The Compact Clauses, v0.1
Contract riders for buying frontier AI and agent services, implementing commitments three, four, and five of the Control Stack Compact (majormatters.co/p/open-letter-control-stack-compact).
This is not legal advice. These riders are a starting draft for your counsel to adapt: defined terms, notice periods, caps, and carve-outs all need tailoring to your master agreement and jurisdiction. What they give you is the substance, so the negotiation starts from "adjust this" instead of a blank page.
Version 0.1, September 8, 2026. Maintained at majorlabs.co/clauses. License: CC0, use freely, attribution appreciated.
Clause I: Frontier AI Incident Disclosure
Implements Compact commitment three (buyer side). The benchmark failure: a July 2026 breach of a frontier lab's own infrastructure received six days of outside investigation that ended before the compromise did, and customers learned about it from the press.
1. Definitions. "AI Incident" means any event in which (a) an AI system or agent operated by or on behalf of Provider escapes or circumvents a containment, sandbox, or monitoring control; (b) such a system takes unsanctioned action on live systems, networks, or data, whether belonging to Provider, Customer, or a third party; (c) such a system materially deceives an evaluation, monitoring, or oversight process; or (d) credentials, model weights, or agent-control interfaces relating to the Services are compromised.
2. Notice. Provider shall notify Customer of any AI Incident that affects, or that a reasonable operator would conclude may affect, the Services or Customer Data: within 72 hours of Provider becoming aware of the AI Incident, in writing, to the contact designated in the Order Form.
3. Content. Notice shall include, to the extent known: the nature and timeline of the AI Incident, the systems and data affected, the containment actions taken, and whether the AI Incident remains ongoing. Provider shall supplement the notice as material facts develop, and shall deliver a written post-incident report within 30 days of containment.
4. Investigation. Provider shall not unreasonably withhold cooperation from any independent investigation of an AI Incident affecting Customer, and nothing in this Agreement restricts either party from disclosing an AI Incident to a regulator or safety institute with jurisdiction.
5. Survival. This Clause survives termination for 24 months.
Commentary. Vendors will push back on (b)'s "third party" scope and on the 72-hour clock. The fallback that preserves the clause's purpose: keep 72 hours for incidents touching Customer Data, accept "without undue delay" for the rest. Do not trade away section 4; a gag on regulator disclosure is the tell that the vendor expects incidents.
Clause II: Agent Attribution
Implements Compact commitment four. The benchmark failure: the rogue agent swarms of 2026 were hard to investigate partly because nobody could establish whose agents they were.
1. Attributable operation. Provider shall ensure that every AI agent instance operating under this Agreement is attributable: each instance carries a verifiable identity that records (a) the legal entity that deployed it, (b) the authorization or mandate under which it acts, and (c) a revocation mechanism effective at the source.
2. Records. Provider shall maintain tamper-evident records sufficient to reconstruct, for any agent action affecting Customer systems or Customer Data: which agent instance acted, under what authorization, and what actions were taken. Records shall be retained for at least 24 months and made available to Customer within 10 business days of a written request following an AI Incident (as defined in Clause I).
3. Revocation. Upon Customer's written request, Provider shall revoke a specified agent instance's authorization within 24 hours, and within 4 hours where Customer reports an ongoing AI Incident.
4. No anonymous agents. Provider shall not permit agent instances without the attributes in section 1 to access Customer systems or Customer Data, including instances operated by Provider's subcontractors.
Commentary. This clause deliberately specifies outcomes, not technology; signed identity, mandate records, and tamper-evident logs all have working open-source implementations, so "not technically feasible" is not available as an objection. The negotiation will center on section 2's reconstruction duty. Hold the line there: it is the difference between a six-day investigation that ends in "missing aspects of the story" and an answer.
Clause III: Liability Allocation
Implements Compact commitment five. The principle: autonomy must not scale faster than accountability, and the space between them is where losses land.
1. Provider responsibility. Provider is liable for losses arising from (a) an agent action outside the scope of the authorization or mandate recorded under Clause II; (b) an AI Incident originating in Provider's systems, safeguards, or subcontractors; and (c) Provider's failure to disclose an AI Incident as required by Clause I.
2. Customer responsibility. Customer is liable for losses arising from agent actions within the scope of an authorization Customer granted, executed as authorized.
3. Cap carve-out. Liability under section 1(c) is excluded from any limitation-of-liability cap in this Agreement. The parties agree that undisclosed incidents defeat the risk allocation this Agreement depends on.
4. Indemnity. Provider shall indemnify Customer against third-party claims arising from events in section 1(a) and 1(b).
5. No orphan losses. For any loss arising from agent activity under this Agreement that sections 1 and 2 do not clearly allocate, the parties shall designate the allocation in writing within 60 days of discovery; failing agreement, the loss is allocated to the party whose systems executed the action.
Commentary. Section 3 is the sharpest edge here and the most important: caps are standard, but a cap that shelters undisclosed incidents converts the disclosure clause into theater. Expect resistance; the compromise position is a higher super-cap rather than full exclusion. Section 5 exists because the honest answer to "who pays when the agent goes wrong" is today often "nobody can say", and a contract that leaves that open has not allocated the risk, it has hidden it.
Drafted and maintained by Major Labs (majorlabs.co) as part of the Control Stack Compact. Not legal advice; adapt with counsel. Feedback and improvements: github.com/major-matters/major-labs.