MeetingMentor Magazine

September 2026

AI and Contracts: What to Watch For

No AI has passed the bar — so why are you taking legal advice from it? While you may not yet be using AI in your contracting process, it’s not too soon to learn what guardrails you need to put around its use involving anything legal.

When HopSkip polled attendees at the start of a recent webinar on artificial intelligence and event contracts, roughly 60 percent said they rarely, if ever, use AI when working on a hotel agreement. Another quarter reach for it only when negotiations stall and new language is needed. Fourteen percent use it on every contract in some capacity.

Neither of the attorneys on the panel treated that 60 percent as a permanent condition.

“I’m delighted that sounds like the majority of you aren’t really using it yet,” said Barbara Dunn, MeetingMentor legal columnist and partner at Barbara Dunn Law, who represents groups in hotel, convention center and venue negotiations. Kelly Bagnell of Holland & Knight, who represents hotel management and ownership on both the transactional and litigation sides, was even more direct: “I think you’re going to see that as a wave of the future.”

The session, hosted by the SITE Florida & Caribbean chapter and moderated by HopSkip co-founder and CEO Sean Whalen, outlined  a set of risks that has less to do with whether AI writes a good force majeure clause than with the obligations planners have already committed to in writing.

The Exposure Most Planners Haven’t Accounted for 

One important distinction that ran through the entire discussion was between what the panelists called open AI — publicly available large language models that learn from user inputs — and closed AI, meaning enterprise or subscription deployments that are locked down and, critically, do not use uploaded material to train a broader model.

Bagnell’s objection to the open type of AI was less about the quality of the output than what a planner is handing over.

Nearly every document a planner might want to run through an AI tool — even the most seemingly inconsequential — likely is already covered by an obligation: a signed NDA, a confidentiality clause inside the venue agreement itself, or a plain commercial expectation that negotiations stay private.

Bagnell used the example of comparing one hotel’s contract form against another’s to understand why their force majeure language differs — a routine, defensible piece of analysis. It still requires a closed system, she said, because both documents contain confidentiality provisions and both hoteliers expect the negotiation to remain confidential.

Dunn extended the same logic well past the contract file. Groups hold attendee registration data, exhibitor data and other personal information that AI could analyze productively. Feed any of it into an unprotected system and the organization risks not only breaching its own confidentiality commitments but violating individual privacy rights under state data protection laws and comparable regimes in the European Union and elsewhere.

She also nixed a workaround planners sometimes assume protects them: using an incognito or private browsing window. If the underlying model is still public and still learning from inputs, Dunn said, the setting changes nothing.

The Breach that Happens Without Anyone Deciding to Use AI

Interestingly, one of the top warnings the attorneys gave in the session had more to do with everyday communications than with contract drafting.

Video platforms in daily use — Dunn named Zoom and Teams — now ship with a range of AI functions covering recording, transcription and note-taking. Many are enabled by default. That means the record gets created without anyone in the meeting making a decision to create it.

For a group, the consequences could be litigation. An AI-generated transcript of a board meeting, a committee session or a privileged conversation with counsel may be discoverable in a subsequent dispute. Bagnell noted that attorney work product — counsel’s reasoning as they formulate clauses and positions — carries an even higher waiver standard than attorney-client privilege, and is correspondingly worth guarding.

Dunn’s recommendation is twofold. First, individual participants should disable AI recording on their own devices. Separately, whoever hosts and provisions the platform needs to confirm the settings at the account level, backed by a stated policy that meetings of this type are not recorded — so participants can speak candidly and understand that no one is capturing the session privately.

The harder problem is the meeting you don’t host. Join a call set up on someone else’s platform and you have no visibility into their configuration. Bagnell described a scenario in which a note-taking function someone else enabled could be routing the conversation into an open system, and the problem has already occurred by the time anyone notices.

A Closed System Only Solves One Problem

The obvious response is to buy a closed AI tool and move on. Both attorneys endorsed that as a baseline — Bagnell pointed out that closed systems allowing confidential upload without training or retention can run as little as $25 a month, a pretty low barrier to entry considering the potential risk. But the protection comes with three material limits.

First, “closed” is not self-certifying. Dunn’s due diligence questions before signing up: How exactly is confidential information locked down, and is it used to train a larger model? Those answers belong in the terms and conditions, confirmed before the subscription starts.

Second — and this is the point most likely to surprise planners — a closed system may still put you in breach of your NDA. Non-disclosure agreements typically define confidential information broadly and restrict its use just as broadly. Absent a specific carve-out permitting AI, Dunn said, feeding covered material into any system, closed included, may violate the agreement.

As Bagnell says, you don’t have to use the word “AI” to have either a carve-out or an inclusion. The language already on the page probably covers it.

The safest bet is to check the underlying contract before uploading anything — and where the use is significant, to raise it with the other side and secure approval. Dunn noted that some vendor agreements are already being written with a separate AI clause alongside the confidentiality clause, permitting defined uses of confidential information under stated restrictions. She expects more of them.

Third, a closed system does nothing for accuracy. Remember, Bagnell said, no AI model has ever been admitted to practice law. A tool may generate a perfectly serviceable force majeure clause and fail to flag that the change requires conforming edits in five other places so the agreement reads as a coherent whole, or that a given state’s law treats the issue differently. Dunn added a second failure mode specific to this industry — a user who doesn’t understand the difference between the grocery list of triggering events and the collective-impact standard can end up with a clause covering only one component, which becomes a serious problem if a dispute follows.

What a Policy Actually Needs to Cover

Asked what an organization with no AI policy should address first, Bagnell offered two non-negotiables: no open systems, because there is no way to know what happens to the data; and AI never substitutes for independent analysis.

Dunn offered three:

– Approved tools. Which system the organization has vetted — and, by implication, which are off limits.

– Permitted uses. What AI may be used for, and what it may not, including feeding confidential data.

– The human in the room. Where human oversight enters the workflow, who is accountable, and what gets reviewed before it leaves the building. For example, an RFP drafted with AI assistance should not go out without a person reviewing it and verifying accuracy first.

While this can be a document, Dunn said that, even absent a formal policy, those three items belong on the agenda at the next brown-bag lunch or coffee chat — because if teams aren’t discussing them, the tools are almost certainly being used anyway, and not in the way that best serves the organization.

The alternative, a blanket prohibition, is itself a dangerous directive, she said. The goal is to educate and shepherd staff toward appropriate tools and use cases, not to drive usage underground. Bagnell, who described her own firm’s internal rules as carrying real consequences for misuse, favored a firmer hand — but agreed on the substance.

On ownership, both attorneys said policy tends to originate in legal, with the technical implementation sitting with a CIO or equivalent. Dunn’s recommended structure is an interdisciplinary working group — meetings, membership, publications, finance and legal at the same table — since every department will encounter AI, and each has different use cases to surface.

The Question to Add to Your RFP

One concrete change planners can make immediately: Ask about AI during vendor selection. Dunn suggested asking a few key questions: Does the organization use AI in its operations? If yes, how? And if yes, what type of system? From there the questions drill down. She recommends it as a standard due diligence item across the vendor chain — housing, registration and event tech — not only hotels.

The reciprocal half matters just as much. Planners should be ready to answer the same question when it comes back at them, which is another argument for having written guidelines: it lets an organization respond quickly and consistently that it uses AI for these purposes, in a closed system, under these controls. Bagnell said her institutional clients would typically answer by pointing to their policies and procedures rather than itemizing use cases.

One important thing to keep in mind is that even if a release is accidental and you want to take it back, there’s no way to retrieve information once it has gone into an open system. So if such an accident does occur, the panelists recommended implementing a standard event crisis protocol: a decision tree covering who gets notified and in what order, a prepared response to the client whose information was exposed, and contemporaneous documentation of what happened.

And don’t assume you’re covered by insurance. The prevailing view, Bagnell said, is that an AI-related exposure would sit within an errors and omissions policy — but carriers are actively working out whether these will be covered claims, and in a field moving this quickly, what holds today may not hold in two months.

Dunn pointed to cyber liability coverage as a core component of any organization’s package, and noted that many carriers will conduct a front-end risk assessment with the group — useful for troubleshooting before anything goes wrong. Her practical advice on any policy is to read the exclusions page first, because anything listed there that the organization actually needs covered is a conversation to have with the broker now, not after a claim.

She also flagged a documentation incentive that cuts both ways: carriers will want to see records. An organization that can demonstrate it had a policy, trained its staff and documented the incident is in a materially stronger position on coverage — evidence, as she put it, that the group acted prudently.

Which loops back to where the panel started. Neither attorney argued that planners should avoid AI. Dunn’s preferred analogy was the office cubicle — AI as the colleague you lean over and ask, do you have any idea about this? A useful first move, or a backstop on work you’ve already done. Never the last word.

 

Image by vectorjuice on Magnific

Free Subscription to
MeetingMentor Online

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*

About ConferenceDirect
ConferenceDirect is a global meetings solutions company offering site selection/contract negotiation, conference management, housing & registration services, mobile app technology and strategic meetings management solutions. It provides expertise to 4,400+ associations, corporations, and sporting authorities through our 400+ global associates. www.conferencedirect.com

About MeetingMentor
MeetingMentor, is a business journal for senior meeting planners that is distributed in print and digital editions to the clients, prospects, and associates of ConferenceDirect, which handles over 13,000 worldwide meetings, conventions, and incentives annually. www.meetingmentormag.com