vendor-ai-review

Extract and compare vendor AI contract terms against governance playbook positions.

9.1k|1.8k|Updated Apr 21, 2026
One-click install
npx skills add https://github.com/anthropics/claude-for-legal --skill vendor-ai-review-anthropics
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/anthropics/claude-for-legal/tree/main/ai-governance-legal/skills/vendor-ai-review
Command: npx skills add https://github.com/anthropics/claude-for-legal --skill vendor-ai-review-anthropics

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vendor AI agreements often grant training-on-data, broad liability limits, and vague operational safeguards that conflict with your internal AI governance positions, creating downstream compliance and risk exposure.

Core Features & Use Cases

  • Term-by-term review of vendor AI provisions: training on data, confidentiality of inputs, model change notice, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessors, data residency, and data deletion/termination obligations.
  • Gap detection against your governance playbook: compares each term to the positions in your configured CLAUDE.md and rates alignment severity to determine what can be accepted versus what must be redlined or escalated.
  • Stacked-vendor accountability checks: identifies flow-down failures between SaaS wrappers, orchestration layers, and model providers so obligations are actually contractually enforceable.
  • DPA vs AI addendum gap check and policy consistency diff: flags where general privacy commitments exist but AI-specific governance terms are missing or inconsistent.

Quick Start

Use the vendor-ai-review skill to review the attached vendor AI terms by running: /ai-governance-legal:vendor-ai-review <vendor-terms-file>.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review vendor AI terms against my internal governance policy?

To review vendor AI terms against your governance policy, the skill performs term-by-term extraction comparing training, liability, model changes, and incident notification obligations against your configured CLAUDE.md playbook, producing actionable redlines.

What is a vendor AI agreement gap analysis?

A vendor AI agreement gap analysis detects conflicts between vendor terms and internal governance positions by comparing training-on-data rights, liability limits, and operational safeguards to determine acceptable terms versus escalated risks.

How do I check if SaaS wrapper AI terms flow down to the underlying model provider?

To check stacked-vendor accountability, the skill identifies flow-down failures between SaaS wrappers, orchestration layers, and model providers, ensuring obligations like incident notification and liability are contractually enforceable.

Can I use this to compare a DPA against an AI addendum for policy consistency?

Yes, you can use this to perform a DPA versus AI addendum gap check, flagging where general privacy commitments exist but AI-specific governance terms are missing or inconsistent with your governance playbook.

How do I start reviewing an uploaded AI addendum or highlighted terms of service?

To start reviewing an uploaded AI addendum, run the skill command with your vendor-terms-file; it confirms the document type, applies a standardized comparison framework, and outputs an escalation report.

What specific clauses are evaluated in a vendor AI contract review?

A vendor AI contract review evaluates specific clauses including training on data, confidentiality of inputs, model change notice, output IP, liability, incident notification, human review rights, auditability, and data deletion obligations.