Congress has not passed a federal AI framework, while states are passing their own safety requirements. [3] If your organization runs an AI tool—a customer-support assistant, a document-review platform, or anything else that processes work at volume—do not wait for Congress before reviewing the contract. This quarter, before the next renewal lands on your desk, add four specific protections and assign an owner to maintain them.
First: The Right to Actually Leave
For this decision, portability means your contractual right to move your data and workflows to a different tool without starting over. A useful portability clause does three things: it names the file format in which the vendor will export your data, sets a timeline for that export, and commits the vendor to basic transition support if you leave.
Data-export rights need their own test. The data your organization generated while using the tool should come back in a form another system can use. A vendor could satisfy a vague export promise with a proprietary structure that requires substantial work before another tool can read it. The clause should therefore name both the format and the standard: readable, importable, and yours to take.
Without those terms, a manager cannot know the cost or time required to leave. If a new requirement later makes the tool unsuitable for a market you serve, the contract determines whether your team can move through a planned transition or must reconstruct its work under pressure. Portability does not remove switching costs. It makes the exit path visible before you need it.
Second: A Cap on Renewal Length
For AI tooling, set a renewal-length cap instead of accepting a long commitment by default. A one-year cap is a practical starting point because it creates a regular chance to review the tool, its underlying model, and the rules affecting the workflow. The right cap depends on your negotiating leverage and migration cost, but the contract should not renew for longer than your organization is willing to carry an unresolved compliance gap.
NIST's Center for AI Standards and Innovation published a summary of public input on AI agent security. It summarizes responses to a request for information, meaning a formal government call for public input. NIST says commenters widely agreed that AI agents present novel security threats and that these security concerns are a barrier to adoption. Commenters also said basic cybersecurity principles remain relevant but need adaptation for agent-specific risks. They identified implementation guidance, information-sharing, and promoting standards as roles for government. [1]
That report is not a standard, a regulation, or a promise that a particular requirement will arrive on a particular date. It shows that organizations are raising agent-specific security problems and asking government for practical guidance. A shorter renewal cycle preserves the option to renegotiate if guidance or applicable rules change. It does not require you to predict what Congress or NIST will do.
For a manager renewing a document-review tool, the action is simple. Compare the proposed term with the next scheduled policy and risk review. If the vendor asks for a commitment extending well beyond that review, require an earlier exit or renegotiation point. The contract should create room for the decision your future evidence may require.
Third: Named Model Disclosure and Notice
Some business AI tools rely on an underlying model supplied by another company. When that is true, your contract with the tool vendor also creates an operational dependency on a model provider you may not deal with directly.
Require the vendor to identify that provider by name and give written notice before the relationship changes. Set the notice period according to how long your team needs to test the replacement, update documentation, and prepare users. The point is not to prevent every model change. It is to prevent the change from reaching your workflow before the people responsible for it can assess the effect.
A different underlying model can change output quality or behavior. In customer support, that could mean different answers or a different tone. In document review, it could mean different handling of borderline cases. Notice gives the workflow owner time to compare the new behavior with accepted examples before customers or employees depend on it.
Pair the notice requirement with transition support: a documented migration process, a named vendor contact, and a defined assistance window. These terms turn an unexpected supplier change into a managed decision. If the vendor cannot offer them, record that limitation before signing and reduce the contract length to match the added risk.
Fourth: A Named Internal Owner
The last item is not a contract clause. It is an internal assignment.
NIST reports that commenters saw roles for government in implementation guidance, information-sharing, and promoting standards. [1] That finding does not guarantee a new rule or timetable. It does mean your organization has a defined body of government work worth checking, because it addresses the security questions affecting agent adoption.
Assign one named person—a procurement manager, legal operations contact, or compliance lead—to a quarterly review. The scope is specific: check the latest NIST and Center for AI Standards and Innovation publications on agent security, review applicable state requirements in the places where your organization operates, compare them with current vendor contracts, and escalate any gap before the next renewal window opens.
That person does not need to become a policy expert. They need a short source list, a calendar reminder, access to the contracts, and a clear route to legal or security specialists when a requirement affects the workflow. Naming the owner matters because a broad instruction to “monitor AI regulation” gives nobody a deadline or a decision to make.
Why the Signals Matter Together
NIST's analysis and OpenAI's policy advocacy come from different institutional positions, but they both show that formal governance for deployed AI is being actively shaped.
OpenAI's chief global affairs officer called voluntary commitments insufficient and advocated mandatory, capability-based national regulation. Capability-based means obligations become stronger as model capabilities and risks increase. The company proposed common testing, independent assessment, cybersecurity protections, and incident reporting. [2] Reuters independently confirmed OpenAI's call for binding national safety requirements. [3]
Treat that position as commercial advocacy from a frontier lab, not neutral policy analysis. OpenAI argues that frontier safety requirements should apply to the handful of well-resourced laboratories developing the most capable systems, rather than to startups or researchers operating away from the frontier. That approach places direct burdens on the largest vendors, including OpenAI, but it could also shape rules around the way those vendors already operate. Both incentives deserve attention. [2]
NIST does not endorse OpenAI's proposal, and OpenAI does not speak for the NIST respondents. The useful connection is narrower: NIST documents demand for adapted security practices and government support, while a major vendor is asking for mandatory rules. Rational Agent's synthesis is that managers should expect contract and operating requirements to remain a live issue even if Congress does not act soon. That is enough reason to preserve options; it is not a forecast that any specific proposal will become law.
The Operating Consequence
At the next customer-support or document-review renewal, check the vendor agreement for usable data export, transition support, a disclosed model provider, notice of provider changes, and a term short enough to revisit those protections. If any item is missing, put it in the redline and record the vendor's response.
Once the agreement is signed, give it to the named owner. That person records the model provider, confirms the export format, sets the next policy review, and opens renegotiation before the renewal deadline if a material gap appears. Congress has not provided a federal framework. Your contract and ownership model still have to provide a workable exit.