Last week a client contacted me with a question about the AI contract they had just signed with a provider to automate part of their customer support.

They had already signed when someone on the team asked: “Does this comply with the AI Act?” Nobody knew — because nobody had checked before signing.

This happens constantly. Using AI in your company is not just about accepting terms and conditions before you start working. If your organisation uses ChatGPT, Copilot or another AI tool, under the AI Act you are probably a deployer.

The problem is not only whether the provider complies with the AI Act. The problem is whether your company can demonstrate that compliance when a client, an auditor or an authority asks for it. That is why these are the clauses you should review in the AI contract before you sign.

Diagram: the company signs a SaaS contract with an AI provider; that contract shapes AI Act, GDPR, logs, DPA and liability.
The SaaS contract is the link between your company, the AI provider and your AI Act, GDPR, logs, DPA and liability duties.

Why your Artificial Intelligence provider contract is key to AI Act compliance

Many companies assume that if they use tools such as ChatGPT, Microsoft Copilot or Gemini, all AI Act responsibility sits with OpenAI, Microsoft or Google. That is not exactly right.

When your company uses an AI tool to speed up internal processes or to work with employees or customers, you also take on certain responsibilities.

AI providers must meet a set of legal and technical requirements, such as documenting the system or assessing risk. The company that uses the tool also has its own duties. In the AI Act, that company is called a deployer.

What does that mean? Paying for an AI tool and starting to use it is not enough. You also need to make sure you can use it safely, transparently and in line with the rules — and that is where the AI contract you sign with the provider matters.

Many of the obligations you must meet in the EU depend directly on what that provider allows you to do.

For example, if you cannot access the logs, you cannot demonstrate human oversight. If the provider does not give you a clear data-processing addendum, you cannot evidence your own GDPR compliance alongside the AI Act.

And if these points are not properly regulated in the contract, it can be much harder to show that your company acted with the diligence the rules require.

That is why reviewing the contract before you roll out an AI solution is not a formality. It is one of the best ways to reduce legal risk and start using AI with more confidence.

Before you sign: four questions to ask any AI provider

If you do not have time to read the whole contract, start with these four questions. The answers will tell you a lot about the provider’s transparency and commitment.

How do you protect the data we put into the tool?

Ask whether they have a Data Processing Agreement (DPA) and whether it includes specific conditions for AI use, not only the usual data-protection clauses.

Can we access information about how the tool has been used?

It is important to know whether the company can consult or export usage records (logs). That can be essential to investigate incidents or to show that there is adequate control over AI use.

What human oversight mechanisms does the tool offer?

AI should not take important decisions without human involvement. Ask how the provider lets you review, validate or correct outputs generated by the system.

What happens to our data when the system is updated or improved?

Make sure you understand whether the information you enter may be used to train or improve AI models, and what options the provider offers to limit that use.

If the answers are unclear, or if the provider avoids the question, gives vague explanations or simply points to hard-to-read general terms, that is a signal to pause and review the contract in more detail.

In many cases, the biggest risks are not in the AI tool itself, but in the conditions we accept without reading.

Clauses you should review before buying an AI tool

When a company buys an AI tool, it usually focuses on price, features or ease of use. The contract, however, can be the difference between working with peace of mind and taking on unnecessary risk.

These are some of the clauses Legal Stones recommends reviewing before you sign.

How will the provider treat your data, and can it use them to train the AI?

It is not enough for the provider to say it complies with the GDPR. You should also ask:

  • Will they use the information you enter to train or improve their AI?
  • Where is that data stored?
  • Who can access it?
  • Can you ask for it not to be used to train the model?

Every provider has a different policy: some use user information to train or improve models by default; others let you turn that option off.

Those options should appear clearly in the contract or in a specific agreement on AI use.

Will you be able to review or correct AI decisions?

AI can help you work faster, but important decisions should not sit entirely with the algorithm.

Make sure the tool allows human oversight and that you can always review, correct or stop an AI-generated response or decision.

This is especially relevant for AI Act compliance if the tool is involved in processes such as recruitment, customer support or evaluating applications.

Will you have access to the usage history?

Imagine a client files a complaint or you need to find out why the application gave a particular answer. Will you be able to look that information up?

The contract should say whether you will have access to activity logs and for how long they will be available. Without that information it can be very hard to demonstrate how the tool was used.

Who is liable if the AI makes a mistake?

No AI system is perfect. So it is worth checking what happens if an incorrect answer, a system failure or unexpected behaviour causes a problem in your company.

Many providers limit their liability as far as possible. Before you sign, make sure you understand which risks you take on and which the provider takes on.

What if the provider stops complying with the law?

AI regulation will keep evolving. If the provider stops meeting its legal duties, your company should be able to end the contract without penalties.

It is a simple clause, but a very useful one for future protection.

Does the provider clearly tell you that you are using an AI system?

The AI Act requires transparency toward the end user when they interact with an AI system — for example a customer-support chatbot. Check that the provider gives you that information and the known limitations of the system, so you can pass them on to your own clients or employees if needed.

If you already signed the contract

Do not worry.

Most companies already use AI tools without having reviewed these points. That does not mean it is too late.

In many cases you do not need to rewrite the whole contract. It is enough to review the current terms, identify the highest-risk points and negotiate an addendum or a contract amendment that clarifies them.

It is often much simpler than it seems, and it can prevent serious problems later.

Not sure whether your AI provider contract protects you enough? At Legal Stones we review AI tool contracts to spot risks before they become a problem.

Checklist: what should you review before signing an AI contract?

Before you buy or renew an artificial intelligence tool, make sure the contract clearly answers these questions:

  • There is a specific agreement on data processing and AI use.
  • You can oversee and, when needed, intervene in the system’s decisions.
  • You have access to the information needed to review how the tool works (logs or activity records).
  • The contract sets out who is liable if the AI causes an error or harm.
  • You can end the contract if the provider stops complying with applicable law.
  • You know exactly what happens to the data you enter into the tool and whether it may be used to train or improve AI models.

FAQ on AI contracts and SaaS

What is a SaaS contract?

A SaaS (Software as a Service) contract is the agreement you sign with the provider of a cloud tool: ChatGPT Enterprise, Microsoft Copilot, Gemini or another AI platform. You do not buy the software; you buy a service with terms on use, data, availability and liability. In an AI contract, those clauses determine what you can demonstrate to a client, an auditor or an authority. Before you sign, review the DPA, logs, model training and liability limits. At Legal Stones we review that contract in plain language so you know what to negotiate.

What is a deployer under the AI Act?

Under the AI Act (Regulation EU 2024/1689), the deployer is whoever uses an AI system under their own authority: your company, if you use ChatGPT, Copilot or a chatbot with clients or employees. It is not enough for the provider to say it complies; you also have duties (transparency, human oversight, traceability). The provider contract conditions whether you can meet them in practice. If your deployer role is unclear, an AI Act Quick Check or a contract review can orient you without jargon.

Is it mandatory to review the ChatGPT Enterprise contract?

There is no rule that says “you must review ChatGPT Enterprise before signing”, but there are diligence duties: GDPR, the AI Act and, in many sectors, what clients or audits require. Signing unread is the usual risk. Reviewing the AI contract is not bureaucracy: it is checking whether you can access logs, limit training use of data and know who is liable if the AI fails. At Legal Stones we do that preventive review for SMEs and teams that want to use AI with confidence — and get clarity before the first claim arrives.

What are logs?

Logs are the tool’s usage history: who asked what, when, and what the system answered. Without access to those records it is very hard to investigate an incident, demonstrate human oversight or evidence compliance to an auditor. The contract should say whether you can consult or export logs and for how long they are kept. If the provider is unclear, that is a red flag. We can help you find that clause and negotiate an addendum if you already signed.

Can the provider use my data to train the AI?

It depends on the contract and the plan settings. Some providers use usage data by default to improve models; others (especially on enterprise plans) let you turn that off. Check it in writing: which data are used, where they are stored, who can access them and whether you can object. Mixing client or employee data into a model without control can clash with the GDPR and with what you promise your own clients. At Legal Stones we review those training clauses and tell you what to ask before you sign or renew.

What is a DPA?

A DPA (Data Processing Agreement) is the document that regulates how the provider processes personal data on behalf of your company. With AI, a generic DPA is not enough: it should cover prompts, model outputs, sub-processors, international transfers and training use. Without an adequate DPA it is hard to demonstrate GDPR compliance when you use ChatGPT, Copilot or Gemini with real data. If you want us to review the DPA and the rest of your provider’s AI contract, write to hello@legalstones.com — no obligation.

One last tip

You do not need to wait for a problem before reviewing a contract.

In fact, the best time is before you sign, when you can still negotiate terms and reduce risk without complications.

If you already use tools such as ChatGPT, Microsoft Copilot, Gemini or any other AI solution in your company, it is worth spending a few minutes checking whether the contract really protects your interests.

A small review in time often prevents far more costly problems later.

Need to review a provider’s AI contract? At Legal Stones we help companies analyse AI tool contracts, identify risks and check whether the terms align with the AI Act and data-protection rules.

Because bringing AI into a company is not only about choosing the right tool. It is also about making sure the contract protects you from day one.