The Truth About AI Vendor Contracts That Most NJ Solo Attorneys Sign Without Reading
AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published September 5, 2026. Reviewed September 5, 2026.
You signed up for an AI legal tool last quarter. Maybe it was a document drafting assistant, a contract review platform, or a research add-on. You clicked through the terms of service in about forty seconds and got to work.
That's the norm. It's also a problem.
AI vendor contracts, specifically the terms of service and data processing agreements (DPAs) that govern nearly every SaaS tool a solo attorney might use, contain provisions that can directly conflict with your obligations under New Jersey's Rules of Professional Conduct. And unlike a client engagement letter you'd scrutinize line by line, these agreements get treated like a phone app update.
Here's what actually deserves your attention.
Training Data Clauses Are the Biggest Risk You're Not Thinking About
The single most consequential provision in most AI vendor agreements is whether the vendor reserves the right to use your inputs to train or improve its models. Several widely marketed legal AI tools, when you read the fine print, do exactly that unless you affirmatively opt out, upgrade to an enterprise tier, or sign a separate DPA.
If you paste a client's contract, deposition summary, or intake notes into a tool that trains on your inputs, you've potentially disclosed confidential information to a third party without client consent. Under NJ RPC 1.6, confidentiality obligations attach to any information "relating to the representation," regardless of whether it's technically privileged. The vendor's privacy policy doesn't cure that.
Before you use any AI tool for client work, find the answer to one specific question: does this vendor use my inputs for model training, and if so, how do I turn that off? If the answer isn't clearly stated in the DPA or terms, assume the worst and ask their sales team in writing.
Business Associate Agreements Matter Even When You're Not a Health Lawyer
If you do any work that touches protected health information (PHI), including personal injury, workers' comp, or employment matters where medical records appear, you need a Business Associate Agreement (BAA) with your AI vendor before that data ever touches their platform. Most consumer-tier AI tools don't offer a BAA at all. Some enterprise tiers do, but only on request.
This is a HIPAA issue that runs parallel to your RPC obligations. The two frameworks reinforce each other. The absence of a BAA doesn't just create regulatory exposure; it's exactly the kind of unauthorized disclosure that can generate a grievance with the Office of Attorney Ethics.
Data Residency Is a Real Question, Not a Technical Footnote
Where does your data actually live? Many AI vendors route inputs through cloud infrastructure that spans multiple countries. That matters for two reasons. First, data stored outside the United States may be subject to foreign government access requests that you can't predict or control. Second, some enterprise clients, particularly those in regulated industries, will ask you directly where their matter data is processed.
If you can't answer that question, you're already behind on your competence obligations under RPC 1.1, which the New Jersey Supreme Court's Committee on Attorney Advertising and the broader bar ethics apparatus have increasingly read to include technology choices that affect client data security.
Look for a vendor's "data residency" or "infrastructure" documentation. If it's not publicly available, that's a red flag.
What a Minimally Acceptable Vendor Agreement Actually Looks Like
You don't need to be a transactional attorney to run a basic review. A vendor agreement that's acceptable for NJ solo practice client work should do four things:
It should clearly prohibit training on your inputs by default, with no opt-out required on your end. It should offer a DPA that you can execute before using the tool for client matters. It should identify where data is stored and processed. And it should commit to notifying you of a breach within a defined timeframe, typically 72 hours or sooner.
If a vendor can't produce a DPA on request, that's your answer. Move on.
The Fee Angle Nobody Mentions
There's a practice economics dimension here that's easy to overlook. When you pay for an AI tool at the consumer tier to save money, you're often implicitly paying with your clients' data. Enterprise tiers cost more but typically include the data protections that actually make the tool ethically usable for client matters.
That cost differential should be factored into your overhead and, where appropriate, into how you structure flat fees or technology surcharges. Attorneys who skip the enterprise tier to save $30 a month and then use the tool for client work are making a false economy.
Before you renew any AI subscription this year, pull up the DPA, find the training data clause, and confirm the data residency. That thirty-minute review is more consequential than most CLE hours you'll log.
Get the weekly roundup
New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.