Hyland AI contract — TermScout contract intelligence report

Hyland Agent Builder - AI Service Card Review & Analysis

Hyland TermScout AI certified contract badge

AI Certification (Beta) Overview:

When TermScout certifies a contract, it means that agreement has met our rigorous standards and made the below commitments to their customers as it relates to their AI product or services.

Receiving Termscout's AI Certification (Beta) means that the product is on the cutting edge of AI development and shows they're committed to establishing trust and transparency with their customers and being a responsible corporate citizen when it comes to their AI development and functionalities.

Termscout acknowledges that presently AI is something of a moving target, but at this point, we believe responsible vendors make these minimum commitments and are continuously evaluating their practices.

AI Commitments Overview:

Review the AI-related commitments and view source language citations below.

Hyland has established guardrails related to the use of their AI offering.
Status
Hyland addresses how they use Customer data related to their AI offering.
Status
Hyland addresses how they retain Customer data as it relates to their AI offering.
Status
Customer retains ownership of input data submitted to Hyland as it relates to their AI offering.
Status
Hyland commits to notifying Customer of a security breach impacting the Customer's data.
Status
Hyland commits to complying with applicable AI laws
Status
In conversations between TermScout and Hyland, Hyland has indicated their ongoing commitment to adopting contractual best practices related to AI as they're developed.
Status

AI Certification (Beta) Guiding Principles:

Termscout's AI Certification (beta) covers five major categories outlined below. Termscout believes while there are other important principles related to AI, these five categories cover the major obligations related to AI found in vendor contracts today and expect over time this will expand to fully realized compliance index.

1. Use Restrictions: Limiting harmful or unintended uses of AI Systems.
2. Transparency and Explainability: Ensuring users understand how AI works and its limitations.
3. Data Usage and Ownership: Clarifying rights around training data and generated content.
4. Security and Incident Response: Protecting data and systems from breaches or misuse.
5. Regulatory Compliance: Ensuring alignment with evolving laws.

AI Certification (Beta) Program:

If you are interested in being part of the AI Certification (Beta) Program and joining a standing group of select customers who has ongoing conversations with us about these standards and how they should evolve over time, please contact us at sales@termscout.com

Frequently Asked Questions

Find quick answers to the most common questions about our platform, process, and agreements.

Security teams frequently escalate AI SaaS agreements when the data processing language does not clearly explain how customer information is stored, reused, retained, or shared across training and operational systems. Review intensity increases when agreements blur the line between core service delivery and broader AI improvement activities. Enterprises also look closely at subprocessors, cross-border transfers, deletion rights, and incident response obligations. Ambiguous processing language tends to create concern because unclear governance boundaries can produce long-term operational and compliance exposure after deployment.

Agreements often appear unusually aggressive when vendors reserve broad rights to retain or reuse customer inputs for undefined model improvement purposes. Enterprise buyers also react negatively to vague anonymization standards, unilateral changes to data practices, or limited visibility into subprocessors handling sensitive information. Security and legal teams increasingly expect AI vendors to provide clearer operational boundaries around training activities, retention periods, and customer control mechanisms. Terms that rely heavily on broad discretionary language tend to trigger more procurement and governance friction.

Buyers often treat privacy language as an indicator of overall governance maturity rather than a standalone compliance issue. Agreements that clearly define processing scope, deletion procedures, audit cooperation, and restrictions on secondary data use generally create more confidence during enterprise review. In contrast, overly broad permissions or unclear operational commitments may signal that the vendor has not fully operationalized AI governance controls. Procurement and security teams frequently use these provisions to assess whether the vendor’s contractual posture aligns with enterprise risk expectations.

Friction usually emerges when contract language creates uncertainty about how customer data may influence future models, shared systems, or downstream commercial activities. Procurement teams often struggle to approve agreements when legal, privacy, and security stakeholders interpret the same clause differently. Delays also increase when vendors provide inconsistent explanations between sales materials, DPAs, and master agreement provisions. Enterprise buyers generally prefer agreements where AI-related processing rights are narrowly scoped, operationally transparent, and aligned with established security review standards.