AI

AI as a service: what you are renting, and what you own when it ends

Almost every AI proposal that crosses my desk in Kuwait is a rental agreement wearing the clothes of a purchase. The deck says built for you. The invoice says per user, per month. Nobody is lying, but the two sentences describe different things, and the gap between them is where the unpleasant surprise lives in year two.

This is not an argument against renting. Renting is usually right. It is an argument for knowing what the money buys, what stays with you if it ends, and whose calendar the whole thing runs on. Those questions have precise answers, and most buyers never ask them, because the phrase AI as a service sounds like one product and is in fact four.

Four different things get sold under one phrase

Renting the model. You call an API and pay per unit of text processed. What arrives has no memory of your business, and everything that makes it useful, you build and hold.

Renting a feature inside software you already use. The AI is a switch inside your CRM or helpdesk. You pay a seat uplift, configure almost nothing, and what you do configure lives in their database.

Renting a built system. Someone assembles a model, your documents, prompts and an interface into a working thing. This is the one called custom, and the one where ownership is most often left unstated.

Renting the team. A monthly fee for people who keep it running. This is the honest one, and it is priced like the retainer it is.

Most companies I speak to believe they are buying the third and are contractually in the second. That confusion accounts for more disappointment than any technical failure I have seen.

What is yours, and here the vendors are unusually clear

Start with the good news, which is better than the anxiety around it suggests. Anthropic’s commercial terms state that the customer retains all rights to its inputs and owns its outputs, and assign to the customer whatever interest the company might have in them. OpenAI’s data documentation says API content is not used to train its models unless you opt in.

So the text your assistant produces is yours, and the documents you fed it are yours. The copyright question that dominates the boardroom conversation is, for business use of the major platforms, largely settled by contract. Which is why it is the wrong worry.

The part that is not yours is the behaviour

The system behaves as it does because a particular model version responded in a particular way to instructions someone tuned against it. Those instructions are yours on paper. The thing they were tuned against is not.

Six weeks of work goes into getting an assistant to answer in the register your customers expect, refuse the four things it must never attempt, and hand over cleanly when out of its depth. That work is real and expensive. It is also written in a language whose grammar belongs to somebody else, and it holds only while that version is available.

Prompts are not portable the way code is. Move the same instructions to another provider and you do not get the same system slightly changed. You get one that must be re-tested from the beginning, because the failures land in different places.

The clock you did not set

This is the clause I ask about first, and it is almost never in the proposal.

Microsoft publishes an explicit lifecycle policy for the models it serves. A generally available model carries an eighteen-month lifecycle, its retirement date set when it launches. At twelve months it is deprecated: existing customers continue, new ones cannot start. For common deployment types Microsoft manages the upgrade itself, region by region, and it can happen where the new version is not yet separately available in your region. Preview models get thirty days’ notice and no option to stay. Where a retiring model has no replacement, requests return 410 Gone. A compliance or security problem allows emergency retirement on shortened notice. Anthropic’s deprecation policy commits to at least sixty days’ notice before retiring a publicly released model.

Read that as a buyer rather than an engineer. Sixty days, or thirty, is the window to re-test a system your operations depend on. Not to rebuild it. To find out whether it still behaves, in Arabic as well as English, across the edge cases you spent six weeks finding. If nobody knows the system well enough to run that test, the notice is worth nothing: you learn it changed when a customer tells you.

It is the question behind what a maintenance retainer has to cover and behind judging a website build on what you can change later. Not what it costs, but who controls the timing of the next unavoidable piece of work.

Three cards separating what the contract gives you, what is yours in name only, and the model version that retires on the vendor schedule
The first card is settled by contract. The third moves on a schedule you do not control.

Where the value quietly accumulates

Something else is being built while you use the service, and it is worth more than the subscription. Every time someone corrects the assistant or escalates a conversation, a judgement is recorded about what good looks like in your business. Accumulate a few thousand and you have the most valuable artefact in the arrangement: a test set that tells you in an afternoon whether any candidate system is fit for your work. It is what makes you able to leave, and the asset most likely to sit in a supplier’s platform with no clause saying you can take it with you.

Retention varies and is worth reading. OpenAI keeps abuse-monitoring logs up to thirty days by default, with zero retention only by prior approval. Google documents that caching is on by default and session resumption stores prompts and outputs for twenty-four hours. None of it is sinister. All of it is defaults somebody has to have read.

Five clauses, and they fit on one page

I ask for these before any AI service contract is signed. None is exotic, and none has ever been refused by a supplier acting in good faith, which makes a refusal informative.

One: name the model version and the notice. Which model, which version, on whose infrastructure, and how many days’ warning before it changes. A supplier who cannot answer is reselling something they do not control, and your notice will be shorter than theirs.

Two: the configuration is yours, in a readable file. Prompts, routing rules, refusal lists, escalation triggers, delivered on request in plain text. Not access to a screen where you can view them. A file.

Three: the interaction history is exportable, including the corrections. The test-set clause, and the one most often missing. Specify format and frequency: an export offered once at termination in a shape nobody can read satisfies the letter and none of the point.

Four: what happens on the last day. How long the data stays available, in what form it is handed over, and when it is deleted from their side. In days.

Five: who pays when the model changes underneath you. Re-testing after a forced upgrade is not a new project and should not be quoted as one. Either it sits inside the retainer or the boundary is written down.

Two columns setting the reassuring sentences in an AI proposal against the five clauses a contract has to carry
Every line in the dark column shrinks what leaving costs you.

The NIST AI Risk Management Framework treats third-party dependency as a first-class risk to be documented, not an operational detail. Five clauses is a modest reading of that.

What renewal actually costs

The first year is priced to be signed. The second is priced against your switching cost, and the supplier knows yours even when you do not. That cost is small if you hold the configuration as files, hold the interaction history with the corrections, and have someone in-house who understands the system. It is enormous if the only complete description of your process lives inside somebody else’s product. That is arithmetic, not a tactic. The question at signature is not the monthly figure, but what leaving would cost in eighteen months.

What I would do

Rent. Almost always rent, and at the highest layer that does the job, because the layers below are somebody else’s problem and should stay that way.

Then spend the saved effort on the three things renting cannot give you: a named person who understands the system, a file of your own configuration, and a growing set of real examples with the right answer beside each one. They cost a fraction of the subscription and they are the whole difference between a supplier relationship and a dependency.

The readiness questions come first, and the shapes an AI build can take are on the AI development page. If you want the contract read before you sign it rather than after, that is most of what I do.

Frequently asked questions

Is it ever right to run our own model instead?

Rarely, and the test is narrow: a regulator or a contract forbids the data leaving a boundary you control, or the volume is so high and so repetitive that the arithmetic flips. For a Kuwaiti company under a few thousand interactions a day, neither applies. What you save on usage you spend several times over on the people who keep it running, and you inherit the upgrade problem with nobody sending you sixty days’ notice.

The supplier says the system is ours. Is that enough?

It is a sentence, not a clause, and the two behave differently at termination. Ask what arrives on the last day and in what format. If the answer names the prompts, the configuration, the interaction history with the corrections and an export format, the sentence is true. If the answer is access to the platform until the account closes, what is yours is the output and nothing that produced it.

How do we keep an evaluation set without it becoming a project?

Make it a by-product of work already happening. Every time someone overrides the assistant, that exchange plus the answer a competent colleague would have given is one row. Fifty rows catch a regression; three hundred let you compare two suppliers. It wants a spreadsheet and ten minutes a week. The discipline is writing the right answer down at the moment of the correction, because a week later nobody remembers what was wrong.

Our data is in Kuwait. Does using a hosted model move it abroad?

In substance yes, and it belongs in the contract rather than in an audit finding. Providers publish where processing happens and offer some regional control, but the defaults rarely put you where you assume. Establish three things in writing: which country processes the data, how long anything is retained and for what stated purpose, and whether any content is used for training.

What should a first-year AI subscription realistically cost?

Less than the meeting time already spent discussing it, if you are renting sensibly. Usage is cheap for most business workloads. What costs real money is the assembly and the evaluation around it, and that is a one-off shaped like a project, not a monthly line. Be suspicious of a large monthly figure that includes no named people: that is a build being amortised where you cannot see it.

Have a project, problem or idea?

Let's discuss what you're trying to build, improve or grow — and whether I can help.

Discuss Your Project