Blog
What should a law firm check in an AI supplier's contract?
Look past the price at the data terms, what the supplier promises about the output, who carries the risk, how the terms can change, and how you get out and get your material back.
Alesis · · 5 min read
Read the contract the way you would read one for a client: start with what you are buying, then the data terms, then liability, then exit. Most AI supplier terms are standard form, so the real question is whether what they say is acceptable to you, not whether you can redraft them. If something important is missing, ask for it in writing before you sign, because a clear email answer from a supplier is worth more than an assumption.
What are you actually buying
The first thing to pin down is the commercial shape, because it drives everything else.
- Is this a subscription, a per user licence, a consumption model, or a bundled module inside software you already pay for?
- What is the minimum term, and does it renew automatically? If so, how long is the notice window and how is notice given?
- Can the price rise during the term, and on what notice?
- Are you paying per named user, per fee earner, or per firm? What happens when someone leaves or joins?
- Does the licence allow use on client matters, or is it limited to internal or non commercial use? Some general purpose tools draw that line in their terms.
If the answer to any of these is buried in a linked policy rather than the contract itself, print the policy and keep it with the signed terms. Linked documents can change without anyone telling you.
The data terms are the ones that matter
You are putting client papers into this tool, so the data terms carry the professional risk. Work through them against what you already tell clients in your privacy notice and your engagement terms.
Look for clear answers on:
- Where the data is held and processed. Not just where it is stored at rest, but where it is processed, and by which sub-processors. A list that can be added to silently is worth raising.
- Training. Is your material used to train or improve anything that reaches other customers? "We do not train on customer data" is a different promise from "we do not train on customer data unless you opt in", and both are different from silence.
- Human access. Who at the supplier can read a matter, in what circumstances, and is it logged? Support access is often legitimate, but you should know it exists.
- Separation. Is your firm's material kept apart from other customers', and can your own staff be restricted to the matters they work on?
- Retention and deletion. How long is material kept after a conversation ends, after a user is removed, and after the contract ends? Is deletion on request, automatic, or neither?
- Breach notification. How quickly will the supplier tell you, and will they give you enough detail to decide whether the Information Commissioner's Office or a client needs to be told?
UK GDPR expects a written arrangement with a processor covering the usual ground. If the supplier has no data processing terms at all, that is a finding in itself.
What does the supplier promise about the output
Most AI supplier contracts disclaim a great deal, and that is not unreasonable, because the output is not advice and you are the one who signs it. But read the disclaimer and make sure you can live with it.
Check whether the contract:
- states plainly that the output is not legal advice and must be reviewed by a qualified person;
- caps the supplier's liability, and at what figure, usually some multiple of fees paid;
- excludes liability for loss of profit, loss of data or consequential loss;
- gives any warranty at all about availability, accuracy or support response times;
- says who owns the output, and whether you can use it freely in client work;
- indemnifies you against third party intellectual property claims arising from the tool itself.
A low cap is normal. The point is to notice it, and to factor it into your risk register and your conversation with your insurance broker, rather than to be surprised by it later.
How the terms can change, and how you leave
Many suppliers reserve the right to amend their terms, their policies or the service itself. Find that clause and read it closely. Are you told in advance? Can you terminate without penalty if a change is material? Does continued use count as acceptance?
On exit, you want to know three things: how you terminate, what you can get back, and when what remains is destroyed. Ask whether you can export your conversations and any work product in a usable form, how long you have to do it, and whether access is cut off immediately on non payment. Suppliers can be acquired, change direction or stop trading, and the contract is where you find out how much that would cost you.
Reading it when you have no time
You do not need a full contract review for every tool. Give the job to one person, usually the compliance officer or the partner who owns technology, and have them work to a short standing checklist: data location, training, deletion, liability cap, change clause, exit. Keep the signed terms, the policies in force on the day you signed, and the supplier's written answers in one folder. If a client, an insurer or a regulator asks what diligence you did, that folder is the answer.
Where Alesis fits
Alesis is an AI assistant for UK law firms, made by L25 Limited, used through the web browser. A firm's information is held in the UK and processed only in the UK and the EU, kept apart from every other firm, and never used to train anything for anyone else; inside a firm, people see only the matters they are on, and seniority alone grants no view. We are funded by credit rather than a subscription, so nothing recurs, there are no feature tiers, and the firm tops up only when it chooses. Alesis assists qualified professionals and does not replace them, and it does not provide legal advice.