Choosing an AI tool: the question set
Most legal problems with AI arise not in operation but at selection. Asking the right questions before the contract saves the difficult ones afterwards.
The success of an introduction is decided by questions that look small on their own and together tip the balance. They do not replace assessing the individual case.
Which tools this covers
The question usually comes first, so here are the tools this is about in practice:
- General assistantsClaude, ChatGPT and Gemini, as a web interface, an app or through an API. Legally, the gap between a personal account and a business plan is wider than the gap between providers.
- Embedded in Microsoft 365Microsoft 365 Copilot and further assistant features in Outlook, Teams and Word. Existing data and model use interlock here, which makes the assessment depend on your existing Microsoft setup.
- In developmentGitHub Copilot and comparable assistants inside the development environment. The questions specific to that are covered under AI in software development.
- Through a cloud platformThe same models, obtained through Azure, AWS or Google Cloud. Your counterparty is then the platform operator, and the terms differ from those of the model provider.
- Self-hostedOpenly available models such as Llama or Mistral on your own or rented infrastructure. The outflow of data falls away. The duties under the AI Act do not.
- Inside line-of-business softwareAssistant features that come with a specialist application. It is often unclear which model sits behind them and where inputs go. That is exactly what to ask.
Two points are regularly underestimated. First, the name of a plan is not a commitment: calling a plan a business plan says nothing in itself about how inputs are handled. Second, terms change. What was checked during selection does not hold indefinitely, and the notice of change rarely reaches the people who assessed the contract.
In this order
Step 1: Describe the deployment
Purpose, categories of data, groups affected and whether decisions about people are prepared or taken.
Step 2: Permissibility and classification
Is the use permitted at all, which risk class applies, and are you provider or deployer?
Step 3: Question the provider
The questions listed below, in writing and before the contract. What is promised orally does not count later.
Step 4: Contract and policy
The load-bearing commitments go into the contract, the rest into an internal usage policy that gives staff clear limits.
The questions for the provider
- Are inputs used for training, and can that be excluded contractually?
- Are voices, faces or other biometric characteristics processed?
- Where does processing happen, and which sub-processors have access?
- How long are inputs and outputs stored, and who sees them?
- Which rights are granted in inputs and outputs?
- Is there an indemnity for third-party claims, and on what conditions?
- What documentation does the provider supply for your own record-keeping duties?
- How are material changes to the model and functionality communicated?
- What happens to the data at the end of the contract?
How we support you
We work through the question set with you, place the answers in their legal context and negotiate the points that belong in the contract. The result is a usage policy that works in daily practice rather than sitting in a folder.
A tool under consideration?
We ask the questions that count later, before the contract is signed.
Have the selection accompaniedFrequently asked questions
Where do we start?
With the intended use, not with the product. Purpose, categories of data and the groups affected determine which requirements apply at all. A tool that is unproblematic for one purpose can trigger considerable obligations for another.
Is this not excessive for a small company?
The scope follows the risk. For an assistant that drafts text, a few points and a short usage policy suffice. It only becomes demanding where personal data on a significant scale or decisions about people are involved.
The tool is already running. Is the question set pointless now?
No, it becomes a review of the existing position. The points stay the same, but the bargaining position is worse. Whatever can no longer be changed contractually has to be caught by internal rules, for instance requirements on what may not be entered.
Which models and services are we talking about?
In practice we mostly meet Claude, ChatGPT, Gemini, Microsoft 365 Copilot, GitHub Copilot and the assistant features embedded in Microsoft 365. Openly available models such as Llama or Mistral, run on your own infrastructure, come on top. The legal assessment does not follow the name but the plan: the same service can come with entirely different terms as a personal account, as a business plan or through a cloud platform.