Zum Inhalt springen
Engagement-Ökonomie9. September 202612 Min. Lesezeit

Retainer economics for enterprise AI

AI work does not end at go-live; models drift, regulations move and the third use case is discovered in the second month. A retainer is the honest contract for that shape of work. This is how to price one, govern it and know when to stop.

Von Altuon

A project has an end. The statement of work names it: an acceptance test, a date, a signature. AI work in an enterprise does not have that shape, and pretending that it does is the most expensive mistake a buyer can make in the first year. The model that passed acceptance in March is answering different questions in September. The regulation that was a draft at signature is in force at renewal. The use case that justified the budget turns out to be the third most valuable thing the system can do, and nobody discovers the first two until the system has been in the hands of real people for a month.

A retainer is the contract that admits this. It buys capacity rather than deliverables: a named team, a cadence, a backlog that both parties govern, and a set of response commitments that hold whether the month is quiet or not. It is not a subscription to attention. Priced badly it is time-and-materials with a nicer name; governed badly it is a project that never ends. This article sets out what the shape of the work is, what a retainer should buy in return, how to price it, how to govern it, and how to know when it should stop.

Why AI work has the shape of capacity

Four things distinguish a production model from a piece of software that has been accepted and left alone.

The first is drift. A model is a function fitted to the world as it was when the training data was collected. The world moves: customers change their vocabulary, a product line is renamed, a competitor's campaign alters what people ask about, a supplier changes the format of a document. The model's inputs stop resembling its training distribution and its answers get quietly worse. Nothing crashes. No alert fires unless someone has built one. Drift is detected by measurement, and measurement is a standing activity with a person's name on it.

The second is regulation. The frameworks that govern this work are not finished. The EU AI Act places continuing obligations on providers and deployers of high-risk systems: risk management that persists through the system's life, logging, human oversight, post-market monitoring and the reporting of serious incidents. The GDPR requires that decisions based solely on automated processing, where they have legal or similarly significant effects on a person, carry safeguards including the right to human intervention, and that high-risk processing is preceded by a data protection impact assessment that is kept under review. The revised Swiss Federal Act on Data Protection requires a record of processing activities, an impact assessment where processing carries a high risk, and notification of the Federal Data Protection and Information Commissioner when a breach is likely to result in a high risk to the persons concerned. Each of these is an obligation that recurs. A system that met them at go-live has not met them; it has met them once.

The third is the third use case. The mandate that funds an AI programme is usually the one an executive could describe before the system existed. The valuable ones are found afterwards, by the people who operate it: a claims handler notices that the classifier's confidence score predicts which cases will be escalated; a treasury analyst discovers that the document extraction built for invoices works on bank confirmations. A project has no mechanism for absorbing this. A change note is raised, priced, argued over, and by the time it is approved the opportunity has been worked around by hand. A retainer has a backlog and a planning cadence built for exactly this.

The fourth is evaluation. A model's behaviour is not specified by its code; it is characterised by its evaluation suite. Every change to a prompt, a retrieval index, a fine-tuning set or the underlying model version must be run against that suite before release, and the suite itself must grow as new failure modes are found in production. This is not testing in the sense a software project means it. It is a permanent function, closer to quality assurance in a laboratory than to a test phase at the end of a build.

A system that met its regulatory obligations at go-live has not met them. It has met them once.

What a retainer buys

A retainer that is worth signing buys four things, and the agreement should name each of them.

A named team. Not a pool, not a bench, not "resources of equivalent seniority to be assigned". The engagement lead, the practice principals and the engineers who hold the system in their heads are named in a schedule, with a deputy for each and a written procedure for what happens if one of them leaves. Continuity of people is most of what you are paying for; a team that rotates every quarter has to relearn the system at your expense.

A cadence. A weekly operating rhythm inside the team, a monthly steering meeting that reviews delivery, risk and spend against the capacity band, and a quarterly planning session that sets the next quarter's priorities. The cadence is the governance. Without it, a retainer degrades into a ticket queue.

A backlog governed jointly. Everything the team might do is written down in one place, sized and ranked. Your side owns the ranking of value; the firm owns the estimate of effort and the statement of risk. Neither side may add work that the other has not seen. The backlog is reviewed at every steering meeting, and its state is the single honest answer to the question of what you are paying for.

Response commitments. What the team will do, and how quickly, when a model degrades, a regulator writes, a provider deprecates a model version or an incident occurs. These are written as severity definitions with acknowledgement and resolution times against each, and reported against at every steering meeting. They are not the same as the availability of the system, which may be an operations matter; they are the availability of the people who can change the system.

How to price it

The unit of a retainer is capacity, and the honest way to express capacity is a band: a stated number of practice-days per month, drawn from named practices, at a blended rate fixed for the term. The band has a floor, which is what you commit to pay, and a ceiling, which is the most the team will deliver without a new agreement. Capacity not drawn in a month should carry forward within the quarter and lapse at its end; capacity above the ceiling should be agreed in writing before it is worked, never invoiced by surprise.

Suppose a retainer of forty units a month, where a unit is a practice-day. The agreement says which practices the units may be drawn from, what proportion may shift between them without approval, and how the blended rate is calculated when the mix changes. It says what is inside the band — evaluation, monitoring, prompt and retrieval changes, regulatory reporting, the steering cadence itself — and what is outside it: a new system, a migration to a different model provider, a change of data plane. Work outside the band is either a separately priced project or a re-banding agreed at the quarterly review.

Two alternatives are usually proposed, and both fail here for reasons worth stating plainly.

Time-and-materials fails because it prices effort and not commitment. The firm has no reason to hold a named team available in a quiet month, and every reason to expand work in a busy one. The buyer cannot budget, and the finance function treats every invoice as a surprise. The result is that time-and-materials retainers are cut in the first cost review, because nobody can say what they bought.

Fixed price fails because it requires a scope, and the whole argument of this article is that the scope is discovered as the work proceeds. A fixed-price contract for continuous work is a contract that will be renegotiated every quarter, with the firm pricing in the risk of the unknown and the buyer paying for that risk whether or not it materialises. Change control becomes the main activity.

A capacity band is the instrument between them. It fixes the price of the month while leaving the content of the month to the governance.

BasisWhat is fixedWhat movesWhere it fails
Time-and-materialsThe rateEverything elseBudget and commitment
Fixed priceScope and priceNothing, until change controlDiscovery of the third use case
Capacity bandPrice, team, cadenceThe content of the backlogOnly if the governance is not operated

Governance

A retainer without governance is a standing invoice. The governance has six parts, and a general counsel should look for each of them.

A steering cadence. Monthly, attended by the executive sponsor, the firm's engagement lead and whoever owns the budget. It reviews the backlog, the response commitments, the risk register and spend against the band. Its minutes are the record of what was decided and why.

A quarterly review. Longer and more senior. It re-plans the next quarter's priorities, re-examines the band against the actual draw, reviews the evaluation results and the regulatory position, and decides whether the retainer should continue, grow, shrink or convert.

Who can stop work. Named individuals on both sides may halt a release, and the agreement says so. On your side, this is usually the system's business owner and the data protection officer or equivalent. On the firm's side, the engagement lead. A stop is not a breach; it is the governance working.

Intellectual property. Deliverables produced under the retainer are assigned to you on payment. This includes code, prompts, evaluation suites, fine-tuned weights trained on your data, documentation and the monitoring configuration. The firm keeps its pre-existing methods and tooling and licenses to you whatever of them is embedded in what it delivers, perpetually and without further fee.

Model and data ownership. Your data stays yours, in the data plane you chose, and the agreement names that plane. Models fine-tuned on your data are yours. Where a third-party model provider is used, the agreement says which, where its processing takes place, what it retains and for how long, and how you are told before any of that changes.

Exit terms and knowledge transfer. A notice period, and a handover obligation that is the same as for a project: documentation current, credentials rotated to you, runbooks in place, evaluation suites and monitoring handed over in working order, and knowledge transferred to named people in your organisation. No exit fee. A firm that resists this clause is telling you what it thinks holds the relationship together.

When to stop, and when to convert

A retainer should end in one of three ways, and the quarterly review is where the question is asked.

It ends because the work has stopped having the shape of capacity. The models are stable, the evaluation suite has not found a new failure mode in two quarters, the regulatory position is settled and the backlog is short. Convert what remains to a light-touch advisory arrangement and stop paying for a team you no longer need. A firm that argues against this at the review has confused a retainer with a rent.

It ends because the work has grown a shape of its own. When the backlog is long, the third use case has become a fifth and a sixth, and the team is becoming the organisation's AI function in all but employment, the right instrument is an embedded team with a capability-transfer plan: the firm's people step back as yours step forward, on a schedule, with overlap. The retainer converts into that plan rather than growing indefinitely.

It ends because the governance has not been operated. Steering meetings are missed, the backlog is not ranked, the band is drawn to the ceiling every month without a decision. This is the most common ending and the least honest. The remedy is not a new firm; it is a sponsor who attends.

What the CFO should ask before signing

Before the agreement is signed, six questions should be put in writing and answered in writing.

What is the band, in units, and what is the blended rate? What is inside the band and what is outside it, by name? Who is on the team, and what is the procedure if one of them leaves? What are the response commitments, by severity, and where will they be reported? Who owns the models, the prompts and the evaluation suites, and where does the data live? What does leaving cost, and how long does the handover take?

An answer that points to a rate card, a bench or a standard terms document is not an answer. The firm that can give six specific answers has done this before and expects to be held to them.

What to do on Monday

  1. Ask the person who runs your production models what they did last month to detect drift, and whether anyone is paid to keep doing it.
  2. List every recurring obligation your AI systems carry under the GDPR, the EU AI Act and the revised Swiss FADP, with the date each was last satisfied.
  3. Write down the use cases discovered since go-live that nobody has funded, and what it costs to keep working around them by hand.
  4. If you hold a time-and-materials arrangement for this work, ask for it to be re-expressed as a capacity band with a named team and a cadence.
  5. Put the six questions above to your current or prospective firm, in writing, and read the answers with your general counsel.

Sagen Sie uns, was nicht scheitern darf.

Eine Angebotsanfrage umfasst sieben kurze Schritte und wird von der Engagement-Leitung gelesen, die die Arbeit führen würde. Referenzen zu realen Engagements erhalten Sie unter Vertraulichkeit, passend zu Ihrer Branche und Region.