What problem does it solve?
Vendor AI agreements often grant training-on-data, broad liability limits, and vague operational safeguards that conflict with your internal AI governance positions, creating downstream compliance and risk exposure.
Core Features & Use Cases
- Term-by-term review of vendor AI provisions: training on data, confidentiality of inputs, model change notice, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessors, data residency, and data deletion/termination obligations.
- Gap detection against your governance playbook: compares each term to the positions in your configured
CLAUDE.md and rates alignment severity to determine what can be accepted versus what must be redlined or escalated.
- Stacked-vendor accountability checks: identifies flow-down failures between SaaS wrappers, orchestration layers, and model providers so obligations are actually contractually enforceable.
- DPA vs AI addendum gap check and policy consistency diff: flags where general privacy commitments exist but AI-specific governance terms are missing or inconsistent.
Quick Start
Use the vendor-ai-review skill to review the attached vendor AI terms by running: /ai-governance-legal:vendor-ai-review <vendor-terms-file>.