Artificial intelligence is increasingly embedded in commercial transactions. While these tools can improve efficiency, they also introduce legal, regulatory, and commercial risks that are often underestimated. The key challenge for businesses is not whether to use AI, but how to ensure it is used in a controlled and appropriately supervised way. 

Nikki Petken

Nikki Petken

One of the most fundamental challenges is the uncertainty surrounding the legal and regulatory framework governing AI use in commercial transactions. The framework is still developing, creating uncertainty around compliance, liability, auditability, and accountability. The EU AI Act is now in force with the broader compliance obligations coming into effect through 2026 and beyond. The ever-changing landscape leaves businesses open to regulatory and compliance exposure in areas of data protection and industry sector rules.

This uncertainty is compounded by the risk that organisations may place too much reliance on AI outputs without sufficient human oversight. The risk of placing too much trust in AI outputs is the reduction of proper legal, financial, and commercial review of important transaction decisions. Reduced human oversight, poor prompt controls, and inadequate policies and training can lead to inconsistent or unsafe use.

Risks in AI drafting and due diligence

A key concern is that AI-generated outputs may appear reliable while in fact being flawed, incomplete, or outdated, which may lead to flawed contract drafting, or reliance on false assumptions.

In addition to accuracy concerns, there is also the risk that AI systems may replicate or reinforce bias. AI can produce biased and unfair outcomes by learning patterns from skewed or historically discriminatory data, leading it to disadvantage certain groups in decisions or recommendations, such as discriminatory pricing, unfair credit, and supplier assessments.

Confidential information and AI platforms

AI tools often process sensitive information, which creates privacy, confidentiality, or data protection concerns. A business is required to ensure any use of AI systems for personal data complies with the UK GDPR data protection principles. AI systems can potentially retain data indefinitely without appropriate justification if there are no suitable deletion protocols and interconnect with other third-party tools, sharing data and creating security risks.

AI-generated materials may also raise questions about ownership, infringement of third-party content, licensing, and whether confidential or copyrighted materials were used in training or outputs.

AI use and dispute exposure

Difficulties can arise in determining responsibility for AI-assisted decision-making. If AI is used to draft, review, approve, or negotiate contract terms, disputes may arise over who is responsible for errors, omissions, or unintended commitments. This is made more complex by the fact that it may be difficult to preserve, audit, and explain AI-assisted decisions or outputs if a transaction is later challenged or litigated.

A further issue relates to legal privilege, which may be put at risk through inappropriate use of AI tools. Legal professional privilege can potentially be lost or challenged if dispute sensitive material is entered into an AI platform that is public or unapproved. In a recent decision of the Immigration and Asylum Chamber, the tribunal confirmed that the uploading of confidential documents to AI tools such as Chat GPT is the same as placing that information in the public domain.

Managing AI risk in practice

To manage these risks effectively, businesses should establish robust governance frameworks that keep pace with evolving regulation and guidance. Meaningful human oversight should remain central to important transaction tasks, with clear boundaries set around permitted and prohibited uses. Staff should be trained on safe usage, and approval processes should be in place for AI-assisted outputs. Current reforms under the EU’s Digital Omnibus package may delay some high-risk AI obligations, meaning businesses should treat the regulatory position as active and evolving rather than settled. Establishing AI governance is not a tick box exercise, but something that requires ongoing monitoring and review.

Confidentiality risks should be addressed through strict controls over the tools being used and the information being input into them. Only approved AI systems with appropriate data processing terms, security safeguards such as encryption and access controls, and no-training provisions should be used. Confidential, personal, privileged, or commercially sensitive information should not be entered into AI systems unless they are explicitly approved for that purpose. Practical steps include carrying out an AI impact assessment covering data protection, sector rules, and cross-border transfers, updating privacy notices and vendor agreements, and maintaining a compliance register of AI use cases.

AI outputs should always be treated as draft material rather than final advice. Human verification should be required for all legal, financial, regulatory, factual, and commercial elements before reliance in any transaction. AI tools should also be tested for bias, with human review applied to any decisions affecting counterparties, customers, suppliers, or pricing, and they should never be used as the sole basis for decisions with legal or commercial consequences.

Risk should also be clearly allocated in contractual documentation where AI is used in commercial arrangements. Agreements such as NDAs and transaction contracts should clearly address permitted uses, confidentiality obligations, security standards, warranties, indemnities covering intellectual property and data risks, liability allocation, audit rights, and obligations relating to disclosure or control of AI use. Ownership of inputs and outputs should also be clearly defined, and parties should agree confidentiality and data protection terms before any sensitive information is shared.

Finally, it is important to ensure that AI use is properly documented so that decisions can be explained and audited if required. A clear audit trail should be maintained showing when AI was used, what information was input, what outputs were generated, who reviewed them, and what final decisions were taken. This record should be retained in accordance with document retention and litigation-readiness policies.

Conclusion

AI offers clear advantages in speed, efficiency, and analytical capability, but it does not remove legal, regulatory, or commercial risk. In the context of commercial transactions, it should be treated as an assistive technology rather than a decision-maker. Without appropriate oversight, the use of AI can introduce significant vulnerabilities. Businesses that adopt a structured and cautious approach will be best placed to benefit from AI while maintaining control over legal and commercial outcomes.

 

Nikki Petken is partner in the corporate and commercial team at SA Law