Two hospitality attorneys uncover where the real exposure lies—and what a closed AI system does and doesn’t protect you from.
Meeting and event planners are incorporating AI into increasing areas of their work—should contracts be one of them? That’s the topic Barbara Dunn of Barbara Dunn Law, who represents groups in hotel and venue negotiations, and Kelly Bagnell of Holland & Knight, who represents hotel management and ownership, discussed during a recent webinar hosted by the SITE Florida & Caribbean chapter and moderated by Hopskip co-founder and CEO Sean Whalen. The lawyers, as always, cautioned that the information they were providing was for general education, not legal advice, but when these two legal eagles educate, it pays to learn.
It seems that the lessons are coming just in time, too. A poll opening the session found roughly 60% of attendees said they rarely or never use AI on hotel contracts, 25% said they used it only when negotiations stall, and 14% said they use AI on every contract in some capacity. But that 60% is going to shrink fast—as Dunn said, it really means “you aren’t really using it yet” and Bagnell called it the “wave of the future.”
Whether you’re currently in the 14% of those who commonly use AI in contracting now, the 60% who aren’t yet, or somewhere in between, it’s not too soon to start putting some guardrails around AI and contracts. Here are eight takeaways from the webinar to help you do just that.
!. The confidentiality trap. A planner comparing two hotel contracts, or drafting an RFP, or analyzing registration data, is likely handling material already covered by confidentiality obligations they signed. This means they risk a breach of agreements currently in force, be they documents governed by signed NDAs, confidentiality clauses inside the venue agreement itself, or just a plain old commercial expectation of privacy. Obviously, if you’re using what the panelists called open AI—publicly available large language models that learn from user inputs — the data you share could be at risk. Bagnell’s test: If you aren’t paying for the tool, you are the product. Even a routine task—comparing one hotel’s force majeure language against another’s to understand the difference—requires a closed system, meaning one of the enterprise or subscription models that do not use uploaded material for training a broader model.
2. The exposure extends beyond the contract file. Registration data, exhibitor data and other attendee information are exactly the material AI is good at analyzing. However, feed any of it into an unprotected system and the group risks violating individual privacy rights under state data protection laws and comparable regulations in the EU — a separate claim, from a different set of claimants, on top of the contractual breach. And no, incognito mode does not protect you. If the underlying model is still public and still learns from inputs, a private browsing window changes nothing about where the data goes, Dunn said.
3. Your video platform is the likeliest breach vector you aren’t even thinking about. Zoom, Teams and similar platforms now ship with recording, transcription and note-taking functions, many enabled by default. That means a record gets created without anyone deciding to create one. Even if you’re vigilant about turning these functions off, join a meeting hosted on another organization’s platform and you have no visibility into their settings. A note-taking function they enabled could be routing the conversation into an open system, and by the time anyone notices, it’s too late (see #8 below). An AI transcript of a board meeting, committee session or privileged call with counsel may be discoverable in later litigation. Dunn recommended disabling AI capture on your own devices, and ensure that whoever provides the platform ensures that it’s also disabled at the account level. It’s also a good idea to have a stated policy that meetings of this type are not to be recorded.
4. A closed system may still put you in breach of your NDA. You may think you’re protected if you’re using a closed system, but even that may not be enough to satisfy an NDA. NDAs typically define confidential information broadly and restrict its use just as broadly. Absent a specific carve-out permitting AI, Dunn said, feeding covered material into any system—closed included—may violate the agreement. Even if the NDA doesn’t specifically include AI, the best practice is to get the other side’s approval, especially if there’s a significant use of AI. Still, if you’re going to use AI for contracts, a closed system is the only way to go, and with subscriptions running as little as $25 per month, the barrier to entry is low. Just be sure the terms and conditions explain how it locks down confidential information, and that it does not use that information to train a larger model, before you start a subscription.
5. More secure doesn’t mean more accurate. No AI model has ever been admitted to practice law, as Bagnell put it. While an AI system may generate a serviceable force majeure clause, it may also fail to flag that the change requires conforming edits in five other places so the agreement reads coherently. It may be a useful tool, but it can’t replace the human expertise of an attorney who knows your organization, the applicable state laws, and all the other nuances that can trip up even the best AI.
6. You need to have a policy for that. While AI use for contracts can be risky, it may be even riskier to ban it altogether. Instead of eliminating AI use, a ban could just drive usage underground. Instead, develop a policy, or at least have the conversation. Dunn said you need three basic items in any AI policy: approved tools, permitted uses and a human in the room who is accountable. For example, an AI-assisted RFP should not go out without a person reviewing it for accuracy. Even if you aren’t ready to create a formal policy document, have a discussion with those three items on the agenda.
7. Ask about AI in your RFPs. Do you know if your vendor partners are using AI in their operations, and if so, how, and what type of system they’re using? It’s time to add those questions into your RFP. Dunn added that it now should be standard due diligence across the vendor chain—housing, registration and event tech—not just for hotels. And be ready to answer those same questions.
8. There is no clawback. Once something goes into an open system, it’s out there. There is no way to retrieve it. An accidental upload is a crisis management challenge with the same requirements as any other crisis to be managed: a decision tree for who gets notified, a prepared response to the affected party, and documentation. And don’t assume insurance will cover it, the attorneys said. Many carriers are still working out whether these are covered claims. Check to see if it’s included in the terms and conditions.
You May Also Be Interested in…
For more about how planners are using AI, check out Prevue’s webinar, How Planners Can Use AI Effectively and What it Can and Can’t Do, available now on demand.
Image by DilokaStudio on Magnific





