vendor-ai-review

Identify AI-specific risks in vendor contracts for LLM APIs and ML services.

17|4|Updated May 25, 2026
One-click install
npx skills add https://github.com/AlsKozlov/ru-legal --skill vendor-ai-review-alskozlov
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/AlsKozlov/ru-legal/tree/main/packs/ai-governance/skills/vendor-ai-review
Command: npx skills add https://github.com/AlsKozlov/ru-legal --skill vendor-ai-review-alskozlov

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill eliminates the risk of missing AI-specific contract clauses, Russian 152-FZ personal data compliance gaps, and post-2022 sanctions exposure that generic SaaS contract reviews fail to catch when evaluating AI vendors.

Core Features & Use Cases

  • AI-Specific Clause Review: Structured checklist covering data training rights, output ownership, model warranty, hallucination liability, rate limits, and API stability for LLM APIs, ML libraries, and AI services.
  • Russian Legal Compliance: Built-in checks for 152-FZ personal data localization requirements, processor obligations, and RKN notification rules.
  • Sanctions Risk Assessment: Evaluation of US/EU vendor access, payment, and termination risks post-2022, plus recommendations for Russian or open-source alternatives. Use Case: A legal team can use this Skill to review a YandexGPT API contract to confirm no unauthorized training on customer personal data and verify compliance with Russian data localization laws.

Quick Start

Use the vendor-ai-review skill to assess the attached AI vendor contract for compliance with Russian data protection rules and sanctions risks.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review an AI vendor contract for Russian data protection compliance?

AI vendor contract review checks for 152-FZ personal data localization gaps, processor obligations, and RKN notification rules to ensure compliance for Russian organizations evaluating LLM APIs and ML services.

What AI-specific contract risks do generic SaaS reviews miss?

Generic SaaS reviews miss AI-specific risks like unauthorized data training rights, output ownership ambiguity, hallucination liability, and API rate limit stability for LLM APIs and ML libraries.

How do I assess sanctions exposure in foreign AI vendor contracts?

Sanctions exposure assessment evaluates US and EU AI vendor access, payment, and termination risks post-2022, providing recommendations for Russian or open-source AI service alternatives.

Does this contract review check ownership of AI model outputs?

AI vendor contract review includes a structured checklist verifying output ownership, model warranty terms, and hallucination liability for LLM APIs, ML services, and AI libraries.

Can I use this to audit a YandexGPT API contract for training rights?

AI vendor contract review can audit YandexGPT API agreements to confirm no unauthorized training on customer personal data and verify alignment with Russian data localization laws.

What are the limitations of automating AI governance legal audits?

Automated AI governance audits focus on structured contract review for 152-FZ compliance and sanctions risks, requiring subsequent legal interpretation for complex, non-standard vendor liability clauses.