SYSTEM NOTICE

Auto translation by AI. Be sure, accuracy, nuances and authorial intent may not be fully reflected.
見出し画像

Characteristics of AI Vendor Contracts / Reflections on Reading Colin S. Levy's Practical Guide


I. AI Procurement is Not an Extension of SaaS Contracting

In mid-March 2026, international practitioners such as Kuba Szarmach and Geoffrey Ceunen were engaged in a series of discussions regarding legal considerations when implementing AI tools. The practical guide they referenced and introduced as a professional guideline was the 2026 work by attorney Colin S. Levy, 'Contracting with AI Vendors: A Practical Guide for Lawyers.' It highlights the dangers of agreeing to standard terms presented by AI vendors with the same mindset used for procuring traditional software, while providing concrete draft clauses. AI output is probabilistic, and input data has the characteristic of irreversibly altering the structure of the model itself. Having read the original text, I also believe that we are forced to adopt an approach different from existing license agreement frameworks regarding data usage restrictions and the allocation of liability. I will examine the challenges of risk control through contracts.

1. Data Diversion for Model Training and Attorney-Client Privilege

The first issue to confront in AI vendor contracts is whether the customer's input data and output results are used for model training. If input data is incorporated into the weights—the internal parameters of the model—it becomes virtually impossible to extract it later. If a vendor reserves broad data usage rights under the guise of product improvement, it invites a situation where the organization's confidential information is indirectly reflected in outputs provided to other companies.

In situations where law firms handle client information, the diversion of data for model training leads directly to the waiver of attorney-client privilege. A February 2026 U.S. federal court decision suggested that the use of consumer AI tools with broad data collection clauses could result in the waiver of privilege [Note 1]. Formal Opinion 512, published by the American Bar Association on July 29, 2024, also imposes a duty on attorneys to accurately understand whether the AI tools they use are autonomous learning systems [Note 2]. It is necessary to explicitly prohibit learning usage by the vendor in the contract and to ensure that equivalent restrictions apply to sub-processors, such as the entities providing the underlying foundation models.

2. Managing Uncertainty and Ownership of Outputs

The performance of AI models does not remain static after deployment. Model drift occurs, where performance deviates from initial levels due to new data input or the passage of time. Traditional service level agreements based solely on uptime are not suitable for AI that produces different results every time. It is necessary to require vendors to perform continuous performance monitoring using objective metrics regarding hallucination rates and bias, and to explicitly stipulate the right to terminate the contract without penalty if performance falls below established standards.

The ownership of generated outputs is also a source of conflict. If a vendor reserves rights to output results in their standard terms and allows them to be used for their own model improvement, the customer's business achievements will be absorbed by the vendor. It is essential to secure the customer's ownership of the output and form an agreement that excludes unauthorized use by the vendor.

II. Allocation of Liability for Imperfect Systems

Large language models inevitably involve hallucinations, where they plausibly output false information that differs from the facts. According to empirical research cited in Levy's guide, even AI tools specialized for legal research are reported to hallucinate with a probability of 17 to 33 percent [Note 3]. If an attorney causes damage to a client by citing a fictitious case generated by the AI, the question arises as to who should bear the responsibility.

Vendors tend to claim limitation of liability in their terms of service, capping it at the usage fees paid over the past 12 months, and disclaiming the accuracy of generated content. In contrast, cases are emerging where vendors themselves are held directly legally liable when AI is used for decision-making support, such as in hiring or credit assessment, and the bias inherent in the algorithm leads to discriminatory results against specific attributes. In the case of Mobley v. Workday, a U.S. federal court recognized claims of disparate impact against an AI vendor providing hiring screening tools, and preliminary class certification was granted in May 2025 [Note 4]. I believe that for damages resulting from hallucinations, discriminatory outputs, or third-party intellectual property infringement by generated content, it is logical to demand that the vendor bear appropriate risk as an exception to liability caps, rather than treating these issues the same as traditional service outages.

III. In Conclusion

Just as the European Union's Data Act, which came into effect on September 12, 2025, mandates data portability and short-term service migration, there is a need to secure exit strategies to prevent dependence on specific vendors [Note 5]. Furthermore, new legal frameworks that stipulate documentation and audit obligations for high-risk systems, such as the Colorado Artificial Intelligence Act and the European Union's AI Act, will be applied sequentially from 2026 onwards.

It can be said that accepting the standard terms presented by AI vendors as a given is no longer permissible from the perspective of legal compliance. Users have a duty to face the technical characteristics of AI tools and prevent potential disadvantages through the scrutiny of contractual terms. I hope this provides some food for thought. For details, please check the original text mentioned above.

[Note 1] K&L Gates, "Generative AI Data, Attorney-Client Privilege, and the Work-Product Doctrine" (February 2026).

[Note 2] ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, "Generative Artificial Intelligence Tools" (July 29, 2024).

[Note 3] Magesh et al., "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools," 22 J. Empirical Legal Studies 358 (2025). First appeared as a Stanford HAI working paper in 2024.

[Note 4] Mobley v. Workday, Inc., No. 3:23-cv-00770 (N.D. Cal.). Claims based on agency theory were dismissed, but direct claims of disparate impact were accepted. Preliminary class certification granted in May 2025.

[Note 5] EU Data Act, effective September 12, 2025. Article 23 et seq. (Obligations for data portability and switching support. The switching period is generally 30 days, with an exceptional extension of up to 7 months if technically impossible.)

(Magazine) "Reflections on AI and Law"

*Please refer to the following for the table of contents

note General Terms of Service Article 3, Paragraph 2, First Sentence
3.2 The copyright of digital content produced by the creator belongs to the creator.
P.S. This is shared for academic discussion only.

いいなと思ったら応援しよう!