The ticket landed at 4:40 on a Thursday. Our support org had picked a new analytics vendor, the order form was already "approved" in the procurement tool, and the VP who owned the budget wanted it signed by Monday so onboarding could start before quarter close. Attached: a 31-page master services agreement, a 9-page data processing addendum, and a two-page order form for $84,000 a year over three years.
I'm commercial counsel at a SaaS company of about 200 people. I review some version of this package most weeks, usually alone, usually with a deadline someone else set. A few years ago that meant a full afternoon per MSA. Today the first pass belongs to an AI contract review tool, and my afternoon goes to the four or five decisions that actually move money or risk.
This post is the exact process I use, shown on that vendor deal (names and some numbers changed). You'll see what the AI flagged, what it missed, what I decided, and the prompts and pushback positions I reuse every week.
TL;DR: AI contract review is fastest when you give the tool your side of the deal, the full document stack, and specific questions, then treat its output as an issue list, not a verdict. In the walkthrough below, LegesGPT's document review flagged 9 of the 12 issues worth negotiating and proposed usable fallback language for most of them; the three it missed were cross-document conflicts and one business call only I could make.
What AI contract review is good at in a vendor deal
Short answer: speed on the first read, consistency, and a draft of the redline. A good tool reads 40 pages in a couple of minutes, sorts clauses by risk to your side, and suggests replacement wording you can paste into your markup.
What it doesn't do is know your company. It doesn't know that our security team will block any vendor that can move data to a new subprocessor without notice, or that the support VP will trade a weaker SLA for a faster go-live. It also doesn't know how much pull you have with this particular vendor. Those three things decide most negotiations, and they stay with the human.
So I think of AI contract review software as a very fast junior reviewer who never gets tired of reading definitions sections. Useful, occasionally wrong, and only as good as the instructions it gets.
Set up the review before you upload anything
Five minutes of setup saves the most time later. Before I upload, I write down four things.
Which side am I on. Customer buying a service. Every flag should be framed as risk to the customer. If you skip this, many tools give you a "balanced" read that is useless for markup.
What the deal is worth. $84,000 a year, $252,000 total commitment. That number tells me which issues deserve a fight. A liability cap of three months of fees is $21,000. On a contract that touches customer data, that's a problem worth a call.
My must-haves and my tradeables. For SaaS vendors that process customer data, my must-haves are a liability cap of at least 12 months of fees, a separate higher cap for data breaches, notice of new subprocessors with a right to object, and no use of our data to train the vendor's models. Tradeables include governing law, SLA credit percentages, and payment terms.
The whole document stack. MSA, order form, DPA, and anything incorporated by URL. This matters more than people expect, and it's where my AI review came up short (more on that below).
The walkthrough: one vendor MSA, clause by clause
The vendor, which I'll call Relaywise, sells conversation analytics for support teams. It ingests every ticket and chat transcript, which means it ingests our customers' personal data. That fact set the priorities.
I uploaded the MSA to LegesGPT's document review, told it we were the customer, and asked for risks ranked by severity with proposed changes. Here's what came back and what happened to each item.
Section 1.4: terms that live at a URL
The MSA said the vendor's Acceptable Use Policy and Support Policy, "as updated from time to time" on the vendor's website, were part of the agreement.
What the AI flagged: Unilateral amendment risk. It pointed out that the vendor could change binding terms without our signature and proposed language freezing the incorporated policies as of the effective date, with later changes binding only if they don't materially reduce our rights.
What I decided: Took the AI's language almost word for word. This one is close to free to ask for, and vendors usually accept a "no material degradation" version.
Section 4.3: renewal pricing
Fees for each renewal term would be "Relaywise's then-current list price."
What the AI flagged: Uncapped price increase at renewal. It proposed a cap tied to CPI or a fixed percentage.
What I decided: Asked for 5%. We settled at 6%. On a $84,000 base that difference is small, but an uncapped list-price reset can be 20% or more once you're locked into the integration. Worth the email.
Section 6.2: usage data and AI training
This is the one I care about most with analytics vendors. The MSA let Relaywise use "Usage Data" to "improve and develop its products and services, including machine learning models."
What the AI flagged: Data use beyond service delivery, with a note that "including machine learning models" could cover training on our content. It proposed limiting use to operating and supporting our account.
What it missed: The definitions section. "Usage Data" was defined as "data derived from Customer's use of the Services, including transcripts as processed by the Services." In plain English, our customers' chat transcripts became Usage Data once the platform touched them. The AI reviewed Section 6.2 on its own and didn't connect it to the definition 20 pages earlier until I asked directly.
What I decided: Rewrote the definition so Usage Data meant only telemetry and performance metrics, excluded all Customer Data and anything derived from it, and added an express no-training clause. The vendor pushed back for a week and then accepted. This was the most valuable change in the deal, and the tool found half of it.
Section 5.3: suspension
Relaywise could suspend the service immediately "if it reasonably suspects" a breach of the Acceptable Use Policy.
What the AI flagged: Suspension without notice on suspicion alone, with no limit on scope or duration.
What I decided: Asked for prior notice except in real emergencies (security threats, legal compulsion), suspension limited to the affected users, and prompt restoration. Accepted with minor wording changes.
Section 8.4: SLA credits as the sole remedy
Service credits of 5% to 15% of monthly fees were "Customer's sole and exclusive remedy" for downtime.
What the AI flagged: Exclusive remedy language that could block termination even for chronic outages. It suggested a termination right after repeated SLA misses.
What I decided: Kept the credit percentages (a tradeable) and added a right to terminate and get a prorated refund if availability fell below target in any three months out of six. The support VP cared about this more than the credits themselves.
Section 10: indemnities
Vendor IP indemnity was standard with the usual exclusions. Our indemnity to them covered "any claim arising from Customer Data."
What the AI flagged: The breadth of our indemnity. "Any claim arising from Customer Data" could pull us into defending a claim caused by the vendor's own breach.
What I decided: Narrowed ours to claims that our data or our collection of it violated law or third-party rights, and excluded anything caused by the vendor's security failures. Straightforward, and the AI's proposed rewrite was close to what I sent.
Section 11: limitation of liability
Cap: fees paid in the three months before the claim. No separate cap for data or confidentiality breaches. Mutual exclusion of consequential damages, which also excluded "loss of data."
What the AI flagged: Low cap relative to contract value, no carve-outs, and the "loss of data" exclusion, which it correctly noted would wipe out most of our recovery for a breach.
What I decided: Asked for 12 months of fees as the general cap and a super-cap of 3x annual fees for data protection and confidentiality breaches, with "loss of data" removed from the excluded list. Final: 12 months general, 2x annual fees for data breaches. That's the trade I expected to make, and I made it knowing the business wanted the tool live.
Section 14.2: assignment
Relaywise could assign the agreement to an acquirer without consent. We couldn't assign at all.
What the AI flagged: One-sided assignment rights.
What I decided: Made it mutual for mergers and acquisitions, with a termination right for us if we get assigned to a direct competitor. Took one round.
What the AI missed in the walkthrough
Three issues the tool didn't surface on its own:
- Order of precedence. The order form said it controlled over the MSA "in the event of conflict," and the order form had its own auto-renewal clause with a 60-day notice window, shorter than the MSA's 90. The AI reviewed the MSA alone, so it never saw the conflict. When I uploaded the order form separately, it flagged the auto-renewal but didn't compare the two.
- The DPA's subprocessor clause. The DPA allowed new subprocessors with 10 days' notice posted on a website, and treated our silence as consent. That conflicted with what our security team requires. Again, separate document.
- No termination for convenience. A three-year commitment with no exit unless the vendor breached. The tool didn't flag the absence because nothing in the text was "risky." Missing clauses are harder to catch than bad ones unless you ask.
None of this is a knock on one product. Cross-document conflicts and missing protections are where AI contract review is weakest across the category, which is why the prompts below exist.
The scorecard
| Issue | AI flagged it? | My ask | Where we landed |
|---|---|---|---|
| Terms incorporated by URL (1.4) | Yes | Freeze as of effective date | Accepted |
| Renewal price uplift (4.3) | Yes | Cap at 5% | 6% cap |
| Usage Data and training (6.2) | Partly (missed the definition) | Telemetry only, no training | Accepted after a week |
| Suspension on suspicion (5.3) | Yes | Notice, scope limit | Accepted |
| SLA credits sole remedy (8.4) | Yes | Termination after repeat misses | Accepted (3 of 6 months) |
| Customer indemnity breadth (10) | Yes | Narrow to our own violations | Accepted |
| Liability cap 3 months (11) | Yes | 12 months + 3x data super-cap | 12 months + 2x |
| "Loss of data" exclusion (11) | Yes | Remove | Removed |
| One-way assignment (14.2) | Yes | Mutual + competitor exit | Accepted |
| Order form overrides MSA renewal | No | MSA controls on renewal and notice | Accepted |
| DPA subprocessor silence = consent | No | 30 days' notice, right to object | 30 days, objection right |
| No termination for convenience | No | Exit after year one with notice | Declined; got a year-two price lock instead |
Total time on my side: about two and a half hours across a week of back-and-forth, versus the full day the first pass alone used to take. The AI's first review took under five minutes. The real savings showed up in drafting, because most proposed changes needed light edits rather than writing from scratch.
What to ask the AI
Generic prompts get generic output. These are the ones I keep in a note and paste in, adjusting the bracketed parts.
- "We are the [customer/vendor]. Review this agreement for risks to our side only and rank them high, medium, low."
- "List every defined term that affects data, IP, or liability, and show where each is used. Flag any definition that expands the other party's rights."
- "Does anything in this agreement let the other party change terms without our signature? Quote the language."
- "What protections would a customer normally expect in a SaaS agreement that are missing here?"
- "Compare the auto-renewal, notice, and termination terms in the MSA and the order form. Which document controls if they conflict?"
- "Calculate the liability cap in dollars assuming annual fees of [$X]. Which claims sit outside the cap and which are excluded entirely?"
- "Can the vendor use our data for anything other than providing the service to us? Include model training, benchmarking, and aggregation."
- "Propose replacement language for each high-risk clause, written as a reasonable first ask, and a fallback position if they refuse."
- "Summarize this agreement in ten bullets for a non-lawyer budget owner, focused on cost, commitment, and exit."
- "What would a vendor most likely reject in our proposed changes, and why?"
Prompts 2, 4, and 5 are the ones that would have caught everything the first pass missed in the walkthrough. I now run them on every vendor package, not just the ones that feel risky.
Red-flag clauses in vendor MSAs and what to push back on
This is my working table for customer-side SaaS reviews. Positions vary with deal size, so treat the "fallback" column as the floor I'd usually accept on a mid-five-figure contract.
| Clause | What it looks like | First ask | Usual fallback |
|---|---|---|---|
| Liability cap | Fees paid in prior 3 or 6 months | 12 months of fees | 12 months, no less for data deals |
| Data breach exposure | No carve-out; "loss of data" excluded | Super-cap at 3x annual fees | 2x annual fees |
| Data use | "Improve our services, including ML" | Service delivery only, no training | Aggregated, de-identified telemetry only |
| Renewal pricing | "Then-current list price" | Cap at CPI or 3-5% | Fixed cap up to 7% |
| Auto-renewal | Long notice window buried in order form | 30 days' notice, reminder required | 60 days |
| Unilateral changes | Policies "as updated" at a URL | Frozen at signature | Changes can't materially reduce rights |
| Suspension | Immediate, on suspicion | Notice first, scoped to affected users | Immediate only for security or legal reasons |
| SLA remedy | Credits are the sole remedy | Termination for chronic failure | Exit after 3 misses in 6 months |
| Subprocessors | Website notice, silence is consent | 30 days' notice and right to object | Right to terminate if objection unresolved |
| Customer indemnity | "Any claim arising from Customer Data" | Limited to our own legal violations | Exclude vendor-caused claims |
| Assignment | Vendor free to assign, customer can't | Mutual for M&A | Exit right if assigned to a competitor |
| Termination for convenience | Absent on multi-year deals | Exit after year one with 90 days' notice | Price lock or reduced commitment |
If you want more depth on how specific tools score these clauses, the roundup of AI contract risk analysis software compares how different products handle severity ranking.
Where AI contract review software falls short
I'd rather you hear the limits from someone who uses this daily than discover them on a deal.
One document at a time. Most tools review whatever you upload as a closed universe. Vendor deals are document stacks. Unless you combine the files or ask comparison questions, conflicts between the MSA, order form, and DPA slip through.
Absences are hard. A tool reads the words on the page. It flags bad language reliably and missing protections less reliably, unless you ask what's missing.
It doesn't know your bargaining position. The AI proposed a 3x data super-cap as standard. Whether I could get it depended on our size relative to the vendor, how badly the business wanted this tool, and how many alternatives were in the running. That's judgment.
Proposed language needs editing. Most suggestions were usable. A couple used defined terms the contract didn't have, which would have created new ambiguity if pasted in blind. Read every redline before it leaves your desk.
Confidentiality is your responsibility. Check the tool's data handling before uploading a counterparty's paper, and check your own obligations. Lawyers should also read their bar's guidance on generative AI; ABA Formal Opinion 512 is a reasonable starting point in the US.
If you're comparing products on these weaknesses, the guide to AI contract review tools covers how the main options differ, and the redlining software roundup is useful if your bottleneck is producing the markup rather than finding the issues.
Running this workflow in LegesGPT
The walkthrough above used LegesGPT's document review. You upload the contract in the browser, tell it which side you're on, and it returns flagged risks with proposed changes you can accept, edit, or ignore. The same workspace answers follow-up questions about the clause in front of you, so prompts like "calculate the cap in dollars" or "what's missing for a SaaS customer" run against the document you just uploaded.
Two honest limits for in-house teams. LegesGPT is web-only, with no Word add-in, so I copy accepted changes into my Word redline by hand; on a 12-issue markup that's about ten minutes. And the review allowance depends on plan: Plus at $49.99 a month includes 50 document reviews, which covers my volume, while Premium at $99.99 a month removes the limit. Basic starts at $19.99 a month, annual billing saves 30%, and there's a 3-day trial for $1 if you want to run your own vendor MSA through it before committing.
For a broader look at where it fits next to other legal AI products for a corporate team, see the roundup of AI tools for in-house legal teams.
What changed in my week
The honest result: I review more vendor paper than I did two years ago and spend less time on each one. The AI handles the reading. I spend my time on the definitions that hide data rights, the order form nobody else looks at, and the call with the vendor's counsel where the real trades happen.
Relaywise went live the following Wednesday, two days later than the VP wanted and with a contract I'd sign again. That's the trade I'd take every time.
Frequently Asked Questions
Can AI review a contract on its own?
AI can do the first read on its own, which means spotting risky clauses, ranking them, and proposing replacement language in a few minutes. It cannot decide which issues are worth fighting for, because that depends on your deal size, your bargaining position, and what your business will trade. Treat the output as an issue list that a person signs off on.
How accurate is AI contract review?
On clause-level problems like low liability caps, one-way indemnities, or uncapped renewal pricing, current tools are reliable enough to save hours. They are weaker on conflicts between separate documents, on definitions that quietly change a clause's meaning, and on protections that are missing entirely. Asking targeted follow-up questions closes most of that gap.
What should I upload for an AI contract review?
Upload the full document stack, not just the main agreement. For a vendor deal that usually means the MSA, the order form, the data processing addendum, and any policies incorporated by reference. Order forms often override the MSA on renewal and notice terms, so reviewing the MSA alone can miss the clause that matters most.
What prompts work best for reviewing a contract with AI?
Start by stating which side you are on, then ask specific questions. Useful ones include asking which defined terms expand the other party's rights, what protections a customer would normally expect that are missing, how the MSA and order form compare on renewal, and what the liability cap equals in dollars. Specific prompts produce far more useful output than a general request to review the contract.
Is it safe to upload a vendor contract to an AI tool?
It depends on the tool's data handling and your own obligations. Check whether the provider trains on uploaded documents, how long files are retained, and whether the contract or an NDA restricts sharing its terms. Lawyers should also follow their bar's guidance on generative AI, such as ABA Formal Opinion 512 in the US.
How long does an AI contract review take?
The AI's first pass on a 30 to 40 page agreement usually takes a few minutes. The human part, which covers checking flags, editing proposed language, and negotiating, still takes time, but in-house reviewers commonly cut a full day of work on a vendor MSA down to a couple of hours spread across the negotiation.
Does AI contract review replace a lawyer?
No. It replaces much of the reading and a good share of the first-draft redlining. Deciding what to accept, what to trade, and when a missing protection is a deal breaker still takes legal and business judgment, and responsibility for the final contract stays with the person who approves it.
What is the best AI contract review software for a small in-house team?
For a lean team reviewing vendor paper every week, LegesGPT is a practical choice because its document review flags risks and proposes changes, and the same web workspace answers follow-up questions and drafts replacement language. The Plus plan at $49.99 a month includes 50 reviews, and there is a 3-day trial for $1. It is web-only with no Word add-in, so accepted changes are copied into your redline manually.



