Skip to content
AI & legal work

AI clauses in client contracts: what you owe the client, and what the clause should say

Suppliers asking whether they must declare AI use are usually asking about etiquette. The enforceable problems sit elsewhere: a confidentiality clause that was breached the instant the client's document was pasted somewhere, and an originality warranty that machine-generated text cannot satisfy. Both are contract problems, both are fixable in advance, and the clause that fixes them is short.

7 min readPublished How we write these

The short version

  • There is no general legal duty to tell a client you used AI. The duty, where one exists, comes from your own contract — which is why the clause matters more than the etiquette.
  • Pasting a client's confidential document into a third-party tool is a disclosure to a third party. Most NDAs limit disclosure to a closed list of permitted recipients, and a vendor you signed up to online is not on it.
  • A warranty that the deliverable is your "original work" sits badly with machine-generated text: under US law a prompt does not make you the author, and an assignment cannot transfer what nobody owns.
  • A workable clause names four things — permitted uses, named tools and data handling, human review, and who carries the risk. Blanket bans get ignored rather than obeyed.

Three questions hide inside "do I have to tell them?"

Most people asking whether they must disclose AI use are asking one question and have three. Whether the contract permits the use at all. Whether the client's confidential material was allowed to leave your hands. And whether anything you warranted about the deliverable has now stopped being true. Disclosure duties, where they exist, mostly follow from the first two rather than standing on their own.

The order matters, because the confidentiality problem bites first and almost nobody drafts for it. It happens at the moment of the paste, before there is any output to disclose.

Putting the client's document into a tool is a disclosure

A standard NDA does not say "do not publish". It says the receiving party may disclose confidential information only to permitted recipients — usually employees, officers and professional advisers who need it for the stated purpose and are bound by obligations at least as protective as the agreement itself. That is a closed list. A model vendor whose terms you accepted through a sign-up page is not on it, and the drafter did not have one in mind.

You paste the client's draft into a general AI tool. Is that a disclosure?

Does the NDA permit it?

On the usual wording, no

Disclosure is limited to named categories of recipient bound by equivalent terms. A tool accepted under click-through terms is outside the list, and deleting the chat afterwards changes nothing.

Yes, if the list includes it

Permitted-recipient wording that covers service providers engaged under written confidentiality terms, plus an account tier where training is excluded, makes the same act unremarkable.

The breach, if there is one, is complete on transmission. Whether the vendor retains the text, trains on it or leaks it goes to damage, not to whether the disclosure happened.

The vendor terms are what you are actually relying on

Once the use is permitted, the question becomes whether the vendor is a reasonable place for the material to sit. Two things decide that, and they are separate: whether your content trains models, and how long it is kept.

Account tierTrained on your contentWhat to check
Consumer assistant, free or personal planOften yes unless you turn it offThe name of the setting, and whether it is per-account or per-conversation
Paid individual planVaries by vendorPaying does not automatically exclude training — the same setting usually still applies
Team, business or enterprise tierNo, under current published termsThe processing terms, the retention period and the list of sub-processors
API accessNo, under current published termsRetention for abuse monitoring, and whether zero retention is available to you
The defaults differ between the consumer and business tiers of the same product, and the setting lives in account preferences rather than in any contract.

Training exclusion is not retention exclusion, and the two get conflated. OpenAI, for example, publishes a default abuse-monitoring window of up to 30 days on API traffic, with zero retention available to eligible customers on request — so content that is never trained on is still held somewhere for a period. Record which tier you are on and under whose terms, because that is the fact a client will eventually ask you to state.

The warranty you have probably already given

Nearly every services agreement contains a version of this: the supplier warrants that the deliverables are its original work, that they infringe no third-party rights, and assigns all intellectual property in them to the client. Read that against a deliverable produced substantially by a model.

  • "Original work." US copyright requires human authorship. The Copyright Office's 2025 report on copyrightability concluded that entering a prompt — however long or careful — does not make you the author of the output. Your own expression, and your creative selection, arrangement and modification of machine output, remain protectable. The machine-generated expression itself is not.
  • The assignment. You cannot assign what nobody owns. Where the expressive content of a deliverable is uncopyrightable, the assignment clause moves an empty box, and anyone — including the client's competitor — is free to reproduce it. Clients who believed they were buying exclusivity rarely priced that in.
  • Non-infringement. A warranty that the deliverable infringes nothing is a statement about provenance you are in no position to verify, because you cannot see what the model drew on.

None of this makes AI-assisted work unsellable. It makes the standard warranty the wrong instrument. The workable version narrows the promise: that you reviewed and adopted the deliverable as your own work, that you have not knowingly reproduced third-party material, and that the client knows which components were machine-generated, so the assignment clause is not doing imaginary work. Who owns AI-generated content takes the ownership question further, and the IP assignment agreement shows the transfer wording this sits beside.

Where a disclosure duty genuinely exists

Very few suppliers have a statutory duty to announce AI use, and the general anxiety about it is mostly misplaced. The duties that do exist are narrow and worth knowing precisely.

  • Lawyers. ABA Formal Opinion 512, issued 29 July 2024, requires a client's informed consent before information relating to the representation is put into a self-learning tool, and says boilerplate in an engagement letter will not do. Disclosure is also required when the client asks and where AI use bears on the reasonableness of the fee. Uncritical reliance on output, the opinion says, is almost certainly malpractice.
  • Regulated occupations in Utah. The Utah Artificial Intelligence Policy Act, narrowed by amendment in 2025, requires disclosure on a clear request, and up-front disclosure in high-risk interactions — those involving sensitive personal data or personalised financial, legal or health advice a consumer could reasonably rely on.
  • The EU AI Act. Article 50 became applicable on 2 August 2026. It makes chatbots say they are chatbots, and requires marking of deepfakes and of AI-generated text published to inform the public on matters of public interest — with an exception where a person took editorial responsibility after human review. A client deliverable is neither of those things.
  • California's AI Transparency Act. It imposes provenance marking on large generative AI providers, not on the people who use their products.

How strong the duty to say so actually is

Most commercial services
Utah, on a clear request
Licensed advice, high-risk
Falls on the AI vendor

No general duty

Tell them if asked

Tell them up front

Mark the output

For ordinary commercial work the duty sits at the far left, which is exactly why the contract is the instrument that matters. Silence in the agreement is not the same as permission.

What a workable AI clause says

Blanket prohibitions do not survive contact with the work. They get ignored rather than complied with, which leaves the client worse off than a clause permitting a defined use under stated conditions. Four parts carry the weight.

Anatomy of an AI-use clause

The AI-use clause

The second part is the one that repairs the confidentiality problem, and the one most drafts leave out. A clause that only requires "disclosure of AI use" fixes nothing.

The free Bonterms AI Standard Clauses are a useful reference for the wording. They define AI Features, Inputs and Outputs, and set out training as an explicit choice — prohibited outright, permitted only for that customer's benefit, or permitted on de-identified and aggregated data. Turning training from a silence into a selected option is most of the value.

Consulting agreement template

The scope, deliverables, confidentiality and IP clauses an AI-use provision has to sit alongside — generated around your answers, with governing law as a required field rather than an assumption.

Open

If you are the client, ask four things

Before the engagement, not after the deliverable

  • Which tools, on which account tier, and whether our material is uploaded to them or only described to them.
  • Whether the vendor's terms exclude training on our content, and whether you can show us where that is written.
  • Who reads the output before it reaches us, and whether you are adopting it as your own work.
  • Which parts of the deliverable are machine-generated, so we know what the assignment clause actually transfers.
  • Whether your professional indemnity cover responds to work produced this way — ask the question in writing.

The honest answer to the last one is often "I have not asked". That is worth knowing before a deliverable goes wrong rather than afterwards, and it costs a supplier nothing to find out.

Silence is a position, and it is the expensive one

A contract that says nothing about AI does not leave the question open. It leaves it to the clauses already in the document — a confidentiality clause with a closed recipient list, an originality warranty written for human authorship, an assignment that assumes there is something to assign. Every one of those reads against the supplier. Two paragraphs agreed at engagement replace an argument that would otherwise happen with a deliverable already in the client's hands, and the argument is not really about AI. It is about whose problem it is that the paperwork was written before the tools existed.

General information, not legal advice. This guide explains how these documents and rules generally work. Law varies by jurisdiction and changes, and none of it is applied to your circumstances here. For anything consequential, consult a licensed attorney where you are.

Frequently asked

Do I have to tell a client I used AI to produce their deliverable?

In ordinary commercial work, no — there is no general statutory duty. The obligation comes from your own contract, from a confidentiality clause that limits who may see the client's material, or from professional rules if you are licensed. Lawyers are the clearest exception: informed consent is required before client information goes into a self-learning tool.

Does pasting a client document into ChatGPT breach the NDA?

Usually yes on standard wording, because most NDAs permit disclosure only to a closed list of recipients bound by equivalent confidentiality terms, and a tool you signed up to online is not on that list. The breach is complete on transmission. Fix it with a written variation to the recipient list, or by not uploading the document at all.

Can a client ban AI use outright in the contract?

They can, and some do. The practical problem is that blanket bans are ignored rather than obeyed, and a supplier who breaches one quietly is worse for the client than a supplier operating under a defined permission. A clause naming permitted uses, approved tools and a human review obligation gets closer to what the client actually wants.

If AI helped write the deliverable, who owns it?

In the United States, purely machine-generated expression has no human author and so no copyright. What you contributed — your own writing, and your creative selection, arrangement and modification of the output — is protectable, and that is what an assignment clause can transfer. Anything else in the file may be free for anyone to reuse.

Does the EU AI Act make me label an AI-assisted report?

Not a client deliverable. Article 50, applicable from 2 August 2026, covers systems that interact with people directly, deepfakes, and AI-generated text published to inform the public on matters of public interest — and even that carries an exception where a person took editorial responsibility after human review. A private report to a client falls outside all of it.

Do the whole thing on your phone

Draft it, check it for risk, rewrite the clauses you do not like, sign it and send it — without opening a laptop.

  • 136 templates across 12 categories
  • AI review in plain English
  • Free every month — 3 documents, 2 reviews
Download on theApp Store
Free to download · no account

iPhone, iPad, Mac & Vision Pro · iOS 15.6+ · 76.1 MB
Premium from $1.99/week