Use case assessment
Is AI contract review worth building?
Genuinely useful, and the boundary between extraction and advice is where this goes wrong.
Finding clauses and comparing them to a playbook is real AI doing real work. Deciding whether to accept a clause is not a job to hand over.
What it usually means
Reading incoming contracts and flagging what deviates from your standard positions: liability caps, termination rights, payment terms, data processing, governing law.
Is it genuinely AI?
Yes. The same clause is written twenty different ways and means the same thing. Keyword search on "limitation of liability" misses the one drafted as a carve-out buried in an indemnity. Semantic matching is the right tool.
The line that matters
There are two jobs here and only one should be automated.
Extraction and comparison — here is the liability cap, here is what your playbook says, they differ. That is a finding, it is checkable, and it saves a reviewer real time.
Judgement — whether this deviation is acceptable given the counterparty, the deal size and your risk appetite. That is advice, and a system that presents it as a finding will be believed.
The distinction is not academic. It is the difference between a tool that makes a lawyer faster and a tool that quietly replaces one.
What the simpler version looks like
A written playbook. Genuinely: many organisations proposing AI contract review do not have one document stating their standard positions and fallbacks. Without it there is nothing to compare against, and writing it is the majority of the value.
Do that first. You will find out whether your positions are actually agreed, which is often the real finding.
What it costs to run
Evaluation is the expensive part, and it needs legal time rather than engineering time. A labelled set of contracts with known correct extractions, maintained as your playbook changes. A false negative — a missed clause — is the failure that matters, and it is the one automated metrics catch least well.
Where it sits under the EU AI Act
Contract review is not an Annex III high-risk use. If you buy a tool and run it as delivered you are a deployer.
Two things to watch. Fine-tuning on your own contract corpus can constitute substantial modification under Article 25. And contracts contain personal data, so where they are processed is a GDPR question before it is an AI Act one.
When it is worth building
When contract volume is high, positions are documented, and legal will own the evaluation set. Buy rather than build unless your contract types are genuinely unusual.
Not to reduce legal headcount. The reviews that need judgement do not go away, and the ones that do not need judgement were not the expensive part.
Common questions
Can AI review contracts without a lawyer?
It can extract clauses and compare them to a playbook, which is checkable work. Deciding whether a deviation is acceptable is judgement, and a system that presents judgement as a finding will be believed when it should be questioned.
What do you need before building AI contract review?
A written playbook stating your standard positions and acceptable fallbacks. Without it there is nothing to compare against, and writing it usually surfaces that the positions were never actually agreed.
Is contract review high-risk under the EU AI Act?
No, it is not an Annex III use. But fine-tuning a purchased tool on your own contracts can be substantial modification under Article 25, and contracts contain personal data, which makes processing location a GDPR question first.
Scoring 40 AI use cases in a regulated enterprise — where the boundary between a finding and a judgement decided what got approved.