Blog Details
The latest news, updates and insights from our technology specialist lawyers at Law 365.
Beware! Your AI Tools Could Be Quietly Breaching Your Client Contracts
Contents
Businesses are racing to embed AI into everything. It’s efficient, it’s innovative, and for tech providers and MSPs, it’s increasingly non-negotiable. But here’s the uncomfortable truth: most businesses are deploying these tools without thinking about the legal and contractual landmines they’re stepping on.
The result? We’re seeing clients caught in breach scenarios they never saw coming.
The Sub-Processor Problem You Didn’t Know You Had
When you feed personal data into an AI tool, that tool provider often becomes a sub-processor under UK GDPR (a third-party processing data on your behalf). If they use cloud infrastructure like AWS or Azure to host their service, that’s potentially another sub-processor down the chain.
Under UK GDPR and most customer contracts, you need prior written authorisation from your customers before engaging any sub-processor. The contract with that sub-processor must also mirror the same data protection obligations you’ve committed to.
Now ask yourself: does your customer know you’re using Claude to draft their proposals? Have you checked where Anthropic’s servers are? Do you have a Data Processing Agreement (DPA) in place?
If the answer is no, you’re likely in breach of your customer contracts and potentially UK data protection law.
It gets murkier. If the AI provider is handling your own operational data (like payment processing or internal support tickets), they could also be a sub-contractor. The legal obligations are different, but most businesses don’t distinguish between the two, and contractual definitions matter enormously when a breach is alleged.
The Gap Between AI Provider Terms and Your Obligations
Here’s where it gets challenging. The terms of service from major AI providers (the likes of Anthropic, OpenAI, Microsoft, Google) are designed to protect them, not you. They can grant themselves broad rights to use your input data for model training. They often cap liability to nominal amounts. They may disclaim warranties about accuracy, fitness-for-purpose, and IP infringement.
Meanwhile, your contracts with customers likely commit you to: - Keeping their data confidential - Not sharing it with third parties without consent - Not transferring it outside the UK without authorisation - Indemnifying them for IP infringement - Maintaining strict cybersecurity standards.
The gap between these two positions is where the lawsuits live.
Real Breach Scenarios We’re Seeing
This isn’t theoretical. Clients are coming to us after they’ve triggered the following breaches:
Confidentiality violations: An employee pastes a confidential client document into an AI tool to summarise it. The tool’s terms state they may use inputs for training. You’ve breached your NDA. If the document was legally privileged, you’ve also waived legal professional privilege, and you can’t get that back.
Unlawful data processing and cross-border data transfers without consent: A marketing team uploads a customer email list to an AI platform to generate personalised campaigns. No DPA is in place, and your customer’s contract prohibits data leaving the UK. The AI provider’s servers are in the US, and they’re not certified under the UK-US Data Bridge. You’ve just committed a contractual breach, unlawful processing and an unauthorised international data transfer under UK GDPR (possibly without even knowing). The ICO can fine you up to £17.5 million or 4% of global turnover.
IP infringement: Your design team uses a generative AI tool to create a client logo. The AI generates something eerily similar to a copyrighted work. You’ve just exposed your client (and yourself) to copyright infringement claims.
The Bargaining Power Problem
So why not negotiate better terms with the AI providers? Because you can’t. Unless you’re a large multinational, FTSE-100 level company, you have virtually zero bargaining power with the likes of Anthropic, Microsoft, or Google. Their terms are take it or leave it.
For SMEs and even mid-sized tech providers, this is the reality: contract terms are one-sided, and you’re accepting all the downstream risk.
The Bottom Line
You cannot blindly bolt AI onto your operations without considering your pre-existing contractual obligations. The mismatch between what AI providers offer and what your customers expect creates legal exposure that many businesses are only discovering when it’s too late.
If you’re a tech provider, MSP, or service business using AI tools, you need to ask:
-
Do my customer contracts permit the use of AI and third-party sub-processors?
-
Have I mapped where data flows when I use these tools?
-
Am I exposing myself to data protection breaches, confidentiality violations, or IP infringement claims?
-
Do I have appropriate DPAs, risk assessments, and transfer mechanisms in place?
Key Takeaways
-
AI tools often become sub-processors under UK GDPR if you input personal data, and you need customer authorisation and data protection provisions in place.
-
Standard AI provider terms don’t align with your customer contract obligations, creating a dangerous gap in liability and data protection.
-
Real breaches are happening: confidential data leaks, unauthorised sub-processor use, unlawful cross-border transfers, and IP infringement risks are live issues.
-
You have little bargaining power with major AI providers, so due diligence, internal policies, and legal advice are your primary defences.
-
Don’t assume AI integration is legally neutral: it’s not. Every AI tool you deploy has contractual and regulatory implications.
Need help navigating AI contracts and compliance? Whether you’re reviewing your existing AI usage, negotiating supplier agreements, or need a gap analysis of your current obligations, Law 365 can guide you through the legal complexities.
Get in touch for tailored advice that protects your business.
What does NCE and CSP mean for your contracts?
We suggest the wording in your contracts is updated to reflect these new changes.
Could ‘best’ endeavours cost your business? | Legal Advice | Law 365
Entering into a mutually beneficially commercial contract with like-minded partners is a great goal to aim for during...
Mind the Cap! Protecting your business with general and super caps
Why should you cap your liability?