AI-assisted contract review without sending contracts to a third party
A vendor agreement, an NDA, a lease, an employment contract, all of it useful to run through an LLM for a first-pass read: summarize the obligations, flag an unusual indemnity clause, check whether the termination terms match what was negotiated verbally. The catch is that a contract is exactly the kind of document a company doesn't want sitting on a third party's servers, especially when the other side to the contract hasn't agreed to that either.
Not legal advice. This post describes an infrastructure setup, not a legal opinion. AI-assisted contract review is a drafting and review aid, not a substitute for a lawyer reading the contract. Nothing here should be read as advice on what terms are acceptable, what risks a specific clause carries, or whether AI review satisfies any professional obligation that applies to you. Check with your own counsel.
What's actually sensitive about a contract
Two things make contracts a distinct category from most business documents. First, the terms themselves are often confidential by the contract's own clauses, meaning sending it through a third-party AI tool could itself be a step toward breaching a confidentiality obligation the document contains, independent of anything to do with AI specifically. Second, a contract almost always involves a counterparty who never consented to their agreement being processed by whichever AI vendor you happen to use, which is a different situation than an internal document where everyone in the loop works for the same company.
That's before getting into privilege. If the review touches anything prepared in anticipation of litigation, or involves counsel's own analysis of a contract's risk, the confidentiality question can shade into a privilege one, which is squarely a question for a lawyer, not an infrastructure choice.
What running the model yourself changes, and what it doesn't
Self-hosting the model, on a dedicated instance rather than a shared cloud AI product, means the contract text goes to your model and nowhere else. No vendor retention policy, no question about whether a specific plan tier trains on submitted documents, because the document never left your infrastructure. That's the same architectural point covered for law firms handling case material, applied here to contracts specifically rather than case files broadly.
What it doesn't change: an LLM reading a contract is not a lawyer reading a contract. It can summarize clauses, flag language that looks unusual against a pattern it's seen, and speed up a first pass before a human reviewer goes through the document properly. It can also miss something a specific jurisdiction's law makes material, misread a defined term that's used unusually in this particular agreement, or summarize confidently without flagging that a clause is ambiguous in a way that matters. Every output needs a qualified human review before anyone relies on it, the same as any draft.
Where this is actually useful
The strongest use case is triage, not final review: running a batch of vendor contracts through a summarizer to flag which ones have unusual termination, liability, or auto-renewal terms, so a lawyer's limited time goes to the contracts that actually need close attention first. A second useful case is consistency checking, comparing a redline against the previous version or a standard template to surface what actually changed, which is a mechanical text-diff problem an LLM handles well and a human would otherwise do by eye.
Weaker fits: anything where the output itself becomes the basis for a negotiating position or a legal opinion without a lawyer's independent judgment applied on top. Keep the model in the "make the human faster" role, not the "make the decision" role.
A workflow, not a one-off query
The most durable way to use this is a standing prompt template a legal or ops team maintains and improves over time, not an ad hoc chat window someone types a question into each time. A template that asks the model to extract term length, termination conditions, liability caps, and any indemnity language into a consistent format turns a pile of PDFs into a comparable table, which is genuinely useful for someone managing a vendor portfolio and wanting to know, across fifty contracts, which ones auto-renew in the next quarter. Keep the template itself version-controlled and reviewed by counsel periodically, the same way you'd review a contract template.
Flag confidence honestly. A model that states a clause's meaning with the same tone whether it's confident or guessing is more dangerous than one that says "this clause is ambiguous, here's why." If the tool you build doesn't currently distinguish between those cases, that's worth fixing before wider rollout, since a reviewer who trusts a confident-sounding wrong answer is worse off than one working from the raw contract.
Where the hardware fits
Contract text is dense but not large in volume compared to something like a full due-diligence data room; a single Spark's 128GB of unified memory runs a large instruct model for summarization and clause flagging with plenty of headroom, and comfortably handles a full contract, appendices included, in one context window rather than needing to chunk it the way longer document sets require. At $0.79/hour in EU-Central, it's a low-cost way to keep this specific document category off third-party infrastructure entirely.