Recovery contract
A short written artifact in an AI vendor evaluation that states how failures are detected, contained, reversed and handed back to people — and who is responsible at each step.
A recovery contract is a small artifact added to an AI vendor evaluation. It does not promise that the system will not fail. It describes, in advance, what happens when it does: how the failure will be noticed, what limits its blast radius, how its effects are reversed, how a case is handed back to a person with the context they need, and who owns each of those steps.
Most procurement exercises show success. A recovery contract makes the buyer design the unhappy path instead, and it turns a vague reassurance such as "we have guardrails" into something that can be tested during the demo.
What it usually covers
- How an error is detected, and how quickly
- What the system may not do without review (see guardrails)
- How actions are reversed or compensated
- Handoff to a human with full context
- The expected recovery distance
A failure test doubles as a supervision test: it shows how much human attention the system will really consume.
Read more in Make the AI vendor demo fail.
Related terms
Recovery distance
The amount of human and system work needed to get from an AI failure back to a safe, correct state — a cost that belongs in the business case, not just the demo.
Supervision load
The human attention an AI system still consumes — context supply, review, approval, correction and exception handling — measured per dependable, completed unit of work.
Guardrails
Controls placed around an AI system — input and output checks, permission limits, review steps and escalation rules — that keep its behaviour within acceptable bounds.