AI Vendor Due Diligence: What Companies Should Check Before Signing the Contract
September 4, 2026 / Irina Bustan
For companies deploying artificial intelligence solutions, we recommend that the legal review should not begin only once an incident occurs. In practice, a significant part of the risk can be identified as early as the vendor selection and contracting stage.
One point needs to be clear from the outset: an AI solution is not an ordinary piece of software. Depending on how it is used, it may process substantial volumes of data, generate outputs on which the company bases its decisions, or become an integral part of an operational process. For this reason, the contract with the vendor must be assessed against the specific risk that use of the solution creates for the company.
From the perspective of a vendor due diligence exercise, there are several areas that deserve particular attention.
1. What does the system actually do, and what data reaches the vendor?
The first question is an operational one: how will the AI solution be used?
To a large extent, this question determines the legal analysis that follows. A tool used for low-risk internal activities raises different issues from a system whose outputs are used in dealings with customers, employees or patients.
Equally important is what data is fed into the system. It is not enough for the vendor to state that the data is "anonymised" or that it is not used for any other purpose. What must be assessed is whether the nature of the information transmitted in fact allows an individual to be identified, and what happens to that information afterwards.
In a recent review of AI solutions, this distinction proved relevant including in the case of medical datasets. The sensitive nature of that information, and the possibility of correlating it, fundamentally changed the legal analysis.
2. Who is liable for the outputs generated by the AI?
A frequent issue in vendor contracts is the gap between the performance promised commercially and the legal liability actually assumed under the contract.
The vendor may present certain levels of accuracy, availability or performance, but these do not, in themselves, answer the question that matters most to the customer: what happens when the system produces an erroneous result?
The risk becomes all the more significant where the company uses the AI output in a process with material impact. A contractual limitation of liability that may be reasonable for a low-impact software tool can become problematic where an error in the system may cause substantial loss to the company or to third parties.
The liability cap must therefore be assessed against the risk generated by use of the solution.
3. Who controls the data, and what can the vendor do with it?
Another sensitive area is the use of the customer's data to develop or improve the product delivered by the vendor.
From the company's perspective, it is important to draw a clear line between data processed in order to provide the service and any secondary uses of that data.
The issue is all the more relevant where the vendor uses the customer's data to train models or to develop products that will subsequently be offered to other clients.
In this context, contractual wording that appears purely technical may have significant commercial consequences for the company's control over its own data and for the ways in which that data may be reused.
4. Is the vendor the only relevant supplier?
Not always.
The AI solution may depend on components supplied by third parties. From the customer's perspective, however, these relationships should not drop out of the legal analysis simply because there is no direct contract with each of those suppliers.
The SLA, third-party dependencies and the company's rights in such situations must therefore be addressed separately.
5. How does the company exit the relationship with the vendor?
One of the aspects that tends to be considered too late is termination of the contractual relationship.
At the time of signing, changing vendors is rarely contemplated. Once the solution has been integrated into the company's processes — even after the testing period has been completed — the picture can change.
What happens to the company's data? May the vendor retain it? Are there deletion or return obligations? How easily can the solution be migrated to another vendor? What happens if the vendor itself discontinues the service?
These are matters of contractual risk allocation and should be assessed before implementation.
***
Effective AI vendor due diligence is not merely a matter of verifying the vendor's compliance status or the existence of a GDPR agreement.
The analysis must start from the specific way in which the company intends to use the solution and track the key risks across the entire contractual relationship: data, performance, liability, security, third-party dependencies, service continuity and exit.
Particularly in the case of AI solutions embedded in processes that matter to the company, these aspects should not be left to the vendor's standard documentation.
The contract is, ultimately, the instrument through which the company can determine the extent to which the risks arising from the use of AI remain with the customer and the extent to which they are transferred to the vendor.
And that allocation is worth negotiating before the solution becomes indispensable to the business.
If you are considering acquiring an AI solution, or have already implemented one without a prior contractual assessment, our team can assist you in identifying the risks and in negotiating or renegotiating contracts with AI solution vendors.
(Photo by Dylan Gillis on Unsplash)



