Strategy · Risk

AI Clauses for Client Contracts: What to Add Before Your Next Project

Your NDA, your IP assignment and your accuracy warranty were all written for a world where a human did every hour billed — here is what to change, with sample wording

B Biztrategy Published 25 September 2026 · 8 min read
Close-up of hands holding a contract, focus on business agreement discussion.

Most small firms have already changed how they work. The contract they send clients has not. It was written for a world where a human did every hour billed, where "our personnel" meant people, and where confidential material never left the building unless someone emailed it. None of those assumptions hold once a language model is in your workflow.

This is not a reason to panic, and it is certainly not a reason to hide the fact that you use AI. It is a reason to spend an hour updating a document you already have. Below are the six clauses worth adding, what each one is actually protecting you from, and sample wording you can adapt. It is a starting point drafted for clarity, not legal advice — have your solicitor check anything you intend to sign.

Why your current contract is now ambiguous

Ambiguity in a contract is not neutral. It gets resolved later, under pressure, usually by whichever party has more appetite for a fight. Three specific gaps show up again and again in SMB and freelance agreements.

Confidentiality. Your NDA almost certainly permits disclosure to "employees, subcontractors and professional advisers". A model provider is none of those. If you paste a client's financial data into a chat window, you may be in technical breach of a clause you signed without ever thinking about it.

Ownership of deliverables. Standard wording assigns copyright in the work to the client on payment. In the UK, US and EU, purely machine-generated output attracts thin copyright protection at best. You may be promising to assign something you cannot fully own.

Warranties. Clauses promising work is "original", "accurate" or "free from third-party rights" were written assuming a human checked every line. If a model invents a citation or reproduces a phrase from its training data, that warranty is the hook liability hangs on.

None of these are hypothetical edge cases. They are ordinary clauses that quietly changed meaning when your tooling changed.

Clause 1: Permitted use of AI tools

Start by establishing that you use AI at all, and on what terms. This converts an awkward disclosure conversation into a routine contractual fact — which is the whole point.

The Supplier may use artificial intelligence and machine-learning tools to assist in producing the Deliverables. All output produced with such assistance is reviewed, edited and verified by the Supplier’s personnel before delivery. The Supplier remains fully responsible for the Deliverables regardless of the tools used to produce them.

That last sentence does the heavy lifting. Clients are rarely worried about the tool; they are worried that "the AI did it" becomes an excuse when something is wrong. Closing that door up front removes most of the objection. If you are weighing up how openly to raise this, our piece on whether you should tell clients you use AI covers the commercial side of that decision.

When a client wants a veto

Some clients — regulated firms, public sector bodies, anyone with their own AI policy — will want approval rights. Offer a tiered version rather than an outright ban: AI permitted for research, drafting and internal analysis; prior written consent required for anything client-identifiable going into a third-party system. That is a distinction they can approve without escalating.

Clause 2: Confidentiality and what may be entered into a model

This is the clause that matters most and the one most often missing. Extend your permitted-disclosure list explicitly, and attach conditions.

The Supplier may disclose Confidential Information to third-party AI service providers solely to the extent necessary to perform the Services, and only where the provider is contractually bound not to use such information to train its models and not to retain it beyond the period required for service delivery. The Supplier shall not enter personal data, credentials, or material marked “Restricted” into any such tool without the Client’s prior written consent.

Two practical points. First, the no-training condition is genuinely achievable: business and enterprise tiers of the major assistants exclude customer content from training by default, whereas consumer tiers historically have not. Check your own plan before you sign this — promising it while your team works on free accounts is worse than saying nothing.

Second, "material marked Restricted" only works if someone marks things. A one-page internal rule — client financials, personal data and credentials never go into a chat window — is enough. A written AI policy setting that out is a version you can adopt in an afternoon, alongside a check of the plan-level data settings on every tool your team uses.

Clause 3: Ownership and IP in AI-assisted work

Do not promise more than the law can give you. The workable approach is to assign what you hold and be candid about the rest.

The Supplier assigns to the Client all right, title and interest it holds in the Deliverables. The Client acknowledges that material generated with AI assistance may not attract copyright protection in all jurisdictions, and that the Supplier makes no warranty as to the enforceability of copyright in any such material against third parties.

For most work this changes nothing in practice: the client gets everything you have, and neither side was planning to litigate over a slide deck. It matters intensely for a narrow set of deliverables — logos, brand names, taglines, characters, anything that becomes a registrable asset. For those, the safer route is a process commitment rather than a warranty: agree that final marks are human-authored, and keep the drafting records to show it.

The training-data risk nobody mentions

Separately, consider a short carve-out on third-party rights. Models can reproduce material resembling their training data, particularly in code and imagery. A clause limiting your liability for infringement claims arising from AI-generated output that you delivered in good faith after reasonable checks is a fair ask. Several large model providers now offer their own copyright indemnities on paid tiers; where yours does, say so — it reassures clients considerably more than your own promise does.

Clause 4: Accuracy, review and the human check

A blanket warranty that all output is accurate is a warranty you will eventually break, with or without AI. Replace absolute promises with a described standard of care.

The Supplier warrants that Deliverables have been reviewed by suitably qualified personnel and are, to the best of the Supplier’s knowledge, accurate at the date of delivery. Where Deliverables include factual claims, statistics, citations or legal or financial references, the Supplier warrants that these have been verified against primary sources.

This is stronger than it looks, because it is a promise you can actually keep — and it converts the hallucination problem from a liability question into an operational one. It only works if you genuinely have a verification step; the practical mechanics are in our guide on preventing AI hallucinations in client work. Keep the evidence too. A dated note of which claims were checked and against what turns a difficult conversation into a short one.

Clause 5: Liability caps that reflect how you work now

Two adjustments are worth making. The first is arithmetic: AI has compressed the time many deliverables take, and if your liability cap is set at "fees paid under this agreement", a job that used to bill €12,000 and now bills €5,000 has quietly halved your ceiling while the exposure stayed identical. Reset the cap to a fixed sum, or to a multiple of fees, rather than letting efficiency erode your protection.

The second is scope. Add the usual exclusion of indirect and consequential loss, and consider carving out liability for the client's own use of AI-assisted deliverables beyond the agreed purpose — a research memo written for internal decision-making should not become your problem when someone publishes it as marketing copy.

Check your professional indemnity policy at the same time. Insurers are actively revising wordings around AI-assisted work, and a policy renewed two years ago may not say what you assume it says.

Clause 6: Subprocessors and data location

If you handle personal data on a client's behalf, you are a processor and any AI provider you route that data through is a subprocessor. That triggers real obligations under the GDPR: a named list, a route for the client to object, and a lawful basis for any transfer outside the EEA or UK.

The Supplier’s current subprocessors, including AI service providers, are listed at [URL / Schedule X]. The Supplier shall give the Client 30 days’ written notice before engaging a new subprocessor that will process Client personal data, during which the Client may object on reasonable grounds.

Maintaining that list is a ten-minute job: provider, what it processes, where it is hosted, the link to their data processing agreement. Keeping it current is the part people forget — every time someone on your team adopts a new tool, the list is out of date. Review it when you audit your stack, which is worth doing in one pass alongside a wider audit of your AI tool stack.

A one-hour plan to get this done

Realistically, nobody is rewriting a master services agreement this week. Do this instead, in order:

  1. Fifteen minutes: open your standard contract and read only the confidentiality, IP and warranty clauses. Note where each one assumes a human did the work.
  2. Twenty minutes: draft Clauses 1, 2 and 4 above into an "AI Use" addendum. Three clauses in a single-page annex is far easier to get signed than an amended main agreement.
  3. Ten minutes: list your AI subprocessors and check whether each plan excludes your data from training. Fix any that do not.
  4. Fifteen minutes: send the addendum to your solicitor for a sanity check, and to one friendly existing client for reaction. Their questions will tell you what to reword.

Then use it on the next new engagement rather than retrofitting every live contract. Existing clients can be brought across at renewal, which is a much easier conversation than reopening a signed agreement mid-project.

The bottom line

Contract wording is one of the cheapest risk controls available to a small business, and one of the few that improves your position with clients rather than just protecting you from them. A supplier who has already thought about where client data goes, who owns the output, and what happens if something is wrong looks markedly more competent than one who has not been asked yet.

The firms that get caught out over the next couple of years will not be the ones using AI. They will be the ones whose paperwork still claims they are not — and who find that out during a dispute. An hour with a document you already own is a very good trade.

If contract exposure is the first place AI risk has surfaced for you, it is unlikely to be the last. Working through how to create an AI strategy for a small business will surface the others while they are still cheap to fix.

Where does your business stand on AI?

Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.

Take the Free Quiz →