What problem does it solve?
Vendor AI agreements often hide high-risk terms—like training on your data, model-change notices, liability for AI outputs, and human review rights—making it hard to tell whether the contract matches your governance positions.
Core Features & Use Cases
- Governance-position comparison: Compares vendor AI terms term-by-term against your playbook positions in ai-governance-legal/CLAUDE.md.
- AI-specific risk coverage: Reviews training-on-data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessors/model providers, data residency, and termination impacts.
- Stacked-vendor flow-down checks: Identifies when there are multiple layers (app, gateway, model provider, RAG/data sources, subprocessors) and checks whether commitments flow down or leave gaps.
- Output-ready negotiation guidance: Produces a bottom line, severity-tagged term gaps, and recommended surgical redlines, plus escalation routing when outside fallback.
- DPA gap awareness + policy consistency: Detects missing AI addenda when a DPA exists and flags inconsistencies with your stated AI policy commitments.
Quick Start
Use vendor-ai-review to review the AI addendum in openai-enterprise-agreement.pdf.