By the time an AI tool reaches legal review, the commercial story may already be half-written.
The supplier has been shortlisted. The demo went well. The business likes the price. Procurement wants to keep things moving. Then legal gets the agreement and sees the familiar shape of a software licence.
But AI procurement brings questions that can sit quietly inside ordinary-looking contract terms. How does the system learn? What data will train it? Who can use the output? What happens if the tool produces a result that is wrong, biased, or hard to explain?
For a legal team, those questions can make the difference between a contract that looks fine at signing, and one that becomes difficult once the AI solution is embedded.
What should lawyers ask before an AI licence is signed?
Start with the supplier and the way the tool will be deployed.
A customer may need to understand whether the supplier has the technical capability, financial stability, and security infrastructure to support the proposed use. The licensing model also matters. An on-premise solution trained on customer data raises different issues from a cloud-based SaaS tool using a shared data environment.
Proof-of-concept testing can help, but it should feed into the contract. If the test exposes limits in accuracy, support, implementation, or explainability, those points should not disappear once the main agreement is drafted.
How should contracts deal with training data and AI output?
Training data is often where the harder questions begin.
If customer data helps train or improve the AI solution, the agreement should deal with access, confidentiality, retention, permitted use, and ownership of any related developments. If personal data is involved, Hong Kong PDPO issues may also need to be considered.
Output needs the same level of attention. The contract should address who owns or can use output data, analytics, decisions, reports, and any improvements created through the use of the system.
AI-generated works can also raise IP questions, especially where human authorship is unclear. In some cases, confidentiality may become an important protection alongside IP drafting.
Who carries the risk if the AI behaves unexpectedly?
AI systems can produce inaccurate, biased, or difficult-to-explain results. That makes acceptance testing, warranties, audit rights, support obligations, and liability allocation harder to treat as boilerplate.
Legal teams may need to ask who is best placed to monitor the system, investigate issues, pause use, correct errors, and deal with third-party claims. Circuit breakers, record-keeping, and auditability can matter where the AI is used in a business process that needs explanation or oversight.
Why does exit planning matter in AI procurement?
AI tools can become sticky.
Once the solution is trained, connected to business processes, and used by teams, moving away from the supplier may become complicated. The agreement may need to cover continuing licence rights, extraction of original data, use of output, confidentiality after termination, escrow, governance review, and support for moving to another provider.
These points are easier to negotiate before the customer becomes dependent on the tool.
The complimentary download, Checklist for AI procurement licensing and contractual issues, produced in partnership with Albert Wan of Denis Chang’s Chambers, gives legal teams a practical way to pressure-test these issues before the agreement is settled.
Complete the form below to download the full checklist.
Note: After completing the form, the whitepaper will appear on the same page. Please stay on the page after submission. If you do not see the whitepaper, contact us at marketing.hk@lexisnexis.com for assistance.

