A November morning. The marketing operations director walks in with a dashboard alert. Overnight, one of the campaign agents had autonomously reallocated £200,000 in media spend, shifting budget from underperforming channels to higher-converting segments with precision a human team would have taken weeks to reach. The reallocation was correct. Nobody had authorised it. Nobody knew until the alerts fired at 7 AM.
That moment crystallises everything about why governance matters in agentic marketing. The fine does not land on the vendor. It lands on the company whose logo sits at the bottom of the email.
That sentence is the shape of every regulatory conversation a CMO will have about agentic marketing between now and 2030. The instruments that matter — Regulation (EU) 2024/1689 (the EU AI Act), the UK GDPR and Article 22, the UK Digital Markets, Competition and Consumers Act 2024, the EU Digital Services Act, the Unfair Commercial Practices Directive — are drafted around a figure the regulator calls the controller, the deployer, or the trader. In each case, that figure is the customer. Not the model provider. Not the integrator. Not the agent. The customer whose brand carries the output.
This article explains why, and what procurement discipline now compensates for what the vendor’s standard contract systematically under-prices.
Why the Liability Sits Where It Sits
The statutory architecture is consistent across the instruments.
Under the EU AI Act, the deployer of a high-risk AI system bears the weight of most customer-facing obligations — Article 26 on deployment duties, Article 27 on fundamental-rights impact assessments, Article 86 on the right to explanation. The provider has upstream obligations on technical documentation, conformity assessment, and registration. The regulator’s direct channel to consumer-facing harm runs through the deployer.
The phased timeline has closed the runway on which CMOs assumed they could delay the conversation. Prohibited practices applied from 2 February 2025. General-purpose AI model obligations from 2 August 2025. The full requirements for high-risk AI systems take effect on 2 August 2026. Bulk enforcement architecture is expected to be live by 2 August 2027. Fines reach €15 million or three per cent of global turnover for high-risk system breaches.
Under the UK GDPR, the controller — the party that determines purposes and means of processing — is the direct addressee of supervisory-authority enforcement. A marketing organisation does not become a processor by outsourcing automated decisioning to a vendor. The vendor is a processor. The controller remains the controller. Article 22’s protections against solely automated decision-making bind the controller. The data subject’s complaint lands at the controller’s door. The Article 82 damages claim is brought against the controller.
Under the DMCC Act 2024, consumer-protection provisions commenced on 6 April 2025. Subscription-contract provisions are expected to come into force in spring 2027 through secondary legislation. The Competition and Markets Authority has administrative enforcement power and turnover-based penalties — up to ten per cent of global turnover for the worst breaches. The Act binds the trader. An agent that sets subscription pricing, constructs checkout flows, or tunes commercial communications is acting as the trader, whoever built it.
The pattern repeats across the EU Digital Services Act, the Unfair Commercial Practices Directive, the UK Equality Act 2010, and their EU analogues. Regulation attaches to the party in the commercial relationship with the consumer. Agentic marketing does not change that. It multiplies the decision count at a scale no human review process can absorb while the statutory addressee remains the same.
Why the Standard Contract Is Wrong
A typical SaaS contract caps liability at twelve months of fees, offers an IP-infringement indemnity subject to that cap, disclaims consequential loss, and places operational risk with the customer under a service-levels schedule that measures uptime, not decisions.
When an agent runs for eleven months, publishes sixty thousand pieces of customer-facing content, and one piece becomes the subject of a CMA enforcement notice, that construction offers no protection. The CMA’s ten-per-cent penalty exposure dwarfs the contract cap by two or three orders of magnitude. The vendor pays the cap. The customer carries the rest.
The remedy is drafting discipline, applied at procurement. Seven clause areas need rewriting before any agentic contract is signed.
Procurement Discipline as Perimeter
The foundational question is who owns what. The vendor’s default is to collapse ownership of customer inputs, prompts, and fine-tuning corpora into a broad grant of rights that survives termination. The CMO’s position should be structural: the customer owns what the customer brought, the customer owns what the customer created, and the customer’s rights do not lapse on exit.
Three drafting points carry this.
Customer Data ownership must extend to derived data, decision traces, embeddings, prompt-completion pairs, and evaluation sets. In agentic systems, the derivatives are often more commercially sensitive than the raw inputs. A definition that stops at the input layer gives the vendor perpetual rights over the operational state of the system the customer paid to build.
Customer Configuration — prompts, system prompts, policy files, autonomy configurations, agent definitions, workflow definitions, fine-tuning data, evaluation data, red-team corpora — is the encoded operational know-how of the marketing function. A default supplier contract grants a perpetual, irrevocable licence to use configuration “for service improvement”. That is a licence to train a future version of the model on the customer’s institutional memory. Close the door: the vendor’s licence is limited to delivering the service in the customer’s instance, during the term, with training uses prohibited.
Outputs pose a legal-uncertainty problem. Copyright in AI-generated output remains unsettled in most jurisdictions. Handle the uncertainty belt-and-braces — assign whatever rights are assignable and grant exclusive licence as to anything that is not, with a supplier warranty on personnel and subcontractor consents.
The Training Rights Walk-Away
The commercially explosive clause in most agentic contracts is the one that grants the supplier rights to train on customer data. Industry drafting ranges from “service improvement” to “evaluation and model development”. Both translate to training.
The CMO’s position should be that training rights are separate from service delivery and must be addressed expressly, with a default answer of no.
Two reasons matter in marketing specifically.
Confidentiality exposure runs upstream. A marketing organisation that permits vendor training on customer interactions is typically in breach of upstream obligations to its own customers, distributors, and partners. The confidentiality clauses governing human handling of the underlying data do not contemplate model training. Without an express no-training default, the CMO has quietly subrogated the organisation’s confidentiality posture to the vendor.
Competitive dilution runs downstream. A vendor that trains on customer A’s operational data improves a model it then sells to customer A’s competitors. The efficiency gain the vendor achieves is partly an appropriation of the customer’s institutional edge. A no-training default is the only posture that preserves competitive differentiation.
Walk-away rule. If the vendor cannot accept some version of the no-training clause, the relationship is not a vendor relationship. It is a data-capture exercise dressed as a service contract.
SLAs Drafted for the Right Failure Mode
The standard SaaS SLA measures uptime and response time. Neither captures what actually goes wrong with an agentic system. Agents fail by making bad decisions at high throughput, not by going offline.
Three SLA constructs belong in every agentic contract.
The Decision-Quality SLA commits the vendor to a minimum proportion of agent decisions passing post-hoc human review, measured on a defined protocol with monthly reporting and a termination right after consecutive breaches. An agent making a million decisions a month at ninety-nine per cent “acceptable” still produces ten thousand bad decisions, many customer-facing.
The Drift SLA commits the vendor to performance within stated drift tolerance on an evaluation framework, with monthly evaluation, 24-hour notification of breach, a 7-day root-cause analysis, and a 30-day remediation window. Silent drift is the defining failure mode of production AI. The drift SLA converts a silent failure into a contractual obligation.
The Explainability SLA commits the vendor to generating decision traces on request, with tiered windows: 24 hours for routine requests, one hour for urgent, and the regulator-specified window for regulatory enquiries — with failure in the regulatory case treated as material breach. Article 22 of the GDPR and the right-to-explanation mechanics under the AI Act both assume the deployer can produce a defensible explanation within the regulator’s clock. A system the vendor cannot explain inside that window has transferred the compliance risk back to the customer.
The service-credit regime should be the customer’s remedy of first resort but must not be mutually exclusive with damages or termination rights. A credit regime capped at the quarter’s fees, while the agent is costing the organisation seven figures a month in regulatory exposure, is not a remedy.
Indemnification for Agentic Failure Modes
Four indemnity constructs belong in the contract.
IP-infringement indemnity extended to training data. The standard cap is meaningless in a serious IP claim. Raise the cap to the greater of three times annual fees and £10 million. Break out the defence obligation from the monetary cap. Extend the indemnity to training data — the vector through which most class-action risk will reach the customer.
Defamation and advertising-regulation indemnity. Place the economic exposure with the vendor where output was generated autonomously, within the vendor’s defined parameters, and breached the UK Defamation Act 2013, the EU Unfair Commercial Practices Directive, or the DMCC Act 2024.
Unlawful-discrimination indemnity. This addresses the failure mode most likely to trigger regulatory action and class litigation. The customer will be the named defendant; the regulator looks to the controller, not the processor. The uncap construction is deliberate; a capped indemnity is not a workable posture on equality exposure.
Uncapped carve-outs. The traditional carve-outs — death or personal injury, fraud, liabilities non-excludable by law — extend in agentic contracting to training-without-consent and breach of training-data lineage warranties. These are not optional additions. They are the categories without which the cap itself becomes an indemnity against fundamental breach.
A practical test: compute, in sterling, what a ten-per-cent of global turnover CMA penalty would be for your organisation. Set that figure against the cap. If the delta is material, the contract is under-priced.
Termination as a Planned Capability
Supplier contracts treat termination as an exception. For agentic systems, the customer should treat termination as a planned capability.
Termination for convenience is the single clause the vendor will fight hardest and the buyer must win. Without it, the customer is locked in for the initial term regardless of performance, technological obsolescence, or strategic change. A 90-day notice with no break payment is the realistic position. A defined break-fee tapering mechanism is the minimum acceptable.
Termination for material breach must specify the breach categories that count as clear grounds. A change-of-control trigger addresses the frequency of acquisition in the agentic-AI vendor population. An insolvency trigger addresses the fragility of several segments of the supplier market.
Exit assistance makes the termination right operational. A termination right the supplier can frustrate by withholding cooperation is not a termination right. A 180-day Exit Period with a priced cooperation obligation, a 15-day Exit Plan delivery obligation, and an anti-degradation commitment that prevents the supplier’s performance collapsing the moment notice is served.
Data and model portability is the pressure point. On termination, the supplier must deliver customer data, customer configuration, audit logs, decision-trace data, evaluation results, and fine-tuned model weights or adapter weights where trained on customer configuration and lawfully transferable — plus a written description of architecture, evaluation methodology, and guardrail configuration sufficient to permit reconstruction. Without that portability, the customer cannot move the operational state to a successor. It can only start again.
Three Procurement Moves Before the Next Renewal
The contract you signed last cycle was not drafted for the systems you are now running. Fix the gap.
Run the ten-per-cent global-turnover penalty calculation against your single largest agentic vendor contract’s liability cap. If the delta is material — and it almost always is — the contract is materially under-priced. Open the renegotiation conversation now, not at the next renewal cycle.
Audit your active agentic contracts for the seven clause areas: ownership perimeter, training rights, decision-quality SLA, drift SLA, explainability SLA, indemnity coverage, and termination portability. Identify the single most exposed gap and close it.
Map every customer-facing agent in production to the EU AI Act risk classification. Anything that lands in the high-risk Annex III category is subject to the full obligations from 2 August 2026. Compliance work that starts in May 2026 arrives at the deadline in panic. Work that started six months earlier arrives on time.
The deployer-side liability case is the part of the second edition that most distinguishes it from the first. The first edition could treat the EU AI Act as forthcoming. The second edition is written for CMOs who will be holding agentic deployments inside the Act’s full enforcement perimeter within the lifetime of the book they are reading.
The fine does not arrive at the vendor’s office. It arrives at the company whose advertising was misleading, whose decision was discriminatory, whose subscription flow was a dark pattern, whose automated refusal could not be explained within the statutory window.
Procurement discipline is the one instrument that redistributes that exposure. Without it, every efficiency gain from the agent portfolio is being financed out of an off-balance-sheet liability the CFO has not priced.
Keep Reading
That’s all for this week book chapter summary, come back next Monday for the next chapter summary.
The Agentic CMO - Second Edition is available today in hardcover, paperback and ebook.
Disclaimer: The views and opinions expressed in The Agentic CMO, Chronicles of Change and on my social media accounts are my own and do not necessarily reflect the official policy or position of S&P Global.
