Introduction
Artificial Intelligence (“AI”) is moving from experimentation into real business use. Organisations already deploy AI for customer service, document review, hiring, marketing and analytics, software development, and internal decision-making. Running a pilot, however, is not the same as deploying at enterprise scale. A pilot tests whether the technology can perform its intended function; deployment tests whether it can be used practically, legally and commercially within the organisation.
The distinction becomes important when an AI system moves into live business processes, where it may process sensitive data, connect with enterprise systems, and produce decisions with real commercial consequences. Pre-deployment is therefore the stage at which the organisation must assess whether the system is fit for practical use against data protection, security, risk, human accountability and compliance requirements.
The central question is therefore not only whether the AI works, but who decides whether it is ready to go live and on what evidence and conditions. That decision requires oversight of contractual obligations, applicable law, data and Intellectual Property (“IP”) rules, and governance. This is where the Fractional General Counsel (“Fractional GC”) becomes particularly valuable, supporting the organisation across the AI lifecycle: defining the legal boundaries of the pilot, assessing readiness for deployment, negotiating vendor contracts, allocating contractual risk, and sustaining governance after go-live. In this role, the Fractional GC functions as a standing legal and strategic advisor across the organisation, its technology vendors, and its evolving legal obligations, present at each stage rather than summoned only when something has already gone wrong.
AI Experimentation to Enterprise Risk
The legal risks of AI surface fully once a pilot moves into deployment. Because AI systems can process data on customers, employees, contracts and finances, a company must know what data enters the system, how it is processed, how long it is retained, who can access it, and whether the vendor may use that data to train or improve its own models. In India, these questions arise under the Digital Personal Data Protection Act, 2023 (“DPDP Act”)[i] and the Digital Personal Data Protection Rules, 2025,[ii] both of which are being brought into force in a phased manner.
An employee who uploads an internal contract, a pricing strategy, or other confidential business information into an external AI application may disclose information the company can no longer control. A standard confidentiality clause may say nothing about whether that information is retained in logs, made accessible to sub-processors, or used in the vendor’s model-development process.
Organisations therefore need clarity on who owns, and who may use, the data fed into an AI system and the outputs it generates including the risk that an output may infringe a third party’s IP, or that an output generated using the company’s own confidential inputs cannot be protected as the company’s own IP at all. Commentary on AI procurement increasingly observes that standard technology contracts do not adequately address these issues, and that contractual terms need to speak directly to inputs, outputs, data use and IP rights[iii].
A pilot can be abandoned with little consequence. Once AI is embedded in core processes, however, the business becomes dependent on the vendor’s infrastructure, pricing and update cycle, so a change to the underlying model, or vendor downtime, becomes a business-continuity issue rather than a purely technical one. What was once a discrete experiment now sits inside the organisation’s critical path, and unwinding it carries operational and contractual consequences that a pilot never did.
Fractional General Counsel as the Bridge Between Pilot and Deployment
The Fractional GC contributes to the AI-readiness assessment before the organisation moves the system into production, rather than carrying out technical testing itself. The GC identifies applicable legal and contractual obligations, coordinates reviews by technical, cybersecurity and industry specialists, records unresolved legal and governance risks, and advises on approval conditions. The National Institute of Standards and Technology’s Artificial Intelligence Risk Management Framework (“NIST AI RMF”) is designed to help organisations manage AI risk across design, development, deployment and operation, with a companion generative-AI profile addressing risks specific to generative systems.
None of this replaces technical specialists, cybersecurity experts or industry specialists where their expertise is required. The Fractional GC’s distinct value lies in coordinating those inputs into a coherent business decision translating technical findings, security assessments and business objectives into a single, defensible position on whether, and on what terms, the organisation should proceed.
AI Procurement and Contractual Risk Allocation
The Fractional GC’s most significant contribution often comes at the procurement and contracting stage, because an AI system is not simply another software subscription, the technology itself, and the vendor’s use of the client’s data, can change after the contract is signed.
Before contracting, the Fractional GC can lead comprehensive vendor due diligence: identifying the underlying model provider, establishing whether third-party model providers or sub-processors are involved, confirming where data is processed and stored, reviewing the vendor’s security practices, and clarifying whether the client’s data may be used to train, improve, or otherwise develop the vendor’s models. Government AI procurement guidance points in the same direction, emphasising that the business problem be clearly defined, that suppliers be properly vetted, and that requirements for responsible use be set out from the outset.
This due diligence should feed directly into the contract itself. Liability caps, indemnities, service levels, audit rights, data-ownership clauses and termination and transition rights all need to reflect how the specific AI system will actually be used, rather than the generic terms a vendor’s standard order form provides. Contracts allocate vendor risk, but internal controls and management decisions must address risks that cannot be contracted away.
Pre-Deployment Readiness Measures
Much of the standing discussion on AI governance addresses what happens after a system is live. Before that point, however, the enterprise needs a distinct set of actions. Procurement due diligence addresses the relationship with the vendor; pre-deployment readiness addresses whether the particular use case, once built into the enterprise’s own systems and processes, is actually fit to go live. The two exercises are related but not interchangeable, and a signed contract should not, by itself, be treated as authorisation to deploy.
Before going live, the Fractional GC can help ensure that the following measures have been completed and documented, so that readiness is demonstrable rather than assumed:
- Categorising the use case by degree of risk, based on the sensitivity of the data involved, the extent of automation, and the consequences of an erroneous or biased result, so that higher-stakes use cases receive proportionately closer scrutiny;[iv]
- Conducting a proportionate privacy assessment to confirm the lawfulness of processing personal data, map data flows, and define retention and access parameters before any live data is processed; where the organisation is a Significant Data Fiduciary, a formal data protection impact assessment should be conducted as required under the DPDP Act;[v]
- Having technical teams test the system’s outputs against representative and edge cases to surface issues of accuracy, reliability and bias ahead of exposure to real customers or employees;[vi]
- Having technical and security teams test security controls, including access management and separation of the firm’s data from the provider’s model environment;[vii]
- Identifying the points at which human review and approval become necessary, particularly where outcomes affect employment, credit, pricing or other consequential decisions;[viii]
- Obtaining documented sign-off from the business owner and relevant specialists spanning legal, IT and security, with legal advising on applicable obligations, contractual protection and residual risk and the rationale for sign-off recorded;[ix]
- Training the employees who will use the system on what is, and is not, a permitted use, so that the boundaries set during the pilot survive the transition to live operation; and[x]
- Having the business owner and relevant technical and compliance specialists approve a contingency plan for taking the system offline if performance or compliance concerns emerge after launch, so that a rollback path exists before it is needed.[xi]
Taken together, these steps form a readiness check that sits alongside, rather than replaces, lifecycle-based risk management. Rather than allowing deployment to follow automatically once a pilot succeeds, the Fractional GC ensures that this review is actually performed and documented so the decision to go live is deliberate and defensible, made with a clear understanding of the system’s data flows, control points and residual risk.
The readiness record should identify the evidence reviewed, the designated business owner and other approvers, any conditions that remain open, and the circumstances that would prevent or pause launch. The Fractional GC can advise on approval conditions and residual legal risk, while the business owner and management remain responsible for the go-live decision.
AI Governance After Deployment
Legal oversight should not end once a contract is signed. Deployment is better understood as an exercise in ongoing governance of a relationship than as a one-time approval.
The Fractional GC can arrange periodic reviews to check whether the system continues to be used as intended, whether the vendor has changed the underlying model or its data-handling practices, whether new categories of personal or sensitive data have entered the system, and whether legal developments require changes at the organisational level. These reviews are what keep the original deployment approval accurate over time, rather than a one-off assessment that quietly stops reflecting how the system is actually being used.
The readiness record should identify the evidence reviewed, the designated business owner and other approvers, any conditions that remain open, and the circumstances that would prevent or pause launch. The Fractional GC can advise on approval conditions and residual legal risk, while the business owner and management remain responsible for the go-live decision.
Conclusion
The central legal question for enterprise AI has shifted from whether a business can use AI to how it manages the transition from experimentation to operation without leaving legal and governance obligations behind. That transition brings new legal exposure spanning data compliance, confidentiality, IP, contracts, liability and regulation, risks that, for established businesses, map onto familiar legal and governance disciplines even as AI raises new questions within them. Treating deployment as simply the next step after a successful pilot overlooks the fact that the legal and commercial stakes rise sharply the moment a system moves from a controlled test into live operation
Accordingly, the role of the Fractional GC is expanding well beyond reviewing the contracts of AI vendors. It now spans the full arc from pilot design to post-deployment governance making the Fractional GC a central, rather than incidental, participant in how an organisation adopts AI. For businesses navigating this shift, the practical lesson is straightforward: engage that function before the system goes live, not after it has already begun making decisions the organisation cannot fully explain.
References:
[i] Digital Personal Data Protection Act, 2023.
[ii] Digital Personal Data Protection Rules, 2025.
[iii] Lisa R. Lifshitz, ‘Procurement in the Age of AI: The Legal Architecture of AI Procurement’ (2026) Oxford Law Pro.
[iv] European Parliament and Council, Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) [2024] OJ L 2024/1689, art 9; NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, 2023) 14–15.
[v] Regulation (EU) 2016/679 (General Data Protection Regulation) art 35; Digital Personal Data Protection Act 2023, s 10 (in relation to Significant Data Fiduciaries).
[vi] NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, 2023) 14–15; NIST, ARIA Evaluation Planning Manual: Elements of ARIA-Style AI Evaluations (NIST AI 200-3, 2026).
[vii] Regulation (EU) 2024/1689, art 15; NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, 2023).
[viii] Regulation (EU) 2024/1689, art 14; art 26(2).
[ix] NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1, 2023); NIST, AI RMF Core (NIST, 2023), ‘Govern’ and ‘Measure’ functions.
[x] Regulation (EU) 2024/1689, art 4; art 26(2).
[xi] NIST, AI RMF Core (NIST, 2023), ‘Manage’ function; Regulation (EU) 2024/1689, art 26(5).
Gaurav Gupta is the Founder and Managing Partner at Bridge Counsels & Ananya Goswami is a 5th year student at Dr. Ram Monhar Lohia National Law University, Lucknow and an intern at BridgeCounsels LLP.
.






