
Human review clauses divide responsibility for AI output between the vendor that builds the tool and the customer that uses it. When vendors draft these clauses, they often make them one-sided. The drafts require the customer to review every output before use. Any failure by the customer to review is a material breach. The icing on the cake? The vendor bears no liability for outputs the customer approves.
We dove into this provision during a How to Contract webinar this week featuring Tamra Moore and Arohi Kashyap. They walked me through a sample human review clause.
In our session, we explored three ways that typical pro-vendor human review clauses create problems for customers. First, a duty to do a human review of ALL outputs may be impossible to perform consistently and reliably. This is especially true for scaling companies. Second, the customer could be in material breach for a single missed review. Third, the customer bears all liability relating to human review, even for aspects that are under the vendor’s control.
But our discussion didn’t end there. They helped me understand that it’s not just the customer’s problem. Vendors have their own problems with these one-way human review clauses. Vendors rely on the customer performing its review, but they have no way to confirm the review happened. In addition, the vendor has created ambiguity by using “meaningful” as the review standard. With no definition, neither party can assess if a breach happened. Finally, the liability release that seems so broad actually only covers approved outputs. It says nothing about outputs the customer used without review.
We can do better. Arohi and Tamra recommended drafting human review clauses that assign each obligation to the party that controls it. The vendor controls the product. So the vendor can commit to review queues, confidence scores, override controls, and a way to pause automated actions. The vendor can also document the system's limits and known failure modes. The customer controls deployment. So the customer can commit to review defined categories of output, such as decisions about a person's employment, credit, or access to services.
And don’t forget about the vague meaningful human review standard. It’s important to take some time to specify what it actually means. The contract could identify the human reviewer's role, the training required, and the authority that person has to reject or change an output.
Human review standards also need to lay out the documentation requirements. For example, the contract could require the customer to keep a record of each review. Each record would show who reviewed the output, when it was reviewed, what information the reviewer saw, and whether the reviewer changed it. That record gives the vendor a way to confirm the review and gives both parties evidence if a regulator asks.
My takeaway from this webinar was that human review provisions should not be “vendors throw it over the fence” provisions. Both parties face problems under a clause that puts all review on the customer.
Assigning duties by control, defining meaningful review, and requiring records may fix both sets of problems. A review clause that each party can perform may offer each party more protection than one written to put all the burden on one side.





