As artificial intelligence becomes increasingly embedded in development services, outsourcing arrangements, and other commercial and technology transactions, customers and vendors are confronting a deceptively simple question: who should bear the risk when something goes wrong with a deliverable created using AI?
The question is particularly important where a vendor is not merely providing access to an AI tool but using AI to perform contracted services or create work product such as software code, reports, analyses, designs, recommendations, or other deliverables (AI Deliverables).
Traditional services agreements generally assume that the vendor stands behind its work product. AI complicates this assumption as AI Deliverables may incorporate probabilistic outputs, depend heavily on customer-provided inputs, and require customer judgment before deployment or use.
The Customer and Vendor Perspectives
Customers often approach a transaction operating under a common assumption: if a vendor agrees to produce a deliverable, the vendor should remain responsible for it regardless of the tools used for its creation. The vendor chose to use AI, selected the applicable models, and is best positioned to test and validate the output.
Consider a vendor engaged to build a software module using AI-assisted coding tools. If the AI introduces a security vulnerability, a customer will typically argue that this is no different from a human developer's coding error: the vendor should remain liable under the agreement's standard warranty terms regardless of delivery methodology.
Vendors see it differently. AI outputs can be probabilistic, may contain inaccuracies, and can be shaped substantially by the customer's own inputs and how the output is used. A vendor delivering an AI-generated market analysis or financial model, for example, may resist liability if the customer supplied flawed underlying data or acted on the analysis without the human review required by the statement of work.
Vendors also raise the economics: open-ended liability for an AI-generated error can be difficult to reconcile with the fees charged for the service, particularly where damages surface well after delivery.
An Emerging Framework: Allocate Risk to the Party in Control
The market has not settled on a single approach. Broad output disclaimers paired with customer responsibility for use remain common for standardized AI products, but that model is under growing pressure wherever AI is embedded in contracted services or performs consequential business functions.
Sophisticated customers increasingly seek performance commitments, testing obligations, measurable accuracy standards, defined human-oversight checkpoints, and meaningful remedies for deficient AI Deliverables, while vendors avoid guaranteeing particular outcomes and seek carveouts for customer inputs, modifications, and misuse.
The most workable middle ground draws a line between two categories of risk: the risk inherent in producing the AI Deliverable and the risk arising from how the customer subsequently uses it.
Under this approach, the vendor remains responsible for producing a deliverable that satisfies the contract's requirements: compliance with specifications and acceptance criteria, use of approved AI tools and models, appropriate testing and validation, adherence to any agreed AI governance requirements, and IP protections for the vendor-selected tools and materials. A vendor should not avoid these obligations simply because it used AI rather than personnel.
The customer, correspondingly, bears responsibility for risks within its own control: the data and instructions it supplies, post-delivery modifications, use outside the agreed purpose or documentation, and decisions made in reliance on the deliverable where the parties agreed to additional customer review.
Returning to the earlier examples: on the coding deliverable, the vendor remains liable for a vulnerability present in the code as delivered and tested, but the customer bears the risk if it deploys that code into an untested environment or modifies it without revalidation. On the financial model, the vendor is responsible for building it to specification, but the customer bears the risk of decisions made on flawed inputs it supplied or made without the required sign-off.
Building This Into the Liability Framework
This allocation works best when reflected directly in the liability provisions, not left to a general disclaimer. Ordinary defects in an AI Deliverable can remain subject to the agreement's general liability cap, with correction or reperformance as the first remedy. Separate or higher caps can apply to specific risks—such as IP infringement, confidentiality, data protection, or regulatory violations—consistent with how the parties allocate those risks elsewhere in the agreement.
Corresponding exclusions should apply where a claim results from customer-supplied inputs, unauthorized modifications, use outside the documented purpose, or a customer's failure to perform an agreed safeguard (such as required human review before a deliverable is acted upon).
AI may be novel, but the underlying principle is not: risk should sit with the party best positioned to understand, control, and mitigate it. A blanket vendor disclaimer can leave a customer holding risk created by a delivery methodology it never controlled. Conversely, making a vendor responsible for every downstream consequence of a deliverable effectively turns the vendor into an insurer of decisions it cannot control.
The more durable approach is to define the intended use of the AI Deliverable upfront, spell out each party's expected safeguards, and allocate liability based on who controlled the conduct that caused the loss.
How We Can Help
Morgan Lewis's technology transactions, outsourcing, and commercial contracts lawyers regularly advise customers and vendors on negotiating technology, outsourcing, development services, and other commercial agreements involving AI, including the allocation of risk and liability for AI-generated and AI-assisted deliverables.
If you have questions on structuring a balanced approach to AI-related liability or other issues arising from the use of AI in commercial and technology transactions, please reach out to any member of our team.