What's Happening?
Employers are increasingly encountering complex contract terms and vendor risks when procuring Artificial Intelligence (AI) technologies or services that utilize AI. Damon Silver and Joe Lazzarotti, co-leads of the Privacy, AI and Cybersecurity group
at Jackson Lewis, highlight the critical need for businesses to understand the specific uses of AI by vendors, as this significantly influences contractual obligations and risk assessment. Key areas of concern include the precise definition of 'services' in contracts, as AI's role can extend beyond direct service provision to internal administrative functions, impacting data confidentiality and record-keeping. Vendors often push back on disclosure obligations and the need for permission to use AI, especially when the line between internal use and material impact on services is blurry. Furthermore, significant negotiation points arise regarding vendors' desire to use client data for training AI models, necessitating clear contractual language on data anonymization and aggregation standards, which must comply with regulations like HIPAA, CCPA, or GDPR. The allocation of liability, particularly concerning intellectual property infringement, data breaches, and inaccuracies or biases in AI outputs, also presents a major challenge, with vendors often seeking to limit their responsibility.
Why It's Important?
The integration of AI into business operations, particularly through third-party vendors, introduces novel legal and operational risks for U.S. employers. Without meticulously crafted contracts, companies could face significant liabilities related to data privacy, regulatory compliance, and the performance of AI-driven services. The discussion underscores that standard contract terms may be insufficient to address the unique challenges posed by AI, requiring specific clauses for data usage, audit rights, and liability allocation. The potential for AI to re-identify anonymized data, as highlighted by a recent case, emphasizes the need for robust de-identification standards and continuous vigilance. Moreover, the push for 'human in the loop' provisions in contracts reflects a growing recognition of the ethical and regulatory implications of AI-driven consequential decisions, such as loan approvals or hiring. Employers must not only negotiate strong contracts but also operationalize these terms within their governance structures to ensure compliance and mitigate risks, especially given the varying legal landscapes across jurisdictions like Colorado's AI statute.
What's Next?
As AI adoption continues to grow, employers will need to refine their AI procurement strategies and contract negotiation processes. This includes conducting thorough front-end analysis to understand vendors' AI usage, meticulously defining 'services' and data handling practices in contracts, and establishing clear audit rights. The increasing scrutiny on AI's ethical implications and potential for bias will likely lead to more stringent regulatory requirements, necessitating contracts that explicitly address human oversight and accountability for AI outputs. Companies should anticipate continued negotiation challenges with vendors regarding data training and liability, requiring them to leverage their bargaining power to secure comprehensive protections. Furthermore, the importance of exercising audit rights, as mandated by regulations like CCPA, will become more pronounced. Employers will need to develop robust programs for onboarding, vetting, contracting with, and regularly auditing AI vendors to ensure ongoing compliance and risk management. The evolving legal and technological landscape will demand continuous adaptation of contractual frameworks and internal governance to keep pace with AI advancements.
Beyond the Headlines
The complexities surrounding AI procurement contracts extend beyond immediate legal and financial risks, touching upon broader societal and ethical considerations. The debate over data usage for AI training, for instance, highlights fundamental questions about data ownership, privacy, and the potential for algorithmic bias to be perpetuated or amplified. The push for 'human in the loop' provisions reflects a societal desire to maintain human agency and accountability in critical decision-making processes, especially as AI systems become more autonomous. The challenges in defining liability for AI errors or misuse also raise questions about the future of legal frameworks in an increasingly AI-driven world. This evolving landscape necessitates a proactive approach from businesses, not just to comply with regulations, but to actively shape ethical AI development and deployment. The need for transparency and accountability in AI systems, as reflected in contract negotiations, is crucial for building public trust and ensuring that AI serves societal good rather than exacerbating existing inequalities or creating new risks.








