vendor-ai-review

Review vendor AI agreements for governance, privacy, liability, and operational risks.

109|20|Updated Mar 7, 2025
One-click install
npx skills add https://github.com/stakwork/stakgraph --skill vendor-ai-review-stakwork
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/stakwork/stakgraph/tree/main/mcp/skills/ai-governance-legal/vendor-ai-review
Command: npx skills add https://github.com/stakwork/stakgraph --skill vendor-ai-review-stakwork

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill identifies governance, privacy, liability, and operational risks in vendor AI agreements so organizations can make informed decisions before deployment or signature.

Core Features & Use Cases

  • Term-by-Term Analysis: Reviews training on customer data, confidentiality, model changes, output ownership, liability, incident notification, human review, use restrictions, auditability, subprocessors, data residency, and termination.
  • Governance Comparison: Compares vendor language against configured governance positions, AI policy commitments, risk tiers, and acceptable fallbacks.
  • Stacked-Vendor Review: Maps upstream model providers and subprocessors, checks flow-down obligations, and identifies gaps in accountability, retention, training, and liability.
  • Redline and Escalation Guidance: Produces surgical redline recommendations, critical issue routing, AI addendum gap analysis, and next-step decision options.
  • Use Case: Review an enterprise AI addendum and determine whether the vendor may train on confidential inputs, whether model changes require notice, and which terms must be redlined before approval.

Quick Start

Use the vendor AI review skill to analyze the attached AI agreement for training, confidentiality, liability, model-change, audit, and flow-down risks against our configured governance positions.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review an AI vendor agreement for training and liability risks?

To review an AI vendor agreement for risks, perform a term-by-term analysis covering training on customer data, confidentiality, model changes, liability, and incident notification against your configured governance positions before signature.

What contractual risks should I check before signing a vendor AI addendum?

Key contractual risks in a vendor AI addendum include whether the vendor may train on confidential inputs, if model changes require notice, output ownership, auditability, subprocessor flow-down obligations, and data residency requirements.

How do I verify flow-down obligations across stacked AI vendors and subprocessors?

To verify flow-down obligations in stacked AI deployments, map upstream model providers and subprocessors, then check whether accountability, retention, training, and liability terms flow correctly through the vendor chain.

Can I generate legal redlines for AI terms of service based on my governance policy?

Yes, you can generate surgical legal redlines for AI terms of service by comparing vendor language against your configured governance positions, AI policy commitments, and acceptable risk fallbacks to identify necessary modifications.

What is AI addendum gap analysis and when do I need it?

AI addendum gap analysis identifies missing or insufficient contractual protections in vendor AI agreements by comparing terms against your governance positions, producing escalation routing and next-step decision options for deployment approval.

Does vendor AI contract review work for acceptable use policies and terms of service?

Yes, vendor AI contract review applies to AI addenda, agreements with embedded AI provisions, terms of service, and acceptable use policies, checking for governance, privacy, liability, and operational risks before deployment.