Contact
← Retour au blog
Expertise26/02/2025 · 6 min de lecture

AI Act: what impact on contract management practice?

Artificial intelligence is emerging as a strategic issue in contract management, and its legal framework keeps evolving through legislation such as the AI Act.…

Pierre MarchèsPartner · fondateur
AI Act: what impact on contract management practice?

Artificial intelligence is emerging as a strategic issue in contract management, and its legal framework keeps evolving through legislation such as the AI Act. Last week, Cigref published section 1.2 of its guide on implementing the Act, setting out the main legal issues raised by AI. That section is built around four major themes with a direct impact on contract management: intellectual property, trade secrets, data protection and cybersecurity.

Beyond a simple summary, this article reads the guide through the lens of contract management. The aim: to identify the points to watch and give contract managers practical recommendations so they can better build AI into their contracts and their contract management strategies.

A. Intellectual property

Although intellectual property, and copyright in particular, raises many questions now that AI models have gone mainstream, it is striking how little attention the AI Act pays to the subject.

Only a handful of articles address it, mainly by cross-referring to “Union law” and “national law”. On copyright, for example, Article 53 requires providers of AI models “to identify and comply with, including through state-of-the-art technologies, a reservation of rights” expressed in line with the Directive on copyright and related rights.

A few specific obligations do emerge, notably the requirement for providers of AI models to make public “a sufficiently detailed summary” of the data used to train the AI model. It will be several more weeks before a summary template is issued by the European AI Office, set up by the European Commission. The French government, through the CSPLA (Conseil supérieur de la propriété littéraire et artistique, the French High Council for Literary and Artistic Property), has already put forward its own template and issued initial recommendations on paying the authors of content used by AI systems, but it is still too early to know precisely what these summaries will contain.

Three recommendations for contract managers:

As things stand, we can only recommend that the contract manager should:

  • Run periodic monitoring, to track developments both in the legislation (the forthcoming summary template, for instance) and in case law;
  • Strengthen contracts with clauses dedicated to artificial intelligence, which do offer protection against possible claims (in particular by reinforcing traditional warranty against eviction clauses);
  • Provide contractually for the delivery of deliverables documenting the creative process and the intellectual effort made by each contracting party

B. Trade secrets and confidentiality

After intellectual property, this is the other “hot topic” raised by the use of AI systems.

Once again, the AI Act largely confines itself to cross-referring to “Union law” and to “national law”. Providers and users of AI systems must therefore comply with the applicable legal rules in this area.

There is no miracle recipe and no magic wand for confidentiality, because the risks of collection and disclosure, including unintentional disclosure, remain wherever AI systems are used.

Three recommendations for contract managers:

The precautions to take and the good practices to observe therefore lie in:

  • Putting in place robust data governance to ensure “that information is used effectively and efficiently to help organisations achieve their objectives”.
  • Limiting or framing the use of AI systems, in particular through contracts and other documentation, in order to clarify the conditions under which these tools may or may not be used, and which data may – or may not – be fed into them;
  • Awareness and training, by adding a slide or a dedicated section on the specific risks of using AI to your contract management training materials or your contract awareness sessions.

C. Personal data protection

On this point, by contrast, the AI Act has far more to say. Without derogating from the regulations already in force (including the GDPR), the text sets out the exceptions and the conditions under which personal data may be processed by AI systems.

It introduces clarifications on security, on pseudonymisation and on information, retention, processing and deletion. Automatically generated logs, and the isolation of personal data in secure training sandboxes, are among the new features.

The AI Act also tackles the question of “non-personal data”, the raw material of artificial intelligence, while making very few cross-references to the Data Act. The two texts are therefore meant to coexist, particularly on data accessibility and data sharing.

Three recommendations for contract managers:

  • Update your contractual risk and opportunity analysis matrices to reinforce (or introduce) the concepts of data governance and personal data.
  • Run constant monitoring, of both commentary and case law, because developments, clarifications and reversals are expected in 2025 and should have a major influence on the way contracts are drafted, negotiated and managed;
  • Involve DPOs in drafting and negotiating contracts that raise issues in this area, so that risks and opportunities are taken into account as early as possible.

D. Cybersecurity

We covered AI & cybersecurity last week in our reading of the ANSSI publication. The CIGREF guide, however, approaches the point from the standpoint of the AI Act, which offers a complementary angle.

First of all, as with parts A and B above, cybersecurity is a theme the AI Act says little about, at least directly. There are a few scattered references to cybersecurity, but it quickly becomes clear that the drafters did not want to add unduly to the obligations in this area.

There are nonetheless some subtleties in the AI Act, with risk governance requirements that include cyber risk and that provide in particular for:

  • A risk map that includes cyber risk;
  • The implementation of a risk management system for high-risk systems;
  • Specific accuracy and robustness requirements in the design and development of high-risk AI systems.
  • As well as mechanisms that are not specific to cybersecurity but may carry cybersecurity parameters, such as setting up and documenting a monitoring system, automatic event logging, and reporting, governance and user information mechanisms, and so on.

Three recommendations for contract managers:

  • Clarify the roles and responsibilities of the contracting parties, whether in building cybersecurity in at the design and development stage, in monitoring and detecting vulnerabilities during performance, or in responding to incidents.
  • Include among the contractual deliverables the documentation on the cybersecurity measures put in place by the contracting parties and, where relevant, the documentation tracing the architecture of the AI system together with the security measures applied to each of its components;
  • Provide for regular tests and audits throughout the life of the contract, so as to identify potential vulnerabilities and items to fix, and thereby limit the risk of attackers exploiting them.

Conclusion:

This analysis of the Cigref guide shows how important it is for contract managers to anticipate the legal challenges of AI. Whether on intellectual property, confidentiality, data protection or cybersecurity, the AI Act imposes obligations that must be built in from the drafting and negotiation of contracts.

Alongside the recommendations set out above, close attention to the changing regulatory and case-law framework will be essential in the months ahead. The rest of the Cigref guide promises to go further: part 2 will address governance issues, while part 3, devoted to contracts and liability, should bring fundamental clarifications. We will of course analyse these next sections to give you the keys to contract management fit for the new challenges of AI.

Expertise
L'auteur
Pierre Marchès

Fondateur de Prime Conseil, Pierre pratique le contract management depuis quinze ans, au sein de grands groupes comme d'ETI, ainsi qu'auprès de collectivités et de ministères français et étrangers. Il est spécialisé dans l'énergie, l'infrastructure et la défense.

Suivre Pierre sur LinkedInLire les 90 articles de Pierre
Le blog

Nos derniers articles.

Voir tous les articles
Processus17/08/2026
Contract memo: content and best practices
The contract memo is the first deliverable expected of a contract manager when they start on a project. Method, pitfalls to avoid and best practices from the field.
Lire l'article →
Staffing03/08/2026
Recruiting contract managers: why the talent shortage does not explain everything
Recruiting contract managers is regularly presented today as a market facing a shortage. The diagnosis is often the same: the pool of professionals is said to have become…
Lire l'article →
Claims16/07/2026
Preparing a letter: everything is decided before the drafting stage
In a previous article on claims under FIDIC contracts, we saw that form determines the very existence of a claim: a perfectly well-founded right but…
Lire l'article →

Let's get to know each other.

By email
contact@primeconseil.com
For the shy ones.
In person
1192, Bd Jean Baptiste Abel, 83000 Toulon38, Rue Jean Bouchet, 86000 Poitiers3 Bis, Rue Taylor, 75010 Paris
For the coffee lovers.
By phone
(+33) 04 12 33 31 01
For the straight talkers.
Emailcontact@primeconseil.comFor the shy ones.Phone(+33) 04 12 33 31 01For the straight talkers.
In person1192, Bd Jean Baptiste Abel, 83000 Toulon38, Rue Jean Bouchet, 86000 Poitiers3 Bis, Rue Taylor, 75010 Paris