
Practical guidance for spotting AI risks in your agreements
You do not need to be an AI expert to face legal or regulatory problems caused by vague or outdated contract language. Artificial intelligence is now built into CRMs, HR tools, marketing platforms, analytics dashboards, and many other services.
This means your company may already be exposed to AI-related risks through its software and technology service contracts, even if no one has labeled them as such. Unlike the Shadow AI problem we covered here, these risks are in documents you have already signed.
Whether you are licensing software, integrating AI into your services, or building your own AI-powered platform, here are three areas to examine closely.
The risk: Many AI vendors seek broad rights to use customer data to improve their products, which often includes training their models. This can mean your confidential, proprietary, or regulated data is incorporated into systems used by other customers or even competitors. This can create exposure for trade secret loss, privacy law violations, and reputational harm if the data is linked back to you.
What to watch for:
What to do:
The risk: Many AI systems are built on open-source models, libraries, or datasets. Some carry restrictive licenses that can extend to your business. For example, a “viral” license could require you to make your own proprietary code public, or a “non-commercial” license could block you from using the tool in your core business.
What to watch for:
What to do:
The risk: Traditional software warranties focus on uptime and conformity to documentation. AI systems can fail in ways those warranties do not address, such as performance decline over time (model drift), biased decision-making, or non-compliance when laws change. Without specific protections, you may be paying for a system that is available but unreliable or legally risky.
What to watch for:
What to do:
Before you sign any agreement for software or technology services, ask:
1. Does this contract allow the vendor to use my data to train models for other customers?2. Do I know every model, library, or dataset being used, and do I understand the license terms?3. Does the warranty address performance, fairness, or compliance, or only system uptime?
If any answer is unclear, the contract needs closer review.
These are not theoretical risks. They are issues that can often be identified and addressed before they become costly disputes or regulatory problems. The “What to do” bullet points in this post are only potential solutions and are only starting points, often requiring more due diligence, creativity, or industry specific solutions.
If you would like to review your existing software agreements or develop templates that address AI-specific risks, our team can help you identify and resolve these issues early.

AI has fundamentally changed how businesses operate. It can summarize documents in seconds, generate first drafts of nearly anything, and make complex information feel accessible. We use AI ourselves, and we believe every business owner should explore it.
View Article
In Before You Use AI, Read the Fine Print, we discussed how vendor terms can leave you exposed to privacy and liability risks. In this follow-up to our AI Landmines post, we focus on another potential problem: treating AI “system cards” as if they provide a complete view of the technology.
View Article
Employees are increasingly using generative AI tools, such as ChatGPT, Gemini, and Copilot, without authorization or oversight. This unsanctioned usage, often referred to as Shadow AI, creates substantial legal and compliance risks.
View Article