Updating Contracts for AI: Clauses Every Commercial Contract Should Include

If your business is buying, selling, or building AI into the products and services you offer, you may have noticed that your existing contract templates were not written with this technology in mind. That is a common and entirely understandable gap, since most commercial contracts were drafted for predictable software that behaves the same way every time, not systems that learn, adapt, and occasionally produce unexpected results as AI does. This guide explains what is changing and the clauses worth reviewing in your own agreements.

Why Standard Contract Terms Fall Short For AI

Traditional commercial contracts tend to assume deterministic software, meaning code that behaves consistently and predictably given the same inputs. AI systems, particularly those built on machine learning, do not necessarily work this way. They can produce different outputs from similar inputs, their behaviour can shift over time as models are updated, and they can occasionally generate results that are simply wrong.

Liability provisions suited to traditional IT procurement are unlikely to be adequate when applied to AI, since AI has the potential to generate harm at scale if something goes wrong. This is why reviewing your contract templates is a genuine risk management step.

Data Ownership And Training Restrictions

One of the most important areas to address is what happens to the data you share with an AI provider. Many AI tools are designed to learn from the data fed into them, which raises a real question about whether your confidential information, customer data, or proprietary content could end up shaping a model used by other customers entirely.

A good idea is to define ownership of inputs, outputs, and training data clearly, and requiring that an AI system does not train on any information you input, including personal or confidential information, unless you have given explicit written approval. If your business handles sensitive client data, this clause deserves particular attention, since the consequences of getting it wrong extend well beyond the immediate contract.

A clause covering this might be worded along these lines, though it should always be adapted to your own circumstances with proper legal input:

“The Provider shall not use any Customer Data, including personal data or confidential information submitted by the Customer, to train, fine-tune, or otherwise improve any model or system, whether for the Customer's own benefit or that of any other customer, without the Customer's prior written consent.”

Liability And Indemnity For AI-Generated Harm

Because AI outputs can be unpredictable, liability clauses need to anticipate scenarios that traditional software contracts rarely considered, such as an AI system producing a discriminatory or factually incorrect output that causes financial loss or reputational damage. Businesses procuring AI may want to negotiate a dedicated liability cap for AI-generated harm, potentially linked to the provider's professional indemnity insurance, while providers will typically seek to limit their liability where the customer's own data, prompts, or configuration contributed to the problem.

A useful illustration of how courts are approaching this question came from a 2024 Canadian tribunal ruling against Air Canada, widely discussed by UK legal commentators including Pinsent Masons, as a warning for any business deploying AI tools. A customer relied on incorrect information given by Air Canada's website chatbot about bereavement fares, and the airline argued it could not be held responsible because the chatbot should be treated as a separate entity from the company. The tribunal rejected that argument outright, finding the airline liable for the chatbot's output in the same way it would be liable for any other information on its own website. The case is a clear reminder that a business cannot expect to disclaim responsibility for what its AI tools say or do simply because the output was generated automatically, which makes a clear contractual allocation of responsibility between supplier and customer all the more important.

Contracts should clearly allocate responsibility for AI outputs, particularly where those outputs feed into decisions affecting individuals, such as HR, credit, or insurance decisions, and should ensure any exclusions or caps on liability do not unlawfully exclude liability for matters such as personal injury or fraud.

Illustrative wording for a liability cap addressing this might read:

“The Provider's aggregate liability for any loss or damage arising from an output generated by the AI System shall not exceed the total fees paid by the Customer in the twelve months preceding the claim, save that nothing in this clause shall limit liability for death, personal injury, fraud, or any other liability which cannot lawfully be excluded or limited.”

Intellectual Property And Third-Party Infringement

AI-generated content can raise difficult intellectual property questions, particularly around whether outputs might unintentionally reproduce or closely resemble existing copyrighted material. Customers procuring AI services often want indemnities protecting them against third-party claims that an AI system's output infringes someone else's intellectual property rights, since this risk sits largely outside their control but could expose them to legal claims regardless.

This is not a theoretical concern. In November 2025, the High Court handed down judgment in Getty Images v Stability AI, the first UK case to consider copyright infringement arising from the training and use of a generative AI model. Stability AI ultimately defeated Getty's main copyright claims, largely because Getty could not show the relevant training had taken place in the UK, but the court did find limited trade mark infringement where the model had reproduced Getty's watermarks in its outputs. The case left many of the core questions about training data and copyright unresolved, which is precisely why indemnity and warranty clauses addressing IP risk remain so important. Businesses cannot assume the law will protect them simply because one early case went a particular way on its own specific facts.

A basic indemnity addressing this risk might be worded as follows:

“The Provider shall indemnify and hold harmless the Customer against any claim, loss, or expense arising from an allegation that the Customer's proper use of the Output infringes the intellectual property rights of a third party, provided that the Customer notifies the Provider promptly of any such claim and permits the Provider to control its defence and settlement.”

Transparency, Human Oversight, And Audit Rights

Where an AI system is being used to make or influence decisions about people, contracts should include clear obligations around transparency and human oversight. This means setting out who is responsible for reviewing AI outputs before they are acted upon, and ensuring there is a documented process for escalating concerns about the system's performance.

For AI systems that fall into higher risk categories, it is recommended that you secure the right to audit or review the AI system's performance and any updates made to it, so your organisation can maintain ongoing oversight rather than relying solely on assurances given at the point of signing.

The value of this kind of clause was demonstrated in January 2024, when UK parcel delivery firm DPD had to disable part of its customer service chatbot after a routine system update caused it to swear at a customer and write a poem criticising the company, an incident widely reported at the time. The fault only became apparent once a frustrated customer posted screenshots online, rather than through any internal monitoring process. Whether you are the business deploying the AI tool or the supplier providing it, a contractual right to be notified of significant updates, along with a clear process for testing and monitoring behaviour after changes are made, is a practical safeguard against exactly this kind of failure.

Wording covering notice and audit rights might look something like this:

“The Provider shall give the Customer no less than [insert number] days' written notice of any material update to the AI System's underlying model, training data, or configuration, and shall permit the Customer, on reasonable notice and during normal business hours, to audit or test the AI System's performance and outputs.”

Compliance With Evolving Regulation

Given how quickly AI regulation is developing across the EU and UK, contracts should reference compliance with relevant frameworks such as the EU AI Act and applicable UK GDPR and ICO guidance on AI and data protection, while keeping the detailed technical controls in a schedule that can be updated without rewriting the whole agreement. This approach avoids the contract becoming outdated every time guidance changes, while still keeping compliance obligations binding.

It is also worth including a disclosure obligation requiring your supplier to tell you, before use, if any AI system will touch your data or deliverables, along with a requirement for written approval before AI is used in higher-risk scenarios, such as content published without human review.

Termination, Data Deletion, And Exit Arrangements

Finally, do not overlook what happens when the relationship ends. Contracts should specify what happens to your data and any models trained on it when the agreement terminates, including clear deletion timeframes and, where appropriate, a requirement for the supplier to provide written confirmation that deletion has taken place.

A simple exit clause covering this might read:

“On termination or expiry of this Agreement, the Provider shall, within [insert number] days, delete or securely return all Customer Data held within or processed by the AI System, including any Customer Data used for training purposes, and shall provide the Customer with written confirmation that such deletion has taken place.”

Bringing Your Contracts Up To Date

AI is moving quickly enough that contract templates drafted even a year or two ago may already be missing important protections. Reviewing your standard terms, whether you are the business supplying AI capability or the one procuring it, is one of the most practical steps you can take to manage the legal and commercial risks that come with this technology.

If you are unsure whether your current contracts adequately address AI use, either by you or by your suppliers, getting specialist legal input on your templates now is far more straightforward than trying to renegotiate after something has gone wrong.

How Can Gerrish Legal Help?

Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property. 

We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements. 

We are here to help you, get in contact with us today for more information.

Next
Next

The Data Act in Practice: A Complete Guide for Businesses