The product became autonomous. The contract never followed.

Sample report 2 (anonymized) — finding format as delivered · Product "A": an AI customer-service agent platform whose agents execute financial actions · September 2026

Scope & sources

Terms of Service, Privacy Policy, Data Processing Agreement, security / trust page, and product marketing — fetched live and cross-checked line-by-line. Every quote was verified against a timestamped capture; clause references point at the live documents as of the audit date.

Findings

F1 MAJOR The contract predates the product

The ToS is dated early 2023 and describes the service as "a tool that connects to your helpdesk software." The product sold today is a suite of autonomous agents that — per the homepage — handle returns, refunds, cancellations and subscription changes "end to end," with an automation rate of "up to 89%." The contract framework (a generic cloud-SaaS standard from 2023) contains no provisions on: the scope of autonomous actions, AI output accuracy, human-in-the-loop routing, or liability for agent-executed financial actions. A wrongly-issued refund falls into generic warranty machinery and a cap of 12 months of fees — designed for downtime, not autonomous money movement.

Recommended fix: update the service definition; add an "Agent Actions" section enumerating permitted autonomous actions (with ceilings), making threshold routing and human escalation contractual, and deciding whether agent-action liability sits inside or outside the general cap.
F2 MAJOR The safety mechanism is marketing copy

The homepage promises: you set the confidence threshold, and anything the agent can't handle "goes to your team with full context." For agents that move money, this routing promise is the risk control — and it appears nowhere in the ToS or DPA. If the behavior changed tomorrow, no contract term would be breached.

F3 MAJOR AI-improvement opt-out with no contractual anchor

The security page states customer data may be used to improve the vendor's AI models, with an opt-out "at any time" — on the same page that says data use limits are "contractual, in our DPA." The DPA is recent and well-built, but contains no AI-improvement or opt-out clause at all. The promise customers rely on is not the contract they sign.

Recommended fix: an "AI Improvement Use" addendum — default state, scope, notice, and the opt-out as a contractual right.
F4 MEDIUM Newest product line missing from the privacy policy's data categories

A voice-AI product line is promoted in the site navigation, but the Privacy Policy's enumerated categories (support interactions, order data) never name call recordings or transcripts, and the DPA annex declares no special-category data. The highest-sensitivity category the company processes is the one the policy never mentions.

Verified-consistent items (included for credibility)

Why this pattern matters in 2026

Agents that execute actions — refunds, cancellations, purchases — are shipping under SaaS contracts drafted for dashboards. The gap is never malicious; it's calendar drift: the roadmap moved to autonomous actions, the paper didn't. It surfaces exactly when it costs most: the first enterprise security review.

Delivered by loveoftheai — docs↔ToS consistency audits, $99 / 72h, pay-after-delivery. Sample anonymized; method, severity scale, and fix format identical to paid reports. See also sample 1 — payments feature with zero contract coverage. Documentation review, not legal advice.