Legal risks of AI: copyright, liability and contracts

The legal exposures a business takes on when it uses AI: rights in inputs and outputs, responsibility, and the contract terms that allocate both.

4 minread 866words last updated

The short answer

Using AI in a business creates three legal exposures worth understanding. The first concerns rights: what you may put in, since client confidential material and third-party content carry obligations, and what you get out, since generated output may attract limited copyright protection and may in rare cases resemble protected material. The second concerns responsibility: you remain answerable to your customers and under your professional obligations for what you deliver, regardless of what produced the draft, and vendor terms are written to place that responsibility firmly on you. The third concerns contracts: the allocation of these risks is decided by clauses that go unread, principally whether the vendor may train on or retain your data, whether any indemnity is offered for third-party claims arising from outputs, and how liability is limited. None of this makes AI use unwise. It makes review before delivery a liability control rather than a quality preference, and it makes three clauses worth reading in every AI contract you sign.

The three exposures

ExposureWhat can go wrongControl
InputsClient confidential material or personal data disclosed to a provider without authority; third-party content used beyond its licenceApproved tools under business terms; minimisation; client consent where the engagement requires it
Outputs, rightsLimited or no copyright protection in some jurisdictions; rare resemblance to protected materialMeaningful human authorship and records; vendor indemnity where offered; review
Outputs, accuracyFabricated facts, citations or figures delivered to a clientVerification before delivery; professional review; no unreviewed output leaves the business
DecisionsAutomated decisions about people creating discrimination or data protection exposureHuman decision, documented criteria, explainability, outcome testing
Contract with the vendorTraining on your data; weak indemnity; low liability cap; data locked inRead the three clauses; negotiate where you can; keep assets portable
Contract with your clientSilence about AI use where the client would careAddress it in your terms or engagement letter
InsuranceProfessional indemnity cover questions about AI useTell your insurer how you use it; check the policy wording

Managing it

  1. Write the input rule: which tools, which data, under what terms, with client confidentiality respected.
  2. Never deliver unreviewed output to a client or the public; make review a step in the process, not a habit.
  3. Verify facts, figures and citations specifically, because fabrication is confident and plausible.
  4. Record human authorship for material where rights matter: the brief, the selection, the edits.
  5. Read the three vendor clauses before signing and record what they say.
  6. Address AI in your client terms where clients would reasonably want to know.
  7. Tell your insurer how AI is used in your delivery and check the policy.
  8. Keep decisions about people human, with criteria and explanations.
  9. Review annually, because both the law and vendor terms are moving.

What contracts should say

With your vendor: no training on your data, retention limited and stated, processing locations known, sub-processors listed, indemnity for output-related third-party claims where available, liability limited but not illusory, and full export on exit. With your client: how you use AI in delivery if they would care, that you remain responsible for the work, and any confidentiality arrangement that constrains which tools you may use on their material. Both conversations are easier before an incident than after one.

What this means for you

AI brings three legal exposures: rights in inputs and outputs, responsibility for what is delivered, and the contractual allocation of both. You remain responsible to your customers whatever produced the work, so verification before delivery is a liability control. Keep client material in approved tools, record human authorship where rights matter, read the training, indemnity and liability clauses, address AI in client terms, and tell your insurer. This is general information rather than legal advice.

Written by the CivSec S.M.A.R.T team

We build and run websites, software and AI systems for businesses. We write about what we see in that work, in plain language, and we update articles when things change.

Last checked . Spotted something outdated? Tell us.

Frequently asked questions

If an AI tool produces something wrong and we send it to a client, who is liable?

You are, to your client, under your own contract and professional obligations. Vendor terms typically disclaim liability for outputs and place responsibility on you to review, so the chain does not protect you. That is why review before anything leaves the business is not a quality preference but a liability control, and why professional indemnity insurers increasingly ask how AI is used in your delivery.

Can we copyright what AI produces for us?

It depends on the jurisdiction and on how much human creative input shaped the result. Purely machine-generated output may attract little or no copyright protection in several jurisdictions, meaning you may not be able to prevent others using something similar. Where a person substantially selected, arranged and edited the result, protection is more likely. For material central to your brand, assume you need meaningful human authorship and keep a record of it.

What should we check in an AI vendor's contract?

Three things above all. Whether they may train on or retain your inputs and outputs, and for how long. Whether they offer any indemnity for third-party intellectual property claims arising from outputs, and what conditions attach. And how liability is limited, which is usually to a small multiple of fees. Then the ordinary terms: processing agreement, locations, sub-processors, uptime, exit and data export.

Sources

  1. EUIPO: Intellectual property and artificial intelligence (accessed 2026-09-12)
  2. European Commission: AI Act (accessed 2026-09-12)