ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build
$ npx -y skills add anthropics/claude-for-legal --skill policy-starter --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/policy-starterContext preview
The summary Claude sees to decide when to auto-load this skill.
Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build
name: policy-starter description: > Draft a firm AI usage policy from published model policies, adapted to your practice profile — a research-and-synthesis tool whose output is a draft for attorney review and adoption, not a finished policy. Use when user says "draft an AI policy", "we need an AI policy", "build an AI usage policy", "our firm needs a GenAI policy", or similar requests to generate a first-cut internal AI policy. argument-hint: "[optional — scope hint, e.g. 'firm-wide', 'legal team only', 'update existing']"
1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. If the practice profile is unpopulated, stop and direct to `/ai-governance-legal:cold-start-interview`. 2. Use the framework below. 3. Run the scope interview — which sections does the policy need to cover, who's the audience, what's the deployment context. Do not skip to drafting. 4. Web search for the current published model policies and guidance relevant to the deployment context (ABA, state bars, ILTA, CLOC, NIST, peer-firm / peer-company policies, current state AI laws, EU AI Act, sector regulators as applicable). 5. Draft the selected sections, sourced from the model policies, with `[review]` flags on every choice point and `[review]` open questions at the bottom of each section. 6. Output with the draft header ("DRAFT FOR INTERNAL LEGAL REVIEW — NOT FOR DISTRIBUTION"), the sources block, the reviewer note, and the adoption checklist. 7. Close with the next-steps decision tree.
/ai-governance-legal:policy-starter /ai-governance-legal:policy-starter "we need an AI policy for our 30-lawyer firm" /ai-governance-legal:policy-starter "update our existing policy for the 2026 state AI laws"
---
**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/ai-governance-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.
---
A lot of firms and in-house teams don't have a written AI usage policy yet, or are running on a 2024-vintage one that doesn't mention the state AI laws, the EU AI Act implementing acts, the 2025 COPPA amendments, or what they actually ended up doing with Copilot and Claude for Work. This skill produces a **draft** policy to bring to the decision-maker — GC, managing partner, executive committee, board, head of IT, head of HR — not a finished policy to circulate.
The discipline of this skill:
1. **Source from published model policies, not from invention.** Search for and read the ABA AI Toolkit, state bar guidance, ILTA's model policy, CLOC's templates, and peer-firm / peer-company policies that are public. Cite what each source says and adapt it — don't generate policy language out of thin air. 2. **Decision-tree the scope before drafting.** A policy that tries to cover everything covers nothing. Ask the user what sections the policy needs. Let them pick. Then build each picked section with `[review]` flags on every choice point. 3. **Flag every judgment call.** The output is a draft the attorney reviews and adopts; every threshold, every named tool, every disclosure trigger, every enforcement consequence is a `[review]` line. 4. **Header signals the scope of the audience.** This output may be read beyond legal — by HR, IT, all staff. The header is adapted accordingly.
This skill does NOT finalize, distribute, publish, or even recommend a specific position on the hard calls. It produces a draft and surfaces the choices.
Before drafting, always read the practice profile. The sections that drive the draft:
external commitments, practice setting
"adopt this" framing
If `## AI policy commitments` is populated, this is an UPDATE, not a new draft — treat the existing policy as the base and propose changes. If it's empty, this is a first-cut draft.
Ask the user which sections the policy should cover. Present as a checklist — the user picks, you build. Do not pre-decide.
> **What should the AI policy cover? Pick the sections you want in the draft:** > 1. **Scope** — who the policy applies to (all staff, certain roles, contractors), what tools it covers (GenAI only, all AI, specific vendors), what data is in/out of scope. > 2. **Permitted and prohibited uses** — the approved categories, the red lines, the "ask first" cases. > 3. **Approval and review** — who approves a new tool, who approves a new use case, how the review request is filed, what the SLA is. > 4. **Disclosure** — to clients (for firms), to courts, to counterparties, to employees, to end users of an AI feature. > 5. **Data handling** — what confidential/client/privileged data can go where, data residency, vendor retention terms, training-on-data posture. > 6. **Training and certification** — who has to take training, on what cadence, consequences for non-completion.
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…