When Your Vendor Adds AI: Key Legal and Practical Considerations for Clients

Torkin Manes LegalPoint
 

Artificial intelligence features are rapidly being embedded into the enterprise software that organizations rely on daily. From customer relationship management platforms and document management systems to human resources tools and financial reporting software, technology vendors are racing to integrate AI capabilities into their existing products, particularly SaaS offerings. For clients, this trend presents a mix of opportunity and risk.

When your vendor announces that it is adding AI features to a product you already license under an existing contract, the legal and practical implications can be significant. Legacy agreements were not drafted with AI in mind, and the terms governing data use, intellectual property, termination, and liability may be wholly inadequate once AI enters the picture.

This article provides a practical framework for evaluating and responding to vendor-initiated AI changes, including the risks created by legacy contract gaps and critical considerations when reviewing vendor-proposed AI addenda. A follow-up article will discuss the key features that should be included when a client decides to develop its own AI addendum for use in negotiations and contracts.

I. AI Features Are Coming—Whether You Asked for Them or Not

Most major SaaS providers have introduced, or are actively rolling out, AI-powered features within their existing product suites. These range from AI-assisted search and summarization tools to automated drafting, predictive analytics, and large language model (LLM) integrations. These features are often activated by default—without explicit customer consent and sometimes without any advance notification. Unfortunately, this so-called “stealth AI” can create significant contract challenges. Under traditional SaaS contracts, your organization provides data, the vendor hosts and processes it, and defined terms control what happens to that data during and after the relationship. AI challenges and changes many of these assumptions.

Legacy Contracts Were Not Drafted for AI

When your vendor adds an AI feature into an agreement that was never designed for it, several critical contract gaps may emerge:

  • Outdated definitions. It’s highly unlikely that the standard definition of “Customer Data” in your existing SaaS agreement capture prompts, outputs, embeddings, or other AI-specific data categories. If your “Customer Data” definition is narrowly defined, the protections you negotiated—including deletion obligations, export rights, and confidentiality protections—may not reach the data that AI features generate or consume.
  • Inadequate deletion obligations. Any termination obligation to delete “Customer Data” at the end of the contract is quite limited if the definition does not capture prompts, outputs, embeddings, or trained model weights. Your vendor may be contractually compliant in deleting your CRM records while retaining the AI-derived insights and analytics learned from your data indefinitely.
  • Broken data flow assumptions. The original SaaS contract may assume a relatively straightforward data flow between your organization and the vendor’s infrastructure, with a few subprocessors thrown in (once you review the data processing agreement). However, AI features may introduce new data complexities. For example, your data may be sent to third-party LLM providers, used to train vendor or third-party models, or otherwise processed in jurisdictions not contemplated by the original agreement. The details may (or may not) be in the fine print.
  • Default activation without consent. Perhaps the most concerning gap is that many AI features are activated by default without express notice from your vendor. Your organization may already be feeding sensitive data into an AI tool without anyone having reviewed or approved the terms under which that data will be processed.
  • Legacy termination clauses fall short. Traditional termination provisions address subjects such as material breach and bankruptcy/insolvency, but they do not contemplate AI-specific termination trigger events such as model deprecation/degradation, foundation model substitution, changes in the vendor’s acceptable use policy that restricts use cases or regulatory prohibitions. These are new categories of risk that require new exit rights.

Why This Matters Now

The window for negotiating favorable AI terms is often narrow. Once AI features are live and customer data is being processed through them, your leverage diminishes significantly. Vendors have little incentive to renegotiate terms after the fact, and the practical difficulty of unwinding AI data processing creates a form of lock-in that is fundamentally different from traditional SaaS lock-in.

Clients should treat any vendor communication about new AI features—whether a product announcement, a contract amendment, or a click-through addendum—as a trigger to review their existing agreement and take any necessary action to remedy any concerns.

II. Reviewing a Vendor-Proposed AI Addendum

When a vendor proposes an AI addendum to an existing agreement, it is essential to approach the document with the same level of diligence, rigour and scrutiny that you would apply to a new contract. Typically, vendor-drafted AI addenda are designed to expand the vendor’s rights and limit its liabilities, often in ways that directly contradict the protections you painstakingly negotiated in the underlying agreement.

A. The Click-Through Trap

Many vendors present AI addenda to clients through click-through mechanisms, such as hyperlinked documents within the existing platform, pop-up acceptance screens, or standalone non-negotiable terms posted on a vendor website. These are likely not benign administrative updates that should be blindly accepted. They are often substantive contract amendments that can fundamentally alter the rights and obligations under your existing agreement. Key risks of click-through AI addenda include:

  • Contradicting negotiated terms. The AI addendum may contain broad license grants, liability disclaimers, or indemnification carve-outs that directly override the extensively negotiated representations, warranties, limitation of liability, data protection and restriction provisions that you carefully negotiated in the master agreement.
  • Embedded and hyperlinked terms. Vendors frequently embed additional terms through hyperlinks within the addendum itself, creating multiple layers of contractual obligations that you may miss during a casual review.

    As a best practice, you should ask to see the vendor’s standard AI addendum at the procurement stage or renewal phase before any AI features are activated. Instruct your organization’s users not to click through or accept any vendor-presented AI terms without legal review.

B. Data Use, Data Privacy, and Data Security

Data provisions are typically where vendor-drafted AI addenda are most vendor-focussed. Areas of concern may include:

  • Broad training rights. Vendors often seek the right to use customer data, including prompts, outputs, and usage patterns, to train, fine tune or “improve” their AI models. This may be framed as improving “the Services,” but it effectively grants the vendor a perpetual right to benefit commercially from your data, including potentially sensitive or proprietary data without economic benefit to you.
  • De-identification as a workaround. Vendors frequently propose de-identification or aggregation as a compromise, permitting them to retain and use data in de-identified form. However, AI systems can re-identify individuals from patterns across datasets, making de-identification far less protective than it appears. Contracts should reference an industry standard for de-identification, such as NIST SP 800-188, and include an affirmative covenant by the vendor not to re-identify your data or your users.
  • Gaps between contract and practice. Actual vendor data usage may differ materially from what the contract says, or the contract may be silent on key data practices. It is critical to understand how the vendor (and its affiliates, subcontractors and subprocessors) actually uses your data (including personal information or the information of your customers), and where it is stored and processed, particularly if you are in a highly regulated industry.

C. Liability and Indemnification for AI-Generated Outputs

AI-generated outputs additionally introduce new categories of risk. Vendor-drafted addenda typically seek to limit the vendor’s exposure in several ways:

  • Disclaiming accuracy. Almost all standard AI agreements state that outputs are made available on an “as-is”, “as-available” basis, and vendors commonly disclaim any representation or warranty regarding the accuracy, completeness, or reliability of AI-generated outputs. This leaves the customer to bear the risk if an AI output is incorrect, misleading, harmful, biased or violates applicable laws.
  • Excluding outputs from indemnification. The vendor’s standard IP indemnity (and other indemnities) often does not extend to AI-generated outputs. If an output infringes a third party’s intellectual property rights, you may have no contractual recourse against the vendor.
  • Disclaiming uniqueness. Vendors routinely disclaim any guarantee that AI outputs will be unique, meaning multiple customers may receive identical or substantially similar outputs. While this reflects a genuine technical limitation, it also underscores the need for robust IP protections.

D. Intellectual Property Ownership

IP ownership in the AI context is more complex than traditional software licensing because there are distinct categories of intellectual property at stake, each often addressed in different sections of the vendor’s contract. These include:

  • Inputs and prompt libraries. While the vendor may acknowledge that you technically own your inputs, prompts, configurations and fine-tuning data, the fine print may reveal that such terms are then reincluded in definitions like “Service Data” or “Usage Data” and licensed back to the vendor perpetually and irrevocably. This means the vendor retains a right to use your proprietary prompts and configurations even after termination of the contract with no compensation to you.
  • Outputs. The statement “you own your outputs” is often not entirely accurate. In practice, ownership is frequently conditioned on ongoing compliance with the vendor’s acceptable use policy, and outputs are generally excluded from vendor’s standard IP indemnity. What you receive may be a conditional assignment rather than true, unfettered and unconditional ownership so confirm the contract language carefully.
  • Feedback and ratings.  Customer feedback and ratings, which may be provided via thumbs up/down ratings, corrections, and evaluation results, are typically defined outside of the standard “Customer Data” definition and may be licensed to the vendor under a separate perpetual, irrevocable license that survives termination. As this data sits outside your negotiated data protections, none of the negotiated contractual safeguards will apply.

E. Opt-Out Rights and Transparency

  • Opt-out rights. Clients should also ask whether the proposed AI features are optional or required to use the updated vendor product. Unfortunately, even where a vendor offers the ability to turn off an AI feature, toggling off the user interface may not actually stop the vendor from using your data for training or model improvement purposes. Clients should confirm whether toggling off the feature actually stop all data processing associated with it. Similarly, you should ask whether toggling off the AI feature preserves your right to delete what has already been ingested.
  • Transparency and model substitution. Vendors may swap, replace or materially reconfigure their underlying foundation models without providing notice to customers. A model swap can materially change the data practices, accuracy and performance characteristics of the vendor product. Clients should require advance written notice of any vendor model changes and should understand whether a model swap changes any data-use, training or processing commitments of the vendor.
  • F. Compliance with Applicable Law

    The regulatory landscape for AI is evolving rapidly. Vendor-drafted addenda may not adequately address: (i) compliance with current and emerging AI-specific regulations in applicable jurisdictions; (ii) regulatory actions or adjudicated IP findings that could impair the client’s permitted use of the product; (iii) the allocation of regulatory risk between vendor and customer, particularly where the vendor’s AI features create compliance headaches for the customer (e.g., bias, discrimination or failure to meet transparency requirements). Additionally, the vendor-drafted AI addenda may not contain sufficient obligations on the part of the vendor to stay abreast of key regulatory developments during the contract period.

    III. Creating a Client-Side AI Addendum

    Rather than accepting vendor-drafted AI terms, it is far better for clients to proactively develop their own standard-form AI addendum for use in negotiations. A well-crafted client-side addendum establishes client’s baseline expectations and provides a structured framework for evaluating the vendor’s AI capabilities and practices. Stay tuned for Part Two of this article for a more detailed discussion about suggested AI Addendum best practices and next steps.

    Torkin Manes can assist with evaluating and responding to vendor-initiated AI changes. For more information please contact Lisa R. Lifshitz of Torkin Manes’ Technology and AI & Innovation Groups.