vendor-ai-review

Compare vendor AI contract terms against configured governance positions and generate redlines.

Updated May 15, 2026
One-click install
npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill vendor-ai-review-az9713
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/az9713/claude-for-legal-tutorial/tree/main/ai-governance-legal/skills/vendor-ai-review
Command: npx skills add https://github.com/az9713/claude-for-legal-tutorial --skill vendor-ai-review-az9713

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It helps you quickly spot where a vendor’s AI agreement (AI addendum, agreement AI provisions, or AI terms in ToS/AUP) conflicts with your organization’s AI governance positions, so you can avoid signing “training-on-data,” weak liability, or inconsistent model-change terms without realizing it.

Core Features & Use Cases

  • Term-by-term vendor AI review: evaluates training-on-data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessor/model-provider terms, data residency, and retention/termination.
  • DPA + AI addendum gap detection: flags when a DPA exists but the AI-specific addendum (or AI provisions) is missing for key AI-risk topics.
  • Playbook consistency diff: compares extracted contract positions against your configured vendor AI governance in the practice-level CLAUDE.md and assigns severity (🟢/🟡/🟠/🔴) plus targeted redlines.
  • Stack mapping + flow-down checks: helps you identify layered AI stacks (SaaS → gateway → model provider → RAG/knowledge → subprocessors) and ensures commitments flow down across vendors rather than being “assumed” at the top layer.

Quick Start

Use the vendor-ai-review skill to review the vendor’s AI terms in a file you attach and generate a governance-aligned redline checklist by asking it to review openai-enterprise-agreement.pdf.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review vendor AI agreement terms against my data governance policy?

To review vendor AI agreement terms, you compare clauses like training-on-data, confidentiality, and liability against your configured governance positions. This identifies gaps and generates targeted redlines for your AI addendum or ToS AI clauses.

What is a stacked-vendor flow-down check for AI model providers?

A stacked-vendor flow-down check ensures AI commitments apply across layered stacks like SaaS, gateways, and model providers. It verifies liability and data terms flow down to subprocessors rather than being assumed at the top layer.

How do I redline AI addendum gaps for missing data residency and model change terms?

Redlining AI addendum gaps involves extracting terms for data residency, model changes, and incident notification, then comparing them to your playbook. Missing or weak provisions are flagged with severity levels and proposed redline text.

Does this vendor AI review tool check output IP ownership and human review rights?

Yes, vendor AI review checks output IP ownership and human review rights. It evaluates these specific clauses within your AI agreement provisions to ensure they align with your organization's governance requirements.

Can I use this for AI terms embedded in a standard SaaS Terms of Service?

Yes, you can review AI terms embedded in a standard SaaS Terms of Service. The tool evaluates ToS AI clauses, main agreement AI provisions, and dedicated AI addenda to catch training-on-data and liability conflicts.

When should I not rely on an AI addendum without checking subprocessor commitments?

You should not rely on an AI addendum without checking subprocessor commitments when using layered AI stacks. Top-layer SaaS agreements often lack flow-down responsibilities, leaving data governance gaps with underlying model providers unaddressed.