Last time I argued that a foundation model is a supplier whenever its output goes into something you deliver, and that since the model makers will not sign a services agreement, the controls have to sit on your side. Five of them: an acceptance criterion, a tolerance stated as a rate, change detection, a qualified alternate, and a process owner. Every one is something a vendor management function already knows how to do, and almost nobody is running that process.
What the major media companies are running instead is a hold: extremely limited commercial model use on anything that touches content, over IP infringement concerns. I think that is a defensible position, and I will come back to why. But a hold on commercial models governs your own people. It says nothing about your vendors, and most media companies are not the ones calling the model. They buy localization and QC from vendors, and the vendors are the ones holding the API keys. Unless somebody wrote the hold into the vendor contracts, and often they have not, the policy stops at the building.
So the companies being most careful about models internally can end up with the least visibility into where models are touching their content.
The supplier inside your supplier
The vendor’s model is the bigger exposure, for two reasons. Far more of a media company’s content work runs through vendors than through its own API keys, so that is where most of the model output is. And nothing in the company’s own AI governance can see it, because that governance was in most cases written for employees.
In supply chain terms the model is a tier-2 supplier sitting inside a tier-1 vendor. Supply chains have handled that arrangement for decades, in manufacturing and in media, through disclosure requirements, flow-down clauses, a right to audit, and treating undisclosed substitution as a breach.
Buying localization and QC is usually the right call, and a tier-2 dependency is ordinary. Every manufacturer and vendor has dozens or hundreds of them and manages those on the critical path closely. What makes this one different is that it is new enough to be under-documented, so it sits outside anyone’s watchlist.
How much trouble a tier-2 model causes comes down to one thing, which is whether the vendor told you about it or not. There are two cases and they are not the same problem.
In the first, the vendor sells “AI augmented localization” or “AI assisted QC” as a named service. The dependency is disclosed, so it is supposed to go into the agreement: which models, what happens when they change, acceptance criteria, where the content goes and whether it trains anything, who does the Article 50 disclosure work given that the duty lands on you as the deployer, and what the fallback is when their supplier pauses a run.
In the second, the vendor swaps model output in under the existing rate card to cut its own cost, and does not tell you. Anyone who has worked with multiple vendors knows this is a possibility. The media company takes on every risk above without knowing it, at the old price, with no clause covering any of it. Quality drift shows up as a QC miss against the vendor’s SLA while the real cause sits two tiers down. The guild terms make it worse. Under the new SAG-AFTRA contract, once a picture starts principal photography on or after July 1, 2027 under performer contracts signed after that date, a digital replica may not carry that performer’s voice into a foreign language without the performer’s consent. A dubbing supervisor will notice the lead’s own voice coming back in German. They are far less likely to notice it on the fourth-billed role in a smaller territory, or to catch a human dub actor’s track blended with a synthetic one, and the dub card will not tell them because it is built from what the vendor reports. Whatever the vendor did, the consent obligation sits with the Producer no matter who ran the model. The vendor is absorbing an upstream risk it functionally cannot manage, under a human-priced rate card, hoping it all works out. In any supply chain that manages its tiers, this is undisclosed substitution, and it is likely grounds for termination.
The first question is not which models we use. It is which models our vendors use, and whether they told us.
Why nobody owns this supplier
Putting terms on the vendor’s model means somebody has to write the terms, and that is the same problem the media companies have not solved for their own use of models. Why is almost nobody running those five controls? For two very understandable reasons.
The first is how the model arrived. A localization vendor gets onboarded into the operation once it is contracted, and someone in operations owns the relationship. A foundation model gets an API key and an engineering owner, and in most operations I have seen that is where it stops. The specific model dependency is usually created by an engineering lead picking the best performer that week, and the legal review comes after the choice is made, on the contract rather than the workflow. A monthly API bill does not trigger anyone’s vendor onboarding process, no matter how pricey it is.
The second reason is the hold I opened with, and the concern behind it is real and unresolved. Andersen v. Stability AI, the lead case on whether training is infringement, is still headed for a jury, and the MPA’s agreement with ByteDance governs what the models produce, not what they were trained on. As The Next Web put it, a model that “politely declines to draw Iron Man” does nothing to resolve whether the film libraries taught it what Iron Man looks like. Refusing to put an unqualified supplier on your most valuable work is what a careful buyer does.
It is also only half of a sourcing decision. Buying anything from outside takes two answers: where in the operation are we willing to use this, and which providers are approved to supply it, on what terms. A hold answers the first question. Very few companies have methodically answered the second. There is generally no published and approved list of model providers for creative work, and no standard set of terms to attach to them. I am not a lawyer; I am reading these as an operations person asking what happens to the delivery when a clause gets tested. No-model-training and content-use clauses are standard now and they do what they say. IP indemnification is worth less than it seems, and the exclusions are where to read. No indemnity anywhere covers the model being confidently wrong, which is the failure that actually costs an operation money.
A hold with no approved list behind it does not hold for long, because the demand for the work does not go away while the policy is unfinished. Two things happen instead. Teams under delivery pressure go around the hold, or they lean on vendors who will do the work for them, which is how the tier-2 problem above gets created. And the technology organization, which already holds the enterprise agreements for the non-content uses of AI, ends up at odds with, and across the table from, operations, when those two together are the only people who could build the list and write the terms.
The last point is happening in real time at different media companies. Tech is on a mission to deliver solutions identified by the C-Suite to drive down costs using AI. Operations is working to manage costs while protecting quality, talent, resourcing, vendor relationships, and a whole raft of other considerations. They don’t feel like Tech is consulting them, so they’re in a stand-off position while searching for their own tech solutions.
Nobody owns this supplier. Technology holds the contract, Operations holds the consequences, and neither is managing the supplier.
Where to start
The Human Layer post closed with a diagnostic and this one should too. Find the dependencies first, starting with the ones you cannot see, then put the five controls around them:
Ask every vendor on the critical path which, if any, models they use in delivering your work, under whose terms, and whether it is in the contract. Expect a surprise. Then put disclosure, change notification, content-use terms, guild flow-down, and a fallback into the next amendment.
Inventory every production workflow of your own that depends on a foundation model, name the model, and mark each dependency sole-source or dual-sourced. Most companies cannot pull this from a system, so ask.
Write the acceptance criteria for each model-dependent workflow, expressed as a pass rate on a reference set, and spec out the ability to score any new version against it before you cut over.
Qualify a substitute for anything sole-sourced on the critical path, using your own titles and your own delivery specs.
If you want to enable the use of AI for creative work, finish the sourcing policy behind any hold on model use: an approved supplier list, no-model-training and content-use clauses, indemnification read with its exclusions in mind, guild flow-down, and an on-premises or open-weights option where content cannot leave.
When you commit a delivery date on model-dependent work, build in the fact that the model may not behave next month the way it does today.
Add “supplier” to your miss attribution categories.
The discipline already exists
Andy’s closing line in August was that none of the four parties was fighting about model quality. They were fighting about the conditions attached to a model. Sizeable media companies already run vendor management functions that know how to qualify a supplier, write flow-down terms, and plan for a supplier failing. That function generally has not been pointed at the model in the middle of the localization workflow, or at the vendor quietly using one, because neither looked like a supplier when it arrived. NIST named the category in its Generative AI Profile, Value Chain and Component Integration, and wrote most of the checklist above as suggested contract terms.
A foundation model is a supplier. It does not arrive labeled as one, and it does not send the kind of invoice that gets a vendor manager’s attention, so nobody handed it to the people who do that work. Those people are already on the payroll and they know how to do this. Give them the relationship.
Sources and further reading:
Andy Beach, Four Ways to Reach the Model (Aug 21, 2026), What the Badge Buys (Aug 14, 2026), The Other Ledger (Aug 28, 2026).
The Next Web, ByteDance signs a copyright pact with Hollywood’s MPA to rein in its Seedance AI video tool.
Andersen v. Stability AI, Joint Case Management Statement, N.D. Cal., Jan 13, 2026. The lead case on whether training a model on copyrighted work is infringement; not yet tried as of this writing.
SAG-AFTRA, 2026 Theatrical-Television Memorandum of Agreement (also at AMPTP), read in full. MOA Section 39 (Artificial Intelligence) is a pointer, not the provision: it modifies Sections 64 and 64.1 of the General Provisions per Attachment D, and the operative text sits there. Dubbing consent is Section 64, Paragraph C: “Effective on motion pictures commencing principal photography on or after July 1, 2027, for which a performer’s contract is entered into on or after July 1, 2027, should the Producer wish to use the Digital Replica of a performer for purposes of adjusting the voice of the performer to a foreign language, it must comply with the consent, but not the compensation, requirements of Paragraph A. above.” Both conditions apply, and compensation is expressly carved out. Replica security is Paragraph G; transfer of rights is Paragraph H, under which a transfer does not relieve the Producer of its consent, use and payment obligations unless the transferee commits in writing to comply and to Union arbitration, and the Union does not disapprove the transferee’s financial responsibility within 21 days; the articulable business reason for scanning is Paragraph I. The training-license notice is Section 64.1, Paragraph D, triggered only where a Producer licenses covered performances to a non-affiliated third party for compensation to the Producer, for training a public-facing commercially available GAI system, and requiring written notice plus a meeting on request rather than consent. Ratified June 4, 2026; term through June 30, 2030. See also the Summary of Tentative Agreement, whose item lettering does not match the MOA’s.
WGA, Summary of the 2026 WGA MBA, Section 4, Artificial Intelligence. Ratified April 24, 2026; term May 2, 2026 to May 1, 2030. 2023 Article 72 provisions carried forward per Know Your Rights: Artificial Intelligence. Both the SAG-AFTRA and WGA agreements require written notice to the union when a producer licenses covered work to an outside party, for compensation, to train a commercially available model.
IP indemnification terms, read from each vendor’s published enterprise terms. The pattern across the five: all will defend against a third-party claim on the output, with conditions, and three of the five cover the model only when it is working alone, which is not how anyone runs a model in production. OpenAI Business Terms Section 13.1 (effective Jan 1, 2026; exclusions include combination with non-OpenAI products, modification, Customer Content, Customer Applications); Anthropic Commercial Terms Section K.1 (effective June 17, 2025; exclusions include Inputs, knowing infringement, modification, combination with non-Anthropic technology); Google Cloud Generative AI Indemnified Services (index, July 20, 2026) and the 2023 announcement; Microsoft Customer Copyright Commitment (Mar 20, 2026; required mitigations, including safety filters on and documented testing producible on a claim); AWS Service Terms Section 50.10, “Defense of Claims and Indemnity for Indemnified Generative AI Services,” read in full: the indemnity runs only to an enumerated list of Indemnified Generative AI Services, all of them Amazon’s own (the Nova and Titan families, HealthScribe, Personalize, Amazon Q, Transform, Lex, Kiro and others). Third-party models served through Bedrock are not on that list and are “Third-Party Content” under Section 50.12.1, governed by the model provider’s own terms. Section 50.10.2 carries seven exclusions, among them infringing inputs, interference with or failure to enable available filters and tools, and any fine-tuning or customization but for which the infringement would not have occurred. There is no combination-with-other-technology exclusion, and the indemnity is uncapped. Google Cloud Service Specific Terms, AI/ML section, read in full: Google runs two indemnities. The output indemnity applies only to “an unmodified Generated Output from a Generative AI Indemnified Service using only Google Pre-Trained Model(s), a Modified Google Model, or a Customer Adapter Model used with a Google Pre-Trained Model,” which is a combination-and-modification limit written as a positive scope condition, with five further exclusions covering known infringement, disabling filters or source citations, use after notice from a rightsholder, trademark claims, and missing rights in customer data used to customize. The separate training-data indemnity covers allegations that Google’s use of training data to create a Google Pre-Trained Model infringes, and is the only indemnity among the five that reaches the training question rather than the output.
NIST, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1). Risk category “Value Chain and Component Integration”; suggested actions GV-6.1-004 (contracts and SLAs specifying content ownership, usage rights, quality standards, provenance), GV-6.1-005 (supplier risk assessment framework), GV-6.1-009 (procurement processes for embedded GAI), GV-6.2-003 (third-party incident response and notification), GV-6.2-004 (continuous monitoring of third-party GAI in deployment), GV-6.2-007 (liability assignment and GAI system changes over time, including fine-tuning, drift and decay).
EU AI Act Article 50: paragraph 2 places machine-readable marking of synthetic output on providers; paragraph 4 places deepfake disclosure on deployers. Applicable from 2 August 2026 per Article 113.



