BLOG POST

Tech & Sourcing @ Morgan Lewis

TECHNOLOGY TRANSACTIONS, OUTSOURCING, AND COMMERCIAL CONTRACTS NEWS FOR LAWYERS AND SOURCING PROFESSIONALS

AI Deliverables and Liability: Considerations for Risk Allocation

As artificial intelligence (AI) becomes increasingly embedded in development services, outsourcing arrangements, and other commercial and technology transactions, customers and vendors are confronting a deceptively simple question: How should risk be allocated when a deliverable is created using AI?

The question is particularly relevant where a vendor is not merely providing access to an AI tool, but is using AI to perform contracted services or create work product such as software code, reports, analyses, designs, recommendations, or other deliverables (AI Deliverables).

Traditional services agreements generally assume that a vendor will stand behind its work product. The use of AI can add complexity to this baseline assumption because AI Deliverables may incorporate probabilistic outputs, depend on customer-provided inputs, and require customer review or judgment before deployment or use.

Common Customer and Vendor Perspectives

Customers may take the view that when a vendor agrees to produce a deliverable, the vendor should remain responsible for meeting the applicable contractual requirements regardless of the tools it used. From this perspective, if the vendor selected the relevant AI tools or models, it may appear the vendor is in the best position to test and validate the resulting output.

Consider a vendor engaged to build a software module using AI-assisted coding tools. If the AI introduces a security vulnerability, a customer may argue the issue should be treated similarly to a coding error made by a human developer and addressed under the agreement’s standard warranty terms and remedy provisions.

Vendors may take a different view and emphasize different considerations. AI outputs can be probabilistic, may contain inaccuracies, and may be influenced by customer-provided data, instructions, and use decisions. A vendor delivering an AI-generated market analysis or financial model, for example, may seek to limit its responsibility where the customer supplied inaccurate underlying data or relied on the analysis without completing review or other procedures required by the statement of work.

Vendors may also focus on the relationship between potential exposure and the economics of the engagement. Liability for errors that result in substantial or delayed downstream damages may exceed the fees associated with the relevant services, leading vendors to seek defined limitations, exclusions, or customer obligations.

Approaches to Allocating Risk

The market has not settled on a single approach. Broad output disclaimers combined with customer responsibility for use remain common for some standardized AI products, but different approaches may be implemented where AI is incorporated into customized services or is used to perform critical business functions.

Customers may seek performance commitments, testing obligations, measurable accuracy standards, defined human-oversight obligations, and remedies for AI Deliverables not meeting agreed-upon requirements. Vendors, on the other hand, may resist exclusions for issues resulting from customer inputs, modifications, or uses outside the agreed-upon scope.

One approach is to distinguish between risks associated with producing the AI Deliverable and risks associated with the customer’s use of the AI Deliverable. In this context, the vendor may be responsible for ensuring the deliverable satisfies the agreed-upon requirements. Depending on the transaction, these requirements could include compliance with specifications and acceptance criteria, use of approved AI tools and models, testing and validation procedures, compliance with applicable AI governance requirements, and intellectual property protections relating to the vendor-selected tools and materials.

Correspondingly, the customer may be responsible for matters within its control, including the accuracy and completeness of the data and instructions it provides, post-delivery modifications, use outside the agreed purpose or documentation, and decisions made in reliance on the deliverable without completing any agreed customer review.

Applying this framework to our earlier example, responsibility for a vulnerability in a software deliverable may depend on whether the vulnerability was present in the code as delivered, whether the vendor completed the agreed testing, and whether the customer subsequently modified the code or deployed it in an environment outside the agreed scope. The analysis may also take into consideration whether the model was built to specification, whether customer-supplied inputs were accurate, and whether required review or approval procedures were followed.

As outlined above, the appropriate approach should consider the type of deliverable, the significance of the decisions for which it will be used, and the parties’ respective access to relevant information and ability to test, monitor, or mitigate the associated risk.

Building Risk Allocation in a Liability Framework

Rather than relying solely on a general AI disclaimer, the intended allocation of risk can also be addressed in the agreement’s liability, warranty, indemnification, and remedy provisions. For example, defects in an AI Deliverable may be subject to the agreement’s general liability cap, with correction or reperformance serving as an initial remedy. The parties may also negotiate separate or higher caps for particular categories of risk, consistent with the treatment of those risks elsewhere in the agreement. The agreement may also identify circumstances in which liability is limited or excluded.

While the use of AI introduces new technical and operational considerations, many of the underlying contractual questions are familiar. Customers may be reluctant to assume risks associated with tools and development methods selected by the vendor. Vendors, in turn, may be unwilling to accept responsibility for downstream decisions, uses, or modifications outside their control.

Based on the applicable context of the deal, the resulting allocation of risk will vary, but defining the intended use of the AI Deliverable, identifying each party’s responsibilities and safeguards, and addressing foreseeable failure scenarios can help the parties determine how warranties, remedies, exclusions, indemnities, and liability caps should apply, and more clearly allocate risk and responsibility.

How We Can Help

Morgan Lewis’s technology transactions, outsourcing, and commercial contracts lawyers regularly advise customers and vendors on negotiating technology, outsourcing, development services, and other commercial agreements involving AI, including the allocation of risk and liability for AI-generated and AI-assisted deliverables.

For questions regarding AI-related liability or other issues arising from the use of AI in commercial and technology transactions, please reach out to any member of our team.