What in-house counsel should ask a legal AI vendor about contract data before uploading a single agreement

In-house counsel are under real pressure right now. Legal AI vendors are everywhere, the pitch decks look compelling, and leadership wants to know why legal isn't moving faster. But the moment you upload your first executed agreement to a third-party platform, you've crossed a threshold that is genuinely difficult to walk back. Your contract repository isn't just files — it's a map of your company's obligations, risk tolerances, counterparty relationships, and commercial strategy. Think of it like handing someone your diary and hoping they only read the parts you intended. What you ask a vendor before that upload determines whether this is a sound decision or an expensive one.
Start With the Data Model, Not the Demo
The demo will always look good. That is what demos are for.
What you actually need to understand is how the vendor structures, stores, and uses the data you give them. Ask directly: does the vendor use customer-uploaded contracts to train or fine-tune its models? Some do. Some do so by default, with opt-out language buried in the terms of service. Others are explicit that your data never touches their training pipeline.
That distinction is material. If your agreements are being used to improve a model that also serves your competitors, you have a confidentiality problem that no NDA with the vendor will fully cure. The exposure is probabilistic and architectural, not transactional. A signed agreement with one downstream user doesn't clean the water for everyone else drawing from the same infrastructure. A signed agreement doesn't reach inside an inference layer.
The Inference Question
Even if a vendor doesn't train on your data, ask how the system handles inference. When your contract is processed, does it leave your tenant environment? Does it pass through a shared infrastructure layer? Is the large language model hosted by the vendor, or is it a wrapper around a third-party model from OpenAI, Anthropic, or Google?
If it's the latter, you need to understand the data handling terms of that underlying provider as well. You are not just contracting with the vendor. You are contracting with their entire stack, and most vendors will not volunteer that framing unless you push for it.
What Happens to Your Data After the Relationship Ends
Ask the vendor to explain their data retention policy in plain language, not just point you to a privacy addendum. How long does your data persist after you terminate? Is it deleted automatically, on what schedule, and what does that deletion process actually look like in operational terms?
This is where a lot of vendors get vague, and the vagueness is telling. The contract may say "deletion upon request," but the operational reality often involves backup systems, audit logs, and vector databases that store embeddings derived from your documents.
An embedding is a mathematical representation of a document's content. It is not the original text, but it can be interrogated. It encodes meaning, structure, and relationships in ways that persist even when the source file is gone — like a ghost that haunts the house long after the furniture has been moved out. Ask whether embeddings are deleted along with source files, or whether they persist in the retrieval infrastructure after your contract is terminated. Most buyers never ask this. Most vendors are relieved when they don't.
Jurisdiction and Sovereignty
Where does your data actually live? Not in the abstract, but physically, in which data centers, in which countries.
Vendors with global infrastructure will route data across multiple regions based on server availability unless you have negotiated otherwise. For companies with EU operations, contracts frequently contain personal data subject to GDPR. For regulated industries like healthcare, financial services, and defense, there are additional requirements governing where data can be processed and who is authorized to access it.
Ask the vendor to specify their data center locations and whether you can elect a data residency option. If they cannot answer that with specificity, that's informative on its own. Vagueness at this stage rarely resolves into clarity later.
Who Inside the Vendor Can See Your Documents
Once your contracts are in the system, who can access them? Customer support personnel often need access to diagnose issues. Data scientists need access for model evaluation. Security teams need it for incident response. None of that is inherently problematic, but you should know about it before you have uploaded anything.
Ask whether vendor employees can access your uploaded documents, under what circumstances, and whether that access is logged. Ask whether access logs are available to you under your service agreement. Ask who holds the encryption keys for your data at rest.
Here is the practical distinction: if the vendor holds the keys, they can access the data. If you hold the keys, they cannot without your active participation. Most vendors hold the keys. Most vendors will not explain this unless you ask.
Contractual Protections That Are Actually Enforceable
The vendor's standard terms of service are drafted to protect the vendor. Your negotiated data processing agreement should reflect the actual risk allocation between the parties, which requires knowing what you're allocating in the first place.
Minimum provisions worth negotiating: an explicit prohibition on using your data for model training without affirmative written consent; defined retention and deletion timelines with operational specificity, not just policy language; breach notification requirements with a timeline short enough to be actionable; indemnification for data misuse; and audit rights that allow you or a designated third party to verify compliance.
On audit rights specifically, they are frequently offered in form and denied in practice. Before you accept an audit clause, ask what an actual audit looks like, what documentation the vendor produces, and whether any existing customer has exercised that right. If no one has, the clause is decorative.
What Separates Serious Platforms From the Rest
The legal AI market is maturing, but unevenly. Some platforms were built from the ground up with enterprise data governance as a core design consideration. Others are consumer-grade tools with enterprise pricing bolted on afterward. The questions above will surface that distinction faster than any feature comparison or analyst report.
Platforms that have genuinely invested in this area share certain characteristics. They can articulate their data architecture without deflecting to a sales engineer. They have executed data processing agreements with large institutional clients who had real legal and compliance requirements. They support data residency elections. They offer verifiable deletion, not just deletion promises.
The differences between platforms are real and worth examining carefully. But the baseline question is the same regardless of which vendor you're evaluating: can they answer the above with specificity, and will they put it in writing?
If a vendor hesitates, redirects, or tells you the details will be addressed in onboarding, you have your answer. By the time onboarding happens, your contracts are already uploaded.
The Practical Standard
Treat every vendor conversation as you would due diligence on a counterparty in a significant transaction, because that is precisely what it is. You would not sign a material commercial agreement without scrutinizing the representations and warranties. The same discipline applies here, applied to the technical and legal infrastructure that will govern your data.
The vendors worth working with will welcome these questions. They've thought through the answers because their better clients already demanded them. The ones who haven't are telling you something important, and they're telling you early, which is exactly the right time to hear it.