AI contract generators are seductive. They draft in seconds, reduce friction, and sound legally competent. But we tested OpenAI's GPT-4, Anthropic Claude, and three domain-specific contract tools (LawGeex, Rocket Lawyer, Gavel) against real-world scenarios. The results are stark: all seven platforms consistently weakened liability clauses, invented indemnification language that contradicts your intent, or buried caps that expose you to unlimited damages. Your legal team can use AI as a first draft—but these seven clauses always need human override. Why AI contracts sound good but leak risk Large language models optimize for plausibility and linguistic smoothness, not legal precision. They have no access to case law, jurisdiction-specific precedent, or the subtle difference between "shall" and "should" in a liability cap. They also have a bias toward balance—they'll often split the difference on contested terms because that's what most training data looks like. That balance costs you money. In our tests, when we asked Claude and GPT-4 to draft a software services agreement with a liability cap, both defaulted to mutual $100K caps—identical for vendor and client. That makes sense in a template. It makes no sense when you're a SaaS vendor with downstream liability and your client has ₹50L at risk. The model saw "mutual" in the training data and assumed fairness meant identical language. Domain-specific tools (LawGeex, Rocket Lawyer) performed better on jurisdiction and terminology, but still flattened nuance. All three recommended indemnification for "third-party claims arising from the other party's breach"—boilerplate that doesn't capture your actual exposure to IP infringement, data loss, or regulatory fines. Clause 1: Limitation of liability (the cap itself) Every AI tool we tested drafted liability caps that are either too broad or too low—rarely both calibrated to your business. What AI drafts: "Neither party shall be liable for indirect, incidental, or consequential damages, including lost revenue, lost profit, or data loss." Sounds good. Then it adds: "Total liability shall not exceed fees paid in the preceding 12 months." Why it fails: If your client pays you ₹50L/year and your platform crashes and costs them ₹2 crore in revenue, your cap is ₹50L. That's not a cap; it's a guarantee you'll be sued beyond it. Judges hate caps that are obviously inadequate to the damage caused. And if you're B2B, a 12-month lookback is weak—you should tie it to contract value or a fixed multiple (often 2–3x ARR for SaaS). What to override: Replace "fees paid" with either a fixed amount ("not to exceed USD 1M") or a clear multiple tied to contract scope ("not to exceed two times the annual contract value"). Add carve-outs: "excluding liability arising from either party's gross negligence, willful misconduct, or breach of confidentiality." Gross negligence is not capped—and it shouldn't be. Clause 2: Indemnification (who pays for whose lawsuits) This is where AI hallucinates most. It drafts indemnification language that sounds mutual but leaves asymmetric exposure. What AI drafts: "Each party shall indemnify the other against third-party claims arising from its own breach." That's toothless. Then it adds: "Indemnified party shall mitigate damages and notify the indemnifying party promptly." Sounds procedural. But AI almost never specifies who pays for defense or who controls the defense . Why it fails: You get sued for ₹1 crore. Your client triggers indemnification. But the contract doesn't say whether you pay the legal defense or they do first, then wait for reimbursement. (Defense comes first; reimbursement is painfully slow.) And if your client controls the defense, they can rack up legal bills you'll never agree to, then demand you cover them. What to override: Add explicit language: "Indemnifying party shall assume defense and control of any indemnified claim at its sole expense. Indemnified party shall not settle without indemnifying party's written consent (not to be unreasonably withheld)." You want control over defense strategy and cost. Also add caps—"indemnification obligations are subject to the liability limitation in Clause X," so indemnification doesn't blow past your cap. Clause 3: Data breach and security liability AI tools tested all recognized "data breach" as a liability category, but none correctly modeled the distinction between liability for your negligence (you lost their data through carelessness) vs. liability for a breach (someone hacked you). What AI drafts: "Provider shall not be liable for data breaches resulting from third-party attacks." Then it pairs that with: "unless caused by Provider's failure to maintain industry-standard security." That's circular. Every breach involves a third party; every breach then requires defining what "industry-standard" means. Why it fails: A sophisticated attacker breaches you. Your client sues. You argue the breach was not caused by your negligence; you had