The 2026 CU AI vendor map ends with a decision tree: core roadmap, point solution, or configured platform. Whichever branch you take, the next artifact on your desk is a contract, and AI contracts hide their risk in different places than the vendor agreements your credit union has signed for twenty years.

An AI agreement governs a service that changes underneath you: models get swapped, outputs drift, and your member data may be feeding the vendor’s product roadmap. The paper needs to account for that, and most templates do not. What follows takes the clauses roughly in the order a careful reader hits them. It pairs with the vendor map and lives in the vendor landscape pillar; as always, we take no vendor money, per the methodology on our About page.

Start with the data flow, not the pricing page

Before reading a single clause, write one paragraph describing what data leaves your environment, where it goes, and what comes back. Member PII, transaction history, call recordings, loan files, internal documents: name them. Every clause below gets evaluated against that paragraph. If the vendor cannot help you write it accurately in one call, that is a diligence finding by itself. NCUA’s third-party framework has expected this kind of understanding since Letter to Credit Unions 07-CU-13, which tells examiners to weigh due diligence against the criticality of the service. A system touching member data and influencing member outcomes sits at the top of that scale.

Data rights: who owns what the system produces

Your inputs, the system’s outputs, and the data derived from both need separate treatment in the contract. Weak agreements blur them, sometimes on purpose.

Your inputs. The data you send should remain yours, full stop. Look for a plain sentence assigning you ownership of submitted data. Watch for license grants that ride along: “customer grants vendor a perpetual, irrevocable license to use customer data” moves real value under boilerplate cover. The only license the vendor needs is narrow: to process your data to provide the service to you, for the term of the agreement.

Outputs are the second bucket. Decisions, summaries, scores, and drafts generated from your data should belong to you, with no restriction on your continued use after termination. If an underwriting assistant helped decide 4,000 loans, you need permanent rights to the records of how, because your examiners and your auditors will ask long after the contract ends.

Derived data is the quiet one. Usage statistics, embeddings, fine-tuned model weights, and “learnings” pulled from your data often default to the vendor. You may accept that for anonymized, aggregated telemetry. You should not accept it for anything reconstructable to your members or your institution. Ask the vendor to define derived data in writing and to state what they keep after you leave.

Model training: pin down how your data gets used

Somewhere in the agreement, usually in a data use section or an incorporated privacy policy, sits language about using your data to “improve the services.” Pin it down.

First, is member data used to train or fine-tune models that serve other customers? The right answer for regulated data is no, or an explicit opt-out that you exercise in writing before go-live. Second, does the vendor’s own upstream provider train on your data? Many CU point solutions are wrappers around a frontier model API; your contract is only as strong as the flow-down terms with that subprocessor, so ask for the subprocessor list and the training commitments each one makes.

Third, what happens to any model artifacts built from your data at termination? If a model was tuned on your members, its disposition belongs in the exit section of the agreement, in writing.

This is the same “know where your data goes” discipline NCUA already expects before you deploy AI on member data, carried into the contract itself.

Performance claims: turn the demo into an exhibit

Vendor decks promise 80 percent deflection and 90 percent faster reviews. Contracts promise 99.5 percent uptime. The self-reported numbers that sold the deal rarely appear in the document you sign.

Move at least one operational metric into the agreement as a measurable service level with a remedy, even a modest one. Accuracy on a defined test set, resolution rate on a defined intake category, turnaround time on a defined queue: pick the number the business case depends on. If the vendor refuses any operational commitment, treat the deck figures as marketing claims when you price the deal, because that is their contractual status.

Two adjacent clauses matter here. Model change notice: the vendor should notify you before material model changes and give you a validation window, because a silent model swap can move your error rate overnight. Human review posture: if the service influences credit, fraud, or account decisions, the contract should acknowledge your right to route outputs through human review and to set thresholds, so your compliance controls are not an unsupported configuration.

Audit rights and the examiner file

Your examiner will not accept “the vendor is SOC 2 certified” as a complete answer, and the AI questions showing up on 2026 exams assume you can produce documentation. The contract has to guarantee the inputs to that file: annual SOC 2 Type II or equivalent reports delivered to you, summaries of penetration tests, incident notification within a defined number of hours (not “prompt notice”), and cooperation with regulatory requests, including making information available to NCUA or your state supervisor when an exam requires it. Vendors serving financial institutions sign this language routinely; hesitation here usually means the vendor has not sold into a supervised institution before. The voluntary NIST AI Risk Management Framework is a useful shared vocabulary here: asking a vendor which AI RMF functions they can evidence is a faster conversation than inventing your own questionnaire.

Exit terms: negotiate the divorce while everyone is friendly

None of the terms below get easier to add after signature.

Data return. Your data, your outputs, and your configuration come back in a documented, usable format (not a proprietary export) within a defined window, at no fee or a capped fee. “Usable” is worth a sentence of its own. A decision log in a format nobody can parse has not really been returned.

Deletion with certification. After return, the vendor deletes your data, including from backups on a stated schedule, and certifies it in writing. Pair this with the derived data definition from earlier, or the deletion clause quietly excludes the thing you cared about.

Transition assistance. A defined period (90 days is common) at a defined rate during which the vendor keeps the service running and cooperates with your migration. Without it, every renewal negotiation starts with the vendor holding your operations.

Change of control. AI vendors get acquired. You want notice of acquisition and a termination right if the buyer is unacceptable, with your data commitments surviving the transaction. The consolidation wave in the point solution tier keeps raising the odds this clause gets used.

The negotiating reality for a $250M to $5B credit union

You will not get everything above from a tier 1 core provider, and you do not need everything from a low-risk internal productivity tool. Spend your leverage where member data and member outcomes are on the line. A practical floor for any system touching member data: narrow license on inputs, no cross-customer training without opt-in, named subprocessors, incident notice in hours, data return and certified deletion, and transition assistance. That floor is achievable at your asset size because vendors selling into credit unions have signed it before. Ask for the paper where they did. One caveat: if you are negotiating with a very early-stage vendor, some of these terms may simply not exist in their template yet, and you will be drafting them together, which is its own diligence signal.

Contract review is also where a pilot earns its keep: a 90-day pilot run under a short-term agreement tells you which clauses you exercised in practice before you sign a three-year term.

Get a second set of eyes before you sign

Advisor Labs reviews AI vendor agreements as part of its vendor-neutral audit work for credit unions: we map the contract against your data flows, flag the clauses that will surface on your next exam, and give you a redline priority list your counsel can execute. If a signature is on your calendar this quarter, book a working session first.

For the weekly signal roundup and the monthly executive briefing, subscribe to the newsletter.