ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does
$ npx -y skills add anthropics/claude-for-legal --skill policy-monitor --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/policy-monitorContext preview
The summary Claude sees to decide when to auto-load this skill.
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does
name: policy-monitor description: > Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and vendor reviews to find policy drift, or direct query for a proposed new AI practice. Use when user says "policy sweep", "does our AI policy cover this", "we want to start doing X — does the policy need updating", "run the policy monitor", or on a recurring schedule. argument-hint: "[describe a proposed new AI practice — or omit / use --sweep for crawl mode]"
**Sweep mode** (no argument or `--sweep`): 1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → outputs folder path, AI policy document, last sweep date. 2. Use the framework below. Scan outputs folder for files since last sweep. 3. For each output: extract approved practices → diff against current policy commitments and use case registry. 4. Classify gaps: REQUIRED (policy misrepresents current practice) vs ADVISABLE (policy silent). 5. For each gap: quote current policy, describe gap, draft suggested language. 6. Flag any use cases in outputs not yet added to the `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` registry. 7. Present results to the human. Only after acknowledgment, update `Last policy sweep` and `gaps_found` in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`.
**Direct query mode** (with description argument): 1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → current policy commitments, use case registry, actual policy document. 2. Parse proposed practice. Diff against policy: use case coverage, automation level, affected parties, disclosure, vendor data use, oversight. 3. Output: covered / missing / conflicting + suggested language for each gap + registry entry if needed + timing recommendation.
**Recurring runs:** Set up a recurring reminder in your own scheduler to run `/ai-governance-legal:policy-monitor` weekly. Scheduled execution requires a scheduled-tasks integration, which is not bundled with this plugin.
/ai-governance-legal:policy-monitor /ai-governance-legal:policy-monitor "We want to use AI to automatically flag expense reports for review"
---
AI policies drift from practice faster than almost any other policy document — the field moves quickly, use cases multiply, and each approved AIA or triage result represents a new commitment the policy may not have caught up with. An AIA approves a new AI use case with a human-oversight condition. A vendor AI agreement permits data processing the policy doesn't mention. A triage result marks a new category of deployment as conditional with a disclosure requirement. The policy sits there unchanged.
This skill catches the drift — either by crawling the outputs folder weekly, or by answering the direct question: "we're about to start doing X, what does that mean for our AI policy?"
The output is always the same: here's the gap, here's the suggested language.
---
Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`:
If `## Outputs` contains `[PLACEHOLDER]`: > "Outputs aren't configured yet. I can still run a direct-query check — describe > what you're planning to do and I'll diff it against your current AI policy. To > enable the crawl sweep, run `/ai-governance-legal:cold-start-interview` and provide the outputs > folder path."
Read the actual AI or acceptable use policy document from the path in `## Outputs` → **AI policy document**. The commitments in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` are a summary; the actual document is authoritative for suggesting edits.
---
**Sweep mode:** No argument, `--sweep`, or triggered by schedule. → Scan the outputs folder. Diff all outputs since last sweep against current policy.
**Direct query mode:** User provides a description of a proposed new AI practice. → Diff that practice against current policy and use case registry. Suggest updates.
---
Read `## Outputs` → **Last policy sweep** date. Scan for output files in the outputs folder dated after that date. If no date is recorded, scan all files and note: "First sweep — scanning all outputs."
If the outputs folder is empty or has no new files since the last sweep: > "No new outputs since [last sweep date]. AI policy appears current with recent > practice. Next scheduled sweep: [date]."
**Do not update `Last policy sweep` or `gaps_found` automatically.** After the sweep results are presented, wait for the human to acknowledge them ("sweep acknowledged," "results reviewed," or equivalent). Only then update `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`:
Updating the stamp before acknowledgment would let an unreviewed sweep silently roll forward and suppress the next sweep's attention to the same gaps.
**AIAs (AI Impact Assessments):**
augmentative / automated), conditions imposed, affected parties, vendor used, any disclosure requirements to affected individuals
reflected in policy, vendor added that policy doesn't cover, automated decision deployed where policy implies human oversight
**Triage results (CONDITIONAL / APPROVED outcomes):**
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Draft a firm AI usage policy from published model policies, adapted to your practice profile…