Bay Area Business Lawyers | Primum Law

AI Product

The Legal Checklist Before You Launch an AI Product 

The Legal Checklist Before You Launch an AI Product 

Your AI product works. The team is ready. Customers want access. 

Before you launch, can you explain where the data behind the product came from and what happens to customer information once the product is live? 

AI products can introduce legal questions at multiple points in the data lifecycle, from development and training through customer inputs, third-party model providers, outputs, and product improvement. 

The time to identify those questions is before customers start sending real information through the system. 

What AI Founders Need to Know 

A useful launch review should follow the product from development through actual customer use. 

Start upstream. What AI training data or other datasets were used to build, train, or fine-tune the system? What rights or permissions govern that data? 

Then follow what happens after launch. 

What can customers submit? Where are those inputs sent? Are they stored? Can they be used for another purpose, including improving a model? That can raise purpose limitation questions when personal information collected for one purpose is later used differently. 

The type of information matters too. A product capable of receiving sensitive personal information may create different risks from one processing only basic business contact information. 

Depending on the processing and applicable law, a company may also need to consider whether a Data Protection Impact Assessment (DPIA) or another structured risk assessment is appropriate or required. 

What This Looks Like in Practice 

Imagine your startup builds an AI assistant that helps businesses analyze internal documents. 

During testing, your team uses a collection of documents to improve the product. After launch, customers can upload their own files and ask the assistant questions about them. 

One customer uploads HR documents containing employee names, compensation information, and other potentially sensitive information. 

Your application sends the document contents and prompts to a third-party model provider. 

Now an enterprise customer asks a series of questions before approving the product: 

Where did the data used to develop the system come from? Does the AI provider retain customer prompts? Can uploaded information be used to train or improve any model? What happens to the information after the customer deletes a document? Can the platform process sensitive information? Have you assessed the privacy risks associated with that processing? 

None of those questions is about whether the AI feature works. 

They are about whether your company understands and can explain the data practices behind it. 

A founder who can answer them before launch is in a very different position from one discovering the answers during enterprise diligence. 

Three Common Founder Mistakes 

  • Mapping only the customer-facing application. The relevant data lifecycle can begin before launch and extend through third-party providers after a user receives an output. 
  • Assuming a third-party AI provider answers the company’s legal questions. You still need to understand what your own product does and what your company represents to customers. 
  • Treating all data as equivalent. The risks can change depending on what users are permitted or likely to submit. 

10-Minute Founder Self-Check 

Take one typical customer interaction and follow it from input to deletion: 

  • What information can the customer submit? 
  • Could that include sensitive personal information? 
  • Where is the input sent? 
  • Which third parties receive it? 
  • Is the input retained anywhere? 
  • Can it be used for training or product improvement? 
  • What happens to generated outputs? 
  • What happens when the customer deletes its information? 
  • Does our privacy policy accurately describe this process? 
  • Do our customer agreements address the relevant AI functionality? 
  • Have we evaluated whether a DPIA or another risk assessment is appropriate? 

Then separately ask where the data used to develop or train your own system came from and whether the company has appropriate rights to use it. 

What to Do Next 

Before launch, build a picture of the entire data lifecycle, not just the information visible on the user’s screen. 

Download Primum Law Group’s Data Mapping Worksheet to document what your product collects, where the information goes, and who has access to it. 

Scroll to Top