AI Is a Supply Contract, Not a Seat License: The Capacity Clauses Your Vendor Agreement Is Missing

Regulated mid-market buyers are signing AI deals on seat-count SaaS terms while the real dependency runs model to cloud to accelerator to memory to power. Here are the capacity and continuity clauses procurement keeps leaving out, and why an auditor will ask for them.

A regulated mid-market buyer, a behavioral health network running automated prior authorization, a property manager screening tenants, a PE portfolio company that just wired an LLM into its revenue cycle, tends to buy AI the way it buys any other SaaS: a per-seat or per-user order form, an annual term, an uptime SLA, a data processing addendum, done. That instinct is wrong, and the events of the last few weeks make the cost of being wrong concrete. Consider what already happened. On May 5, 2026, the default model behind the most-used consumer assistant changed to a new release exposed as a floating "chat-latest" alias, meaning the model answering your users can change underneath you with no version pin and no change notice. That is the benign version of the problem. The harsher versions are capacity rationing and export-control action: a model you validated can be throttled when demand spikes, or pulled offline by a directive you have no say in. The lesson is not "models are unstable." The lesson is that the asset you are licensing sits on top of a physical supply chain you do not control, and your contract should reflect that. The dependency is a supply chain, not a subscription When you sign an AI deal, the seat count is the visible layer. Underneath it runs a chain: the model depends on cloud compute, which depends on AI accelerators, which depend on high-bandwidth memory, which depends on power and interconnect. Each link is capacity-constrained and, as the alias swap hinted, can be politically constrained too. A seat license prices your right to make API calls. It says almost nothing about whether the capacity behind those calls will exist next quarter, whether it will be rationed during a shortage, or where you sit in line when it is. This is the same structural blind spot the BAA chain exposed for healthcare data, you contract with the vendor in front of you and inherit obligations and dependencies you never see. We covered that mapping problem in our Vendor BAA Chain Procurement Field Guide (/blog/vendor-baa-chain-procurement-field-guide). Capacity is the operational twin of that legal chain. You are not buying software; you are buying a claim on scarce physical infrastructure, intermediated by a vendor who is themselves a downstream buyer of that infrastructure. Treat the deal accordingly. A supply contract for a critical input, and an LLM that runs your prior-auth queue or your tenant decisions is a critical input, asks three questions a SaaS order form never asks. Is my capacity reserved or best-efforts? What happens in a shortage? Where am I in the allocation queue? None of those appear on a standard seat license. What the old control model misses The familiar AI procurement debate has been about pricing mechanics, the shift from seat pricing to agent-action metering, and the middleware layer that obscures what you are actually paying per task. We have written about both; this is not that. Metering is a cost-control problem. Capacity is a continuity problem, and continuity is what regulators and boards actually examine after an outage. A standard SaaS uptime SLA promises 99.9% availability of the service. It does not promise that the specific model you validated will still be served, that your throughput will not be throttled when demand stampedes onto a replacement, or that a healthcare customer ranks above a hobbyist when the vendor rations tokens. The May 5 alias swap sits entirely outside what a conventional SLA covers: your service was "up," your model was quietly changed. The Cloud Security Alliance's May 20 non-human-identity governance work noted that machine identities now outnumber humans roughly 45:1, and as high as 144:1 in some estimates, every one of those agents is a consumer of the same constrained capacity. When you scale from a pilot to production, your demand curve is not linear in seats; it is driven by autonomous calls. A contract priced and provisioned on human headcount will not survive that curve. What the audit and the board will ask After the next disruption, expect three questions, and expect them from your auditor, your board's risk committee, and, for anyone touching the EU, a regulator. EU AI Act GPAI enforcement powers activate August 2, 2026, with fines up to 3% of global turnover, and downstream deployers must collect provider documentation now even though the high-risk Annex III obligations slipped to December 2027. The US Treasury's February 19 Financial Services AI RMF lays out 230 control objectives across seven domains; resilience and third-party dependency are explicitly among them. Texas TRAIGA has been in force since January 1. The questions are blunt. First: when your primary model became unavailable, what was your documented fallback and how fast did it engage? Second: what contractual commitment did you hold on capacity, and can you produce it? Third: who decided your AI dependency was acceptable concentration risk, and on what written basis? If your answer to any of these is "we had a seat license and an uptime SLA," you do not have a control, you have an invoice. The clauses to put in the contract Hand your procurement team a short checklist and require these terms before signature. Five clauses, each a column in a redline tracker: Reserved vs. best-efforts capacity. State explicitly whether your throughput is contractually reserved or provided on a best-efforts basis. If best-efforts, price the risk and document the fallback. Reserved capacity costs more; for a workload that touches PHI or housing decisions, that is the price of continuity. 30-day shortage fallback. Require that if the contracted model becomes unavailable or materially throttled, a named substitute model is made available at agreed terms within a defined window, with a 30-day minimum continuity guarantee while you revalidate. Models already get swapped and throttled, the May 5 alias change is the mild end of that spectrum, so this is not hypothetical. Allocation priority. During capacity rationing, where do you sit? Negotiate a stated priority tier, or at minimum a most-favored-class commitment that you will not be deprioritized below comparable customers. Model-pinning and change notice. Forbid silent swaps of floating aliases. Require a pinned model version, a defined deprecation runway, and written notice before any substitution, exactly the gap the "chat-latest" default exposed. Exit and portability. On suspension, deprecation, or export-control action, you get your prompts, fine-tunes, embeddings, and logs in a usable form, plus contractual cooperation to stand up an alternative. For data that genuinely cannot tolerate this exposure, capacity risk is also an argument for an owned fallback. Open-weight models released May 1 give you a self-hosting path inside your own perimeter, slower and more expensive per token, but a continuity floor no directive can pull. What we recommend For regulated mid-market buyers, four moves before your next renewal: 1. Reclassify your top AI vendors as critical-input suppliers, not SaaS subscriptions, and route their contracts through whoever owns supply-chain and third-party risk, not just the software buyer. 2. Add the five clauses above as standard redlines. If a vendor will not commit to reserved capacity or a shortage fallback, that refusal is itself the risk disclosure your board should see. 3. Designate and pre-validate a fallback model for every workflow that touches regulated data, including at least one self-hostable open-weight option, and write the cutover into your continuity plan. 4. Document the concentration-risk decision in writing, owned by a named accountable executive, mapped to your applicable framework, Treasury RMF, TRAIGA, or the EU AI Act deployer obligations now active. This is the substance of the work we do with regulated mid-market clients in a fixed-scope Diagnostic: read the actual order forms, find the missing capacity terms, and hand back a redline and a fallback plan you can put in front of an auditor. Buy AI like the supply contract it already is, before the next model gets pulled and your continuity plan is someone else's press release.