Four Contract Questions Before You Sign Any AI Tool

Standard SaaS agreements are not neutral documents. They are written by vendor legal teams whose job is to protect the vendor, and small business founders sign them without the legal capacity to know what they are giving up. OECD and GPAI research found that 27% of SMEs avoid available AI support because they see a mismatch between what vendors offer and what they actually need: control, simplicity, and predictability. The contract is where that mismatch becomes permanent.
The strongest argument against this checklist
The sharpest objection to asking these four questions is not that they are wrong. It is that they are inert. A five-person business asking "who owns the training data?" and receiving an unsatisfactory answer has no realistic path to renegotiation. The vendor will not rewrite standard terms for a single small account. The founder cannot afford the legal counsel required to pursue alternatives. Awareness of a problem without a remedy is not protection.
This objection stands. The checklist does not give you negotiating leverage you do not already have.
What it gives you is something cheaper and more useful at the moment you still have it: the choice to walk away before your data is embedded. The research documents that technical and contractual frictions make exits expensive by default, and that proprietary data formats compound switching costs over time. The cost of asking these questions before signing is near zero. The cost of asking them after eighteen months of customer data sits in a vendor's proprietary format is not.
What each question is actually testing
"Can I export my data?" is not a technical question. It is a test of whether the vendor has built an exit path or a trap. Proprietary formats that cannot be exported to standard file types are documented in EU cloud switching research as the primary mechanism through which switching costs become prohibitive.
"Who owns the training data?" targets a legal gap that existing compliance frameworks did not anticipate. Generative AI models absorb user inputs and generate outputs with uncertain intellectual property status. The research is explicit: AI-specific ownership questions intensified with generative AI in ways that predate the regulatory frameworks founders are often told provide adequate safeguards. A contract that grants the vendor broad rights over inputs you feed the model is a contract that transfers your operational knowledge to a competitor's training dataset. [Inference: the research documents the legal uncertainty and the contractual pattern, but does not study specific cases of competitive harm from training data transfer in SME contexts.]
"What happens if they shut down?" sounds catastrophic and therefore easy to dismiss. It should not be. The research traces a decade-long pattern of SME lock-in concerns across cloud adoption studies. Vendors shut down, get acquired, or discontinue products. A contract with no data return clause on termination leaves you with no legal basis to retrieve what you built.
"Can I switch tools easily?" is the question that reveals whether the first three answers were honest. A vendor confident in its product does not need proprietary formats and punitive exit terms to retain customers. I find vendors who resist this question specifically more suspect than those who fumble the training data question, because the training data question is genuinely legally complex, while the portability question has a simple answer that either exists in the contract or does not.
What you do with a bad answer
If a vendor cannot answer these questions in plain contract language, that is the answer. You are not looking for a guarantee of perfect terms. You are looking for evidence that the vendor has thought about your exit, not just your onboarding.
The 27% of SMEs who avoid AI support because of misaligned needs are not being irrational. They are correctly identifying that generic AI tools are built for generic customers, and that the contracts reflect the same indifference. The four questions do not fix the power asymmetry between a small founder and a large vendor. They do tell you, before you sign, whether the asymmetry is one you are willing to accept.

Read next

Human-Centered Transformation
Vendor Contracts Are Where AI Lock-In Starts
Before you sign an AI development contract, ask these questions about data ownership, model transparency, compliance certifications, and exit terms — or find
3 min read

Human-Centered Transformation
Three Questions That Cut the AI Vendor List Down Fast
SMBs evaluating AI tools face real legal and operational risk if they skip data compatibility, privacy control, and integration checks. Here's the filter that
3 min read

AI as Strategy
Four AI Guardrails Every Small Business Needs Now
Most small businesses run AI tools on informal rules or none at all. Here are four specific controls that close the failure points where real harms occur.
3 min read