You ask an AI contract tool to draft a service agreement. Fifteen seconds later, you have a document that looks complete, reads professionally, and carries zero liability guardrails. Your legal ops team opens it and sees seven separate places where ambiguous language could cost you six figures if a dispute lands in court. AI doesn't understand context—it mirrors patterns from its training data, which includes badly drafted contracts, template farms, and jurisdiction-mismatched boilerplate. The tool is not malicious. It's just not liable if the contract fails. You are. We've reviewed hundreds of AI-generated service, SaaS, and contractor agreements across Southeast Asia and the UK. Seven clauses appear consistently underspecified. This guide walks you through each one, shows you what broken looks like, and gives you the audit questions that catch the gap before it hardens into a signature. 1. Indemnification scope: who pays for what, and when AI generators default to mutual indemnification—both parties agree to cover the other's legal costs if something goes wrong. Sounds balanced. It's not. The gap: The clause never specifies what "indemnification" actually covers. Does it include defense costs, or only settlement amounts? Does it apply if you're partially at fault? Can the indemnified party negotiate the defense, or must they accept the indemnifying party's choice of counsel? Real example: Your SaaS vendor's AI-drafted agreement says you indemnify them for "any claims arising from your use of the service." A customer sues both of you for data loss. The vendor's legal team demands you cover their defense costs, even though the root cause was their failure to encrypt. The clause doesn't say indemnification applies only to third-party claims, or only when you're at fault, or only to specific types of harm. Audit questions: Does indemnification apply only to third-party claims, or also to claims between you two? Who controls the defense—the indemnifying party or the indemnified party? Does it cover defense costs, settlement, judgment, penalties, and lost business separately, or one lump sum? Does it cap indemnification at the same limit as general liability, or higher? Does it exclude claims that arise from both parties' actions (comparative negligence)? 2. Liability caps: the number everyone ignores until it matters AI tools routinely insert liability caps at "the fees paid in the last 12 months" or "$X,000"—whichever is lower. It sounds standard. It rarely reflects what you actually need. The gap: The cap is often blind to what each party can actually afford to lose. If you're a 10-person services firm and the vendor is a 500-person software company, a mutual cap of $50K protects them far more than you. Also, the cap frequently doesn't carve out exceptions—if the cap applies to everything, it includes indirect damages, IP infringement, confidentiality breach, and gross negligence, none of which should be capped. Real example: You sign a data integration contract with a cap of $25K. Their API fails silently for three days. Your downstream system posts $400K in bad reconciliations. Your customer sues you. Your cap agreement limits your recovery against the vendor to $25K, while you're exposed to the customer for the full $400K. Audit questions: Is the cap the same for both parties, or does it scale by company size or use case? Does the cap apply to direct damages only, excluding indirect, consequential, and punitive damages? Are confidentiality breaches, IP infringement, and gross negligence carved out (uncapped)? Does the cap reset annually, or is it a lifetime maximum? If you use the vendor's service to deliver to customers, is the cap high enough to cover your customer liability? 3. Termination for convenience: the open exit no one defines AI drafts "either party may terminate this agreement on 30 days' written notice for any reason." Sounds fair. It's a trap. The gap: The clause doesn't specify what happens to data, ongoing work, or payment obligations after termination. If the vendor terminates, do they keep your data? Do they refund unused fees? Can they terminate mid-project? The absence of detail forces renegotiation under duress, often at the other party's advantage. Real example: You're a service provider with a three-month project running on a SaaS platform. The platform's AI-drafted agreement says either party can terminate on 30 days' notice. The platform terminates after month one. They delete your data, claim it's compliant with the contract, and offer a 10% refund. No obligation to cooperate on transition. You lose the client because you can't recover their data. Audit questions: What work or deliverables must be completed or paid for even after termination? Does termination for convenience require mutual consent if the contract is ongoing (retainers, subscriptions)? Who owns data at termination, and how long does the vendor retain it for recovery? Is there a kill fee or wind-down period, or is