AI is quietly becoming one of the most negotiated parts of commercial agreements.
A year or two ago, AI provisions were often fairly simple: Can a vendor use AI in providing the services? Can customer data be used to train a model?
Those questions haven't gone away, but the negotiations have become much more sophisticated.
We are now regularly dealing with questions like:
• Can confidential information be submitted to third-party AI tools?
• Can customer data be used to train or fine-tune a model—or improve a service more generally?
• Who owns AI-generated or AI-assisted work product?
• What rights does a customer receive in prompts, configurations and outputs?
• What level of human review is required before AI-assisted work is delivered?
• Who bears the risk if an AI-generated output infringes someone else's intellectual property?
• What happens when the AI functionality is provided by a third-party model provider rather than the company actually signing the contract?
What I find particularly interesting is that these issues are no longer confined to AI companies.
They are showing up in SaaS agreements, services agreements, agency agreements, data agreements, software licenses and ordinary enterprise customer contracts.
And I'm not convinced that simply prohibiting the use of AI is a particularly good solution.
For most businesses, AI is quickly becoming another tool used to provide services. The better approach is usually to understand how it is being used, identify the data and intellectual property actually at risk, allocate that risk appropriately, and put reasonable safeguards around the use.
The contracts are starting to catch up with the technology.
And I suspect we're still very early.
