vendor-ai-review

Review vendor AI agreement terms against internal AI governance positions.

Updated May 26, 2026
One-click install
npx skills add https://github.com/yachela/claude-for-legal-ar --skill vendor-ai-review-yachela
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: vendor-ai-review
Source: https://github.com/yachela/claude-for-legal-ar/tree/main/ai-governance-legal/skills/vendor-ai-review
Command: npx skills add https://github.com/yachela/claude-for-legal-ar --skill vendor-ai-review-yachela

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It prevents silent governance drift by checking vendor AI agreement language against your organization’s AI policy positions so you can catch risky terms before signing or deploying.

Core Features & Use Cases

  • Term-by-term vendor AI governance review covering training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, sub-processors, data residency, and term/termination.
  • Gap checks for common contract shapes including DPA-without-AI-addendum and agreements that embed AI provisions in ToS/AUP materials.
  • AI policy consistency comparison to flag mismatches between vendor terms and your configured commitments, including escalation guidance when outside fallback positions are detected.
  • Stack and flow-down risk analysis to identify upstream-model and sub-processor accountability gaps across the AI service chain.

Quick Start

Review the attached vendor AI addendum or agreement PDF by running the command /ai-governance-legal:vendor-ai-review and then paste the key provisions or upload the document.

Frequently Asked Questions about vendor-ai-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review vendor AI terms for alignment with internal AI governance policies?

Review vendor AI terms by performing a term-by-term comparison against your governance positions, checking training-on-data, liability, model-change notice, output IP, incident notification, and human-review rights to catch risky clauses before signing.

What is vendor AI contract gap analysis for data processing agreements?

Vendor AI contract gap analysis identifies missing provisions in DPAs lacking AI addenda or agreements embedding AI terms in ToS, flagging escalation needs when vendor language falls outside your configured fallback governance positions.

How do I assess upstream model and sub-processor accountability in vendor AI agreements?

Assess upstream model and sub-processor accountability by performing stack and flow-down risk analysis across the AI service chain, identifying gaps in auditability, data residency, and termination handling within the vendor terms.

Can I check AI policy consistency for vendor contracts without a dedicated AI addendum?

Yes, you can check policy consistency for contracts without a dedicated AI addendum by extracting embedded AI provisions from ToS or AUP materials and comparing them against your playbook commitments for mismatches.

What vendor AI agreement provisions should I extract for a governance risk assessment?

Extract and summarize training-on-data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, auditability, sub-processors, data residency, and termination handling for a complete risk assessment.