
Your agent does not own its brain. It rents one, by the token, from OpenAI, Anthropic, Google or another provider. That makes the model vendor a supplier, and a critical one. It sets the price. It decides when your model retires. It holds your documents for some period. It can suspend you. Most teams never put it on the supplier register. They should.
In one sentence: read the model vendor's terms the way you read your bank's, because your agent cannot work without them.
Where it comes from
Procurement already has a playbook for critical suppliers: price protection, notice periods, data terms, continuity, exit. Model vendors fit it, with one twist. The product you bought changes underneath you. A model is retired and replaced by a newer one that behaves differently on your cases.
NIST's AI RMF names the category. Manage 3 says "AI risks and benefits from third-party entities are managed"5. Its sub-item: third-party resources "are regularly monitored"5. That is supplier management with a new supplier.
What the terms and docs say
We read two vendors' published terms and docs. Numbers and words are theirs.
| Question | Anthropic | OpenAI |
|---|---|---|
| Training on your data | "Anthropic may not train models on Customer Content from Services"1 | See its data docs4 |
| Retention | See the data residency page | Abuse monitoring logs kept "for up to 30 days" by default4 |
| Model retirement notice | "at least 60 days' notice before model retirement for publicly released models"2 | Generally available models: "At least 6 months"3 |
| Faster retirement | Not stated on the page we read | "Unless safety or compliance concerns require a faster timeline"3 |
| Price changes | Effective "the earlier of 30 days after the updates are posted by Anthropic or Customer otherwise receives Notice"1 | See its pricing page |
| Termination for convenience | Either party, but "Anthropic must provide 30 days prior Notice"1 | See its agreement |
"See its..." means the page we cite did not answer the question. It does not mean the answer is bad.
Read the price row carefully. "The earlier of" means a rate change can apply before 30 days are up, if you get notice first. Thirty days is the ceiling, not the floor.
Read the retirement rows twice. Sixty days is short for a finance process. Your golden set replay, your approver's re-training and your change record all have to fit inside it. Six months is more room, with a safety exception.
What a model costs you, beyond the price
The per-token price is the visible cost. Three others matter more for an agent that acts.
Migration. Every retirement costs your team a replay, a review and a sign-off. Budget for it once or twice a year per agent.
Behaviour drift. A replacement model can be cheaper per token and cost more per run: longer answers, more retries, more holds. Measure the run, not the token.
Concentration. If every agent you run sits on one vendor, a suspension or a price rise hits all of them at once. That may be a fine trade. Decide it on purpose.
What changes when the model changes
A retired model is not an outage. It is a forced change to your control. The new model reads the same invoice differently. Its confidence scores sit in a new range. It may be more willing, or less willing, to follow instructions hidden in a document.
So treat each retirement notice as a change request:
- /01
Log it, with the date.
- /02
Replay your golden set on the replacement.
- /03
Re-run the confidence band table.
- /04
Record the new model version in the rules.
- /05
Tell your approver what changed.
If that takes longer than the notice period, you have a supplier risk to raise now.
What it is good at, and what it is not
Good at. Clarity. The big vendors publish their data terms, notice periods and prices. That is better than many software suppliers manage.
Not good at. Protecting your process. The terms protect the vendor's service, not your control environment. A model can retire on schedule and still break your agent's behaviour on your edge cases.
Where teams go wrong. Signing up with a company card and a developer's email. Then the retirement notice goes to someone who left. Put the account under a shared finance or IT owner.
What to check
- /01
Is the model vendor on your supplier register, with a named owner?
- /02
Who receives retirement notices? Is that a person who will act?
- /03
What is the retirement notice period for each model you use? Can your change process fit inside it?
- /04
Do the terms exclude training on your content? Where is that written?
- /05
How much notice do you get of price changes?
- /06
What is your exit? Could the agent run on a second provider, and has anyone tested it?
Where it is going
Model generations are arriving faster than a finance change cycle. Our view: buyers will push for longer notice and pinned versions for regulated work, and vendors will sell them at a premium. OpenAI already mentions dedicated capacity for continued access after a model's shutdown date3. The teams that cope best will be the ones that can switch models with a replay, not a rebuild.
Gatehouse fit
Gatehouse names the model provider in each deployment's signed rules, and every record carries the rules version in force, so you can see which model made which decision. Before a model change ships, it is replayed against your approver's labelled examples. Surehand processes engagement material under API terms that exclude training. The Trust page lists the sub-processors.
At a glance
| Category | Cost (supplier management) |
|---|---|
| Also called | Foundation model provider, LLM vendor, model API |
| Borrowed from | Critical supplier management. NIST AI RMF Manage 3 |
| Key docs | Anthropic Commercial Terms and deprecations page. OpenAI deprecations and data pages |
| Typical owner | Procurement or vendor risk owns the contract. IT owns the account. The process owner owns the replay |
| The one test | When your model is retired, how many days does your change process need? |
Sources
- [1]Commercial Terms of Service, Anthropicanthropic.com In text
- [2]Model deprecations, Claude Platform docsdocs.claude.com In text
- [3]Deprecations, OpenAI API platform docsplatform.openai.com In text
- [4]Your data, OpenAI API platform docsplatform.openai.com In text
- [5]NIST AI 100-1, AI Risk Management Framework 1.0, January 2023 (PDF)nvlpubs.nist.gov In text
Read next

Data residency for AI agents: where your prompts, documents and records actually live
An agent sends your documents to a model, keeps state between steps, and writes a record. Each can sit in a different place. What the main providers' docs say, and what to ask.

How much does an AI agent cost?
Three numbers. What it costs to build, what each run costs, and what it can commit in your name. Most quotes only give you the first.

Evaluating agents in production: a golden set for back-office work
How to know your agent still works after a model update, a new rule or a new supplier: a golden set of your own labelled cases, replayed before every change and sampled every week.