Contracts

In this section you will find recommended content for drafting contract clauses relating to AI systems. This content, organised through the principles of the PIO Model, is relevant for many use cases and for determining the application of european legislation on artificial intelligence (AI Act) as well as compliance with the highest standards of responsibility, security and respect for human rights.

1.1. Preliminary analysis of the use of the system

Clause recommendation

No.

The system shall be accompanied by precise information on what it is used for, as well as the identity and contact details of the provider or representatives.

1.1.1

It shall be ensured that the system’s output generation process complies with the following requirements:

  • It is well documented and reproducible to detect future problems.
  • It uses the simplest and most intelligible model in favour of transparency.
  • It takes into account the artificial intelligence skills and literacy of all people.
  • It makes automatic records of its operation.

1.1.2

1.2. Explainability

Clause recommendation

No.

The following information relating to the system shall be documented and made public:

  • Its development process and the people involved.
  • The technical information necessary for its use.
  • Concise, clear instructions, written in accessible language, on how it works.
  • The process by which the system arrives at a given result and the expected results.
  • The possible limitations of the system.
  • Information regarding the exchange and transfer of data, as well as the channels and mechanisms enabling data subjects to exercise their rights.

1.2.1

The system will have a mechanism to identify the content it generates as its creation.

1.2.2

Measures shall be taken to ensure that the level of transparency and explainability of the system does not pose a risk to the privacy of individuals or to the security of the system itself.

1.2.3

1.3. Traceability and representativeness

Clause recommendation

No.

In relation to the data used by the system, compliance with the following requirements shall be ensured:

  • The system shall be accompanied by documentation of the type of data used, their provenance, and the changes they have undergone at each stage of their life cycle.
  • Steps will be taken to verify the representativeness and adequacy of the data used.
  • The system will have safeguards to verify the age of individuals.

1.3.1

The record of files generated by the IA system shall be kept for a minimum period of six months.

1.3.2

1.4. Communication protocols

Clause recommendation

No.

The system shall have the following communication tools:

  • A function to allow users to comment on its performance.
  • A notification system in case of serious incident or error.

1.4.1

A stakeholder participation policy will be established, including end-users and/or recipients.

1.4.2

2.1. Inclusion and diversity

Clause recommendation

No.

The AI system will include inclusion and equity measures, especially in relation to the following aspects:

  • Testing the results of the system for different affected groups.
  • Measures to increase accessibility.
  • Measures to support their use by people in vulnerable situations.
  • Measures to ensure that the system accommodates a broad spectrum of individual preferences and abilities.

2.1.1

The system will be evaluated to verify that it does not use unfairly discriminatory variables or proxies prior to locating into the market or using.

2.1.2

The AI system development group should include people of non-male gender, people from diverse backgrounds or cultures and from diverse knowledge disciplines (beyond computer science and engineering).

2.1.3

The organisation shall promote an organisational policy that prioritises diversity, equity and inclusion.

2.1.4

2.2. Identification and mitigation of biases

Clause recommendation

No.

The system shall have measures and mechanisms in place to detect, correct and mitigate potential biases throughout its life cycle.

In particular, measures will target the biases present in:

  • The design or implementation phase.
  • Training and post training data.
  • Changing or inappropriate categories.

2.2.1

Prior to locating into the market or using, the system will be subject to an assessment of the impact of potential biases, especially those that could affect the rights, health or safety of people.

2.2.2

The system will comply with classification standards that address bias related to age, ethnicity, race, gender or disability in accordance with applicable regulations.

2.2.3

The system shall include security mechanisms in order to prevent the following incidents:

  • Anomalies or actions outside predetermined limits.
  • Biased outputs and feedback loops.

2.2.4

Measures for the detection, correction and mitigation of bias shall comply with applicable data protection regulations. In particular, compliance with Regulation (EU) 2016/679, Directive (EU) 2016/680, and Regulation (EU) 2018/1725 shall be ensured.

2.2.5

Detailed information will be provided on the data and resources used to prevent and detect data inadequacy or bias, as well as the risk of automation bias.

2.2.6

3.1. Operation of the system

Clause recommendation

No.

The system shall be accompanied by the following information:

  • The level of accuracy and security of the system.
  • The manner and degree of influence that the actions of users can have on the performance of the system.
  • The possible behaviours and scenarios that should never be transgressed in order to ensure safety and preserve the non-maleficence of the system.
  • The system’s monitoring and control mechanisms (both internal and external).

3.1.1

The people who have designed/will design the system will provide guidance on how to interpret and respond to the metrics it generates.

3.1.2

3.2. Traceability for Risk Management

Clause recommendation

No.

Prior to locating into the market or using the system will be subject to an evaluation incorporating the following aspects:

  • The potential impacts of the system on the health, safety and rights of those affected.
  • The risk that data collected, generated or used by the system will be used to discriminate against individuals in a negative way.
  • The potential risks and damages that would be caused by the system in case of inaccurate predictions in the envisaged scenarios.
  • The risks of using the system beyond its intended uses.

3.2.1

The system will have a general protocol on traceability of data for risk management.

3.2.2

The system shall have the means to enable the following functions:

  • Identify, assess and take action on risks arising from its use and from data collected after it becomes operational.
  • Report on residual system risks that could not be corrected or mitigated.

3.2.3

3.3. Security mechanisms

Clause recommendation

No.

The system will have the following measures:

  • Resilience measures for errors arising from their interaction with other systems or people.
  • Resistance and error mitigation measures arising from tampering attempts by unauthorised persons.
  • Continuous review measures on the accuracy of the decisions taken by the system.

3.3.1

Users of the AI system will be able to control the extent to which they are exposed to it and to withdraw their consent at any time without compromising its performance.

3.3.2

3.4. Protection against attacks

Clause recommendation

No.

Prior to locating into the market or using the system will be assessed to ensure its security, integrity and resilience to different forms of attack.

3.4.1

Prior to release/use, the data sets used by the system will be evaluated to verify that they have not been previously compromised or hacked.

3.4.2

4.1. Monitoring

Clause recommendation

No.

Measures shall be taken to ensure that those involved in monitoring the decisions taken by the system have an adequate understanding of its functioning and have the necessary training to perform this function.

4.1.1

The system shall have the tools to enable the persons in charge of its control to intervene, modify, delete or reverse the decisions taken by the system.

4.1.2

The system shall be accompanied by information and documentation relating to the following aspects:

  • The limits of the system’s control mechanisms.
  • The human oversight measures available in the system.

4.1.3

4.2. Accountability

Clause recommendation

No.

Prior to the use/commercialisation of the system it shall be determined:

  • The person legally responsible for the actions and/or decisions they take throughout their life cycle.
  • The person responsible for the system’s human oversight measures.

4.2.1

The organisation shall take the following measures:

  • It will carry out an evaluation to determine the influence the system has on the organisation’s decision-making.
  • It will establish mechanisms for periodic review of responsibility and accountability with the different actors involved in its development and use.

4.2.2

4.3. Protective figures

Clause recommendation

No.

The organisation will take the following measures:

  • Facilitate the demonstration of compliance with current legislation.
  • Ways of redress or compensation in case of damage caused by the system.
  • Determine protection figures for users and people affected by the system.

4.3.1

4.4. Training

Clause recommendation

No.

The organisation undertakes not to make any claims that would lead to overestimate the capabilities of the system and that are not demonstrable by sharing data and system code.

4.4.1

4.5. Promoting a culture of ethics and responsibility related to AI

Clause recommendation

No.

The organisation will develop a code of ethics for the responsible use of artificial intelligence.

It will include the following points:

  • Promotion of the responsible use of artificial intelligence by the organisation’s staff.
  • Carry out the determination of the system’s objectives and the review of its functioning from the perspective of the responsible use of artificial intelligence.
  • Take measures to ensure that the system, in the process of generating decisions, takes into consideration the implications for people’s rights and well-being.

4.5.1

5.1. Protection of privacy

Clause recommendation

No.

The system shall have data protection mechanisms in place throughout its life cycle to ensure the following aspects:

  • That personal data are treated in accordance with the legally required degree of protection to prevent their misuse, alteration, loss or theft by third parties.
  • That the data provided by the person concerned are not sold, rented or transferred without their consent.
  • The system has processes in place to maintain or enhance the privacy and protection of data throughout its lifecycle.
  • That anonymisation, encryption and aggregation techniques are used.
  • There is a protocol in place to obtain the consent of the individuals concerned before any data processing is initiated through the system, and information regarding these actions is understandable and accessible to all potential users, including those with special needs.
  • There should be a mechanism through which the data subject may request that his or her information be deleted.

5.1.1

The system will ensure equal access for persons with disabilities and in vulnerable situations while respecting their privacy and dignity.

5.1.2

5.2. Data governance

Clause recommendation

No.

The system shall have a record of data access information that clearly identifies who is accessing the data, when and for what purpose.

5.2.1

Measures shall be taken to ensure that persons responsible for data processing and management have the necessary skills and up-to-date knowledge to perform these functions.

5.2.2

In order to ensure the appropriateness and responsible use of the data used by the system, the following measures shall be taken:

  • A procedure shall be established to ensure that the data sets used are appropriate and relevant to the performance and intended outcome of the system, and that they are suitable for the context in which they will be used.
  • The process of collecting and preparing the data used will be documented.
  • The system shall use privacy measures (e.g. pseudonymisation of data) and limit the re-use of sensitive personal data.

5.2.3

The system is/will be designed in such a way that the following issues can be guaranteed:

  • The system adheres to the principles of data minimisation and data protection by design and by default.
  • The system can be trained without the need to transmit or copy raw or structured data.

5.2.4

6.1. Impact on users' capacities

Clause recommendation

No.

The system shall include an evaluation process to ensure that it does not diminish the number of possible choices and does not force or compel certain choices in general or at any stage of its life cycle.

6.1.1

The system will be accompanied by a testing protocol to certify that it helps people make better and more informed decisions.

6.1.2

The system will have mechanisms to ensure the following aspects:

  • End-users are aware that they are interacting with an artificial intelligence and are sufficiently empowered and informed to do so.
  • That the results it generates are labelled in some way that allows people to identify that this content has been generated by an artificial intelligence.
  • That it does not jeopardise the levels of autonomy of the end-users, avoiding the use of manipulative or subliminal techniques and adapting to the preferences and needs of the person.

6.1.3

6.2. Perception of the system

Clause recommendation

No.

The system will have mechanisms to ensure that its operations are transparent, clear, honest and do not encourage users to overestimate their capabilities.

6.2.1

The system will have the following mechanisms:

  • Human supervision measures that make it possible to manage their degree of autonomy and adaptability.
  • Mechanism for limiting the degree of autonomy of the system to avoid unwanted or high-risk behaviour.
  • Adapt and learn from their environment without compromising safety and ethical standards.

6.2.2

The system will be assessed to identify and mitigate risks to its capabilities and degree of autonomy, as well as its adaptability to new tasks.

6.2.3

7.1. Sustainable development

Clause recommendation

No.

It will ensure that the constraints and obstacles arising from the digital divide and unequal social access have been taken into consideration in the design, implementation and use of the system.

7.1.1

Before being placed on the market and/or used, the system will be subject to an assessment of its impacts on human rights, safety, health and the environment.

This assessment will take particular account of the following areas:

  • Impact on labour rights.
  • Impact on people’s quality of life.
  • Impact and risks related to sustainable development.
  • Fair compensation measures and ethical treatment of those involved in all phases of the life cycle of the system and of those affected by its implementation and use.

7.1.2

The system shall have measures in place to ensure the respect and ethical use of proprietary data. These measures shall include making publicly available information on the IPR-protected data used by the system.

7.1.3

The development, marketing, implementation and/or use of the system will be compacted with the participation of relevant stakeholders.

7.1.4

The organisation shall actively engage with employee representation in order to identify, correct and mitigate potential risks to the welfare and labour rights of employees arising from the acquisition, implementation and/or use of the system.

7.1.5

7.2. Environmental impact

Clause recommendation

No.

The system will have mechanisms to record its energy consumption and environmental impact throughout its life cycle.

7.2.1

The organisation shall implement mechanisms and strategies aimed at improving the energy efficiency of the system and reducing its environmental footprint, especially when large data sets are used.

7.2.2

Before being placed on the market and/or used, the system shall be subject to an evaluation addressing at least the following aspects:

  • The energy efficiency of the system.
  • Explore the use of renewable energy sources and green IT practices.

7.2.3

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.