AI & Agent Legal Stack

The legal stack for AI assistants, copilots, and agents

Terms.Law, the online practice of California attorney Sergei Tokmakov, offers a fixed-fee legal stack for AI assistants, copilots, and agent products from $2,500, covering customer data, model vendors, output rights, reliance disclaimers, and subscription terms, through a writing-first private workroom; enterprise procurement negotiation is separately scoped.

I'm Sergei Tokmakov, a California attorney, Bar #279869. My practice runs writing-first: a private workroom and email threads, not phone calls. You work with me directly on your matter, not a paralegal or an intake team. See more about my practice.

What's included, from $2,500

One coordinated stack, drafted around your actual product and your actual model vendor, not a generic template.

  • Master Services Agreement, plus an Order Form / Statement of Work template for individual customers.
  • Terms of Service built around how your assistant, copilot, or agent actually works and is sold.
  • Privacy Policy and Data Processing Addendum? matched to your real data flows.
  • Acceptable Use and AI Addendum covering model-vendor rights, output rights, and reliance disclaimers?.
  • Two consolidated revision rounds, with defined terms coordinated across every document so they say the same thing.
Best for: a company shipping an AI assistant, copilot, or agent feature that needs its customer terms, privacy policy, and vendor paperwork to agree with each other and with what its model vendor actually allows.
Not for: enterprise procurement negotiation with a specific counterparty, or state-by-state regulatory filings. See What's not included below.
from $2,500

Starting fixed fee, confirmed in writing after conflict and scope review. No outcome is guaranteed; every engagement is a defined set of documents and services.

How it works

Everything runs by email and inside a private workroom. Four stages, no open-ended meter.

1

Send the brief

Tell me about your product, your model vendors, your users, and your data flows.

2

Conflict check + written scope

I confirm there is no conflict and send a fixed-fee written scope before any drafting starts.

3

Delivery in about two business days per stage

Drafts arrive staged, not all at once, after I have what I need for that stage.

4

Consolidated revisions

You send comments in one consolidated batch per round, within the two included rounds.

🤖 AI Legal Analyst

Ask my AI Legal Analyst about this package

Scopes your product against the AI Assistant & Agent Startup Legal Package and flags whether the Enterprise Procurement Upgrade or the AI Advisory & Governance Package fits better. AI-generated legal information, not legal advice, and it does not create an attorney-client relationship.

The AI Assistant & Agent Startup Legal Package is a coordinated set of documents, not a stack of unrelated templates. Every document uses the same defined terms for the same concepts (your product, your customer, your model vendor, personal data), so a court, a regulator, or an enterprise buyer's counsel reads one consistent position across the whole set.

  • Master Services Agreement and an Order Form / Statement of Work template for individual customer deals.
  • Terms of Service for self-serve or consumer-facing use of your assistant, copilot, or agent.
  • Privacy Policy describing what personal data you collect and why.
  • Data Processing Addendum for business customers who need one before they will sign.
  • Acceptable Use and AI Addendum setting rules for AI features and stating your position on inputs, outputs, and training rights.
  • Two consolidated revision rounds, comments delivered in one batch per round.

Turnaround is about two business days per delivery stage after I have the documents and answers I need for that stage.

Data typeTypical free / consumer-tier termsTypical paid API / enterprise-tier termsWhat I draft into your contract
Customer inputs (prompts, uploads) Often broad rights reserved to use submitted content to improve or train models, sometimes with an opt-out. Most major paid API and enterprise tiers state inputs are not used to train models by default. Your Terms of Service and Privacy Policy state plainly what happens to input at the vendor tier you actually pay for, and your DPA matches it.
AI-generated outputs Ownership and downstream-use rights are often ambiguous or reserved to the platform. Paid tiers commonly assign or license usable rights in the output to the API customer, subject to responsible-use terms. The AI Addendum states who owns or may use the output, and what your own customers may do with it.
Model training on your data Training use is often the default, with an opt-out if one exists. Training use is commonly off by default on paid tiers, sometimes available only as an explicit opt-in. A written no-training-by-default representation to your customers wherever your actual vendor contract supports it, with a flag where it does not.
General patterns, not a citationThese rows describe common industry patterns, not any single vendor's current terms. Model-vendor terms change frequently and vary by product tier. I confirm the specific terms of the vendor you actually use as part of the engagement, and the documents are drafted to match what your contract actually says, not a generic assumption.
Risk / responsibility areaTypically the model vendor's jobTypically your company's job
Accuracy and hallucination riskImprove the underlying model over time.Reliance disclaimers, human-review points, and accuracy limits stated to your own users.
Uptime and availabilityIts own infrastructure uptime commitments.Your uptime commitments to customers, sized to what the vendor actually promises you, not more.
Infrastructure data securityInfrastructure-level security controls.Application-level security, access control, and the representations in your own DPA.
Compliance representations to your customersIts own compliance posture and certifications.Your own representations, which cannot promise more than your vendor actually gives you in writing.
Moderation of harmful outputsModel-level safety filtering.Product-level moderation, escalation, and acceptable-use enforcement.
Substantiation riskIf your marketing describes your product as "privacy-safe," "zero-retention," or similar, that claim needs to match what your actual model-vendor contract and your own infrastructure actually do. A claim that outruns your real architecture is a substantiation problem, and in some cases a deceptive-practices exposure. Before you publish language like this, I check it against your real vendor terms and your real data flow, not just your intended design.

This review is part of how I draft the AI Addendum and the Privacy Policy: the promises in your public-facing copy and the promises in your contracts should be the same promise, stated consistently.

Main exclusion: negotiation with a specific counterparty. This package delivers your documents. It does not include live back-and-forth negotiation with a specific enterprise customer's procurement or legal team over their own paper. That is the separate Enterprise Procurement Upgrade, described below.

Also not included:

  • Regulatory filings and government registrations.
  • Trademark, patent, or IP prosecution.
  • Ongoing counsel on a continuing basis (see Outside General Counsel, linked below).

This is for

  • Seed-stage through growth-stage companies shipping an AI assistant, copilot, or agent feature.
  • Teams built on a single model API or a combination of vendors, who need one consistent story across their contracts.
  • Products that already have, or are about to have, real users and real customer data.

This is probably not for

  • A pre-product idea with no live users yet. A written consultation is a lighter, cheaper starting point.
  • A company that needs a specific state money-transmitter or securities filing. That is separately scoped, not part of this package.
  • A company already deep in one specific enterprise customer's redline. See the Enterprise Procurement Upgrade instead.
  • A product handling health data at HIPAA scale. See the Healthcare SaaS Legal Package instead.
ApproachTypical priceTailored to your data flowsAttorney-reviewedCoordinated across documentsRevisions
Generic template off the internetFree to about $50NoNoNoNone
Legal-tech document-assembly subscriptionRoughly $20 to $400 per monthForm fields onlyUsually noneSometimesDepends on plan
Traditional law firm hourly engagementOften well above $2,500 at typical hourly ratesYesYesOftenBilled by the hour, open-ended

Ranges above are general market patterns, not quotes from any specific competitor. No outcome is guaranteed under any approach.

A software company preparing to launch an AI copilot feature came to me before its public launch. It was already using a paid third-party model API and needed its Terms of Service, Privacy Policy, Data Processing Addendum, and Acceptable Use and AI Addendum to say the same thing about customer inputs, model outputs, and training rights that its actual vendor contract said, not what a generic template assumed.

I built the coordinated stack around its real data flow: which vendor processed customer prompts, whether outputs fed back into training anywhere, and what its own paying customers needed to see about reliance and accuracy. The engagement was the AI Assistant & Agent Startup Legal Package described on this page.

No outcome, revenue result, or regulatory approval is promised or was promised in that engagement. No names and no dollar figures beyond the package price are used here.

Enterprise Procurement Upgrade

from $1,500 (add-on)
  • DPA hardening for enterprise data terms.
  • Security and trust addendum posture.
  • Indemnity and liability-cap architecture review.
  • Redline playbook: your fallback positions on the ten most-negotiated clauses.
  • One consolidated revision round.

Does not include live negotiation with the enterprise counterparty itself, which is separately scoped, or SOC 2 / security certification work.

Request this package · from $1,500

AI Advisory & Governance Package

from $2,000
  • AI use policy tailored to your business.
  • Vendor and model diligence checklist and contract terms.
  • Client or customer disclosure language.
  • Professional-rules gap analysis (CA RPC 1.1 / 1.6 / 5.3 / 1.4 / 1.5 for law firms, or the sector equivalent).
  • One consolidated revision round.

Does not include litigation and enforcement defense, or technical model evaluation and security testing.

Request this package · from $2,000

Which model vendors does this cover?

The package is not tied to one vendor. I draft your documents to match whichever model API or combination of vendors you actually use, and I confirm the specific vendor terms that apply to your account as part of the engagement.

Can you promise my product will be legally compliant?

No. I can tell you what a well-built AI and SaaS legal stack looks like for your actual product and data flows, and I draft it accordingly, but no attorney can promise a product is compliant or legally safe in the abstract. That depends on your specific facts, your jurisdiction, and how your product actually operates, and it can change as regulations and your product change.

Do you review documents I already have, or only draft new ones?

Both. Tell me what you already have at intake. Where an existing document fits, I revise it into the coordinated set; where it does not, I draft a new one. Either way the goal is one coordinated set with matching defined terms.

What if I add a new AI feature after delivery?

Material product changes, such as a new AI feature or a new model vendor, are outside the two included revision rounds. They are scoped separately, whether as a small update or, if the change is substantial, a new engagement.

Is enterprise contract negotiation included?

No. Negotiating directly with a specific enterprise counterparty's paper is the separate Enterprise Procurement Upgrade, from $1,500, described above.

How fast is delivery?

About two business days per delivery stage after I have your documents and answers, per the written scope. Two consolidated revision rounds are included after that.

Ready to start your AI legal stack?

Start package intake and I will confirm conflicts and scope, in writing, before any drafting begins. See all services if you are not sure this is the right one.