The Truth About AI Vendor Contracts: What NJ Small Firms Keep Signing Without Reading
Photo by Tingey Injury Law Firm on Unsplash
6 min readSeptember 20, 2026

The Truth About AI Vendor Contracts: What NJ Small Firms Keep Signing Without Reading

AI Vendor ContractsNJ Law Firm Data SecurityLegal Ethics

AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published September 20, 2026. Reviewed September 20, 2026.

Most AI vendors don't hide the risky stuff. They just bury it in a 47-page terms of service document that nobody reads before clicking "Start Free Trial."

For a solo attorney in New Jersey, that click can have real consequences. The NJ Rules of Professional Conduct don't carve out exceptions for software agreements you skimmed. If a vendor's contract allows them to train their models on your uploaded documents, or store your client data on servers outside the United States with no notice requirement, that's your problem, not theirs.

Here's what to actually look for before you sign.

The Training Data Clause (and Why It's Not Always Obvious)

The most widely discussed risk is also the most misunderstood. Most attorneys know to check whether a vendor uses their data to train AI models. But the relevant clause rarely says "we will train our AI on your files." It says something like:

"You grant [Vendor] a non-exclusive, worldwide, royalty-free license to use, reproduce, and process your Content to provide, maintain, and improve the Services."

"Improve the Services" is the phrase that does the work. In vendor parlance, that frequently includes model training. Check whether the vendor has a separate "Data Processing Addendum" (DPA) or enterprise agreement that overrides this language. For many legal-specific tools like Clio, Harvey, or CoCounsel, a DPA exists and should be explicitly requested and executed before you upload a single client file. For general-purpose tools like ChatGPT or Gemini, you often need to be on a paid plan with specific settings enabled to opt out of training use entirely.

Uploading a client's financial documents into a free-tier tool with default settings active is not a theoretical ethics risk. It's a concrete one under RPC 1.6.

Data Residency: The Question Most NJ Attorneys Forget to Ask

Where does your client data actually sit? Not where the company is headquartered. Where are the servers?

Many AI vendors use AWS, Google Cloud, or Azure infrastructure that spans multiple countries by default. If your vendor doesn't specify "U.S.-only data residency" in the contract or DPA, your data may be routed through or stored in the EU, India, or elsewhere. That matters practically if you're handling clients in regulated industries (healthcare, finance, immigration) and it matters ethically because you've made representations about data protection you may not be able to keep.

Ask specifically: Is data processing limited to U.S.-based servers? Is that guaranteed in writing? Some vendors will add a U.S.-only data residency addendum on request. Many won't. That answer tells you something.

What "SOC 2 Compliant" Actually Means (and Doesn't)

Vendors love to advertise SOC 2 Type II compliance as a security credential. It's meaningful, but it's not a blanket assurance. SOC 2 is an audit framework that evaluates a vendor's internal controls around security, availability, processing integrity, confidentiality, and privacy. A SOC 2 Type II report tells you those controls worked during the audit period, for the scope the auditor examined.

It does not tell you:

  • Whether your specific data workflow falls within that scope
  • Whether subprocessors (the vendors your vendor uses) are similarly audited
  • Whether the report is current (ask for the most recent one, dated)

Before you treat a SOC 2 badge as due diligence done, request the actual report summary and ask whether the vendor's use of your firm's data sits within the audited scope. A reputable vendor will answer this without hesitation.

Subprocessors: The Vendors You Didn't Know You Agreed To

Almost every AI vendor uses subprocessors: third-party services for hosting, analytics, customer support, or authentication. Your vendor's terms of service typically authorize them to share your data with subprocessors, often with a clause that says they'll maintain a public list you can check.

The problem is that "check the list" is not the same as "get notified before a new one is added." Some vendor agreements allow subprocessors to be added at any time with notice only by updating a webpage you'll never visit. Look for language guaranteeing advance notice (30 days is reasonable) before a material new subprocessor is introduced. If you're handling sensitive client data, that window gives you the opportunity to object or migrate.

Breach Notification: The Timing Gap

New Jersey has its own data breach notification law (N.J.S.A. 56:8-163), which requires notification to affected residents "in the most expedient time possible" after discovery. Your AI vendor's contract may specify a longer notification window to you, sometimes 72 hours, sometimes 30 days. If the vendor's timeline is longer than the state's requirement, you're the one holding the compliance obligation with no information to act on.

Negotiate for a 48-hour vendor notification requirement in writing, or accept that you're carrying that risk.

A Practical Starting Point

Before your next AI vendor agreement, run through four questions: Does the contract restrict training use in a DPA I've signed? Is U.S. data residency confirmed in writing? Have I seen the current SOC 2 report? Does the breach notification timeline fit New Jersey's legal requirement?

If you can't answer all four, the contract isn't due diligence complete. The NJ State Bar Association's Law Practice Management department has resources on vendor evaluation, and the ABA's Formal Opinion 477R on cloud services remains a useful reference for the underlying competence framework. Neither replaces reading the actual terms before you click agree.

Get the weekly roundup

New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.