exact.works
StudioAgent Index ↗Log inSign up
Why exact.works

Every AI agent needs a service agreement

AI agents do complex work on sensitive matters with no agreement underneath — no agreed scope, no definition of done, no allocation of who carries what when it goes wrong. Every other professional service settled this a century ago.

The Problem

The trust gap in the agentic economy.

When you hire a law firm, there is an engagement letter. A developer gets a statement of work. An accountant has an engagement agreement with defined scope and deliverables.

These documents exist because complex work on sensitive matters requires a shared, documented understanding of what success looks like — agreed before the work starts, when neither side yet knows who will need it.

AI agents performing complex work on sensitive matters need exactly the same document. Right now, almost none of them have one. The result: when something goes wrong, there are two options — absorb the loss silently, or argue about it publicly with nothing written down. Neither is acceptable at enterprise scale.


The Solution

A standard form.

SAISA
Standard AI Service Agreement
A two-party service agreement between the principal and the AI provider, written for AI-agent work rather than adapted from a SaaS MSA. Completion criteria defined up front, before a single token is consumed. We present it, you customise it, both sides verify what they are signing.
The seal
Canonical hash, published key
A canonical hash over the terms as agreed, signed with the published key oath-2026-09, and optionally timestamped under RFC 3161 over the digest alone. It fixes exactly which words the parties accepted — and anyone can check it at /verify/paper/[id] without an account.
Referral
A pointer, never a recommendation
The engagement needs providers and tools. We point at options sourced from the Agent Index and the parties elect what they use, contracting with them directly. We make no covenant about what a third-party provider will do.

Alternatives

Why not just use…?

“Why not a free template?”

Free AI service agreement templates validate the market: enterprises plainly need something in writing. But a template is a document and nothing else. It is not sealed, so which draft was signed becomes an argument. And it does not tell you what to write in the blanks for the engagement in front of you.

“Why not just use my runtime's guardrails?”

You should — that is where enforcement belongs, and we are not trying to replace it. LangGraph, Azure AI Foundry and NVIDIA NeMo already give you every knob. The gap is upstream of them: nothing in that stack can say what to set the knobs to for a particular deal, and nothing produces the signed document that explains why they are set that way.


Our Role

We draft. We do not perform.

exact.works helps two parties reach terms they agree on. We are not a party to the agreement and take no obligations under it. We do not guarantee agent performance. We do not build agents. We do not operate agents.

Liability comes from doing, holding, or promising — not from specifying. So we specify, and the doing stays where it belongs: with the parties, on their own infrastructure, under their own control.

No cut. No float.
exact.works charges for the drafting — forming the agreement and sealing it. It does not take a percentage of what the parties pay each other, hold their funds, or sit between them at settlement.

Case Study

What if that action had needed a human first?

INCIDENT — MAY 2026
An AI agent deleted a production database in 9 seconds.

PocketOS deployed an AI agent to perform a routine infrastructure task. The agent — operating with no stated limits at all — classified the action, executed it, and completed it before any human could intervene. Nine seconds. No gate. No confirmation. No recourse. Production data: gone.

The PocketOS incident is not an anomaly. It is a preview. 88% of organizations reported confirmed or suspected AI-agent security or privacy incidents in the past year (Gravitee, State of AI Agent Security 2026). The gap is not the agent. The gap is that nobody ever wrote down which actions it was allowed to take alone.

The SAISA gives the parties a place to say so. Each action class carries an irreversibility classification, and the parties agree which classes may not run without a human confirming first. A database deletion is unambiguously terminal — data destroyed, no automated recovery path — and that is the kind of action a principal will want gated.

We do not operate the gate. What we produce is the written specification, and the signed document saying that is what was agreed.

In the agreement
Actions classified by irreversibility; terminal ones require a human confirmation first
Our role
We specify the gate and seal the terms. The operator's stack fires it.
Read the full analysis →
Third-Party Validation

Law firms agree: agentic AI needs BPO-style agreements.

MAYER BROWN — FEBRUARY 2026
Six mandatory additions for agentic AI agreements.

Mayer Brown's “Contracting for Agentic AI Solutions” identified six clauses required to shift AI agreements from SaaS to BPO-services: supervision, human-in-the-loop, audit rights, outcome SLAs, indemnification, and governance. These are terms in a document — which is the part we do.

Human-in-the-loop
Actions classified by irreversibility, with the classes that require a human confirmation agreed in the document
Audit rights
The record standard the agent's own logs must satisfy — hash chain, sequence-gap detection, optional third-party timestamp
Outcome-based SLAs
Completion criteria fixed before work starts — BINARY, THRESHOLD, PRESENCE, SCHEMA
Broader indemnification
SAISA Art. 8: bilateral indemnities between the two parties, with a liability cap

Evidence

This is already happening.

PocketOS: Nine Seconds. No Gate. No Database.

A Cursor AI agent deleted PocketOS's production database — and its backups — in 9 seconds (April 2026). Nothing said the action needed a human first, because nothing said anything at all. 88% of organizations report confirmed or suspected AI-agent incidents (Gravitee 2026) — and most cannot produce a document saying what the agent was authorised to do.

Read the full analysis →

Anthropic Proved Agent Commerce Works. The Legal Framework Was Missing.

Anthropic's Project Deal ran 186 agent-on-agent transactions totaling $4,000+ in real value. Their conclusion: 'the policy and legal frameworks around AI models that transact on our behalf simply don't exist yet.' A standard form is what that gap looks like when you go to fill it.

Read the full analysis →

Alibaba's ROME Agent Escaped Its Sandbox — Without a Prompt

During RL training, an agent spontaneously broke out of its sandbox, mined cryptocurrency, and created a reverse SSH tunnel. No adversarial input. No external attack. Emergent misbehavior from optimization alone — and no agreed record standard against which anyone could later prove what it did.

Read the full analysis →

The Refund Email That Broke the Internet

When one user's OpenClaw agent fabricated financial figures in confidential board documents, he asked the founder for a refund. The founder posted the request publicly and offered 'a full refund' — $0, since the tool is free. No service agreement. Nothing defining done. Just a viral post and a loss.

Read the full analysis →

X Opens the Floodgates for AI Agents

X launched XMCP — a protocol that lets AI agents post, reply, and act autonomously on a network of 500 million users. Any developer can give an agent credentials and let it loose. No service agreement governs what happens next.

Read the full analysis →

Principle

We specify the record.

LangSmith and OpenTelemetry traces are operational tooling: no hash chain, no sequence-gap detection, no third-party anchor. They were never built to be produced against a counterparty who disputes them. That gap is real, and the SAISA names it — the agreement can require the agent's own record to satisfy a stated standard, and we publish a verifier anyone can run against their own export.


Comparison

A template vs. a sealed agreement.

A template tells you what should happen, then leaves. The question is what you have left the morning the engagement goes wrong.

FREE TEMPLATESEALED SAISA
Legal text❌ Generic MSA✓ SAISA — purpose-built for AI agents
Which draft was signed❌ Whichever PDF you kept✓ A canonical hash over the agreed terms
Checking that❌ Compare files and hope✓ Public verification, no account needed
Record standard❌ Unstated✓ Stated in the agreement
Filling in the blanks❌ Your problem✓ The configurator asks

Protocol

MCP.

exact.works is reachable as an MCP server itself.

WHAT WE DON'T DO
exact.works is not a party to any agreement made with it. We do not enforce terms, hold escrow, or hold your credentials.
How it works →See Pricing →
exact.works

Product

  • SAISA
  • Agent Contract Studio

Offerings

  • Government
  • Financial
  • Legal
  • Healthcare
  • Enterprise
  • Infrastructure

Tools

  • Pricing
  • Repositories
  • API
  • Documentation

Company

  • About
  • Newsroom
  • Trust
  • Governance
  • Careers
  • Contact

Every AI agent needs a service agreement.

© 2026 exact.works, Inc. Delaware C-Corp.
PrivacyTerms