Your AI Vendor Contract Already Decided Who Pays
Picture the closing table. The file is clean on its face. Everyone is present. One number on one line came out of a tool. The…
Picture the closing table. The file is clean on its face. Everyone is present. One number on one line came out of a tool.
The number is wrong. Not maliciously wrong. Wrong the way a prediction engine is wrong, confidently and in the correct format.
The reflex question is who pays. The reflex answer is the vendor.
Under Georgia Rule of Professional Conduct 5.3, the supervising attorney carries professional responsibility for AI output. Most AI vendor contracts disclaim any warranty of accuracy, and the State Bar of Georgia warns that terms of service commonly shift risk to the user. The vendor is not carrying it. You are.
The vendor already answered that question, in a contract nobody at your firm has read.
Forensic Case File
What follows is an illustrative scenario. It is not a real matter, a real firm, or a real client.
Thursday afternoon. A payoff figure comes back from an AI-assisted title tool your firm licensed last spring. It reads clean. The number is close enough to plausible that nobody double-checks it against the underlying file.
The wire goes out. Six weeks later, the servicer flags a discrepancy. The tool produced a number that was internally consistent but wrong.
Someone pulls the vendor agreement for the first time since it was signed. Buried in Section 14 is a clause disclaiming any warranty as to the accuracy of output and shifting reliance risk to the user. Nobody at the firm had read it. The vendor was never required to explain it.
The firm covers the difference. The disclaimer holds.
What Does Your AI Vendor Contract Actually Say About a Bad Output?
Two separate things are true, and they come from two different places.
The first comes from the State Bar of Georgia. Its Generative AI Toolkit tells Georgia lawyers that standard-form clickwrap and shrinkwrap agreements, the kind accepted by using the product, frequently include broad disclaimers and may expressly exclude any obligation of confidentiality. In its confidentiality analysis, the Toolkit goes further. It states that terms of service commonly allocate the risk inherent in the technology to the user, with the vendor disclaiming responsibility. The Bar put that in writing, to Georgia lawyers, about the contracts they are signing.
The second comes from reading the contracts themselves. Most AI vendor agreements disclaim any warranty as to the accuracy of output. That is not a Bar finding. It is what the documents say, and it is why the Toolkit tells you to read them.
Put together: the Bar told you these agreements shift risk and carry broad disclaimers. Your specific contract tells you exactly how far. Almost nobody has looked.
The Toolkit includes a contract review checklist for this reason. It asks firms to examine the scope of client data use, whether the vendor trains its models on identifiable client data, whether obligations flow down to the underlying model provider, what assurances exist against biased output, and what happens to prompts and output when the contract term ends.
Most firms using an AI tool today have never run that checklist against their own vendor.
Which Clauses in Your AI Vendor Contract Shift the Risk to You?
Three of them. The warranty disclaimer, the limitation of liability, and the indemnification provision.
They sit in different parts of the agreement, they are rarely labeled in plain terms, and together they do most of the work.
The warranty disclaimer. Usually set in capital letters somewhere past the middle of the document. It states that the service is provided as is, without any warranty of accuracy, reliability, or fitness for a particular purpose. Read plainly, the vendor is telling you it does not promise the output is correct. Everything the marketing page said about accuracy sits outside the contract. This clause is the one that governs.
The limitation of liability. This does two things at once. It caps the vendor’s total exposure, often at the fees you paid in the preceding twelve months, and it excludes consequential and indirect damages entirely. A wire sent on a wrong number is a consequential damage. If your annual subscription is a few thousand dollars, that is the ceiling on what the vendor could owe, and the category of loss you actually suffered is likely carved out above it.
The indemnification provision. Look at which direction it runs. Many AI vendor agreements require the customer to indemnify the vendor, not the reverse. That means a claim arising from your use of the tool can become your obligation to defend, including the vendor’s costs.
Your Vendor AI Tool Vetting Checklist captures all three in the contractual examination tier. Pull them together, in writing, for every tool that touches a closing file.
Who Is Responsible Under Georgia’s Ethics Rules When an AI Tool Is Wrong?
You are.
Georgia Rule of Professional Conduct 5.3 requires supervision of nonlawyer assistance. The State Bar of Georgia Generative AI Toolkit defines a nonlawyer assistant to include any technological tool not licensed to practice law, whose work must be ethically supervised by an attorney. Your AI tool is not licensed to practice law.
GRPC 1.1 requires competent representation, which includes understanding a tool well enough to know where it fails. GRPC 1.6 requires protecting client confidentiality, regardless of what a vendor’s data practices turn out to be. GRPC 5.1 places responsibility on supervising and managing attorneys for the conduct of those working under them, tools included.
ABA Formal Opinion 512 reinforces the same point nationally. It states that relying on or submitting a generative AI tool’s output without an appropriate degree of independent verification can violate the duty of competence. It further states that lawyers should read the terms of use, privacy policy, and related contractual terms of any tool they use, or consult someone qualified who has.
Georgia is not waiting for a test case. In Shahid v. Esaam, the Georgia Court of Appeals addressed a brief built on citations that were fake or unsupported. In 2026, the Georgia Supreme Court suspended an attorney from practice before it for the same conduct.
The vendor’s disclaimer was never going to appear in either opinion. The attorney’s name did.
What Is Shadow AI Hiding in Your Closing Workflow?
The tool nobody procured, and therefore nobody vetted.
A paralegal’s personal AI account, used to draft a summary that was pasted into the file. A title vendor’s AI feature, embedded in software your firm already licenses, switched on by an update nobody approved. A drafting assistant built into a platform your firm has used for years, active by default.
None of these went through a contract review. None appear on a vendor list anyone can produce.
The exposure deepens at intake. The Toolkit addresses AI intake and screening tools under GRPC 1.7, 1.9, and 1.10, the conflicts rules, and directs firms to take one of two paths. Either prevent the intake system from soliciting or receiving detailed confidential information until a conflicts check is performed, or include clear and conspicuous disclaimers that no attorney-client relationship is formed until the firm confirms it has no conflict and agrees to undertake the representation. Most firms have done neither.
The Toolkit also addresses what happens when the safeguard fails. If confidential information is collected before the conflicts check, the firm should isolate and embargo it internally, disclose the nature of the conflict to the prospective client, explain why representation cannot proceed, and describe what was done to secure or delete the information, consistent with GRPC 1.18.
An intake chatbot that gathers a prospective client’s financial details before anyone runs a conflicts check has created a problem before the file even opens.
The Three-Step Fiduciary Audit
One. Inventory and pull. List every AI tool that touches a closing file, including embedded features and personal accounts. For each one, retrieve the current terms of service and privacy policy. Date them. Retain them. You cannot supervise a tool whose terms you have never read.
Two. Name the human. Assign a named reviewer for every AI-assisted output that leaves the firm or reaches a client, a lender, or a court. Log the verification itself, not just the conclusion. Under GRPC 5.3, fiduciary duty does not distribute across a team. It lands on a person.
Three. Run the checklist, and run it again. Test each vendor against the Toolkit’s contract review checklist: scope of client data use, training on identifiable data, flow-down to the underlying model, bias assurances, and data disposition at termination. Re-run it at renewal. Terms change without notice to you.
What Separates a Protected Firm From an Exposed One?
Not which tool it uses. Two firms can run the identical AI feature. One has an audit trail. One has a hope.
| Point of Exposure | The Wild West Firm | The Governance Way Firm |
|---|---|---|
| Vendor accuracy claim | Accepted from the marketing page | Tested against the written terms and documented |
| Terms of service | Accepted by clickwrap, never read | Read, dated, retained, risk allocation identified |
| Who carries a bad output | Assumed to be the vendor | Known to be the signing lawyer |
| Output review | Spot-checked by whoever is closest | Named reviewer, logged per file |
| Client data in prompts | Entered as it appears in the file | Anonymized identifiers or dummy data |
| Intake and conflicts | Chatbot collects first, checks later | Conflicts check first, or a clear disclaimer |
| Staff use | Undocumented | Written policy plus a training record |
The Wild West firm is not violating a rule simply by using the tool. It is carrying an unmeasured position. When the output is wrong, that firm starts from zero, under deadline, discovering its exposure for the first time in front of a client or a court.
The Bottom Line
Your AI vendor contract has almost certainly already decided that a wrong output is your problem. The State Bar of Georgia told you these agreements shift risk and carry broad disclaimers. Georgia Rule of Professional Conduct 5.3 confirms where the responsibility lands by placing supervision on the attorney.
Audit-Ready Compliance is not a promise that no tool will ever be wrong. It is the difference between a firm that can produce its verification record on demand and one that is discovering its exposure in real time. An ethically engineered practice knows what it signed, knows who reviewed what, and can prove both. That is where peace of mind actually comes from.
Frequently Asked Questions
Does my AI vendor cover me if the tool gives a wrong answer? Almost certainly not. Most AI vendor agreements disclaim any warranty as to the accuracy of output, and the State Bar of Georgia Generative AI Toolkit warns that terms of service commonly allocate the risk inherent in the technology to the user. Read your specific contract to confirm your own risk allocation.
Who is responsible if an AI tool makes a mistake in a client matter? The supervising attorney. Georgia Rule of Professional Conduct 5.3 requires supervision of nonlawyer assistance, and the Toolkit defines that term to include technological tools not licensed to practice law. Professional responsibility does not transfer to the vendor.
What should I actually check in an AI vendor contract? The Toolkit’s checklist: scope of client data use, whether the vendor trains on identifiable client data, whether obligations flow down to the underlying model, assurances against biased output, and what happens to prompts and output when the contract ends.
What is Shadow AI in a law firm context? AI tools operating inside a firm’s workflow without formal procurement or contract review. Examples include a staff member’s personal AI account, an AI feature embedded in already-licensed software, or a vendor tool activated by an update nobody approved.
Does an AI intake chatbot create conflicts problems? It can. The Toolkit addresses this under GRPC 1.7, 1.9, and 1.10, and directs firms either to prevent the intake tool from receiving detailed confidential information until a conflicts check is performed, or to disclose clearly that no attorney-client relationship exists until the firm confirms it has no conflict.
Has a Georgia attorney actually faced consequences for this? Yes. In Shahid v. Esaam, the Georgia Court of Appeals addressed a brief built on citations that were fake or unsupported. In 2026, the Georgia Supreme Court suspended an attorney from practice before it for the same conduct.
Where Does Your Firm Actually Stand?
Most Georgia attorneys using an AI tool today have never read the contract that governs it. The AI Liability Quiz measures your firm’s exposure in under five minutes and returns a specific risk tier, along with the governance gaps behind it.
Take the AI Liability Quiz and find out whether your firm is a Statutory Time Bomb, Fragile Hybrid, or Digital Fortress.
This article is provided for general informational purposes and does not constitute legal advice. It does not create an attorney-client relationship. Georgia attorneys should consult the Georgia Rules of Professional Conduct, the State Bar of Georgia Generative AI Toolkit, and their own vendor agreements before making compliance decisions for their own practices. Juniata C. Ford, Esq., Ford Innovations, P.C.