
An AI product demo often begins with an impressive answer. A useful contract review begins with a different question: what information and authority will the product receive inside your business?
A tool that drafts public marketing copy has a different role from one that reads customer files, reviews applications, or can send messages and change records. Write down the intended use before reviewing the vendor’s standard terms. The questions below are practical negotiation points, and the right answers depend on that use.
What may the vendor do with your information?
Identify the material employees may submit: prompts, uploaded documents, customer information, source code, internal communications, and the resulting outputs. Ask whether the vendor can use each category for model training, product improvement, human review, or evaluation.
Check whether a no-training promise covers the particular plan, connected services, underlying model providers, and support interactions. Ask who can change the setting and whether the contract preserves the restriction if the product changes. Save the agreed version of any online terms.
Where does the information go, and when is it deleted?
Request a clear description of retention, hosting, subprocessors, employee access, and account deletion. If the tool connects to your document system, identify whether it copies files, creates a separate searchable index, or keeps logs containing content.
Ask what remains after a user deletes a conversation or disconnects an integration. Negotiate a usable deletion process and an explanation of backup and legal-retention exceptions. The people administering the product need instructions they can actually follow.
What can the tool do on your behalf?
For tools that take actions, map permissions separately from data access. Reading a calendar, changing it, sending invitations, and emailing customers are different capabilities. Decide which actions require a person to approve them, how access is revoked, and whether an audit trail is available.
Use a limited pilot to check those controls. Define who can stop the tool, how you would reverse an incorrect action, and who receives an incident report. Put essential vendor support commitments into the agreement.
How will you evaluate the outputs?
NIST’s Generative AI Profile is a resource for evaluating generative-AI risks. Its companion AI Risk Management Framework is voluntary. It can inform a review without becoming a promise that following a checklist establishes legal compliance.
Build a small set of representative tasks and evaluate the output before wider use. Decide what accuracy, source checking, human review, and escalation the task requires. Include difficult examples and cases where the appropriate response is to ask for more information.
Read any performance commitment alongside its exclusions. A demonstration and a marketing claim do not explain the remedy for repeated failure on your actual workflow.
Who may use the output, and who bears a claim?
Review the contractual rights to use outputs, restrictions on that use, and any intellectual-property indemnity. Check exclusions, required safeguards, notice obligations, and liability caps. A vendor’s allocation of rights in an output does not answer every question about third-party material contained in it.
Finish with an exit plan covering exports, access revocation, deletion, and replacement of business processes that have come to depend on the tool. Bring the proposed contract, product description, planned integrations, and sample data categories to a AI and technology-contract consultation. That preparation keeps the discussion tied to the decisions your business needs to make.
General information, not legal advice for a particular matter. The applicable documents, facts, and deadlines control.
