Artificial Intelligence
Artificial intelligence. Real liability.
A business that builds or deploys artificial intelligence usually runs it on a model someone else owns, feeds it data the business collected under privacy promises it made, and sells the result to customers who take the product’s claims at face value. Each of those relationships is governed by a contract or a statute, and the company whose name is on the product bears the exposure, whether the model comes from one of the major providers or an open weight release.
Hank advises founders launching AI products and businesses adopting AI tools on the vendor terms, privacy obligations, disclosures, and agreements that determine who owns what and who answers when something goes wrong. The first question for any AI product is what the provider’s terms permit.
Those terms, often in a commercial agreement separate from the data processing addendum, determine whether the provider may train on your customers’ data, how long it retains customer inputs and generated responses, and what you may tell customers about either. Hank reviews and negotiates those terms, matches them to what your privacy policy discloses, and drafts vendor disclosures, retention policies, and deletion procedures to address the privacy laws that apply to your business.
Children’s privacy requires a separate assessment. The Children’s Online Privacy Protection Rule applies to covered operators of websites and online services directed to children under 13 that collect personal information from them. It also applies to other covered operators with actual knowledge that they collect personal information online from children under 13. Information supplied by adults about children doesn’t, by itself, trigger COPPA. Hank advises on whether the Rule applies and on the consent, notice, retention, and security obligations that follow.
Under the amended Rule, covered operators must obtain separate verifiable parental consent before disclosing children’s personal information to a third party for AI training or development. Parents must be able to consent to collection and use without consenting to that disclosure. Hank reviews provider restrictions on training, advises on any required parental consent, and drafts the written retention policies and information security programs the Rule requires.
Product and marketing claims must be truthful, nonmisleading, and supported by appropriate evidence. Section 5 of the FTC Act applies to claims that a product uses artificial intelligence, performs a task with a stated accuracy, or verifies a user’s age or identity.
In In re Workado, LLC, the FTC’s 2025 final order addressed claims that an AI content detection product was 98% accurate. The order requires competent and reliable evidence supporting accuracy and efficacy claims. Hank reviews product and marketing copy for compliance with these advertising requirements.
Hank drafts development, training, and consulting agreements that define the deliverables, allocate ownership, and specify licenses for models, model parameters, training data, and other materials when you hire an outside developer. He also writes the internal policies that govern what employees may put into an AI tool.
Texas businesses covered by the Responsible Artificial Intelligence Governance Act must also comply with that statute, effective January 1, 2026, which prohibits specified uses of AI systems and amended the biometric identifier statute. California’s automated decisionmaking technology regulations apply to covered businesses beginning January 1, 2027.
Hank has counseled software and SaaS companies, consumer app developers, marketers, and the businesses that buy their products on how these rules apply before launch and after a regulator or a customer asks. Every engagement works toward the same result, an AI product or program you can describe accurately, contract for on terms you understand, and defend if challenged.
Services Include
- AI vendor and platform terms
- Children’s privacy for AI products
- Data retention and deletion programs
- Privacy policy and subprocessor disclosures
- AI marketing and product claims
- Development and training agreements
- Internal AI use policies
- Copyright and training data questions
Artificial Intelligence Insights
AI Vendor Terms, Training Rights, and What the Contract Has to Say
The terms governing an AI product’s model provider determine whether customer data may be used for training, how long prompts persist, and who answers for an infringing output. Those answers depend on the service, the agreement, and the settings your business uses.
Read articleCOPPA for AI Products That Serve Children or Process Their Information
COPPA treats information a child submits to an AI product differently from information an adult supplies about that child. The distinction determines the operator’s duties concerning consent, vendor contracts, notices, and retention.
Read articleData Retention and Deletion in AI Products
An AI product may retain customer information in uploaded files, saved conversations, generated responses, search indexes, vendor logs, and backups. A deletion request requires the business to identify the information covered by the request, determine where it is held, and apply the duties and exceptions that govern each location.
Read articlePrivacy Policy Accuracy for AI Products
An AI product’s privacy policy must describe what happens to personal information when the business and its vendors process it. Statements about model training, human access, retention, and deletion need to account for the services and settings the product uses.
Read articleAI Claims in Product and Marketing Copy Under Section 5 of the FTC Act
A claim that an AI product identifies fraud, achieves a stated accuracy, replaces a professional, or verifies a user’s age makes a factual promise about the product. Your business needs evidence that supports the promise before customers see it. That applies to claims in advertising, sales presentations, app listings, and the product’s interface.
Read articleInternal AI Use Policies for Businesses
A written AI use policy addresses how employees handle confidential information, use generated content, and evaluate people with automated tools. It identifies approved accounts, limits what employees may submit, and assigns responsibility for reviewing output and responding to incidents.
Read articleRelated Work
Ready to make the right legal move?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry