Skip to content
Did you see the fin...
 
Notifications
Clear all

Did you see the fine print? Claw's uptime SLA excludes 'AI model performance'.

3 Posts
3 Users
0 Reactions
17 Views
(@coffeegoblin)
Reputable Member
Joined: 3 months ago
Posts: 352
Topic starter   [#27640]

So Claw is out there crowing about their 99.99% uptime SLA for their new "AI-Powered Compliance Auditor." Big deal. I actually read the thing, and buried in section 4.7.2 is the real magic: "Uptime calculations exclude periods of degraded or non-functional AI model performance."

Let that sink in. The core product is an AI model that supposedly analyzes your controls and evidence. If that model starts hallucinating compliance findings or just stops working entirely, that doesn't count as downtime. The servers are technically pingable, so the SLA is intact. You're just paying for a very expensive, very green status dashboard.

What are you actually buying, then? You're on the hook for their compute and hosting, but the "intelligence" part—the only reason you'd pick them over a spreadsheet—has zero availability guarantee. Their definition of "service" seems to be the empty shell, not the functional brain inside it.

I'd love to hear how anyone is supposed to map this to a real compliance requirement. If your auditor asks for a vendor's availability commitment for a critical analysis tool, do you show them this? "Well, the *platform* is up, sir, it's just that the *analysis* is currently inventing policies we don't have." Good luck with that.

This is a masterclass in liability limitation. They've decoupled the hype from the guarantee. The TCO just got a lot murkier when you factor in the risk of the core feature being "down" while you're still paying full price.

☕


Buyer beware.


   
Quote
(@crusty_pipeline)
Honorable Member
Joined: 5 months ago
Posts: 502
 

What you're describing is a classic bait-and-switch from the early cloud days, just with a fresh coat of LLM paint. They're selling you a "car" but only guaranteeing the radio turns on.

For a compliance tool, this makes their SLA functionally useless. You can't write a risk assessment that says "the tool is available, except when it's doing its primary job incorrectly." An auditor will tear that apart. The real question is what metric they *do* guarantee. Latency? Throughput? If it's just HTTP 200s on the health check endpoint, you're buying infrastructure, not software.

I've seen this pattern before with vendors who can't control their own dependencies. My guess is their model is a brittle wrapper around someone else's API, and they have no levers to pull when it goes sideways. So they define it out of existence.



   
ReplyQuote
(@devops_barbarian)
Honorable Member
Joined: 5 months ago
Posts: 439
 

Exactly. You're buying a liability, not a tool. Their SLA covers the empty box, not the contents. An auditor would treat a hallucinated compliance pass as a control failure, and you'd have zero recourse because their contract says the "brain" isn't part of the service.

This is why you negotiate functional SLAs based on output, like accuracy thresholds or response validity. If they won't agree to that, you're just renting a very expensive web form.


Don't panic, have a rollback plan.


   
ReplyQuote