Skip to content
Call, 0511 – 47 55 58 11

Choosing an AI tool: the question set

Most legal problems with AI arise not in operation but at selection. Asking the right questions before the contract saves the difficult ones afterwards.

The success of an introduction is decided by questions that look small on their own and together tip the balance. They do not replace assessing the individual case.

Which tools this covers

The question usually comes first, so here are the tools this is about in practice:

Two points are regularly underestimated. First, the name of a plan is not a commitment: calling a plan a business plan says nothing in itself about how inputs are handled. Second, terms change. What was checked during selection does not hold indefinitely, and the notice of change rarely reaches the people who assessed the contract.

In this order

  1. Step 1: Describe the deployment

    Purpose, categories of data, groups affected and whether decisions about people are prepared or taken.

  2. Step 2: Permissibility and classification

    Is the use permitted at all, which risk class applies, and are you provider or deployer?

  3. Step 3: Question the provider

    The questions listed below, in writing and before the contract. What is promised orally does not count later.

  4. Step 4: Contract and policy

    The load-bearing commitments go into the contract, the rest into an internal usage policy that gives staff clear limits.

The questions for the provider

How we support you

We work through the question set with you, place the answers in their legal context and negotiate the points that belong in the contract. The result is a usage policy that works in daily practice rather than sitting in a folder.

A tool under consideration?

We ask the questions that count later, before the contract is signed.

Have the selection accompanied

Frequently asked questions

Where do we start?

With the intended use, not with the product. Purpose, categories of data and the groups affected determine which requirements apply at all. A tool that is unproblematic for one purpose can trigger considerable obligations for another.

Is this not excessive for a small company?

The scope follows the risk. For an assistant that drafts text, a few points and a short usage policy suffice. It only becomes demanding where personal data on a significant scale or decisions about people are involved.

The tool is already running. Is the question set pointless now?

No, it becomes a review of the existing position. The points stay the same, but the bargaining position is worse. Whatever can no longer be changed contractually has to be caught by internal rules, for instance requirements on what may not be entered.

Which models and services are we talking about?

In practice we mostly meet Claude, ChatGPT, Gemini, Microsoft 365 Copilot, GitHub Copilot and the assistant features embedded in Microsoft 365. Openly available models such as Llama or Mistral, run on your own infrastructure, come on top. The legal assessment does not follow the name but the plan: the same service can come with entirely different terms as a personal account, as a business plan or through a cloud platform.

Related