Workflow · September 25, 2026
Draft a Targeted AI Kill-Switch Policy Clause for Enterprise Contracts
The task
In-house counsel and outside redliners are getting asked — often mid-negotiation — to insert an "AI kill switch" obligation into MSAs, DPAs, and SaaS order forms. The prompt is usually a Slack from procurement: "Legal, can you add something about shutting the model down if it goes sideways?" You need a clean, defensible clause in an hour, not a week.
Before AI
Today this means pulling the vendor's AI services section, cross-checking your firm's AI risk playbook, drafting suspension triggers by hand, negotiating with the business on notification timelines, and coordinating with the indemnity partner on carve-outs. Realistically: two to three hours for a first draft, more if you loop in a specialist. Most teams skip it and rely on generic termination-for-cause language, which does not do the job when a model starts hallucinating into production.
The workflow
The framing here follows the governance position Microsoft Vice Chair and President Brad Smith recently said he supported the idea of a kill switch, alongside his broader view that advanced AI systems should have an "emergency brake" that allows them to be slowed or shut down. Smith has been specific about who holds the switch: "The people who create the model should have the ability to turn it off. The cloud infrastructure providers like us should have it." That maps cleanly onto a three-party contractual obligation — model provider, hosting provider, customer — which is what the clause below allocates.
You can read the underlying position in Microsoft's own AI governance blueprint on the On the Issues blog before drafting.
Step 1 — Extract and classify the AI-relevant obligations already in the contract
Paste the vendor's AI services section (or the whole SaaS agreement if AI is scattered through it). The model returns a structured map of what's actually there, so you're not drafting into a vacuum.
You are a senior commercial technology lawyer reviewing a vendor contract before proposing a kill-switch clause. From the contract text that follows this instruction, extract and return a structured summary with these exact headers: 1. **AI/ML functionality described** — what the vendor's system actually does, in one sentence. 2. **Existing suspension/termination rights** — any clause that already lets either party pause or terminate service. Quote the clause reference (section number) and paraphrase. 3. **Existing notification obligations** — timelines for incident notice, breach notice, service change notice. List each with its trigger and clock. 4. **Existing indemnity structure** — who indemnifies whom, for what, with any caps or carve-outs. Note whether AI output is expressly covered. 5. **Sub-processor / model-provider references** — any mention of upstream model providers (OpenAI, Anthropic, Google, etc.) or cloud hosts. 6. **Gaps for a kill-switch clause** — 3-5 bullets on what is missing before a mandatory suspension obligation could be inserted cleanly. Be concise. Do not draft new language yet. If the text does not contain something, write "Not addressed" — do not infer. CONTRACT TEXT:
EXCERPT — Master Services Agreement between Nordwell Financial Group ("Customer") and Larkspur AI Systems, Inc. ("Provider"), effective 1 March 2026.
Section 4. AI Services.
4.1 Provider will make available the "Larkspur Advisor" platform, a generative AI assistant that drafts client-facing investment summaries using large language models licensed from an upstream model provider ("Upstream Provider"). Provider may substitute the Upstream Provider on 30 days' written notice.
4.2 Provider will use commercially reasonable efforts to maintain 99.5% monthly uptime, excluding scheduled maintenance.
4.3 Customer acknowledges outputs are probabilistic and shall implement human review before external use.
Section 8. Suspension and Termination.
8.1 Either party may terminate for material breach on 30 days' written notice, uncured.
8.2 Provider may suspend the Services immediately if Customer's use threatens the security or integrity of the platform, with notice as soon as reasonably practicable.
Section 11. Notifications.
11.1 Provider will notify Customer of any confirmed security incident affecting Customer Data within 72 hours of confirmation.
11.2 Provider will notify Customer of material changes to the Services at least 15 days in advance.
Section 14. Indemnification.
14.1 Provider will defend and indemnify Customer against third-party claims that the Services, as delivered, infringe a US patent, copyright, or trademark, subject to the liability cap in Section 15.
14.2 Provider's indemnity excludes claims arising from (a) Customer's modification of outputs, (b) combination with non-Provider systems, or (c) use in violation of the Documentation.
14.3 Aggregate liability capped at 12 months of fees paid.
Section 17. Sub-processors.
17.1 Provider's current sub-processors are listed at larkspur.example/subs. Provider will give 10 business days' notice of additions.Step 2 — Draft the kill-switch clause as a redline against those specific gaps
Now the model uses its own Step 1 map to draft language that plugs the gaps — not a boilerplate clause pasted on top of what's already there.
Using the gap analysis you just produced, draft a new contract clause titled "AI Suspension and Kill-Switch Obligations" to be inserted into the contract. The clause must: (a) Define **Mandatory Suspension Triggers** — enumerate at least five, covering: model malfunction causing material inaccuracy in outputs, unauthorized capability expansion by the upstream model provider, regulatory order or credible regulatory inquiry, confirmed data exfiltration via the model, and a documented safety incident published by the upstream provider. (b) Allocate the **switch itself** across three parties — Provider, Upstream Provider, and Customer — specifying which triggers each party can invoke unilaterally versus which require notice-and-consult. Reflect the governance principle that model creators, cloud/infrastructure hosts, and deploying customers should each hold an independent ability to halt the system. (c) Set **Notification Timelines** tighter than the contract's existing 72-hour and 15-day defaults: no more than 24 hours from Provider awareness for any triggered suspension, and no more than 4 hours for a regulatory-order trigger. Include a running clock definition. (d) Address **Restoration** — conditions for lifting suspension, including written root-cause analysis, remediation evidence, and Customer's right to withhold consent to resumption for defined categories. (e) Add **Indemnity Carve-Outs** that expressly preserve Provider's indemnity for claims arising during the suspension window, and that carve *out* of Customer's obligations any losses caused by Provider's failure to trigger a mandatory suspension when required. Do not disturb the existing 12-month fee cap unless flagged separately. (f) Include **Fee Abatement** — pro-rata fee credit during any suspension not caused by Customer misuse. Format as numbered subsections (e.g., 4A.1, 4A.2 …) styled to slot in after Section 4. Use defined terms consistent with the contract. Bold each defined term on first use. Keep the drafting tight — no throat-clearing.
Step 3 — Produce the negotiation memo and fallback positions
Business teams push back on tight timelines and broad triggers. Get ahead of it.
Now produce a one-page internal negotiation memo for the deal lead. Structure: **Ask (opening position):** the clause as drafted, verbatim key terms. **Likely vendor pushback (3 items):** for each, one sentence on the business rationale the vendor will assert, and one sentence on why it is or is not credible. **Fallback ladder:** three tiers of concessions, from smallest to largest, with the specific clause language that changes at each tier. Label them Fallback A, B, C. Each tier must preserve at least the regulatory-order trigger and the 24-hour notification. **Walk-away line:** the two provisions that cannot be conceded without escalation to the GC, with a one-sentence reason each (privilege-sensitive — frame as legal risk, not commercial preference). **Privilege footer:** one sentence marking the memo as attorney work product prepared in anticipation of contract negotiation. Keep it under 400 words. No tables — the deal lead will paste this into email.
Gotchas
- The clause is only as good as the sub-processor chain. If the vendor won't flow the kill-switch obligation upstream to the model provider, subsection (b) is aspirational. Confirm the vendor's contract with its Upstream Provider actually permits customer-initiated suspension — many don't.
- "Model malfunction" is a drafting trap. LLMs will happily generate a plausible-looking trigger definition that is unenforceable because it lacks an objective measurement standard. Insist the redline references either the vendor's own published eval thresholds or a mutually agreed benchmark. If neither exists, flag it and use "material and reproducible inaccuracy" with a cure-attempt protocol.
- Regulatory-inquiry triggers can create disclosure problems. A suspension caused by a regulator's informal inquiry may itself be a reportable event under the customer's own regulator's rules (SEC, FCA, state DFS). Loop in your regulatory partner before finalizing.
- The model will invent statute citations if you let it. Do not ask it to cite specific laws in the clause. Keep legal authority references out of the contract body and in the negotiation memo, where you can verify them.
- Privilege on the memo is fragile. Step 3's memo is only privileged if it stays inside the legal function and is marked as such. Forwarded to procurement without the footer, it's discoverable.
Time saved
A first-pass kill-switch clause plus negotiation memo typically eats 60-90 minutes of a mid-level associate's time, more if the contract is long. This workflow gets you a reviewable draft in about 10 minutes of prompting plus 20-30 minutes of lawyer review and fact-checking against the actual contract. Conservative estimate: 60-90 minutes saved per contract, with the caveat that the AI draft is a starting point, not filed language — every trigger, timeline, and carve-out needs a human sign-off before it goes into a redline.
## What we got when we ran it We executed every prompt above, in order, against the sample input (model: claude-sonnet-4-6). Outputs below are real and unedited apart from length truncation. ### Step 1 output # Structured Summary — Nordwell Financial Group / Larkspur AI Systems MSA (Effective 1 March 2026) --- ## 1. AI/ML Functionality Described Larkspur Advisor is a generative AI platform that drafts client-facing investment summaries for Nordwell Financial Group using large language models sourced from an undisclosed upstream model provider. --- ## 2. Existing Suspension/Termination Rights | Reference | Party | Right | Trigger | Notice | |---|---|---|---|---| | §8.1 | Either | Terminate | Material breach, uncured | 30 days' written notice | | §8.2 | Provider only | Suspend immediately | Customer use threatening platform security or integrity | As soon as reasonably practicable (post-action) | **Key observation:** No Customer-side right to suspend or pause services exists. §8.2 is unilateral in Provider's favour and is platform-integrity-focused, not harm-to-Customer focused. --- ## 3. Existing Notification Obligations | Trigger | Clock | Reference | |---|---|---| | Confirmed security incident affecting Customer Data | 72 hours from confirmation | §11.1 | | Material changes to the Services | At least 15 days in advance | §11.2 | | Substitution of Upstream Provider | 30 days' written notice | §4.1 | | Addition of a sub-processor | 10 business days' notice | §17.1 | **Notable gap:** No notification obligation is triggered by AI output failures, model degradation, bias incidents, regulatory inquiries directed at the model/platform, or harmful outputs generated at scale. --- ## 4. Existing Indemnity Structure - **Provider → Customer:** Defence and indemnification against third-party IP infringement claims (US patent, copyright, trademark) *…output truncated at 250 words.* ### Step 2 output # Section 4A — AI Suspension and Kill-Switch Obligations --- ## 4A.1 Defined Terms For purposes of this Section 4A: **"Suspension Trigger"** means any event enumerated in Section 4A.2. **"Kill-Switch Action"** means an immediate, unilateral suspension of the Services or any discrete AI output function, effected without prior consent of any other party. **"Notice-and-Consult Suspension"** means a suspension effected only after the notifying party has delivered written notice and allowed the other party a defined consultation window before suspension takes effect, except where an intervening Suspension Trigger independently requires immediate action. **"Provider Awareness"** means the earlier of: (a) actual knowledge by any officer, engineer, or operations personnel of Provider; or (b) receipt by Provider of written or electronic notice from Customer, a Regulatory Authority, or any Upstream Provider identifying a potential Suspension Trigger. The clock under this Section 4A begins running at the moment of Provider Awareness and does not reset upon internal escalation or verification. **"Regulatory Authority"** means any governmental, self-regulatory, or supervisory body with jurisdiction over Customer's provision of investment services or Provider's operation of the Services, including but not limited to the SEC, FINRA, and any applicable state securities regulator. **"Confirmed Data Exfiltration"** means a reasonably substantiated determination, including based on preliminary forensic indicators, that Customer Data or Customer client data has been accessed, copied, transmitted, or processed by or through the model inference pipeline outside the scope authorised by this Agreement. **"Safety Incident Publication"** means any public disclosure by an Upstream Provider, a government body, or *…output truncated at 250 words.* ### Step 3 output **PRIVILEGED AND CONFIDENTIAL — ATTORNEY WORK PRODUCT** **To:** Deal Lead **Re:** Larkspur AI MSA — Section 4A Negotiation Posture --- **Ask (Opening Position)** Insert Section 4A as drafted. Key non-negotiable terms on opening: five enumerated Suspension Triggers including regulatory order (4A.2(c)) and Safety Incident Publication (4A.2(e)); Customer's unilateral Kill-Switch right on regulatory, data exfiltration, and model substitution triggers (4A.3.1); Provider's mandatory Kill-Switch obligation with failure constituting material breach (4A.3.2(a)); 4-hour regulatory-order notification clock with continuously running definition of Provider Awareness; and pro-rata fee credit for all non-Customer-caused suspensions (4A.7.1). --- **Likely Vendor Pushback** **1. "The 4-hour clock is operationally impossible."** Vendor will argue its incident response SLA requires internal triage before external notification. This is partially credible for complex incidents but not for a regulatory order, which is a discrete written instrument requiring no forensic analysis — reject entirely on that trigger, consider narrow concession elsewhere. **2. "Mandatory Kill-Switch failure should not be a per se material breach."** Vendor will assert that breach determination requires a cure period and that automatic materiality over-penalises good-faith operational errors. This is commercially self-serving; failure to halt a regulated financial AI on a confirmed trigger is precisely the conduct that warrants strict liability framing — hold the position. **3. "We cannot bind Upstream Providers by contract within 30 days."** Vendor will argue 4A.3.3(a) requires renegotiating upstream terms it does not control. This is credible for legacy agreements but not for renewals; push for a best-efforts obligation with a defined longstop date of 90 days, *…output truncated at 250 words.* --- This content is for informational purposes only and is not legal advice. Confirm confidentiality, privilege, and jurisdictional rules before using any AI tool with client matters.
Source: news.google.com
More for Legal professionals →
Get the next one in your inbox