When a CIO makes a new technology purchase, the sophistication of the solution isn’t the only thing that determines how much innovation will be unlocked. And it’s not just the price that determines how much value the deal will bring to the organization, either. 

One of the most important factors in the success of IT investment is also one that is often overlooked: the vendor agreement. 

“The ability for enterprises to innovate rapidly is key as AI evolves and agentic systems rewrite the rules of business,” says Dr. Martin De Saulles (LinkedIn: Dr. Martin De Saulles), principal analyst for Information Matters. “CIOs need to ensure their vendor agreements are not a roadblock to this.”

The consequences of a restrictive vendor deal can be significant. A single buried clause concerning data portability, API access, or intellectual property can limit an organization’s ability to experiment, integrate new tools, or painlessly move to a new vendor. And any agreements signed today will shape what organizations can (and can’t) do for years to come.

How can organizations ensure fair agreements? To find out, we posed this question to the technology experts in the Foundry Influencers Network: What should CIOs look for in vendor agreements to ensure they have the tools and freedom they need to foster innovation?

Data agency, portability, and API access

Nearly all the experts stressed the importance of contract language that gives organizations agency over their own data, as well as the ability to integrate disparate tools. 

“CIOs should negotiate for data portability and API access as non-negotiable contract terms, not nice-to-have add-ons,” says Will Kelly (LinkedIn: Will Kelly), a writer focused on AI and the cloud. “Lock-in is the enemy of innovation, and the vendors who resist interoperability clauses are telling you exactly how they plan to keep your business. Look for agreements that give your teams the freedom to integrate, extend, and replace components without requiring vendor permission or a professional services engagement every time.”

Similarly, flexible licensing and data agency top the list of contract considerations for Vivek Singh (LinkedIn: Vivek Singh), senior vice president of IT and strategic planning at PALNAR. “Ensure that there are no lock-ins, and that there are APIs and interoperability,” he says. “Transparency in pricing and alignment of the roadmap are important, as well.”

Scott Schober (LinkedIn: Scott Schober), president and CEO at Berkeley Varitronics Systems, Inc., says that CIOs should prioritize clauses concerning data agency, portability, and access to ensure comprehensive control over their data. “Also, integration is crucial,” he says. “All vendors should facilitate open APIs and interoperability, avoiding the imposition of inflexible ecosystems. Contractual stipulations regarding customization, scalability, and usage rights should accommodate organizational evolution, rather than impede future innovation.”

Security and governance

Schober also emphasizes the importance of security—not only how the vendor safeguards data, but also what responsibility they will take in the event of a breach. “Security and compliance obligations must be explicitly delineated, with transparency regarding the vendor’s protective and monitoring measures,” he says. 

Tom Allen (LinkedIn: Tom Allen), founder of The AI Journal, says that data governance and responsibility should be “hard-wired” into contracts. “Vendor agreements must address who owns what data and derivatives, how models trained on your data can be used, and what transparency you get into security, incident response, and regulatory compliance,” he says. 

Ownership of IP and innovation

Allen adds that CIOs should insist on language guaranteeing they will be able to push technology forward in partnership with their vendors. “Contracts need explicit commitments on innovation and roadmap collaboration,” he says. “For example, they should include regular joint reviews, access to sandboxes, and the ability to co‑create pilots, rather than just static SLAs.” 

Even something as simple as who provides AI capabilities can create ambiguity around ownership of intellectual property (IP), says Peter Nichol (LinkedIn: Peter Nichol), data and analytics leader for North America at Nestlé Health Science. “Tools like ChatGPT and GitHub Copilot are increasingly assumed, not defined, creating hidden risk,” he says. “If the vendor provides them, they may assert rights over the IP. If the client provides them, ownership is clearer, but costs shift. CIOs must make explicit who pays, who owns, and who has rights to the output. If it is not defined upfront, you are not enabling innovation. You are creating exposure.”

Oreoluwa Adesanya (LinkedIn: Oreoluwa Adesanya), an engineer, cybersecurity specialist, and developer in AI and fraud, echoes the idea that CIOs must insist on contract language that protects innovation. “Get source code escrow in writing,” he says. “If the vendor folds or gets acquired, you need a contingency plan that doesn’t involve scrambling to rebuild from scratch. Any innovation your team builds on top of the platform should legally belong to your organization, not handed back to the vendor through a buried IP clause nobody read carefully.”

Exit terms and flexibility

Finally, experts stressed the importance of contracts that allow for clean, drama-free exits if the organization moves to another vendor in the future. 

“Vendor lock-in often starts quietly at the data layer,” Adesanya notes. “Before signing anything, CIOs need to make sure they can actually take their data and leave if things go wrong.” 

Javier Campos (LinkedIn: Javier Campos), AI safety researcher and group chief technology officer at Peach, says that CIOs can protect their organizations by treating vendor agreements as “strategic enablers,” rather than as mere “procurement checkboxes.” 

“Innovation dies the moment you’re locked into a single vendor’s roadmap,” Campos says. “Look for agreements that guarantee access to your own data in standard formats, allow integration with best-of-breed tools, and don’t penalize you for scaling down or switching. The best vendor relationships are the ones where the vendor earns your renewal through value, not contractual friction.” 

Campos adds: “Ultimately, if an agreement limits your ability to experiment, pivot, or compose new solutions, it’s not a partnership. It’s a constraint.” 

To learn more check out the Insider’s Guide to Intelligent Enterprise Modernization.

Share
Share