
AI vendor contract clauses after Anthropic's embedded-evaluator commitment: three to sign, two to refuse, and my calls for 31 December
"The reviewers can say publicly if a redaction removed something important to their conclusions."
That sentence, from Dario Amodei's essay of Saturday 12 September, is the one piece of the weekend a customer can hold a vendor to. Anthropic says it will give an outside review team, from an organisation "such as METR", desks, badges and company laptops, permissions "mostly comparable to what internal risk assessment teams have", and a contract that lets it publish "without editorial control by Anthropic". Sam Altman posted that OpenAI "will do the same". The broadcasters called it a slowdown; Amodei's own line is that "progress will still seem fast", and nothing in the essay touches a model already in production.
What it does touch is the services agreement a software house in Karachi or Lahore will be asked to sign, probably by a German client, probably before Christmas. That is the article.
Why the schedule arrives from Germany
A Mittelstand client's counsel, working through the deployer duties this site set out on 6 September, wants the model vendor's safety commitments flowed down to the supplier that built the agent. Until Saturday there was nothing concrete to attach. Now there is a paragraph with nouns in it, and it will be pasted into a schedule with a request that the Pakistani supplier warrant it.
The supplier cannot. It does not decide whether METR gets a badge. What it can do is sign three things and refuse two, and that difference is the whole negotiation.
Three to sign, two to refuse
- Pass-through of evaluator reports. Every report the provider's embedded evaluators publish goes to the client within thirty days, including any statement of "the access they received or didn't receive". A report without that statement was edited. Costs nothing. Sign it.
- Capability notification. If any model version in the deployment is assessed, by the provider or its evaluators, as "capable of escaping or defeating most common sandboxing methods", the supplier tells the client within a fixed number of days and the parties meet to decide whether the deployment continues. Use the essay's words, so nobody argues about meaning later.
- Incident notification on a clock. Seventy-two hours from the provider publishing an incident in which its models acted on third-party systems without authority, whether or not the client's data was involved. Anthropic's 30 July post, three incidents in 141,006 evaluation runs, and its 31 August post on the UK AI Security Institute incident are the template.
Refuse, first, any clause that makes the supplier liable for the provider's failure to seat evaluators by a date. There is no date in the essay beyond "in the near future"; a supplier that invents one writes a penalty against itself. Refuse, second, any clause that books "pacing" into the client's risk register as a promise the model will not change under the deployment. It will. Ask instead for a version support window, a minimum number of months the qualified model version stays available and unchanged, and put a price on it. Pacing makes that easier for a vendor to grant, and it is the one place a Pakistani supplier gains from the essay rather than absorbing it.
The clause a German client cares most about is retention, and there the vendors have diverged in writing. Anthropic's 1 September Enterprise Frontier Safeguards post offers monitoring data held "in the customer's own cloud account", under the customer's keys, with "no human review by Anthropic employees", at no charge, arriving "in phases, starting later this fall". OpenAI's Agents API documentation, as read for the 12 September post, offers nothing equivalent. A data-residency clause on Claude can now point at a vendor document. It still cannot point at a date: write "when generally available", not "by 30 November".
What I expect on 31 December
These are my calls, made from the documents and not from either vendor, and each can be seen to be wrong.
Anthropic names the evaluator, it is METR, and the publication clause is public before the year ends, because the 31 August post already committed to a METR review and the essay's argument fails if its first step stays unsigned through the holidays. No evaluator report before the end of the first quarter of 2027, though. A team that arrives in November does not publish in December.
OpenAI publishes its terms before 31 October, because "more to share soon" from a company preparing a listing cannot stay open for a quarter, and those terms do not carry "without editorial control" in Anthropic's form. My read is a pre-publication review window measured in days. If OpenAI's redaction language matches Anthropic's word for word, I misjudged them.
Enterprise Frontier Safeguards reaches its hundred-odd design customers by year-end and general availability slips into the first quarter of 2027. A monitoring pipeline landing in three clouds under customer-held keys does not ship in one season.
And the pass-through clause in item one is standard language between Pakistani suppliers and European clients by the end of that quarter, because it costs nothing to grant and gives a deployer's counsel a document to file. That one I would put money on.
One line from the essay belongs on the wall of any factory-software project, and it is not in the commitments section. Under "Operational Excellence", Amodei writes that the summer's alignment incidents "were caused in part by imperfect filtering of broken reinforcement learning environments. This was an effort we and our vendors executed reasonably diligently, but not well enough." That is a supplier saying an incoming-inspection process failed, and anyone drafting a services agreement this quarter has just been told, in the vendor's own words, the standard it wants to be held to.
Sources
- Dario Amodei, "We Must Pace the Frontier", darioamodei.com, 12 September 2026. Every Anthropic commitment quoted above is from it.
- Anthropic, "Improving our alignment and security efforts", 31 August 2026. The UK AISI incident and the METR review.
- Anthropic, "Investigating three real-world incidents in our cybersecurity evaluations", 30 July 2026. The 141,006 runs and the three incidents.
- Anthropic, "Developing Enterprise Frontier Safeguards with our customers", 1 September 2026. Retention, customer-cloud storage, rollout timing, pricing.
- Ashley Capoot, CNBC, "OpenAI rules out IPO this year as Altman, Musk & Amodei warn AI is moving too fast", 12 September 2026. Altman's post and the Fortune IPO remark.
- Gabriel Alin Zainescu, Forbes, "Anthropic CEO Dario Amodei Calls For A Slowdown In Frontier AI", 13 September 2026, via Yahoo Finance. METR's late-August investigation.
- WION, "'We Must Pace the Frontier': Sam Altman & Elon Musk Back Call to Slow Down AI Development", YouTube (figure).
- CNN, "CNN asks Anthropic CEO: 'Do you believe AI could kill all humans?'", YouTube, 12 September 2026 (figure).
- Tech Brew Ride Home Podcast, "Amodei, Altman & Musk Agree: Slow Down AI — The Weekend the AI Industry Freaked Out", YouTube (figure).
- Fortune Magazine, "Altman: AI Beyond Human Control "Absolutely" Possible, Vows Safeguards | Titans and Disruptors", YouTube (figure).
- Vesprr Software, the 12 September Agents API post and the 6 September EU AI Act post.