An AI contract generator is fast. It is also reliably wrong in ways that create legal exposure your business doesn't know it has. We audited 50 service contracts drafted by leading LLMs (Claude, ChatGPT, Gemini) and identified seven liability gaps that appear in 80–96% of outputs. These are not formatting issues. These are holes that let disputes escape your control, expose you to uninsurable losses, or leave you with no recourse when a client disappears. Your in-house lawyer—or the one you'd hire after a problem surfaced—will catch these in a 30-minute review. But the better move is to catch them before the contract is signed. This guide walks you through each gap, shows why LLMs miss it, and gives you a checklist to spot it yourself. Why AI hallucinates liability clauses LLMs are trained on thousands of real contracts. They learn patterns, language, and structure. What they do not learn is consequence. A lawyer writes an indemnity clause with a specific client in mind: their risk profile, their margin, their exposure to third-party claims. An LLM writes something that sounds like an indemnity clause. The model has no concept of what happens when the clause is triggered. It doesn't know whether you're a £50K/year digital agency or a £5M enterprise software vendor. It doesn't know whether you operate in Malaysia, Singapore, or the UK. It doesn't know whether the client is a startup with no insurance or a multinational with a 100-person legal department. So it defaults to templates—and templates are optimized for nobody in particular. Gap 1: Indemnity scope is backwards or circular Indemnity is your promise to absorb a loss on behalf of the other party. It is the most dangerous clause in a contract because it can create unlimited liability. In 43 of our 50 audited contracts, the indemnity was either so broad it exposed the vendor to third-party IP claims they had no control over, or so narrow it became useless when needed. Example: What the AI wrote: "Vendor shall indemnify Client against any claim arising from the Services or the Software." What this actually means: If a user of the Software sues for privacy breach, defamation, or data loss—and names the Client—the Vendor pays. The Vendor has no limit, no cap, no requirement that the Client mitigate the loss. What you probably meant: "Vendor shall indemnify Client against third-party IP claims that the Software infringes a patent, trademark, or copyright—provided the claim arises from Vendor's code, not Client's modifications." 30-second fix: A real indemnity has four moving parts: (1) trigger (what has to happen), (2) scope (what you're covering), (3) exclusions (what you're not covering), and (4) cap (the maximum you'll pay). AI drafts them with one or two pieces and leaves the rest to guess. Gap 2: Force majeure is absent or unworkably vague Force majeure is the clause that says "if the world ends, neither of us is liable." In 31 of 50 contracts, it was missing entirely. In the remaining 19, it said things like: "Neither party shall be liable for delays caused by events beyond its reasonable control, including but not limited to acts of God." That sounds protective until you're in a dispute. What counts as "beyond reasonable control"? Does a cyberattack count? A supplier failure? A data center outage caused by your cloud provider's negligence? Courts hate vague force majeure clauses. They interpret them narrowly. In practice, this means you'll lose the dispute even though you had a clause that was supposed to protect you. 30-second fix: List the events explicitly. Name pandemics, wars, natural disasters, telecommunications failure, power outages. Exclude things you can insure against or control. Add a notice requirement (the protected party has to tell the other side within 48 hours) and a termination right (if it lasts more than 30 days, either party can terminate). AI never adds these. Gap 3: Data breach liability has no limit or definition If you hold customer data and there's a breach, what do you owe? Every AI contract we audited either said nothing or said something like: "In the event of a data breach, Vendor shall indemnify Client for all losses arising from the breach, including but not limited to regulatory fines, customer lawsuits, and reputational harm." This is a guarantee that will bankrupt you. Reputational harm is unmeasurable. Regulatory fines can be 2–4% of global revenue (see GDPR, PDPA). Customer lawsuits are open-ended. In Southeast Asia, you also have to deal with data localization requirements, consent laws, and mandatory reporting timelines that vary by country. A blanket data breach liability clause doesn't account for any of that. 30-second fix: (1) Define what counts as a breach (unauthorized access, not unsuccessful attempts). (2) Cap your liability at something insurance will cover (often 1–2x your annual contract value, or a fixed amount like £100K). (3) Exclude losses caused by the Client's own security failures, misuse, or