Applied AI

Agentic AI – Sliding Toward Services on the Contracting Spectrum

Written by Vorys | Aug 31, 2026, 4:04:29 PM

AI Licensing and Services Tip

On Applied AI, we will regularly share AI licensing and services tips from Craig Auge, a partner in the Vorys Columbus office and a member of the firm’s technology and commercial transactions practice. This tip focuses on key Agentic AI services-oriented provisions.

Agentic AI – Sliding Toward Services on the Contracting Spectrum

Over two decades ago, on-premises software licensing agreements began to be adapted to fit the newer model of software-as-a-service (SaaS) offerings, hosted by vendors. More recently, SaaS forms and provisions were bent to accommodate GenAI. However, Agentic AI requires sliding more toward services-oriented provisions on the contracting spectrum.

Unlike a mere licensed tool that the customer wields, an “AI Agent” performs tasks or makes decisions on the customer’s behalf and may be defined in an agreement as:

“any artificial-intelligence-enabled software component supplied or operated by Vendor that can plan, select, sequence, recommend, initiate, or perform one or more actions, including through tools, application programming interfaces, plugins, software applications, robotic process automation, or other systems, with or without contemporaneous human instruction.”

Descriptions

Just as in traditional outsourcing services agreements with humans providing “warm-body services,” Agentic AI agreements require AI Agent services descriptions that address permitted use cases and customer-business purposes and describe workflows that it executes, customer systems being accessed by the AI Agent to pull data, types of AI Agent decisions or outcomes to occur, and guardrails.

Performance Warranties

The familiar performance warranty in a services agreement of people being “good and workmanlike” can be stretched to the “AI Agents” performing as if people.

GenAI and SaaS measurements of platform uptime may carry over in part, but Agentic AI services can be measured by more human-like outcomes, e.g., support tickets timely dealt with a certain percentage of the time or the accuracy of charges listed on invoices sent out on behalf of a company supplying manufactured products to its distributors.

Consider also adding a vendor commitment such as:

“Provider will configure and operate the Services so that the Agent cannot knowingly exceed applicable authorization, monetary limit, system boundary, data-access scope, or approval requirement.”

Guardrails and Human Approvals

Providers and customers may agree on categories of authorizations that are applied to different AI Agents and associated tasks or actions. For example:

“(i) Autonomous – Agent may execute,

(ii) Recommend – Agent cannot execute, but may recommend,

(iii) Human Approval – Agent needs human approval before executing, and

(iv) Prohibited – Agent cannot recommend or execute an action.”

Related, the parties may specify certain AI Agent actions that may never be executed. For example:

“(a) communicating with a regulator or the government,

(b) modifying security controls, or

(c) accepting click-wrap or linked third-party legal terms and conditions on Customer’s behalf.”

Liability

As with human actors causing damages, customers may ask providers to indemnify them. For example:

“Provider agrees to indemnify, defend, and hold harmless Customer and its affiliates and their respective officers, directors, employees, agents, successors and assigns from and against any and all claims, demands, actions, liabilities, losses, damages, regulatory penalties, and expenses (including reasonable attorneys’ fees) arising out of or relating to an unauthorized AI Agent action caused by (i) Provider’s breach of any of its commitments in this Agreement or (ii) failure of Provider-controlled authorization safeguards.”

Commitments regarding providers keeping records or logs become more important. They may not prevent an unauthorized and undesirable result of an AI Agent, but records or logs can help customers reconstruct how and what went wrong – and both address it (e.g., explaining to an invoice recipient how an inaccurate invoice was generated and sent) and correct to prevent recurrence.

Insight and Approach

Sculpting your Agentic AI agreement’s commitments, limitations, and risk allocations starts with being mindful of the services-oriented purposes and outcomes of Agentic AI, not merely reaching for a SaaS or even a GenAI form agreement.

By: Craig Auge