The first enterprise AI deal often reveals the company’s legal maturity. The buyer asks where customer data goes, whether inputs train the model, who the subprocessors are, what happens if the output is wrong, how deletion works, whether the system uses third-party models, and whether the startup can sign the buyer’s DPA. The answers should not be invented live.
For founders, the goal is not to sound like a large company. The goal is to be crisp, credible, and prepared. A focused contract and trust packet can make a young AI company easier to buy from.
The enterprise AI sales checklist: your trust packet
- Commercial terms. MSA or SaaS terms, order form, support terms, termination rules, renewal mechanics, and limitation of liability.
- AI terms. AI addendum covering inputs, outputs, training, model limitations, prohibited use, human review, disclosures, and customer responsibilities.
- Privacy and data processing. DPA, privacy policy, data map, subprocessors, retention and deletion process, and data subject request support.
- Security posture. Security summary, access controls, encryption posture, incident process, vendor controls, and answers for common security questionnaires.
- Model and vendor file. Model-provider summary, vendor terms review, no-training support, output-rights position, and pass-through limitation map.
Questions enterprise buyers ask
Does customer data train the model?
This is often the first serious AI question. If the answer is no, the contract, product setting, vendor terms, privacy policy, DPA, and internal operating rules need to support that answer. If the answer is yes, consent, disclosure, retention, deletion, and customer-control questions become central.
Who are the subprocessors and model providers?
Enterprise buyers want to know where data goes and who can access it. A clean subprocessor list and model-provider summary reduce friction because the buyer can review the actual dependency chain rather than guessing from generic AI language.
What happens if the output is wrong?
The contract should explain user responsibility, product limitations, human review, prohibited use, support, escalation, and liability allocation. This matters most when the system supports decisions in regulated, sensitive, or high-consequence environments.
Can the company sign the buyer’s DPA?
Sometimes yes, but the buyer’s DPA may include obligations the startup cannot meet. Review audit rights, deletion, subprocessors, security measures, transfer mechanics, breach notice, assistance obligations, and whether the DPA assumes a data flow that does not match the product.
Enterprise buyers do not need a startup to look huge. They need the startup to know its own data flow, model stack, contract boundaries, and risk story.
Deal blockers that are avoidable
- The sales deck overpromises. Claims about accuracy, compliance, automation, security, privacy, or ownership should be backed by product reality and contract language.
- The DPA and product disagree. The buyer’s data rights, deletion expectations, or subprocessor approval process do not match how the system actually works.
- The AI addendum is missing. The MSA handles ordinary SaaS issues but never addresses inputs, outputs, model-provider dependencies, prohibited use, or human review.
- The vendor stack is undocumented. Procurement asks about model providers, hosting, subprocessors, and data retention, but the company has no clean answer.
- The liability position is backwards. The startup accepts broad downstream risk from the customer while receiving narrow protection from its own providers.
A better founder sequence
- Map the product, data flow, model stack, subprocessors, and customer-facing promises.
- Prepare the MSA or SaaS terms, DPA, AI addendum, privacy policy, and security summary together.
- Review model-provider terms and identify which customer promises are unsupported or need qualification.
- Align the sales deck, website copy, contract language, and product settings.
- Keep the materials in a diligence folder so procurement and investors see a coherent operating story.
For the contract layer, read AI contracts, data privacy, and SaaS terms. For the operating record behind enterprise trust, read AI governance and risk readiness. For the vendor layer, read AI vendor and model-provider terms. For the contract procurement asks about first, read the DPA guide.