Legal risks of AI: copyright, liability and contracts
The legal exposures a business takes on when it uses AI: rights in inputs and outputs, responsibility, and the contract terms that allocate both.
The short answer
Using AI in a business creates three legal exposures worth understanding. The first concerns rights: what you may put in, since client confidential material and third-party content carry obligations, and what you get out, since generated output may attract limited copyright protection and may in rare cases resemble protected material. The second concerns responsibility: you remain answerable to your customers and under your professional obligations for what you deliver, regardless of what produced the draft, and vendor terms are written to place that responsibility firmly on you. The third concerns contracts: the allocation of these risks is decided by clauses that go unread, principally whether the vendor may train on or retain your data, whether any indemnity is offered for third-party claims arising from outputs, and how liability is limited. None of this makes AI use unwise. It makes review before delivery a liability control rather than a quality preference, and it makes three clauses worth reading in every AI contract you sign.
The three exposures
| Exposure | What can go wrong | Control |
|---|---|---|
| Inputs | Client confidential material or personal data disclosed to a provider without authority; third-party content used beyond its licence | Approved tools under business terms; minimisation; client consent where the engagement requires it |
| Outputs, rights | Limited or no copyright protection in some jurisdictions; rare resemblance to protected material | Meaningful human authorship and records; vendor indemnity where offered; review |
| Outputs, accuracy | Fabricated facts, citations or figures delivered to a client | Verification before delivery; professional review; no unreviewed output leaves the business |
| Decisions | Automated decisions about people creating discrimination or data protection exposure | Human decision, documented criteria, explainability, outcome testing |
| Contract with the vendor | Training on your data; weak indemnity; low liability cap; data locked in | Read the three clauses; negotiate where you can; keep assets portable |
| Contract with your client | Silence about AI use where the client would care | Address it in your terms or engagement letter |
| Insurance | Professional indemnity cover questions about AI use | Tell your insurer how you use it; check the policy wording |
Managing it
- Write the input rule: which tools, which data, under what terms, with client confidentiality respected.
- Never deliver unreviewed output to a client or the public; make review a step in the process, not a habit.
- Verify facts, figures and citations specifically, because fabrication is confident and plausible.
- Record human authorship for material where rights matter: the brief, the selection, the edits.
- Read the three vendor clauses before signing and record what they say.
- Address AI in your client terms where clients would reasonably want to know.
- Tell your insurer how AI is used in your delivery and check the policy.
- Keep decisions about people human, with criteria and explanations.
- Review annually, because both the law and vendor terms are moving.
What contracts should say
With your vendor: no training on your data, retention limited and stated, processing locations known, sub-processors listed, indemnity for output-related third-party claims where available, liability limited but not illusory, and full export on exit. With your client: how you use AI in delivery if they would care, that you remain responsible for the work, and any confidentiality arrangement that constrains which tools you may use on their material. Both conversations are easier before an incident than after one.
What this means for you
AI brings three legal exposures: rights in inputs and outputs, responsibility for what is delivered, and the contractual allocation of both. You remain responsible to your customers whatever produced the work, so verification before delivery is a liability control. Keep client material in approved tools, record human authorship where rights matter, read the training, indemnity and liability clauses, address AI in client terms, and tell your insurer. This is general information rather than legal advice.
Frequently asked questions
If an AI tool produces something wrong and we send it to a client, who is liable?
You are, to your client, under your own contract and professional obligations. Vendor terms typically disclaim liability for outputs and place responsibility on you to review, so the chain does not protect you. That is why review before anything leaves the business is not a quality preference but a liability control, and why professional indemnity insurers increasingly ask how AI is used in your delivery.
Can we copyright what AI produces for us?
It depends on the jurisdiction and on how much human creative input shaped the result. Purely machine-generated output may attract little or no copyright protection in several jurisdictions, meaning you may not be able to prevent others using something similar. Where a person substantially selected, arranged and edited the result, protection is more likely. For material central to your brand, assume you need meaningful human authorship and keep a record of it.
What should we check in an AI vendor's contract?
Three things above all. Whether they may train on or retain your inputs and outputs, and for how long. Whether they offer any indemnity for third-party intellectual property claims arising from outputs, and what conditions attach. And how liability is limited, which is usually to a small multiple of fees. Then the ordinary terms: processing agreement, locations, sub-processors, uptime, exit and data export.
Sources
- EUIPO: Intellectual property and artificial intelligence (accessed 2026-09-12)
- European Commission: AI Act (accessed 2026-09-12)