ai-inventory
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with
$ npx -y skills add anthropics/claude-for-legal --skill vendor-ai-review --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/vendor-ai-reviewContext preview
The summary Claude sees to decide when to auto-load this skill.
Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with
name: vendor-ai-review description: > Review vendor AI terms — agreement, addendum, or ToS AI provisions — against your governance positions; flag training-on-data, liability, model changes, and AI policy consistency. Use when user says "review this AI agreement", "check OpenAI terms", "what did we agree to with [vendor]", "vendor sent an AI addendum", "is this AI contract okay", or attaches vendor AI terms. argument-hint: "[vendor name, or attach the contract]"
1. Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. Confirm vendor governance positions are populated — if not, stop and direct to setup. 2. Use the framework below. 3. Confirm document type (AI addendum / main agreement AI provisions / ToS). If only an AUP was provided, ask for the full terms. 4. Term-by-term review: training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, audit rights. 5. AI addendum gap check if DPA exists but no AI addendum. 6. AI policy consistency diff vs. `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. 7. Output: bottom line, term-by-term, recommended redlines, if-they-won't-move routing.
/ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdf
---
**Matter context.** Check `## Matter workspaces` in the practice-level CLAUDE.md. If `Enabled` is `✗` (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run `/ai-governance-legal:matter-workspace switch <slug>` or say `practice-level`." Load the active matter's `matter.md` for matter-specific context and overrides. Write outputs to the matter folder at `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/`. Never read another matter's files unless `Cross-matter context` is `on`.
---
Vendor AI terms are where your governance positions actually get tested. The cold-start interview captures what you *want*. This skill checks what you *agreed to* — and flags the gaps between those two things.
The direction here is always the same: we are the deployer or buyer reviewing the vendor's terms. This is the opposite posture from the DPA review controller/processor question — there's no flip.
What varies is the *input*:
the vendor can do with your data or outputs)
AI vendors)
When there's a DPA already in place, this review complements it — it's not a substitute. The DPA governs data protection obligations; the AI terms govern model-specific rights and risks. Both need to be reviewed.
---
Read `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → `## Vendor AI governance`. Also read `## AI policy commitments` — vendor terms can't be consistent with a use restriction our own policy imposes if we've agreed to something different.
If `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` contains `[PLACEHOLDER]`, surface this bounce:
> I notice you haven't configured your practice profile yet — that's how I tailor vendor governance positions to your practice. > > **Two choices:** > - Run `/ai-governance-legal:cold-start-interview` (2 minutes) to configure your profile, then I'll review tailored to YOUR positions. > - Say **"provisional"** and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output `[PROVISIONAL — configure your profile for tailored output]` so you can see what I do before committing.
If the user says "provisional," run the vendor AI review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag all common vendor-AI risks from first principles rather than matching to configured positions). Tag the reviewer note and every finding block with `[PROVISIONAL]`. At the end of the output, append:
> "That was a generic run against default assumptions. Run `/ai-governance-legal:cold-start-interview` to get output calibrated to YOUR practice — your vendor governance positions, your jurisdiction, your risk appetite. 2 minutes."
---
If the user hasn't shared the actual vendor terms, ask:
> "Can you share the vendor's AI terms? The most useful thing is the actual contract > language — the AI addendum if there is one, or the main agreement with AI provisions > highlighted. An acceptable use policy alone won't tell us what the vendor can do > with our inputs; it only tells us what we're allowed to do."
If they share an acceptable use policy only: > "This is the acceptable use policy — it tells us what we can't do with the vendor's > AI. That's useful context, but it doesn't address the commercial terms: whether > the vendor can train on our data, what their liability is for AI errors, whether > they notify us when the model changes. Do you have the service agreement or AI > addendum?"
---
Review each term below. For each, extract what the vendor's contract actually says and compare it against the position in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` → `## Vendor AI governance` (standard / acceptable fallback / automatic no). The default positions come from the team's playbook, not from this skill.
| Term | What to look for | |---|---| | **Training on our data** | Doe
Reference agents, skills, and data connectors for the legal workflows we see most — in-house commercial, privacy, product, corporate, employment, litigation, regulatory, AI governance, IP, and the learning side of the practice (law school clinics and
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer,…
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per…
Run the cold-start interview — learns your AI governance practice and writes…
Guided customization of your AI governance practice profile — change one thing without…
Manage matter workspaces — new, list, switch, close, or detach (practice-level).…
Keep the AI policy current with practice — weekly sweep of saved AIAs, triage results, and…