What Legal Issues Should Businesses Consider before Buying AI?
Before procuring any AI system, the starting point is understanding what data the tool was trained on, and whether the data you input will be used to train the model further for other customers. It is a good idea to ask vendors directly whether your information, including any personal or confidential data, will be used to refine their model, and to secure a contractual commitment that it will not be, unless you give specific written approval. This matters because once your data has shaped a model, you generally cannot undo that, regardless of what happens to your relationship with the supplier afterwards.
Liability is the second major area to examine closely. AI systems can behave unpredictably, and traditional software contracts were not written with this in mind. You should check how the contract allocates responsibility if the AI produces a harmful, biased, or factually incorrect output, whether there is a liability cap that genuinely reflects the scale of risk involved, and whether the vendor offers any indemnity if the AI's output infringes someone else's intellectual property rights. Where the system will be used to make or influence decisions about people, such as recruitment or credit assessments, you should also confirm what human oversight is built into the process, since regulators increasingly expect a person to remain accountable for automated decisions.
Finally, consider where the system sits under current regulation. If the AI touches anyone in the EU, the EU AI Act's risk-based obligations may apply regardless of where your business is based, and if the tool processes personal data, UK GDPR and the ICO's guidance on AI and data protection will apply in parallel. Before signing anything, it is worth running through a short due diligence checklist covering data handling, security certifications, audit rights, and what happens to your data if the contract ends, since these questions are far easier to resolve before you sign than after.