What problem does it solve?
It helps you quickly spot where a vendor’s AI agreement (AI addendum, agreement AI provisions, or AI terms in ToS/AUP) conflicts with your organization’s AI governance positions, so you can avoid signing “training-on-data,” weak liability, or inconsistent model-change terms without realizing it.
Core Features & Use Cases
- Term-by-term vendor AI review: evaluates training-on-data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessor/model-provider terms, data residency, and retention/termination.
- DPA + AI addendum gap detection: flags when a DPA exists but the AI-specific addendum (or AI provisions) is missing for key AI-risk topics.
- Playbook consistency diff: compares extracted contract positions against your configured vendor AI governance in the practice-level CLAUDE.md and assigns severity (🟢/🟡/🟠/🔴) plus targeted redlines.
- Stack mapping + flow-down checks: helps you identify layered AI stacks (SaaS → gateway → model provider → RAG/knowledge → subprocessors) and ensures commitments flow down across vendors rather than being “assumed” at the top layer.
Quick Start
Use the vendor-ai-review skill to review the vendor’s AI terms in a file you attach and generate a governance-aligned redline checklist by asking it to review openai-enterprise-agreement.pdf.