FISTA Solutions does not load Google Analytics until you accept. Rejecting keeps optional analytics off. Read the Cookie Policy.

All field notes

Leadership · 5 minute read

The General Counsel's Guide to AI and Agentic AI

General counsel governs agentic AI by establishing that the company remains accountable for what its agents do, contracting with AI vendors on data use, liability, and portability, mapping privacy and IP obligations to each use, maintaining a regulatory inventory by jurisdiction, and requiring the records that make decisions defensible. This is general guidance, not legal advice.

By FISTA Solutions· AI-Native Engineering Team·
The General Counsel's Guide to AI and Agentic AI article cover

When software takes actions inside the business, the legal questions arrive immediately: who is accountable for what the agent did, what the vendor agreed to, how privacy and intellectual property rules apply, and which regulations attach to each use. This guide gives general counsel a practical structure for governing agentic AI and for using it in legal operations. It is general guidance, not legal advice; the rules vary by jurisdiction and are changing.

Why does agentic AI change the legal picture?

Earlier AI produced outputs that people reviewed before acting. Agents act: they send communications, post transactions, change records, and make commitments within their permissions. Three consequences follow for counsel.

  1. Accountability stays with the company. Customers, employees, and regulators will treat an agent's action as the company's action. Recourse against a vendor is a separate question from responsibility to third parties.
  2. Controls become legal evidence. Permissions, approval gates, logs, and evaluation records are what demonstrate reasonable oversight after an incident.
  3. Obligations attach per use. An agent that handles customer data in one jurisdiction and employment decisions in another carries different obligations for each.

FISTA's guide on who is accountable when an AI agent fails covers the accountability model in more depth.

What should counsel require in AI vendor contracts?

TermWhy it mattersWhat to look for
Data use and trainingPrevents your data from improving a shared modelExplicit prohibition on training; clear retention and deletion
Security and breach noticeYour obligations flow downDefined controls, certifications, notice periods
Change and deprecation noticeModels are retired and behavior changesMinimum notice; migration support; version pinning
Service levelsAgents depend on availability and latencyMeasurable SLAs with remedies
Liability and indemnityAllocation of loss and IP claimsCaps proportionate to risk; IP indemnity for output
Subprocessors and auditData may flow to third partiesTransparency, notice of changes, audit rights
Portability and exitAvoids lock-inExport of prompts, data, logs, and evaluation assets

The LLM vendor lock-in guide explains the technical protections that complement these terms, and the how to negotiate an AI development contract guide covers services agreements.

How do privacy obligations map to agents?

Map data flows per agent: what personal data enters, where it goes (models, tools, logs), how long it is retained, and what decisions it informs. Then apply the rules that attach to each flow, which may include lawful basis, purpose limitation, minimization, transparency to individuals, restrictions on automated decisions with legal or similar effects, and cross-border transfer requirements.

Two areas need particular attention. Logs often retain more personal data than the process itself, because agents record inputs and outputs for observability. Automated decisions in employment, credit, insurance, and similar contexts are regulated in several jurisdictions and may require human review, explanation, or notice. The AI data privacy compliance guide provides a mapping method.

What are the intellectual property questions?

Three, and they are distinct:

  • Inputs: does the company have the rights to use the content it feeds to models, including licensed data, customer content, and third-party material?
  • Outputs: who owns generated output, and is it protectable? Vendor terms typically assign rights to the customer, but copyright protection for purely machine-generated work is limited in several legal systems.
  • Confidentiality: does sending material to a model risk trade-secret status or breach confidentiality obligations to clients and partners?

The practical response is a policy per data class, vendor terms that assign output rights and prohibit training, and documentation of human contribution to valuable output.

How should counsel maintain regulatory readiness?

Keep an inventory that maps each AI system to the obligations that attach in each jurisdiction where it operates: sectoral rules (financial services, healthcare, employment), horizontal AI laws where they exist, privacy law, consumer protection, and advertising rules. Assign a risk tier to each system, and require the controls and records each tier demands. Review the inventory when systems change and when laws change. The AI governance framework guide describes an inventory structure that many legal teams adopt, and the EU AI Act explained guide covers one of the horizontal regimes.

What records make AI decisions defensible?

The records that show the company acted reasonably: the inventory and risk tiers; permissions and approval gates for each agent; evaluation evidence before release and on a schedule; logs of agent actions; human oversight assignments and their records; incident reports and remediation; and the policies employees were trained on. Counsel should confirm these exist before an incident, not discover their absence after one.

How should legal use agents in its own work?

Legal operations has strong candidates: contract review against playbooks, clause extraction, intake triage, matter summaries, and research support from approved sources. The controls are the same ones counsel asks of the business: a lawyer accountable for every output, restricted sources, logging, and no external communication or advice without review. FISTA's AI in legal operations whitepaper covers the use cases and controls in detail.

How can FISTA Solutions help general counsel?

FISTA Solutions builds AI agents with the permissions, approval gates, logging, and evaluation records that make oversight demonstrable, and works with legal and executive teams through its AI enablement practice to establish inventories, risk tiers, and vendor requirements. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.

To review the controls and records behind agents your business is deploying, talk to FISTA on WhatsApp, or start with the AI risk management guide.

Share-ready article cover

Download the generated social format.

Download cover

Clear answers

Questions raised by this field note.

Straightforward guidance for evaluating scope, fit, and the next step.

01Who is liable when an AI agent makes a mistake?

In most circumstances the company deploying the agent bears the consequences toward customers, employees, and regulators, whatever recourse it may have against a vendor. Liability frameworks are still developing and vary by jurisdiction and context. The practical position is to design controls and records as if the company is fully accountable. This is general guidance, not legal advice.

02What should an AI vendor contract include?

Restrictions on using your data for training; retention and deletion terms; security commitments and breach notice; deprecation and change notice periods; service levels; liability and indemnity provisions, including for IP claims; audit and subprocessor transparency; and portability of your prompts, data, and evaluation assets on exit. Review how each maps to your risk tier.

03How do privacy laws apply to AI agents?

They apply to the data the agent processes: personal data sent to models, retained in logs, or used for personalization or decisions. Obligations may include lawful basis, purpose limitation, minimization, transparency, automated-decision rules, and cross-border transfer restrictions, depending on jurisdiction. Map each agent's data flows and apply the rules per flow.

04Who owns AI-generated output?

Ownership and protectability of AI output vary by jurisdiction and are unsettled in several. Contract terms with vendors typically assign output rights to the customer, but copyright protection for purely machine-generated content is limited in some legal systems. Treat valuable output as requiring human contribution and documentation. This is general guidance, not legal advice.

05How should legal use AI in its own work?

Legal operations has strong candidates: contract review against playbooks, clause extraction, intake triage, matter summaries, and research support. Keep a lawyer accountable for every output, restrict agents to approved sources, log what was reviewed, and never let an agent give advice or make a commitment externally without review.

Start with the hard problem

Need the outcome owned, not merely analyzed?

Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.

Start a project