Why does the contract matter more than the demonstration?
A demonstration shows the product on its best day, with clean sample data and a presenter who knows exactly which buttons to press. The contract governs every other day: the outage during a filing week, the support ticket that goes unanswered, the moment a client asks where their information is held, the day you decide to stop using it.
Most AI products aimed at firms of 20 to 200 people are sold on a monthly or annual subscription with standard terms presented as a link. Nobody reads them, because they look like the terms attached to every other piece of software the firm has signed. They are not quite the same. The new clauses sit around data use, model behaviour and output, and those are the clauses that interact with your professional obligations.
What does it say about your data?
Start here, because everything else is secondary. You are looking for plain answers to three questions. Is customer content used to train or improve any model? How long is content retained, and where in the stack: in the product, in logs, in support tickets? Can vendor staff view content, and under what controls?
Watch for soft wording. Phrases such as "to improve our services" can cover training, and "aggregated and anonymised" can cover more than you expect when the material is a distinctive client document. Wording that says training is off by default is weaker than wording that says it does not happen under this agreement. If the position is good, the vendor will put it in the contract rather than in a blog post that can be edited.
Then set that against what you have already promised. Engagement letters and client confidentiality agreements often restrict onward disclosure, and some clients impose supplier terms of their own. Our own position is simple: we work under whatever confidentiality agreement a client uses with any other supplier, and nothing a client shares is used for anyone else. Hold a vendor to the same standard. The guide to data protection in AI client work sets out how this sits alongside UK GDPR and the Data Protection Act 2018.
Who sits behind the vendor?
Very few AI products are built end to end by the company selling them. There is usually a model provider, a hosting provider, maybe a transcription service and an offshore support function. Each is a sub-processor, and each is a place your client's information can travel to.
Ask for the current list, in writing, and for the notice you get when it changes. Ask where processing happens and whether you can require UK or EU hosting. Ask what happens if the vendor swaps the underlying model, because that can change both the behaviour of the product and the data terms you thought you had agreed. A supplier who cannot describe their own supply chain clearly is not in a position to make promises about it. Your IT provider can help you test the answers, and there are more of those questions in what to ask your IT provider.
Who owns what goes in and what comes out?
Two separate questions, and contracts often blur them.
Going in: you will upload templates, precedents, style guides, past reports, maybe a knowledge base. Check that the vendor takes only the licence it needs to run the service for you, that the licence ends when the contract ends, and that it does not extend to using your material to build features for other customers.
Coming out: check the contract confirms you own the output and can use it in client work without restriction. Some terms disclaim all ownership of generated material, which is awkward if the material becomes part of a deliverable. Check too whether the vendor claims any right to use your name as a reference, and strike it if you have not decided to talk about it yet. That decision belongs to the firm, and we have written about the timing in telling clients you use AI.
What happens when you leave?
Exit terms are the most skipped section and the most expensive to get wrong. Look for four things:
- Export. What you can take out, in what format, and whether it is usable without the product. A PDF dump of years of records is not an export.
- Deletion. What is deleted on termination, within what period, including backups and logs, and whether you get written confirmation.
- Configuration. If you spent weeks tuning prompts, templates and workflows, establish whether any of that is portable or whether it dies with the subscription.
- Notice and renewal. Auto-renewal windows, price uplift mechanisms and whether the vendor can change the terms unilaterally mid-term.
Lock-in is not created by the licence fee. It is created by the records that only exist inside one supplier's system. This is one of the practical arguments in custom build versus off the shelf: a process rebuilt in the tools you already run leaves far less hostage.
What does the liability clause actually cover?
Expect a cap tied to fees paid in the preceding twelve months, exclusion of indirect and consequential loss, and a disclaimer saying output accuracy is not warranted. That combination is normal, and it tells you something important: the commercial risk of a wrong answer reaching a client stays with you.
So read the clause not as protection but as confirmation of where the duty sits. It means review by a named person is not optional, which is the discipline described in reviewing AI output on client work. It also means your professional indemnity position matters more than the vendor's cap, and that is a conversation worth having early, as we set out in telling your PI insurer about AI. Where there is an indemnity worth having, it is usually for third party intellectual property claims arising from the output. Check it exists and check what it excludes.
How should a firm run this check without it taking a month?
Write the questions once and reuse them. A single page covering data use, retention, sub-processors, hosting location, output ownership, export, deletion, liability and change of terms will cover most of what matters, and it turns a vague review into a short exchange of emails. Record the answers alongside the supplier record so the next person does not start again, which is the same logic as any other supplier vetting step.
Then make it the rule. If staff can sign up to tools on a card without the check, you have the exposure anyway, which is the problem described in shadow AI. Fold the page into your AI policy so there is one route in and one standard applied.
One last point. The contract check is easier when you know what the tool is for. A firm that has decided which single process it is fixing can ask narrow, answerable questions about that process. A firm shopping for AI in general ends up reading everything and deciding nothing. The audit will tell you which process to put first.