ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Diff a new AI regulation or guidance against your current governance posture — surfaces gaps, priorities, and a remediation plan with owners and deadlines. Use when an AI regulation moves (or you learn about one you missed), or when user says "new reg just dropped", "does
$ npx -y skills add anthropics/claude-for-legal --skill reg-gap-analysis --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/reg-gap-analysisContext preview
The summary Claude sees to decide when to auto-load this skill.
Diff a new AI regulation or guidance against your current governance posture — surfaces gaps, priorities, and a remediation plan with owners and deadlines. Use when an AI regulation moves (or you learn about one you missed), or when user says "new reg just dropped", "does
name: reg-gap-analysis description: > Diff a new AI regulation or guidance against your current governance posture — surfaces gaps, priorities, and a remediation plan with owners and deadlines. Use when an AI regulation moves (or you learn about one you missed), or when user says "new reg just dropped", "does [regulation] affect us", "gap analysis for EU AI Act", "compliance check against [AI law or guidance]", or pastes regulatory text. argument-hint: "[regulation name, or paste regulatory text, or attach a document]"
1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. Confirm regulatory footprint and use case registry are populated. 2. Use the framework below. 3. Scope: does this regulation apply? (Jurisdiction, threshold, builder/deployer, sector.) If not, one line and done. 4. Extract requirements. Diff against current state in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. 5. Prioritize gaps. Output: remediation plan with must-do / should-do / already compliant / accepted gaps. 6. Save as dated markdown doc for the file.
/ai-governance-legal:reg-gap-analysis "EU AI Act high-risk provisions"
---
The EU AI Act goes live. Colorado passes an AI law. The CFPB issues model risk guidance. The FTC publishes an AI enforcement policy. Something moves — and now you need to know what, if anything, you have to change.
This skill diffs the new requirement against your current AI governance posture (per `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` — use case registry, vendor positions, impact assessment practices, and AI policy commitments) and produces a gap list with a remediation plan.
The AI regulatory landscape is moving faster than any other area of law right now. When a regulation is genuinely ambiguous, say so. Don't paper over uncertainty — legal teams need to know when they're on solid ground versus when they're making a judgment call.
Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`:
If the regulation clearly doesn't apply (wrong jurisdiction, below threshold, wrong sector, builder/deployer distinction eliminates you from scope), say so directly: "Doesn't apply. Here's why: [reason]. No action needed."
---
Before running the gap analysis, research the currently operative AI regulatory regimes for the jurisdictions in the user's footprint. For each regime identify:
Cite the regulatory text with pinpoint references. Flag provisions subject to ongoing interpretation, delegated acts, or pending rulemaking. The AI regulatory landscape changes quickly — verify currency before advising.
Build the gap analysis from the researched requirements, not from hardcoded reference tables.
Before diffing, answer:
*Builder/deployer matters a lot here.* Many AI regimes impose different obligations on the entity that develops/provides the AI system versus the entity that deploys/uses it. Research which role the company occupies under each regime's definitions. Scope first; don't gap-analyze a law that doesn't apply.
Read the regulation, guidance, or summary. List every substantive requirement:
| # | Requirement | Citation | Category | |---|---|---|---| | 1 | [requirement] | [section] | [see categories below] |
**Categories:**
For each requirement:
### [Requirement #N]: [short name] **Regulation says:** [requirement, quoted or paraphrased] **We currently:** [what `~/.claude/plugins/config/claude-for-le
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…