is more fragmented across state and federal levels. Spanish courts enforce reasonable liability caps between commercial parties but do not allow liability for wilful misconduct to be excluded in advance, and statutory fines are not freely transferable by contract. IP assignment and procurement norms also differ, making Spain-specific drafting essential.
Liability depends on the facts, the contractual allocation, applicable product and civil liability rules, and whether the harm stems from negligence, a defect or a regulatory breach. A well-drafted contract allocates responsibility expressly and includes indemnities for regulatory exposure where legally permissible, supported by insurance as a backstop.
Include a data processing agreement defining controller and processor roles, the lawful basis and purpose, DPIA obligations, technical and organisational measures under Article 32, subprocessor controls, audit rights, support for data subject requests, and breach notification timelines aligned to the buyer’s Article 33 duty (without undue delay and, where feasible, within 72 hours). Restrict use of buyer data for model training without consent.
Not entirely. Liability for statutory penalties cannot always be excluded or transferred by contract, and Spanish courts will not enforce exclusions covering wilful misconduct. The practical approach is a loss-arising indemnity for exposure caused by the vendor’s breach, combined with adequate insurance, rather than a simple contractual pass-through of fines.
Escrow is advisable where the AI system is business-critical and you cannot tolerate an abrupt vendor exit. Define precisely what is deposited, model weights, training-data provenance, build scripts and configuration, the release triggers, and the confidentiality regime. Reproducibility matters: weights without build instructions may be unusable, so specify what genuine continuity requires.
wage underpayment class actions in Australia | GLE News
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Negotiate AI Vendor Contracts in Spain (2026): Clauses, Liability, IP & Compliance

Send welcome message

Custom Message