AI in Business: Why Terms of Use Are Not Enough to Ensure Legal Certainty for Companies

AI tools have entered business operations much faster than companies have been able to regulate the rules for their use. In practice, it is increasingly common for employees, agencies, developers, consultants or other external associates to use AI in the creation of materials for a client, while the relevant contract and the company’s internal rules remain silent on the matter.

At first glance, the issue may appear to be technical: which tool was used, whether the result is of sufficient quality and whether it can be commercially used. However, the legal risk most often arises later — when the company wishes to transfer that result to a client, incorporate it into software, use it in a campaign, protect it as part of a brand, present it to an investor or release it for public use.

At that point, what matters is not only what AI has produced, but also who controlled the process, which data were entered into the tool, whether the use of AI was permitted, who warrants the legality of the result and who bears the risk if a third party challenges the content, code, design or other work product.

For this reason, the use of AI tools in business cannot be reduced to reviewing the platform’s general terms of use. A company needs its own contractual and internal framework regulating how AI is used, who uses it, with which data, for which purpose and subject to which allocation of responsibility.

Why the General Terms of AI Tools Are Not Enough

Companies often assume that the legal issue is resolved if the terms of use of a particular AI tool allow the commercial use of generated content. This is important, but it is not sufficient.

The platform’s general terms regulate the relationship between the user and the provider of the AI tool. They do not automatically resolve the relationship between the company and its client, the employer and employee, the client and the agency, or the company and an external developer or consultant.

In other words, the platform’s permission to use a particular result does not necessarily mean that the company has properly regulated ownership of the work product, confidentiality of data, transfer of rights to the client, liability for infringement of third-party rights or restrictions on further commercial use.

The legal risk is therefore assessed not only by reference to which AI tool was used, but also by reference to who used it, with which data, for whose account, at which stage of the project and what is subsequently done with the work product.

AI in the Employer–Employee Relationship

The first level of control concerns the internal use of AI tools by employees.

Employees may use AI tools to prepare draft documents, analyses, tables, presentations, software code, client responses or internal materials. The problem arises when such use takes place without the employer’s knowledge, without clear rules and without an assessment of which information may be entered into an AI system.

A company should know whether employees are permitted to use AI tools, which tools they may use, for which types of tasks, whether prior review is required and which data must never be entered into publicly available tools.

Business secrets, client data, contracts, financial data, source code, technical documentation, databases, internal strategies and other materials with commercial or confidential value are particularly sensitive.

If an employee enters such data into an AI tool without clear rules, the company may lose control over information it was required to protect. Depending on the circumstances, the consequences may be contractual, regulatory, reputational and commercial.

Therefore, internal rules on AI tools should not be treated as a general recommendation, but as part of a broader system for protecting confidential information, trade secrets, personal data and intellectual property.

AI in Contracts with Agencies, Freelancers and Developers

A specific risk arises where AI tools are used by external associates — marketing agencies, designers, copywriters, developers, consultants, production companies or other service providers.

In such relationships, it is not sufficient for the contract to provide only that a particular material, software, campaign, analysis or other work product will be delivered to the client. It is also necessary to regulate whether the use of AI tools is permitted, to what extent and subject to which allocation of responsibility.

In practice, the most important questions are the following: whether the service provider may use an AI tool, whether it must notify the client of such use, whether it may enter the client’s materials into an AI system, who warrants the legality of the work product, who is liable for infringement of third-party rights and which scope of rights is transferred to the client.

These questions are particularly important in software development, marketing campaigns, branding, design, creation of visuals, content creation, production, consultancy services and other projects in which the work product has economic value and is intended for further commercial use.

Legally unregulated use of AI tools may result in the client factually receiving the delivered work product, but not the level of legal certainty required to use, transfer, protect or further commercialise that work product.

The Right of Use Is Not the Same as Ownership

In business practice, the right of use and ownership of a work product are often conflated.

The fact that a party may use certain AI-generated or AI-assisted content does not necessarily mean that it owns copyright in that content, nor that it may transfer it to a third party without limitation. Similarly, the fact that content was created within a business project does not in itself mean that all relevant rights have been duly transferred to the client.

This is particularly important where the company uses the work product as part of software, a product, campaign, visual identity, investor presentation, client material or public communication.

The contract should therefore distinguish several levels: permission to use AI tools, the right to use the work product, the transfer or licensing of intellectual property rights, liability for the legality of the result and protection of confidential information used in the creation process.

If these issues are not clearly regulated, the dispute usually does not arise at the moment when the material is created, but later — when the client wishes to use it on a broader scale, incorporate it into a product, sell it, transfer it, protect it, present it to an investor or use it in a public campaign.

Who Bears the Risk if AI-Generated Content Infringes Third-Party Rights

One of the most important contractual issues is liability for infringement of third-party rights.

An AI tool may generate text, an image, design, code, slogan, musical work or other content that is similar to an existing copyright work, trademark, design, brand identity or other protected subject matter. In a commercial context, it is not sufficient to rely on the explanation that the content was “generated by AI”.

A company that uses such content towards the public, clients or users may be the first to face a third-party claim, even if the content was previously created by an agency, freelancer, developer or other external associate.

Contracts should therefore contain clear rules on who reviews the work product, who provides warranties regarding its originality and legality, who bears the risk in the event of third-party claims and how liability is allocated between the contracting parties.

Not every project is the same, and contractual protection should not be the same either. One level of control may be sufficient for an internal draft presentation, but it will not be sufficient for software code delivered to a client, a visual identity used publicly, a marketing campaign, documentation containing confidential data or a product intended for further commercialisation.

AI clauses should therefore not be copied as a generic add-on to a contract. They must be tailored to the type of project, the role of the contracting parties, the data being processed, the expected transfer of rights, the level of confidentiality and the actual risk of third-party claims.

AI in SaaS and Vendor Agreements

Particular attention should be paid to agreements with providers of software, cloud, SaaS and AI solutions.

In such relationships, the question is not only whether the company uses an AI tool, but also what the vendor does with the company’s data. It is necessary to understand whether the data are used for training or improving the model, where they are processed, who has access to them, how long they are retained, whether they can be deleted, whether certain processing activities can be excluded and which level of security the vendor guarantees.

In these agreements, it is particularly important to review the regime governing confidentiality, personal data protection, intellectual property rights, subcontractors, location of data processing, limitation of liability, termination rights and post-termination obligations.

In practice, the most important risks are often not visible from the basic commercial offer, but from technical schedules, data processing terms, privacy policies, security documentation and special terms of use.

For this reason, AI and SaaS agreements should not be treated merely as standard IT terms, but as agreements that may directly affect confidentiality, regulatory compliance, ownership of data and commercial use of work products.

The EU AI Act as an Indicator of Regulatory Direction

Although the Republic of Serbia is not a member of the European Union, the EU regulatory framework is relevant for domestic companies that operate on the EU market, provide services to EU clients, use AI systems in cross-border business or develop products that may be made available to users in the EU.

The EU AI Act indicates a clear regulatory direction: the use of AI systems is increasingly becoming a matter of transparency, documentation, responsibility and control. Specific rules are envisaged for providers of general-purpose AI models, including obligations relating to transparency, documentation and compliance with copyright rules.

For companies using AI tools, this does not mean that they automatically become subject to all obligations applicable to providers of AI models. However, it does mean that clients, investors, business partners and regulators will increasingly expect a company to know which AI tools it uses, for which purposes, with which data and with what level of control.

Companies should therefore already be developing a basic contractual and internal framework for the responsible use of AI tools, even where certain regulatory obligations are not yet directly applicable.

What Companies Should Regulate

Companies using AI in their business should have clearly defined rules for several key areas.

First, the internal use of AI tools should be regulated: who may use them, for which purposes, with which types of data and subject to what level of control.

Second, the use of AI tools by external associates should be regulated: agencies, freelancers, developers, consultants and other service providers.

Third, rights in work products created with the assistance of AI tools should be regulated, including rights of use, transfer of rights, restrictions on use and liability for the legality of such results.

Fourth, it is necessary to regulate the protection of confidential information, trade secrets, personal data, source code, databases and other information that must not be entered into AI systems in an uncontrolled manner.

Fifth, the terms of use of specific AI, SaaS and cloud tools should be reviewed, particularly in relation to the processing of input data, rights in output, use of data for model training, data retention, subcontractors and limitation of liability.

These issues should not be regulated generically. Rules appropriate for a marketing campaign will not necessarily be sufficient for software development, personal data processing, work involving trade secrets or the creation of content that is subsequently transferred to a client.

Conclusion

AI tools can significantly improve business efficiency, but their use should not remain legally unregulated.

Companies using AI tools should understand that the risks do not relate only to technology, but also to copyright, confidentiality, trade secrets, data protection, contractual liability, third-party rights and the relationship with clients.

AI should therefore not be viewed merely as an operational tool, but as part of a broader system of legal, contractual and compliance control. In practice, this means that a company should have an appropriate internal policy, clear rules for employees, carefully drafted contractual clauses with external associates and verified terms of use for AI and SaaS tools.

Properly regulated use of AI tools may represent a significant business advantage. Unregulated use, however, may lead to ownership disputes, infringement of third-party rights, loss of confidential information, regulatory risks and reputational damage.

For this reason, timely legal regulation of the use of AI tools is becoming an increasingly important part of responsible business operations

Disclaimer:  This text is written for informational purposes only as well as to give general information and understanding of the law, not to provide specific legal advice. For any additional information feel free to contact us.