The Vendor Contract Your AI Tool Sent You Was Not Written With Your NJ Clients in Mind
AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published July 26, 2026. Reviewed July 26, 2026.
You found an AI tool that looks promising. Maybe it drafts motions, summarizes depositions, or auto-fills court forms. You click through the signup flow, hit "I Agree," and get to work. That moment, the one that takes about four seconds, is where a surprising number of NJ attorneys quietly hand over significant control of their client data.
Vendor contracts for AI legal tools are not neutral documents. They are written by the vendor's legal team to protect the vendor. That's not a criticism; it's just reality. Your job is to figure out whether what they've drafted is compatible with your obligations under New Jersey's Rules of Professional Conduct before you start uploading anything.
What the Fine Print Usually Says
Most AI vendor agreements contain at least three categories of clauses that deserve your attention.
Training data provisions. Some vendors reserve the right to use inputs, meaning the text you paste in or upload, to improve their models. A few have moved to opt-out systems rather than opt-in. If the default is that your submissions feed the training pipeline, you need to turn that off or confirm it's off. Uploading a client's contract or deposition transcript to a tool that ingests it for model training is a confidentiality problem under RPC 1.6, full stop. Check the data processing addendum, not just the main terms of service. The training carve-out is almost never in the primary agreement.
Data residency. Where does your data sit? On which servers, in which countries? This matters less for purely domestic litigation but becomes a real issue in matters touching export-controlled information, healthcare records, or any client who has expressed concerns about foreign access to their files. If the vendor's infrastructure runs entirely through data centers in the EU or Asia-Pacific, that's worth knowing. A simple email to vendor support asking "where is my data stored and processed" is not an unreasonable request, and a vendor who can't answer it clearly is a vendor you should think twice about.
Breach notification timelines. Compare what the vendor contract promises against what NJ's data breach notification law (N.J.S.A. 56:8-163) actually requires. The state mandates "expedient" disclosure to affected New Jersey residents and requires notification to the Division of Consumer Affairs in certain circumstances. If your vendor's contract gives them 72 hours to notify you of a breach, but you have obligations that kick in faster under state law, that gap is your problem, not theirs. Negotiate for faster contractual notification or at minimum document that you've flagged the discrepancy.
The Clauses You Should Push Back On
Solo attorneys often assume they have no leverage with large SaaS vendors. Sometimes that's true. But "no leverage" doesn't mean "no obligation to try." Document your outreach. If a vendor refuses to modify a problematic training data clause, that refusal is relevant to your competence analysis under RPC 1.1 when you're deciding whether to use the tool at all.
A few specific asks that are reasonable and, in many cases, granted:
- Request a data processing addendum (DPA) if one isn't offered by default. Many GDPR-era vendors have these ready; they just don't advertise them.
- Ask for written confirmation that your firm's inputs are excluded from model training, and get the confirmation in an email you can save.
- Request the vendor's most recent SOC 2 Type II report. A SOC 2 Type II audit evaluates whether a vendor's security controls actually operated effectively over time, not just whether they exist on paper. A Type I only tells you the controls were designed correctly at a single point in time. If a vendor offers you a Type I and calls it equivalent, that's worth noting.
- Ask whether they will sign a Business Associate Agreement (BAA) if you ever handle health-related matters. If the vendor flatly refuses to sign a BAA, that's a hard stop for any work touching PHI.
A Practical Starting Point for NJ Solos
Before you sign up for another AI tool, build a one-page checklist into your intake process for new vendors. At minimum it should capture: who controls training data, where data is stored, what the breach notification timeline is, and whether the vendor will provide a DPA. Keep a copy of each vendor's terms as of the date you signed, because those terms can change.
The New Jersey Lawyers' Fund for Client Protection and the NJSBA's ethics hotline can't vet your vendor contracts for you. That's your work. But it's also not a heavy lift, one focused hour reviewing a vendor agreement is far less painful than explaining a data exposure to a client.
If a vendor's contract is genuinely non-negotiable and contains terms that conflict with your RPC obligations, you have two options: find a different tool, or document why you concluded the risk was acceptable and what mitigations you put in place. Undocumented acceptance of a bad contract is the one outcome you want to avoid.
Get the weekly roundup
New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.