What problem does it solve?
This Skill helps you assess whether a vendor’s AI agreement (addendum, contract provisions, or ToS terms) matches your organisation’s UK AI governance positions and surfaces risky gaps before you sign or deploy.
Core Features & Use Cases
- Term-by-term vendor AI review: Checks training on data, confidentiality of inputs, model change notices, output IP, liability, incident notification, human review rights, use restrictions, auditability, subprocessors/model providers, data residency, and termination/deletion.
- UK GDPR international transfer check: Verifies that transfers outside the UK have an appropriate UK GDPR Chapter V mechanism (e.g., adequacy, UK IDTA, or UK addendum to SCCs).
- DPA-to-AI addendum gap detection: Flags when a UK GDPR DPA exists but no AI-specific addendum is present.
- AI policy consistency comparison: Diffs vendor terms against your configured AI policy commitments and highlights mismatches.
- Actionable outputs: Produces a bottom line, severity-rated findings, and recommended redlines plus escalation routing when items are outside fallback positions.
Quick Start
Review vendor AI terms by running the vendor-ai-review skill with the document you were sent, for example: review the AI agreement you received from the vendor by attaching the PDF and asking for a governance check.