← Back to AI Legal Lab
Insight
Contract ReviewM&A Legal

AI vendor due diligence and contract review checklist

Hello, this is Legal Agent.

Requests to onboard a new AI tool frequently arrive with a pricing sheet, feature overview, and standard SaaS security checklist attached. Evaluating uptime, price, and features the way an organization evaluates conventional SaaS is insufficient for AI services, which often process sensitive corporate data. Reviewing an AI vendor requires confirming whether customer inputs train models, how logs are retained, and who bears responsibility for output errors.

Five baseline determinations before vendor discussions

Before issuing questions to an AI vendor, a company should settle five internal points. First, determine whether confidential information, personal data, or third-party copyrighted material will enter the prompt. Second, define who uses the output, for what specific workflow, and under what operational limits. Third, ensure the company can explain data transmission, model training, log retention, and data reuse through contracts and internal guidelines. Fourth, confirm that vendor terms, privacy policies, customer agreements, and internal rules rest on compatible terms. Fifth, establish clear human review checkpoints so that AI-generated decisions are never adopted automatically.

Divergent risk profiles within the same software category

Tools in the same software category can carry fundamentally different risk profiles. For example, two services marketed as meeting-notes assistants may operate under entirely different architectures: one processes audio in temporary memory and deletes it immediately, while another retains recordings to train algorithms, transmits transcripts to a third-party model provider, routes data through overseas data centres, or allows vendor administrators to inspect customer logs. Category labels provide little clarity on their own; confirming actual data flows requires technical input from information security and IT teams alongside the requesting business department.

Contractual allocation of responsibility and data flow tracing

Because AI tools analyse, draft, and in agentic configurations execute operational actions autonomously, contracts must address failure scenarios directly. Ambiguity creates serious difficulties when an automated message contains errors, an employee uploads customer data by mistake, a model update degrades performance, or a service outage raises questions about service-level commitments. Furthermore, modern AI architectures often stack an application provider, a foundation model developer, and an infrastructure cloud host behind a single interface. Tracing data flows requires reviewing subprocessor lists, admin console configurations, and technical security documentation alongside the contract terms. Special attention must be paid to model training: if sales representatives promise that customer inputs will not be used for training, the agreed terms and any priority provisions need to be checked. The restriction should be recorded explicitly in the contract, inconsistent descriptions resolved, and the actual settings verified.

Keywords
Legal due diligence
Browse all keywords

Related articles

Articles connected to this topic.

Insight / 2026.06.13 Review basics for indemnity, price adjustment and closing clauses in an SPA Insight / 2026.06.13 Review basics for M&A letters of intent Insight / 2026.06.01 Founder shares and shareholders' agreements before startup M&A
View AI Legal Lab articles