top of page

ACG Strategic Insights

Strategic Intelligence That Drives Results

About the Author

Jerry Justice is Founder and CEO of Aspirations Consulting Group, bringing three decades of global entrepreneurial and corporate executive experience to ACG's consulting work with organizations across five industries facing growth, transition, and operational change. Through ACG Strategic Insights™, he reaches more than 10 million executives and aspiring leaders worldwide each weekday. He writes and speaks internationally on leadership, business strategy, and organizational performance, guided by his personal philosophy, Living to Serve, Serving to Lead™.

AI Is Moving Fast — Your AI Contracts Aren't

  • Writer: Jerry Justice
    Jerry Justice
  • Jul 30
  • 7 min read
Stacked enterprise software contracts beside a laptop displaying generative AI output and governance metrics.
The software changed. The paper next to it didn't get the memo.

Your legal team read every line of that enterprise software agreement two years ago. They just haven't read what it turned into.


The AI didn't arrive through a separate procurement process or a carefully planned pilot. It showed up inside routine software updates, new licensing tiers, and product enhancements that promise more output for less effort. The same platforms your organization signed for now routinely generate written content, produce software code, analyze proprietary business information, create images and presentations, recommend strategic decisions, and process sensitive customer data through embedded AI models.


None of that required a new signature. That's precisely the exposure. A feature rollout doesn't trigger a contract review the way a new vendor relationship does. It should.


The Software You Signed For Isn't the Software You Have


Microsoft has spent 2026 bundling Copilot capabilities directly into existing licenses. Basic AI features now ship inside Dynamics 365 app licenses at no additional cost, and a standalone SKU that used to require its own procurement review has been retired and folded into the broader Microsoft 365 suite, per a recent Dynamics 365 Copilot licensing update. Adobe followed a similar path, embedding its Firefly AI Assistant across Creative Cloud and extending it into external platforms your teams may already be using for content and design work, per recent reporting on the rollout.


Master service agreements written before 2024 often granted vendors permission to use aggregated customer interactions to enhance service quality. In an earlier environment, that language covered basic bug fixes and usage analytics. Today, the same clause is doing very different work. Vendors increasingly rely on it to justify training proprietary models on your organization's information, without renegotiating a single term.


What Your Legacy Agreements Never Anticipated


An analysis by Stanford Law School's CodeX center, published in Navigating AI Vendor Contracts and the Future of Law: A Guide for Legal Tech Innovators (2025), found that ninety-two percent of AI contracts claim data usage rights well beyond what's needed to deliver the service. Only seventeen percent commit to full regulatory compliance. And just thirty-three percent offer indemnification against third-party IP claims, compared to fifty-eight percent across the broader SaaS market.


Several specific provisions deserve renewed attention across the agreements already sitting in your repository:


  • Intellectual property ownership over AI-generated content

  • Rights the vendor retains to use your data for model training or improvement

  • Data retention practices tied to prompts and generated output

  • Confidentiality obligations covering everything an employee types into the tool

  • Indemnification language addressing copyright and infringement claims

  • Liability limitations written before AI-generated content became routine


Most modern platform addendums explicitly exclude indemnification for claims arising from AI-generated output, even where the base agreement once protected you against third-party patent infringement. Even where a vendor does agree to indemnify, protection is frequently capped at a single year of fees paid under the contract. For a platform costing a mid-market company a few hundred thousand dollars annually, that ceiling bears no relationship to what an actual infringement claim, regulatory fine, or data exposure event could cost.


Who Owns What AI Creates


Suppose your marketing team generates a campaign using embedded AI. Engineering writes code through an AI assistant. Human resources builds training material with AI support. A research group drafts product concepts the same way. In each case, ownership of the resulting work depends entirely on the specific vendor agreement governing that tool, and the answer differs more often than most executives assume.


Under standard intellectual property law, machine-generated content lacks clear copyright protection without deliberate human authorship. Some vendor agreements define customer ownership broadly. Others reserve rights around model improvement, aggregated data, or specific categories of generated content. If your contract doesn't state plainly that all system outputs belong exclusively to your organization, a piece of your core intellectual property may be sitting in legal uncertainty right now.


Three Places the Exposure Hides


Modern software architecture creates three distinct categories of contract risk that rarely show up on a standard review checklist:


Data leakage through extended supply chains. Enterprise vendors regularly rely on third-party model providers to power specific features. Your primary contract may include strict confidentiality terms, but a secondary data-processing addendum can permit that vendor to pass information to sub-processors operating under an entirely different privacy framework.


Uncapped liability from automated decisions. The liability cap covered above assumes a single, identifiable failure. An autonomous agent handling supply chain routing, pricing, or customer communications can compound a bad decision across thousands of transactions before anyone notices, generating losses in a single day that dwarf the value of the software contract.


Shadow deployment across departments. Marketing turns on automated copy generation. Finance enables automated reconciliation. Engineering activates code completion tools. Each activation quietly triggers online terms that bind the entire organization to data rights and liability provisions nobody in legal ever reviewed.


The Legacy Contract Blind Spot


Ask most CFOs and general counsels which of their AI contracts actually reflect what the platform does today, and you'll get a guess, not an answer. IntelAgree's 2026 CLM Trends Report found that sixty-two percent of contract and legal teams cite unknown risks hidden in older agreements as a top concern heading into this year. That number holds even though speed still dominates the industry's stated priorities, with eighty-one percent of teams ranking faster contract review and approval as their top objective and seventy-one percent citing shorter turnaround timelines as their biggest challenge. Legacy risk is competing for attention against the metric every legal department is already measured on, and it's still landing on nearly two out of three lists.


"The pressure on contract teams has fundamentally changed," said David Hull, chief executive of IntelAgree, in the release accompanying the report. Executives increasingly treat contracts as strategic assets tied to forecasting and revenue rather than filed paperwork, and agreements sitting in a shared drive from three years ago were never built to carry that weight.


Richard Susskind has made a related argument. Speaking at a legal technology debate hosted by Amsterdam University of Applied Sciences in 2025, recounted in the university's recap of the debate, Susskind argued that AI's real value in managing legal risk lies less in accelerating old habits and more in preventing problems before they start. That distinction, between reacting to risk and designing it out, is exactly what most legacy contracts fail to do.


I've watched executive teams treat an AI feature update as a technical rollout, right up until the day it becomes a legal event instead, and by then the exposure has already been running for months.


The Cost of Waiting Keeps Rising


Contract reviews rarely produce a visible return. Sales initiatives do. Product launches do. Market expansion does. Leadership naturally gravitates toward investments with an obvious payoff, and risk management earns its value by preventing losses that never become public, which makes that value difficult to measure until something fails.


AI changes that math. Product development now moves fast enough that a single software agreement may govern capabilities introduced every few months instead of every few years. Organizations no longer have the luxury of assuming contractual language will stay aligned with the technology it covers across a multi-year licensing cycle. Time itself has become part of the risk.


A Systematic Review Beats a Reactive One


Waiting for a breach, a lawsuit, or a board question to trigger a review of your AI contracts is the expensive way to find out what changed. The disciplined move is a proactive audit run jointly by legal, finance, operations, and information security, since no single function holds enough of the picture to run this alone.


That review should answer a short list of specific questions:


  • Which platforms introduced AI capabilities after the original contract was signed?

  • What proprietary information enters those systems each day, and does the contract's data usage language actually cover it?

  • Where does liability sit if AI-generated output infringes a third party's intellectual property?

  • Have acceptable-use policies kept pace with how employees are actually using these tools?

  • Do insurance policies and customer commitments still align with the organization's current AI risk profile?


A handful of organizations are already building this review into quarterly vendor governance rather than treating it as a one-off legal exercise, and the difference shows up the first time a vendor's underlying model changes without warning. The regulatory layer sitting on top of all this makes the timing worse, not better. State-level AI statutes are already in force in multiple jurisdictions, and the European Union's AI Act continues rolling out obligations that reach companies with no physical presence in Europe but customers or data that do.


Governance Needs AI Contracts, Not Just Policy


Many executives believe an acceptable-use policy amounts to an AI governance program. Policies matter, but contracts matter more. A policy defines how employees should behave. A contract defines the legal framework governing the technology itself. When the two conflict, leadership inherits exposure it never intended to accept, and no employee training session can fix a liability clause written for a different product.


Leadership Cannot Delegate This


Boards ask about artificial intelligence now. So do investors, customers, and regulators, and the questions rarely stop at the technology itself. They examine governance, oversight, and accountability. Legal counsel provides advice. Technology teams deploy the tools. Procurement negotiates commercial terms. None of that changes who owns the enterprise-wide consequences of the decisions built on top of an outdated contract.


"An ounce of prevention is worth a pound of cure," wrote Benjamin Franklin in an anonymous 1735 essay, Protection of Towns from Fire, published in his own Pennsylvania Gazette to urge Philadelphia residents to prepare for fires before they started rather than fight them afterward. The essay helped inspire the volunteer fire brigade the city organized the following year. Prevention has outperformed remediation for nearly three centuries, and the software governing your enterprise has done nothing to change that math.


The information in this post reflects general legal and business principles related to AI vendor agreements and enterprise contract risk and is intended for executive awareness and strategic planning purposes only. It does not constitute legal advice. Consult qualified technology or contracts counsel before reviewing, negotiating, or relying on any specific vendor agreement.


When Leadership Needs Broader Perspective


Growth, performance pressure, acquisitions, changing technology, and shifting market expectations rarely arrive one at a time. They intersect. That is where Aspirations Consulting Group works alongside mid-market and Fortune 1000 executives. When strategy, operations, leadership, and financial performance begin pulling against one another, an independent perspective can help leadership regain clarity before complexity becomes cost. If your organization has reached that point, I invite you to begin a confidential conversation at https://www.aspirations-group.com.


Continue Thinking Ahead


Today's blog is one of five published each week to a global readership of current and aspiring executives working through exactly this kind of overlooked risk. If you'd like ACG Strategic Insights delivered directly, request a complimentary subscription at https://www.aspirations-group.com/subscription.


Thanks for reading!


~ Jerry Justice

Living to Serve, Serving to Lead™

Comments


ACG Diagnostic Series™

Know exactly where you stand.

 

Two suites. Four instruments. Rigorous assessments of your leadership and financial judgment — built for serious leaders.

 

Leadership Suite
 

ACG Leadership Diagnostic™ 
ACG Leadership Assessment™ 

Financial Edge Suite
 

ACG Financial Edge Diagnostic™ 
ACG Financial Edge Assessment™

©2026 ASPIRATIONS CONSULTING GROUP, LLC™.  ALL RIGHTS RESERVED.

bottom of page