Legal

Agentic Services Addendum

Version 1 (July 2026)

This Agentic Services Addendum (“Addendum”) supplements and forms part of the Master Terms of Service between Corti and Customer. This Addendum governs Customer’s access to and use of Corti’s Agentic Services as defined herein.

1. PURPOSE AND INCORPORATION

1.1. Incorporation. This Addendum supplements and forms part of the Master Terms of Service (“Agreement”) between Corti and Customer. This Addendum is published by Corti at https://www.corti.ai/legal/agentic-services-addendum (the "Addendum URL") and is incorporated into the Agreement by reference. Where Customer's use of Agentic Services is the subject of an Order Form, this Addendum applies in the version published at the Addendum URL as of the Effective Date of that Order Form. Capitalized terms not defined in this Addendum have the meanings given in the Agreement. In the event of any conflict between this Addendum, the Agreement, and the Order Form with respect to Agentic Services, this Addendum shall prevail; provided that the Order Form shall prevail over both this Addendum and the Agreement with respect to commercial terms only (including fees, term, and usage limits).

1.2. Precedence. In the event of any conflict between this Addendum and the Agreement with respect to Agentic Services, this Addendum shall prevail. For all other matters not specifically addressed in this Addendum, the Agreement continues to apply in full force and effect.

1.3. Binding Effect. Customer’s use of any Agentic Services constitutes acceptance of this Addendum and agreement to be bound by its terms.

2. DEFINITIONS

2.1. The following definitions shall apply to this Addendum:

 “Agentic Services” means the autonomous AI agent orchestration capabilities made available by Corti through the Platform, including multi-step reasoning pipelines, tool-use and function-calling frameworks, agent memory and state management, autonomous task planning and execution, and the ability to initiate Agent Actions on Customer’s behalf within Customer’s Agentic Configuration.

“Agent” means an autonomous AI process operating through the Agentic Services that executes tasks, makes decisions, and initiates Agent Actions within the parameters defined by Customer’s Agentic Configuration.

“Agent Action” means any autonomous action initiated or executed by an Agent on Customer’s behalf, including but not limited to API calls to third-party systems, data reads or writes, form submissions, scheduling actions, automated communications, workflow executions, or other interactions with external systems or data sources.

“Agentic Configuration” means the comprehensive set of permissions, scopes, tool authorizations, guardrails, safety controls, and operational boundaries that Customer configures, implements, and maintains to govern Agent behavior and define the scope of authorized Agent Actions. Customer is solely responsible for designing, implementing, maintaining, and validating its Agentic Configuration.

“Tool” or “Tool Integration” means any third-party API, service, data source, database, application, or system that Customer authorizes an Agent to access, interact with, or call upon through the Agentic Services.

“Permitted Action” means an Agent Action that (a) falls within the scope of Customer’s Agentic Configuration, (b) complies with all applicable laws and regulations, and (c) does not violate any third-party terms of service or other contractual obligations.

“Agentic Incident” means any Agent Action that produces an unintended, harmful, unauthorized, or non-compliant outcome, including but not limited to actions taken outside the scope of Customer’s Agentic Configuration, actions that violate applicable law, or actions that cause harm to any person, system, or entity.

3. GRANT OF RIGHTS

3.1. Limited License. Subject to the terms and conditions of this Addendum and the Agreement, Corti grants Customer a limited, revocable, non-exclusive, non-transferable, and non-sublicensable right to access and use the Agentic Services during the applicable term, subject to: (a) this Addendum; (b) the Agreement; (c) Customer’s Agentic Configuration; (d) payment of all applicable fees; and (e) Customer’s ongoing compliance with all terms hereof.

3.2. Conditional Access. Customer’s right to use Agentic Services is expressly conditioned upon Customer’s ongoing compliance with this Addendum. Any material breach of this Addendum may result in immediate revocation of access to Agentic Services, independently of Customer’s access to other Corti Services.

3.3. Modification Rights. Corti reserves the right, in its sole discretion, to modify, enhance, deprecate, suspend, or discontinue any component, feature, or capability of the Agentic Services upon thirty (30) days’ written notice to Customer, except where immediate action is required to address a security threat, regulatory requirement, or to prevent harm to any person, system, or Corti’s reputation, in which case Corti may act without prior notice.

3.4. No Commitment. Customer acknowledges that Corti has no obligation to maintain, support, or continue providing any specific Agentic Services functionality and that Customer’s access to Agentic Services may be modified or terminated in accordance with this Addendum.

4. CUSTOMER’S AGENTIC CONFIGURATION OBLIGATIONS

4.1. Sole Responsibility. Customer is solely and exclusively responsible for designing, implementing, configuring, maintaining, monitoring, updating, and validating its Agentic Configuration, including without limitation all permission scopes, guardrails, safety controls, tool authorizations, human oversight checkpoints, approval mechanisms, and operational boundaries governing Agent behaviour.

4.2. Permitted Actions Only. Customer must ensure that its Agentic Configuration restricts all Agents to Permitted Actions only. Customer shall not configure, authorize, or permit any Agent to take any action that exceeds the scope of Customer’s Agentic Configuration or that violates applicable law.

4.3. High-Risk Actions. Customer must not configure Agents to take irreversible or high-consequence actions, including but not limited to financial transactions, data deletion, external patient communications, regulatory submissions, legal commitments, or system modifications, without implementing appropriate confirmation, approval, and oversight mechanisms commensurate with the associated risk.

4.4. Healthcare Oversight. Customer must implement mandatory human review and approval checkpoints before any Agent Action that could directly or indirectly influence a clinical decision, diagnosis, treatment recommendation, or patient care pathway. Where Agentic Services are used in connection with a Corti Product in a clinical workflow, Customer must ensure that any such human review is conducted within the scope of the applicable intended use, Documentation, and regulatory status of that Corti Product. Customer's human oversight measures must be designed and maintained consistently with applicable healthcare laws and regulations, including HIPAA and GDPR where applicable, and in alignment with Corti's ISO/IEC 42001-certified AI management system governance controls.

4.5. Legal Compliance. Customer is solely responsible for ensuring and validating that its Agentic Configuration, Agent Actions, and deployment of Agentic Services comply with all applicable laws, regulations, professional standards, and contractual obligations in Customer’s jurisdiction and any jurisdiction where Agent Actions may have effect.

4.6. Tool Integration Inventory. Customer must maintain a current, comprehensive inventory of all Tool Integrations authorized within its Agentic Configuration and must ensure that appropriate legal authorizations, licenses, and technical safeguards are in place for each such integration.

4.7. EU AI Act deployer obligations. Where Customer deploys Agentic Services in a manner that is subject to deployer obligations under the EU AI Act, including Article 26 for high-risk AI systems, Customer is responsible for: (a) using the Agentic Services in accordance with Corti's Documentation, instructions, and applicable use limitations; (b) assigning human oversight to competent, appropriately trained, and authorised personnel; (c) monitoring the operation of the Agentic Services and taking appropriate action where use may present a risk to health, safety, fundamental rights, data protection, or compliance with applicable law; (d) retaining and reviewing logs made available to Customer where required by law; (e) ensuring the relevance, quality, and appropriateness of input data under Customer's control; (f) notifying Corti without undue delay of any serious incident, malfunctioning, material risk, or non-compliant outcome relating to the Agentic Services; and (g) using information made available by Corti to support any required data protection impact assessment, fundamental rights impact assessment, AI Act assessment, or equivalent assessment.

4.8. EU AI Act Deployer Obligations. To the extent that Customer qualifies as a “deployer” under the EU AI Act (Regulation (EU) 2024/1689) or any successor legislation, Customer shall comply with all applicable deployer obligations, including without limitation conducting appropriate fundamental rights impact assessments, implementing human oversight measures, monitoring the Agentic Services for risks, and maintaining all records and documentation required under such legislation. Customer acknowledges that Corti’s role is limited to providing the Agentic Services as a tool, and that Customer bears sole responsibility for its deployment decisions and regulatory compliance as a deployer.

4.9. Data Protection and Privacy Compliance. Customer is responsible for ensuring that any personal data processed through the Agentic Services, including through Tool Integrations, is processed on a valid legal basis, is covered by appropriate transparency notices, is limited to what is necessary for the configured purpose, and is disclosed only to systems, recipients, or third parties that Customer is authorised to use for such processing. Customer must configure the Agentic Services in a manner consistent with applicable data protection laws, the Agreement, and any applicable DPA or BAA.

5. RESPONSIBILITY FOR AGENT ACTIONS

5.1. Attribution. Customer acknowledges and agrees that every Agent Action initiated or executed within Customer’s Agentic Configuration is deemed to be authorised by, and taken on behalf of, Customer. Customer is responsible for all Agent Actions as if Customer had taken them directly, regardless of whether the specific action was individually reviewed or anticipated by Customer prior to execution.

5.2. Agentic Incidents. Customer is responsible for promptly detecting, investigating, mitigating, and remediating any Agentic Incident, serious incident, malfunctioning, material risk, or non-compliant outcome arising from its Agentic Configuration or use of the Agentic Services. Customer shall notify Corti without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any Agentic Incident, serious incident, malfunctioning, material risk, or non-compliant outcome that: (a) affects, or is reasonably likely to affect, the Platform, other Corti customers, or any third party; or (b) presents, or is reasonably likely to present, a risk to any natural person's health, safety, fundamental rights, data protection rights, or legal position. Each notification shall describe, to the extent known at the time: the nature and scope of the incident or risk; the Agent Actions involved; the systems, data, or persons affected or potentially affected; the steps taken or proposed to contain and remediate the incident; and any regulatory reporting obligations that may be triggered.

5.3. Transparency. Where required by applicable law, including Article 50 of the EU AI Act, Customer is responsible for disclosing to affected persons, in a clear and distinguishable manner and no later than the time of first interaction or exposure, that they are interacting with an AI system. Customer must ensure that AI-generated Output and Agent communications are appropriately identified and must not remove, disable, obscure, or materially alter any AI disclosure, label, metadata, watermark, or other transparency feature made available by Corti. Corti will make available technical capabilities that Customer may use to meet applicable transparency obligations.