What an AI-use audit clause covers
Vague audit rights over AI use turn into open-ended discovery. A scoped clause, plus the record set that makes the whole audit take an hour.
Audit rights over AI use started appearing in enterprise creative contracts because the client now has an obligation they cannot discharge on trust. If a brand has to represent that it knows how its published assets were made, and its suppliers are the ones who made them, an inspection right is the only mechanism that turns the representation into something a compliance team can sign.
The clause is reasonable. The drafting usually is not. "Supplier shall maintain records relating to the Services and shall permit Client to inspect the same upon request" is the standard shape, and it has no scope, no notice period, no frequency limit, and no boundary on what "inspect" means. That is not an audit right. It is a request for open-ended discovery with your name on the cost.
Why the clause exists now
Audit rights are the newest item on the practitioner clause lists, and they arrived last for a reason. Numonic's clause set for agency contracts puts them at the end of a stack that opens with disclosure and metadata preservation, because an inspection right is not really a commitment in its own right. It is the mechanism that makes the earlier ones checkable. Without it, every AI provision in the agreement is a statement you made once at signature and nobody can test afterwards.
The external pressure is dated. The EU AI Act's Article 50 transparency obligations reached enforcement in August 2026, and separately, US state-level rules keep arriving with their own timelines, including the AB 853 platform duties landing in January 2027. Enterprises with exposure to any of it are pushing the evidentiary burden down their supply chain, which is where you are.
So the clause is not going away and negotiating it out is usually the wrong ask. Negotiating it into shape is the right one.
The three ways it goes wrong
Undefined scope. "Records relating to the Services" is everything. Emails, internal chat, financial records, staffing. An AI-use audit should reach production records for the deliverables produced under the agreement and nothing else. If the auditor wants your P&L, that is a different clause and it should be negotiated separately.
No notice or frequency limit. An unbounded right is a standing burden, because you have to be permanently audit-ready rather than able to prepare. Ten business days' notice and once per contract year is normal, with a carve-out for a genuine investigation into a specific incident.
Access rather than production. This is the expensive one. There is a meaningful difference between "Supplier will produce the records listed in Schedule X" and "Client may access Supplier's systems." System access means an auditor in your tooling, seeing every other client's material, forming opinions about things they were never entitled to look at. Production of a defined document set is the version you can live with, and it is the version that answers the client's actual question.
The fourth issue is cost, and it is easy to fix. Cost sits with the requesting party unless the audit finds a material breach, in which case it flips. That is standard commercial drafting and it does more than anything else to keep audits proportionate, because an audit that costs the requester something gets scoped before it gets requested.
Clause text
Records. Supplier maintains, for each Deliverable, the production record set out in Schedule [X], and retains it for [24] months from delivery.
Inspection. On [10] business days' written notice, and no more than [once] per contract year, Client may request production of the records described above for Deliverables produced under this Agreement. Supplier will produce the records in written or exported form. This clause does not confer access to Supplier's systems, personnel files, financial records, or materials belonging to any other client.
Confidentiality. Where Client appoints a third-party auditor, that auditor is bound by confidentiality terms no less protective than those in this Agreement, and Supplier may redact material relating to other clients.
Cost. Each party bears its own costs, unless the inspection identifies a material breach of the AI provisions of this Agreement, in which case Supplier bears the reasonable cost of the inspection.
Investigation. The frequency limit does not apply where Client is responding to a regulatory enquiry, platform enforcement action or third-party claim concerning a specific Deliverable, in which case Supplier will produce the record for that Deliverable within [5] business days.
The investigation paragraph is the one to volunteer rather than wait to be asked for. It is the scenario the client is genuinely worried about, and conceding it cheaply is what buys you the frequency limit everywhere else.
The record set that makes an audit an hour
Everything above is only tolerable if producing the record is trivial. Define the schedule tightly, because a schedule you wrote is a schedule that bounds the request.
| Field | Example | Why an auditor wants it |
|---|---|---|
| Deliverable ID | acme-q3-hero-v4 |
Ties the record to a published asset |
| Model name and version | Named model, exact version string | The whole question, and the field most often missing |
| Generation date | 2026-08-14 | Establishes which tool terms applied at the time |
| Operator | Named person or role | Accountability, and it is usually in the client's own policy |
| Prompt or workflow reference | Template ID plus version | Shows the method was controlled, without exposing the library |
| Client material used | Yes/no, and what | Answers the training and confidentiality question directly |
| Human modification | One line describing the human contribution | The field that supports the authorship position |
| Disclosure applied | Label text and surface | Answers the compliance question the audit exists for |
| Licence basis | Commercial use permitted under tool terms | Answers the indemnity question |
| Delivery | Date, format, recipient | Fixes the state of the asset at handoff |
Ten fields, one row per deliverable. If a client's audit schedule is longer than this, ask what decision each extra field informs. Usually one or two survive that question and the rest were copied from a software audit template.
Note what is not on the list. Raw prompt text is not there, and neither is the library itself. The prompt reference proves the method was controlled and versioned, which is what the auditor actually needs to establish. Handing over the strings gives away a retained asset for no evidentiary gain, so keep the library structured and versioned separately from the record: building a prompt library your team actually uses is the practice that makes the reference column meaningful.
Keeping the record without adding a job
The reason audit clauses feel heavy is that most teams imagine reconstructing all of this at audit time. That is genuinely a week of work. Capturing it at generation time is about fifteen seconds per deliverable.
Three habits do it.
Name assets so the record is derivable. Half the fields above are recoverable from a disciplined filename and folder structure. Asset naming and version discipline for content teams and version control for brand creative assets are the same practice pointed at a different problem, and they cover most of the deliverable ID, date and version columns without any extra step.
Log at the moment of generation, not at delivery. The model version field is the one people cannot reconstruct, because catalogs move and a model you used in March may have shipped a new version by August. Search over your own generation history covers the recall case, and finding something you made before is the primitive for that, but a written version string at the time is what an auditor accepts.
Use one sheet for two jobs. The per-client credit ledger described in tracking credits per client and per deliverable already wants deliverable ID, model, date and phase. Add the four compliance columns and the same sheet answers a profitability question and an audit request. Two reasons to maintain one artefact is the only version of record-keeping that survives a busy quarter.
The approval side is worth wiring in too. If a deliverable cannot reach delivered status without the disclosure and human-modification fields populated, the record maintains itself. Content approval workflows that don't stall covers making that gate light enough that people do not route around it, and governance guardrails for brands is the same control set written from the client's side, which is useful reading before you negotiate the clause.
FAQ
Can I refuse an audit clause entirely?
You can try, and with a smaller client you will often succeed. With an enterprise client it usually reads as evasion, which costs you more than the clause does. Scoping it is a better use of the negotiation than removing it, and offering the record schedule yourself is the strongest position in the conversation because it makes you the party proposing rigour.
What if a deliverable predates the record-keeping?
Say so plainly, give the retention start date, and describe what you can reconstruct. An honest gap disclosed up front is a normal audit finding. A reconstructed record presented as contemporaneous is a much worse problem, and it is the kind of thing that turns a routine inspection into a serious one.
Does an audit right let the client see other clients' work?
Not under the clause above, and this is worth holding firm on regardless of how the client's template is drafted. Their own suppliers' confidentiality is the mirror image of yours, so the argument is one they already accept in principle. Redaction rights and an auditor confidentiality undertaking are the standard answer.
Is an automated detection check part of an audit?
Sometimes, and it is worth understanding what those tools do before agreeing to it, because their outputs are probabilistic and a false positive in an audit report is expensive to unwind. Running detection tools against your own exports is the useful preparation, since it means you know what an auditor's tool will say before they run it.