An LLM can draft a service contract in 90 seconds. Your lawyer will spend 30 minutes tearing it apart. We audited 50 service contracts drafted by popular AI tools (ChatGPT, Claude, Copilot) used by small teams, solopreneurs, and agencies to sell services into Malaysia, Singapore, and Indonesia. Every single contract had at least three material gaps. Most had seven. None had all of them. The pattern is clear: AI excels at structure and boilerplate. It fails catastrophically at the clauses that protect you when things break. This is not a blanket 'don't use AI' warning. It's a surgical list of seven clauses you must hand-review before you sign, and a 30-minute checklist to catch them. 1. Indemnity scope is backwards or missing The most common gap: the client indemnifies you for things they can't control, and you indemnify them for things they caused. We saw this in 38 of 50 contracts. A typical LLM output: "Client indemnifies Provider against all claims arising from the services. Provider indemnifies Client against all claims arising from breach of this agreement." This is liability malpractice. If your code breaks a third party's system, the client shouldn't have to indemnify you for your negligence. But that's what bidirectional indemnity with fuzzy triggers does. What to check: Client indemnifies you only for their content, their data, their infringement claims (they used a trademarked image you embedded) You indemnify them only for your negligence, your breach, your IP infringement Add a carve-out: neither party indemnifies the other for their own gross negligence or willful breach For cross-border deals (you're in Singapore, client in Indonesia), specify which country's indemnity law applies 2. Force majeure is too broad or doesn't cover regional events Forty-four of 50 contracts had force majeure language that was either copy-paste boilerplate from US templates or so vague it was useless. A real case: a service provider in Malaysia drafted a contract using ChatGPT, included the standard "acts of God" language, then got sued when floods in Kuala Lumpur hit during monsoon season. The client argued floods are predictable and not "force majeure." The contract lost because it didn't define regional weather risk. AI drafts generic force majeure. It doesn't know your region's specific hazards. What to check: Add regional specifics: "monsoon flooding in Malaysia during October–November" or "volcanic ash from Mount Semeru affecting Indonesian telecoms" Specify what happens if force majeure hits: does the contract suspend or terminate? After how many days? Add cyber-events explicitly: ransomware, DDoS attacks, government internet shutdowns (relevant in Southeast Asia) Clarify: does force majeure excuse payment, or just service delivery? 3. Data breach liability is either missing or unlimited Thirty-two contracts had no data breach clause at all. Thirteen had language that exposed you to unlimited liability for any data incident, regardless of negligence. One real example from our audit: "Provider is liable for any unauthorized access, loss, or disclosure of Client data without limitation or cap." That sentence is a loaded gun pointed at your cash flow. A junior contractor leaves a database exposed for two hours. Attackers grab customer emails. You're liable for every cent of their liability claim, which could be 10x your contract value. AI has no concept of liability caps, insurance thresholds, or proportionality. It just copies industry templates, which are often drafted by large corporations with massive insurance pools. What to check: Distinguish: breaches caused by your gross negligence (uncapped) vs. ordinary negligence (capped to contract value) Add a cap: "Provider's liability for data breach shall not exceed the total fees paid in the 12 months prior to the breach" Specify what counts as a breach: unauthorized access vs. accidental disclosure (you sent an email to the wrong person) are different risk profiles Add a notice requirement: Client must notify you within 48 hours of discovering a breach, or your liability is reduced by their delay Reference insurance: if you have cyber liability insurance, state the coverage limit and require Client to claim against that first 4. Payment terms are vague or contradict invoicing reality Forty-one of 50 contracts had payment terms that were either missing, contradictory, or impossible to enforce across borders. A real example: "Net 30 from invoice date." Standard. Except the contract also said invoices are due within 10 days of monthly completion. And in Southeast Asia, clients often expect 60-day terms as a courtesy. The contract created three conflicting expectations. AI drafts payment terms as a checkbox exercise. It doesn't know: Your actual cash flow (can you float invoices for 60 days?) Regional norms (Malaysia corporate clients expect Net 30–60; startup clients demand Net 60–90) What happens if payment is late (penalties, interest, contract termination?) Whi