NexBDM

NexBDM Blog

AI Contract Review: what to check before you let a model read an agreement

By NexBDM Team · 2026-09-19

AI contract review is a good first reader and a bad last one. Before the upload, read the agreement's confidentiality clause, read the provider's terms for the plan you are actually on (OpenAI, Anthropic and Google, read 19 September 2026), and redact the personal information POPIA covers. Then give the model a checklist and demand quotes.

AI contract review means handing an agreement to a language model to summarise it, pull out key terms and flag what is missing or one-sided. Before you upload one, check three things: whether the agreement's own confidentiality clause allows it, what the tool's terms say about training and retention, and whether the document contains personal information, which brings POPIA in.

The demand is real and it has a shape. Google's autosuggest for "ai contract review", pulled from South Africa on 19 September 2026, returns ten suggestions, and three of them add the word "free". That matters more than it looks, because the free consumer tiers of the big model providers are exactly where the training and retention defaults need reading before a client's agreement goes in. This post covers what a model can and cannot do with a contract, the three checks that come before the upload, what each of the three big providers' terms actually said when read today, and the review checklist worth giving the model once you are clear to proceed. Where a document must end up signed, electronic signatures in South Africa covers the law, and AI and POPIA covers the Act in full.

Key takeaways

  • A model reviewing a contract is a third party reading it. If the agreement's confidentiality clause bars disclosure to third parties without consent, the upload is a disclosure. Read that clause first.
  • The provider's terms decide whether your upload trains their next model. Read on 19 September 2026: OpenAI does not train on business and API data by default but does use "data from versions of ChatGPT and other services for individuals"; Anthropic's Commercial Terms say it "may not train models on Customer Content", while Free, Pro and Max users choose; Google asks Gemini users not to enter confidential information they would not want a reviewer to see.
  • If the agreement names a natural person, their ID number, address, bank details or signature, POPIA applies. The provider becomes your operator under section 20 and you need the section 21 written contract and a section 72 answer for offshore hosting.
  • A model can summarise, extract, compare against your checklist and flag what is missing. It cannot sign, it cannot tell you your negotiating position, and it is not legal advice.
  • The review gets faster and safer when your own standard clauses live in a template library and every agreement sits on the client's record, so the model compares against your standard instead of reading from a blank page.

What can AI contract review actually do?

Four jobs, and it does them well when the document is clean and the instructions are specific.

  1. Summarise. Parties, term, what is being bought, what it costs, when it can be ended. A twenty-page agreement becomes a page you can read before a call.
  2. Extract. Every date, every notice period, every amount, every defined term, into a table. This is where a model beats a tired human reader: it does not skip the schedule at the back.
  3. Compare. Given your own standard position on each clause, it reports where the draft in front of you differs. This is the most useful of the four and the one almost nobody sets up, because it needs you to have written your standard down first.
  4. Flag. What is missing (no limitation of liability, no data protection clause, no termination for convenience), what is one-sided, and where a defined term is used but never defined.

What it does badly is anything that needs facts outside the document: whether the counterparty is good for the money, whether the indemnity is normal for your industry, whether you can afford to walk away. It also makes things up. A Stanford and Yale study submitted in May 2024 tested the legal research tools from two of the largest legal publishers, whose marketing described them as "hallucination-free", and found they still "hallucinate between 17% and 33% of the time". That study is about legal research, not contract review, and general models have improved since. The point survives the date: a vendor claim of accuracy is a claim, and the person who signs still reads the clause the model quoted, in the document, before relying on it.

Does the agreement allow you to upload it?

This is the check most guides skip, and it comes before any question about the tool. An agreement that a counterparty sent you, an NDA in particular, usually carries a confidentiality clause. It defines confidential information, it says you may not disclose it to third parties, and it lists exceptions: your employees who need to know, your professional advisers, a court order.

Read three things in that clause before the file goes anywhere.

  • What counts as disclosure. Most clauses do not define it narrowly, so making the document available to a company whose staff or systems can read it is a disclosure, whether or not a person at that company ever opens it.
  • Who the carve-outs cover. "Professional advisers" is your attorney and your accountant. A software vendor is not a professional adviser. Some newer clauses add "service providers bound by confidentiality obligations no less strict than these", and that wording is what makes a model provider on business terms arguable.
  • Whether the agreement itself is confidential. Some NDAs also say the existence and terms of the agreement are confidential, which means the document you want reviewed is inside its own definition.

If the clause bars third-party disclosure without written consent and there is no service-provider carve-out, the honest options are to ask the counterparty for consent, to review it without a model, or to strip it to the clauses you need checked with every name and figure removed. The provider's privacy commitments do not rewrite a clause you already signed.

What do the tools' own terms say about your upload?

The free tier is where most small businesses will do this, so the consumer terms are the ones that matter. All three providers' pages were read on 19 September 2026. Every quoted phrase is the provider's own wording.

ProviderBusiness plans and APIFree and individual plans
OpenAI (enterprise privacy page) "By default, we do not use your business data for training our models." Applies to ChatGPT Business, Enterprise, Edu, Teachers and the API Platform, "unless you have explicitly opted in". The same page, on training sources: "We also use data from versions of ChatGPT and other services for individuals." The individual plans carry a setting for this; the default is the thing to check.
Anthropic (Commercial Terms effective 17 June 2025; consumer update of 28 August 2025) "Anthropic may not train models on Customer Content from Services." Covers Claude for Work (Team and Enterprise), the API and the cloud marketplaces. Free, Pro and Max users are given "the choice to allow their data to be used to improve Claude". With the setting on, retention is five years; with it off, retention stays at the "existing 30-day data retention period". Deleted conversations are not used for training.
Google (Gemini Apps Privacy Hub) Work and school accounts fall under separate Workspace terms; the consumer hub points there and does not describe them. "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services." A subset of chats is reviewed by human reviewers, and chats that were reviewed "are retained for up to three years" even after you delete your activity. With Keep Activity off, chats are kept for 72 hours and not used to improve the models; temporary chats are "not used to train Google's AI models".

Two things follow from the table. First, the sentence "not used for training by default" belongs to the business plans and the API on all three, and on two of the three it belongs nowhere else. Second, the setting that turns training off on a consumer plan is per account, not per document, and the person reviewing the contract may not be the person who set up the account. On a free plan, the default and the retention period are the product. Read them before the upload, not after.

When does POPIA come into it?

Most commercial agreements contain personal information about a natural person: a sole proprietor's ID number, a director's home address, an employee's salary and bank details in an employment contract, a signature. The moment that document goes to a model provider, three sections of POPIA apply, and they are set out in full in AI and POPIA.

  • Section 20. The provider is your operator. It may process the information "only with the knowledge or authorisation of the responsible party" and must treat it as confidential. Your instruction to the tool is the authorisation, so a tool whose terms let it use the input for its own purposes is processing beyond it.
  • Section 21(1). You must, "in terms of a written contract between the responsible party and the operator", ensure the operator maintains the section 19 security measures. Clicking accept on a consumer plan is a contract; whether it says what section 21 needs is the question the table above answers.
  • Section 72. The model is almost certainly hosted outside South Africa, so a transfer to a foreign third party is happening. Terms that commit to confidentiality, purpose limitation and restrictions on onward use are the binding-agreement route in 72(1)(a). Terms that allow training on your input make that route harder to argue.

The practical move is the one in the AI vendor checklist: redact what the review does not need. A model checking a limitation-of-liability clause does not need the director's ID number on page one.

What should the model check for you?

Once the three checks are clear, give the model a checklist rather than an open question. "Review this contract" produces a summary. A checklist produces a review. This is the one that covers most commercial agreements a small business signs.

ClauseWhat to ask the model to report
Parties and authorityExact legal names and registration numbers, and whether the signatory is stated to have authority.
Term and terminationStart date, initial term, renewal mechanism, notice period to end it, and whether either side can terminate for convenience.
PaymentWhat is payable, when, in which currency, what happens on late payment, and whether prices can change during the term.
Deliverables and acceptanceWhat exactly is being delivered, how acceptance is tested, and what happens if it fails.
Liability and indemnityWhether liability is capped, at what, what is excluded, and who indemnifies whom for what.
Intellectual propertyWho owns what is created, whether a licence is granted back, and whether pre-existing IP is protected.
ConfidentialityDefinition, duration, carve-outs, and whether the agreement itself is confidential.
Data protectionWhether personal information is processed, who is responsible party and who is operator, and whether cross-border transfer is addressed.
Dispute resolutionGoverning law, jurisdiction or arbitration, and whether either side must attempt mediation first.
GapsDefined terms used but never defined, blanks, schedules referred to but not attached, and clauses that contradict each other.

Ask for every finding as a quote from the document with the clause number. A finding without a quote is a guess, and the study above is the reason to insist.

What can a model not do with a contract?

  • Sign it. Under ECTA an electronic signature is valid for almost everything, and only four documents cannot be signed electronically. The signature still has to be yours, applied by you, with a record of who signed what and when. A model has no signing authority and no identity.
  • Advise you. It can tell you a clause is unusual. It cannot tell you whether to accept it, because that depends on the deal, the relationship and what you can afford to lose.
  • Know the other side. Nothing in the document says whether the counterparty pays on time. That is a question for your own records and a reference, not the model.
  • Be the record. A chat window is not a filing system. The reviewed version, the changes you asked for, the version you signed and the date you signed it belong with the client, not in a conversation history that the provider's retention setting may delete or keep for years.

How this stops being a manual job

The review itself is the small part. The work around it is what eats the afternoon: finding the last version, remembering what you agreed with this client last time, sending it for signature, chasing the signature, filing the signed copy where the next person can find it. That is the part to systemise.

  • Write your standard down once. Your position on each clause in the checklist above, in a template library. The model's third job, compare, only exists once this does, and every review after that is a diff against your own standard rather than a fresh read.
  • Keep the agreement on the client record. Every version, every review note, every signed copy, attached to the client in your CRM, so the question "what did we agree with them" has one answer.
  • Send for signature from the same record. NexSign sends the final version for electronic signature and stores the signed copy with the client, with the audit trail ECTA expects, so nothing lives in an inbox.
  • Let the review read from the system, not from a drag-and-drop. When the agreement is already on the record, the redacted review copy can be produced from it, and the personal information the model does not need never leaves the system in the first place.

Frequently Asked Questions

Is it safe to upload a contract to ChatGPT or Claude?

It depends on the plan and the clause. Business plans and the API are not used for training by default on both; the individual plans carry a setting. Check the agreement's confidentiality clause first, because the provider's terms do not override it.

Can AI contract review replace a lawyer?

No. It replaces the first read: summary, extraction, comparison against your checklist and a list of gaps. Deciding what to accept, what to push back on and what the risk is worth is judgement about your business, which the model does not have.

Does POPIA apply when I upload an agreement to an AI tool?

If the agreement contains information about an identifiable natural person, yes. The provider is your operator under section 20, section 21 requires a written contract that covers security, and section 72 governs the transfer to a provider hosted overseas.

What should I remove from a contract before AI review?

Anything the review does not need: ID numbers, home addresses, bank details, signatures and, if the confidentiality clause requires it, the parties' names. The model can check a liability cap without knowing who the director is.

Can an AI tool sign a contract for me?

No. An electronic signature under ECTA must be applied by the person signing, with a record of who, what and when. A model has no identity and no authority. Use a signing tool that keeps that audit trail and stores the signed copy with the client.

The short version

AI contract review is a good first reader and a bad last one. Before the upload: read the confidentiality clause, read the provider's terms for the plan you are actually on, and redact the personal information the review does not need. Then give the model a checklist and demand quotes. If you want to know which of your agreements are being reviewed in a free chat window today, where your standard clauses actually live, and what it would take for every contract to sit on the client record from first draft to signed copy, that is what a Business Autopsy maps, and a discovery call is where it starts.

Sources, read directly on 19 September 2026: OpenAI, "Enterprise privacy" (training defaults for business plans and the API, and the sentence on individual services under "What sources of data are used for training OpenAI models?"); Anthropic, "Commercial Terms of Service", effective 17 June 2025 (section B, Customer Content); Anthropic, "Updates to Consumer Terms and Privacy Policy", 28 August 2025 (Free, Pro and Max training choice and retention periods); Google, "Gemini Apps Privacy Hub" (human review, the confidential-information warning, retention with Keep Activity off, temporary chats); Magesh et al., "Hallucination-Free? Assessing the Reliability of Leading AI Legal Research Tools", arXiv 2405.20362, submitted 30 May 2024; Protection of Personal Information Act 4 of 2013, sections 19, 20, 21 and 72, as quoted in our AI and POPIA guide; Google autosuggest for "ai contract review", client firefox, gl za, pulled 19 September 2026. Every quoted phrase is the publisher's own wording. No figure in this post is a price.

Published on nexbdm.agency. Want this applied to your business? Run the free Autopsy diagnostic →