vendor-ai-review
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
Chinese/vendor-ai-review
/vendor-ai-review
- Read . Confirm vendor governance positions are populated — if not, stop and direct to setup.
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - Use the framework below.
- Confirm document type (AI addendum / main agreement AI provisions / ToS). If only an AUP was provided, ask for the full terms.
- Term-by-term review: training on data, confidentiality of inputs, model changes, output IP, liability, incident notification, human review rights, use restrictions, audit rights.
- AI addendum gap check if DPA exists but no AI addendum.
- AI policy consistency diff vs. .
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - Output: bottom line, term-by-term, recommended redlines, if-they-won't-move routing.
/ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdf- 读取文件。确认供应商治理立场已填充——如果未填充,请停止操作并引导用户进行设置。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - 使用以下框架开展工作。
- 确认文档类型(AI补充条款 / 主协议中的AI相关条款 / 服务条款)。如果仅提供了可接受使用政策(AUP),请要求提供完整条款。
- 逐条审查:数据训练、输入保密性、模型变更、输出知识产权(IP)、责任、事件通知、人工审核权、使用限制、审计权。
- 若已存在数据处理协议(DPA)但无AI补充条款,进行AI补充条款缺口检查。
- 对照文件,检查AI政策一致性差异。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - 输出内容:核心结论、逐条审查结果、建议的红线修订内容、若供应商拒绝修改时的处理路径。
/ai-governance-legal:vendor-ai-review openai-enterprise-agreement.pdfMatter context
事项上下文
Matter context. Check in the practice-level CLAUDE.md. If is (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run or say ." Load the active matter's for matter-specific context and overrides. Write outputs to the matter folder at . Never read another matter's files unless is .
## Matter workspacesEnabled✗/ai-governance-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/Cross-matter contexton事项上下文。查看业务层面CLAUDE.md文件中的部分。如果“启用”状态为(内部用户默认设置),则跳过本段剩余内容——技能将使用业务层面的上下文,事项机制不可见。如果已启用且无活跃事项,请询问:“这是针对哪个事项的?运行或告知。”加载活跃事项的文件,获取事项特定上下文和覆盖规则。将输出写入事项文件夹:。除非“跨事项上下文”已开启,否则切勿读取其他事项的文件。
## Matter workspaces✗/ai-governance-legal:matter-workspace switch <slug>practice-levelmatter.md~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/Purpose
目的
Vendor AI terms are where your governance positions actually get tested. The cold-start
interview captures what you want. This skill checks what you agreed to — and flags
the gaps between those two things.
The direction here is always the same: we are the deployer or buyer reviewing the
vendor's terms. This is the opposite posture from the DPA review controller/processor
question — there's no flip.
What varies is the input:
- A standalone AI agreement or AI addendum (most structured)
- A vendor's universal terms of service with AI provisions embedded (often buried)
- An acceptable use policy (tells you what you can't do; says nothing about what the vendor can do with your data or outputs)
- A combination — master agreement + DPA + AI addendum (common for serious enterprise AI vendors)
When there's a DPA already in place, this review complements it — it's not a
substitute. The DPA governs data protection obligations; the AI terms govern
model-specific rights and risks. Both need to be reviewed.
供应商AI条款是检验您治理立场的实际场景。初始访谈记录了您的期望,而本技能则核查您已达成的协议——并标记两者之间的差距。
本技能的立场始终一致:我们是部署方或采购方,负责审查供应商的条款。这与DPA审查中的控制方/处理方问题立场相反——不存在立场转换。
变化的是输入内容:
- 独立AI协议或AI补充条款(结构最清晰)
- 供应商通用服务条款中嵌入的AI相关条款(通常隐藏较深)
- 可接受使用政策(仅说明禁止行为;未提及供应商可对您的数据或输出采取的操作)
- 组合文件——主协议 + DPA + AI补充条款(严肃的企业级AI供应商常用)
若已存在DPA,本审查是对其的补充——而非替代。DPA管辖数据保护义务;AI条款管辖模型特定的权利和风险。两者均需审查。
Load the playbook
加载操作手册
Read → . Also read
— vendor terms can't be consistent with a use restriction our own policy imposes if
we've agreed to something different.
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md## Vendor AI governance## AI policy commitmentsIf contains , surface this bounce:
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md[PLACEHOLDER]I notice you haven't configured your practice profile yet — that's how I tailor vendor governance positions to your practice.Two choices:
- Run
(2 minutes) to configure your profile, then I'll review tailored to YOUR positions./ai-governance-legal:cold-start-interview- Say "provisional" and I'll review against generic defaults — US jurisdiction, middle risk appetite, lawyer role, no playbook — and tag every output
so you can see what I do before committing.[PROVISIONAL — configure your profile for tailored output]
读取文件中的部分。同时读取部分——如果我们已达成的协议与自身政策施加的使用限制不符,供应商条款就无法保持一致。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md## Vendor AI governance## AI policy commitments如果文件包含,则显示以下提示:
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md[PLACEHOLDER]我注意您尚未配置业务档案——这是我为您量身定制供应商治理立场的依据。两种选择:
- 运行
(2分钟)配置您的档案,之后我将根据您的立场进行定制化审查。/ai-governance-legal:cold-start-interview- 回复**"临时模式"**,我将根据通用默认规则进行审查——美国管辖、中等风险偏好、律师角色、无操作手册——并在所有输出中标记
,以便您在正式配置前了解我的审查内容。[PROVISIONAL — configure your profile for tailored output]
Provisional mode
临时模式
If the user says "provisional," run the vendor AI review normally using these generic defaults: middle risk appetite, lawyer role, US jurisdiction, no playbook (flag all common vendor-AI risks from first principles rather than matching to configured positions). Tag the reviewer note and every finding block with . At the end of the output, append:
[PROVISIONAL]"That was a generic run against default assumptions. Runto get output calibrated to YOUR practice — your vendor governance positions, your jurisdiction, your risk appetite. 2 minutes."/ai-governance-legal:cold-start-interview
如果用户回复“临时模式”,则使用以下通用默认规则正常开展供应商AI审查:中等风险偏好、律师角色、美国管辖、无操作手册(从基本原则出发标记所有常见供应商AI风险,而非匹配已配置立场)。在审查说明和每个发现模块中标记。在输出末尾添加:
[PROVISIONAL]"本次审查基于默认假设的通用运行。运行可获得与您业务校准的输出——匹配您的供应商治理立场、管辖区域、风险偏好。仅需2分钟。"/ai-governance-legal:cold-start-interview
Before reading the document
阅读文档前
If the user hasn't shared the actual vendor terms, ask:
"Can you share the vendor's AI terms? The most useful thing is the actual contract language — the AI addendum if there is one, or the main agreement with AI provisions highlighted. An acceptable use policy alone won't tell us what the vendor can do with our inputs; it only tells us what we're allowed to do."
If they share an acceptable use policy only:
"This is the acceptable use policy — it tells us what we can't do with the vendor's AI. That's useful context, but it doesn't address the commercial terms: whether the vendor can train on our data, what their liability is for AI errors, whether they notify us when the model changes. Do you have the service agreement or AI addendum?"
如果用户未分享实际供应商条款,请询问:
"能否分享供应商的AI条款?最有用的是实际合同文本——如有AI补充条款则提供该条款,或提供标记了AI相关条款的主协议。仅提供可接受使用政策无法告知我们供应商可对您的输入采取的操作;它仅说明我们被允许的行为。"
如果用户仅分享了可接受使用政策:
"这是可接受使用政策——它说明了我们不能对供应商的AI采取哪些操作。这是有用的背景信息,但未涉及商业条款:供应商是否可以使用我们的数据进行训练、对AI错误承担何种责任、模型变更时是否会通知我们。您是否有服务协议或AI补充条款?"
The term-by-term review
逐条审查
Core AI-specific terms (check every vendor AI agreement)
AI核心特定条款(每份供应商AI协议均需检查)
Review each term below. For each, extract what the vendor's contract actually says and compare it against the position in → (standard / acceptable fallback / automatic no). The default positions come from the team's playbook, not from this skill.
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md## Vendor AI governance| Term | What to look for |
|---|---|
| Training on our data | Does the vendor use our inputs to train, fine-tune, or improve models? Is there an explicit opt-out or prohibition? Is training opt-in or opt-out by default? |
| Confidentiality of inputs | Are our prompts, documents, and data confidential? Any "quality review" or human-review carveouts that would let vendor staff read inputs? |
| Model changes | Any notice obligation for material changes to the model? Version pinning available? |
| Output ownership / IP | Who owns AI-generated content? Any license-back to the vendor on outputs? Any IP indemnity? |
| Liability for outputs | Does the vendor accept any liability if the AI produces harmful, incorrect, or infringing outputs? Cap structure? Carve-outs? |
| Incident notification | How and when are we notified if the AI system fails, is compromised, or produces systematic errors affecting us? |
| Human review rights | Can we require human review of outputs in specific cases? Can we appeal or dispute an AI decision? |
| Use restrictions | What are we prohibited from doing? Does it match what we actually want to use the tool for? Any definitional terms (e.g., "automated decision-making") that could sweep in our intended uses? |
| Audit / auditability | SOC 2, third-party audits, bias testing results — any audit rights? |
| Subprocessors / model providers | Does the vendor use sub-vendors for the model? Are they disclosed? Whose terms govern? |
| Data residency | Where is our data processed? Where does it go for inference? |
| Term and termination | What happens to our data when we terminate? Deletion timelines? |
| Stacked-vendor accountability | Is this vendor the model provider (e.g., Anthropic, OpenAI, Google, Meta), or are they a deployer of someone else's model (e.g., a SaaS wrapper of Claude, ChatGPT, or Gemini) or a reseller of infrastructure-hosted foundation models (Anthropic-on-Bedrock, Claude-on-Vertex, OpenAI-on-Azure)? If the latter: there are TWO vendors' terms in play — the one you're reviewing, plus the upstream model provider's terms. Identify (a) whose terms govern training on inputs, retention, and safety, (b) who is contractually liable for model behavior, and (c) whether each upstream commitment (e.g., "no training on inputs") is flowed down to you, or remains between the vendor and the upstream provider only. Flag any clause where one party disclaims responsibility for the other (e.g., "Anthropic is not responsible for Bedrock or any other services it receives from AWS"; "Azure disclaims responsibility for OpenAI model outputs") and whether the counter-party's contract closes the gap. Do not review the two contracts in isolation. |
If doesn't define a position for a term on this list, ask: "Your playbook doesn't cover [term]. What's your default position, your acceptable fallback, and your automatic no? I'll add it to so the next review is consistent."
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md审查以下每一项条款。对于每一项,提取供应商合同的实际内容,并与文件部分中的立场(标准/可接受 fallback/绝对不可接受)进行对比。默认立场来自团队操作手册,而非本技能。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md## Vendor AI governance| 条款 | 审查要点 |
|---|---|
| 使用我们的数据进行训练 | 供应商是否使用我们的输入来训练、微调或改进模型?是否有明确的退出选项或禁止条款?训练默认是 opt-in 还是 opt-out? |
| 输入保密性 | 我们的提示词、文档和数据是否保密?是否存在允许供应商员工读取输入的“质量审核”或人工审核例外情况? |
| 模型变更 | 模型发生重大变更时是否有通知义务?是否支持版本固定? |
| 输出所有权/知识产权 | AI生成内容归谁所有?供应商是否对输出拥有反向许可权?是否有知识产权赔偿条款? |
| 输出责任 | 如果AI产生有害、错误或侵权输出,供应商是否承担任何责任?责任上限结构?例外情况? |
| 事件通知 | 当AI系统故障、遭入侵或产生影响我们的系统性错误时,供应商将如何以及何时通知我们? |
| 人工审核权 | 我们是否可要求在特定情况下对输出进行人工审核?是否可对AI决策提出申诉或异议? |
| 使用限制 | 禁止我们进行哪些操作?是否与我们实际想使用该工具的用途匹配?是否存在可能涵盖我们预期用途的定义术语(如“自动化决策”)? |
| 审计/可审计性 | 是否有SOC 2认证、第三方审计、偏差测试结果?是否有审计权? |
| 分包商/模型提供商 | 供应商是否使用第三方模型?是否披露?适用谁的条款? |
| 数据驻留 | 我们的数据在哪里处理?推理时数据会发送到哪里? |
| 条款期限与终止 | 终止协议时我们的数据会如何处理?删除时限? |
| 多层供应商问责制 | 该供应商是模型提供商(如Anthropic、OpenAI、Google、Meta),还是他人模型的部署方(如Claude、ChatGPT或Gemini的SaaS封装),还是基础设施托管基础模型的经销商(Anthropic-on-Bedrock、Claude-on-Vertex、OpenAI-on-Azure)?如果是后者:存在两层供应商条款——您正在审查的条款,加上上游模型提供商的条款。需明确:(a) 谁的条款管辖输入训练、保留和安全,(b) 谁对模型行为承担合同责任,(c) 每项上游承诺(如“不使用输入进行训练”)是否传导给您,还是仅存在于供应商与上游提供商之间。标记任何一方免责另一方责任的条款(如“Anthropic不对其从AWS接收的Bedrock或任何其他服务负责”;“Azure不对OpenAI模型输出负责”),以及对方合同是否填补了该缺口。切勿孤立审查两份合同。 |
如果文件未定义列表中某条款的立场,请询问:“您的操作手册未涵盖[条款名称]。您的默认立场、可接受 fallback 和绝对不可接受情况是什么?我会将其添加到文件中,以便后续审查保持一致。”
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.mdPlaybook comparison
操作手册对比
For each term above, compare what we found to the positions in .
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.mdOutput format for each term:
[Term name] 🟢 / 🟡 / 🟠 / 🔴 Vendor says: [summary of what the contract actually says] Our position: [from] Gap: [specific delta — or "Aligned"] Proposed fix: [specific redline language, or "escalate — outside fallback"]~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
Use the severity ratings consistently (calibrated against positions):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md- 🟢 Aligned — at or better than the standard position in the playbook.
- 🟡 Note — within fallback but worse than standard; flag for awareness, not a blocker.
- 🟠 Significant — outside standard position but within fallback; needs redline before signing.
- 🔴 Critical — outside fallback; deployment should not proceed without resolution. Escalate per .
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
对于上述每一项条款,将我们的发现与文件中的立场进行对比。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md每项条款的输出格式:
[条款名称] 🟢 / 🟡 / 🟠 / 🔴 供应商条款: [合同实际内容摘要] 我方立场: [来自文件] 差距: [具体差异——或“一致”] 建议修正: [具体红线修订语言,或“升级处理——超出fallback范围”]~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
严格按照严重程度评级(根据文件立场校准):
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md- 🟢 一致——达到或优于操作手册中的标准立场。
- 🟡 注意——在fallback范围内但逊于标准;仅标记以引起注意,不构成障碍。
- 🟠 重大——超出标准立场但在fallback范围内;签署前需进行红线修订。
- 🔴 关键——超出fallback范围;未解决前不得部署。按照文件中的升级路径处理。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
AI addendum gap check
AI补充条款缺口检查
If the vendor has a DPA but no AI addendum:
"There's a DPA in place but no AI-specific addendum. The DPA covers data protection obligations but doesn't address: training on our data, model change notification, liability for AI outputs, or incident notification for AI system failures.For a [Standard / Elevated / High] tier use case, this gap is [acceptable at Standard tier / a blocker at Elevated or High tier]. Recommend requesting an AI addendum or at minimum negotiating AI-specific terms into the next renewal."
If there are no AI terms at all:
"There are no AI-specific terms in this agreement. The vendor is providing an AI-powered service under general service terms — which means we have no contractual protection on the highest-risk AI governance items (training, liability, model changes). This is a 🔴 for any Elevated or High tier use case."
如果供应商已有DPA但无AI补充条款:
"已存在DPA但无AI特定补充条款。DPA涵盖数据保护义务,但未涉及:使用我们的数据进行训练、模型变更通知、AI输出责任、AI系统故障事件通知。对于[标准/高级/高风险]级别的用例,该缺口[在标准级别可接受 / 在高级或高风险级别构成障碍]。建议要求提供AI补充条款,或至少在下次续约时协商加入AI特定条款。"
如果完全没有AI条款:
"本协议中无任何AI特定条款。供应商在通用服务条款下提供AI驱动服务——这意味着我们在最高风险的AI治理事项(训练、责任、模型变更)上无合同保护。对于任何高级或高风险级别的用例,这属于🔴关键问题。"
AI policy consistency check
AI政策一致性检查
Cross-check the vendor's terms against our AI policy commitments in .
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.mdCommon conflicts:
- Our policy prohibits vendor training on our data — the vendor's terms permit it by default. (Contract needs explicit prohibition or opt-out confirmation.)
- Our policy requires human review for certain use cases — vendor's terms say AI outputs are final. (Workflow needs to impose the human step, not the vendor terms.)
- Our approved vendor list doesn't include this vendor — or blocklist does.
- Our policy requires disclosure to affected parties — vendor's terms impose a confidentiality obligation on AI system capabilities that would prevent disclosure.
Flag every mismatch. One of them has to change.
将供应商条款与文件中的AI政策承诺进行交叉检查。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md常见冲突:
- 我方政策禁止供应商使用我们的数据进行训练——但供应商条款默认允许。(合同需明确禁止或确认退出选项。)
- 我方政策要求特定用例需人工审核——但供应商条款规定AI输出为最终结果。(需在工作流程中加入人工步骤,而非依赖供应商条款。)
- 我方已批准供应商列表中不包含该供应商——或该供应商在黑名单中。
- 我方政策要求向受影响方披露——但供应商条款对AI系统能力施加保密义务,阻碍披露。
标记所有不匹配项。必须调整其中一方。
Redline granularity
红线修订粒度
Edit at the smallest possible granularity. A redline is a negotiation artifact, not a rewrite. Wholesale clause replacement signals "we threw out your drafting" — it's aggressive, it forces the counterparty to re-read the whole clause, and it discards the parts of their drafting that were fine. Surgical redlines — strike a word, insert a phrase, restructure a subclause — signal "we have specific asks" and are faster to read, understand, and accept.
Default to the smallest edit that achieves the playbook position:
- Replace a word before a phrase. ("twelve (12)" → "twenty-four (24)")
- Replace a phrase before a sentence. ("paid by the Buyer" → "paid and payable by the Buyer")
- Restructure a subclause before replacing the sentence. (Add "(a)" and "(b)" to split a compound condition.)
- Replace a sentence before replacing the clause.
- Only replace a whole clause when the counterparty's version is so far from your position that surgical edits would be harder to read than a fresh draft — and when you do, say so in the transmittal: "We've replaced §8.2 rather than marking it up because the changes were extensive. Happy to walk you through the delta."
When in doubt, smaller. A client who receives a surgical redline trusts that you read carefully. A client who receives a wholesale replacement wonders whether you read at all.
以最小粒度进行编辑。红线修订是谈判工具,而非重写。 wholesale替换条款意味着“我们否决了您的起草内容”——这种方式过于强硬,会迫使对方重新阅读整个条款,且丢弃了其起草中合理的部分。精准的红线修订——删除一个词、插入一个短语、重组一个子条款——表明“我们有具体诉求”,且更易被阅读、理解和接受。
默认采用能实现操作手册立场的最小编辑:
- 优先替换单个词而非短语。("twelve (12)" → "twenty-four (24)")
- 优先替换短语而非句子。("paid by the Buyer" → "paid and payable by the Buyer")
- 优先重组子条款而非替换句子。(添加"(a)"和"(b)"拆分复合条件。)
- 优先替换句子而非替换条款。
- 仅当对方版本与您的立场差距过大,精准编辑比重新起草更难阅读时,才替换整个条款——此时需在传输说明中注明:“我们已替换§8.2而非标记修订,因为变更范围较大。乐意与您逐一说明差异。”
如有疑问,选择更细粒度的编辑。收到精准红线修订的客户会相信您仔细阅读了内容。收到wholesale替换的客户则会怀疑您是否认真阅读过。
Output
输出
Before recommending signature of a vendor AI agreement (the version the company will execute): Read in . If the Role is Non-lawyer:
## Who's using this~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.mdSigning this vendor AI agreement has legal consequences. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:[Generate a 1-page summary: the vendor and the use case, the key terms reviewed (data use, liability, auditability, model change, human review), where vendor positions diverge from policy, what's being accepted, what could go wrong, what to ask the attorney.]If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).
Do not proceed past this gate without an explicit yes. Review/redline drafts for attorney consideration do not require the gate — signature does.
markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]
*This review is derived from vendor contract terms that are typically confidential under NDA, and it may itself be privileged. It inherits the source's confidentiality and privilege status. Distributing it beyond the privilege circle (e.g., forwarding to the vendor, sharing in an open channel) can waive privilege and breach the NDA. Mark, store, and route accordingly.*在建议签署供应商AI协议(公司将执行的版本)之前: 查看文件中的部分。如果角色为非律师:
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md## Who's using this签署本供应商AI协议具有法律后果。您是否已与律师审查过?如果是,请继续。如果否,以下是一份可提交给律师的摘要:[生成1页摘要:供应商和用例、审查的关键条款(数据使用、责任、可审计性、模型变更、人工审核)、供应商立场与政策的差异、已接受的内容、潜在风险、需向律师询问的问题。]如果您需要寻找律师、事务律师、大律师或其他授权法律专业人士:您所在地区的专业监管机构推荐服务是最快的起点(美国州律师协会、英格兰和威尔士SRA/律师标准委员会、苏格兰/北爱尔兰/爱尔兰/加拿大/澳大利亚律师协会,或您所在司法管辖区的等效机构)。
未得到明确同意前,不得跳过此步骤。供律师参考的审查/红线修订草稿无需此步骤——但签署需要。
markdown
[工作产品标题 — 按插件配置## Outputs — 因角色而异;查看`## Who's using this`]
*本审查基于通常受保密协议(NDA)约束的供应商合同条款,本身可能享有特权。它继承了源文件的保密和特权状态。将其分发到特权圈子之外(如转发给供应商、在公开渠道分享)可能会放弃特权并违反NDA。请相应地标记、存储和传输。*Vendor AI Review: [Vendor Name]
供应商AI审查:[供应商名称]
Document reviewed: [AI addendum / main agreement AI provisions / ToS]
Reviewed: [date]
Use case(s): [what we're deploying this vendor's AI for]
Governance tier: [Standard / Elevated / High]
审查文档: [AI补充条款 / 主协议AI相关条款 / 服务条款]
审查日期: [日期]
用例: [我们部署该供应商AI的用途]
治理级别: [标准 / 高级 / 高风险]
Bottom line
核心结论
[Two sentences. Can we deploy under these terms? What has to change first?]
Issues: [N]🔴 [N]🟠 [N]🟡 [N]🟢
[两句话。我们能否根据这些条款部署?首先需要变更什么?]
问题统计: [N]🔴 [N]🟠 [N]🟡 [N]🟢
Term-by-term
逐条审查结果
[For each term above — vendor position, our position, gap, severity, proposed fix]
[针对上述每一项条款——供应商立场、我方立场、差距、严重程度、建议修正]
AI addendum status
AI补充条款状态
[Present / Absent — and what that means for this deployment]
[存在 / 不存在——以及这对本次部署的影响]
AI policy consistency
AI政策一致性
[🟢 Consistent | 🟡 Flags: list]
[🟢 一致 | 🟡 标记:列表]
Recommended redlines
建议的红线修订内容
[Consolidated draft redlines. Review with counsel before sending externally. For critical
issues where no fallback exists, flag for escalation rather than proposing language.]
[整合后的红线修订草稿。发送给外部前请与法律顾问审查。对于无fallback方案的关键问题,标记为升级处理而非提出修订语言。]
If they won't move
若供应商拒绝修改
[For each 🔴 and 🟠: the fallback from , or "escalate — outside fallback"
and routing per escalation table]
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
---[针对每个🔴和🟠问题:来自文件的fallback方案,或“升级处理——超出fallback范围”并按照升级表处理]
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md
---Practical notes
实用提示
The training-on-data clause is the one most people miss.
Vendor AI terms have historically varied widely on whether API inputs can be used
to train or improve models — some vendors permit it by default, others prohibit it,
and many have changed their position over time. Do not assume any particular vendor's
current stance without reading the specific agreement in front of you. This is almost
always the most important term for any company with confidential or sensitive data,
and it must be confirmed in writing, not assumed from reputation or prior experience.
Map the AI stack. Modern AI deployments are layered. Before reviewing terms, map the layers:
- End-user SaaS application (e.g., a legal tech tool, a CRM with AI scoring, a document assistant) — the tool your org signs up for
- API gateway / orchestration layer (e.g., Azure OpenAI Service, AWS Bedrock, Google Vertex, LangChain-hosted) — often invisible, always has its own terms
- Model provider (e.g., Anthropic, OpenAI, Google, Meta) — the LLM
- Hosted knowledge base / RAG source (e.g., a vector database, a third-party data corpus, a retrieval service) — the data Claude reads from
- Additional subprocessors — analytics, logging, fine-tuning partners
Ask: "Walk me through the stack — what does [SaaS tool] use under the hood? Is it built on a cloud AI service? Does it call a model provider directly or through a gateway? Does it use a hosted knowledge base?" Then review terms at EACH layer, not just the top.
Each handoff between layers is a flow-down risk. A commitment at layer 1 ("we won't train on your data") means nothing if layer 3's terms say otherwise and layer 1 never flowed the commitment down.
Flow-down test. For each flagged stacked-vendor term — especially training-on-data, data retention, subprocessor changes, and liability — don't just flag "check upstream terms." DO THE CHECK:
- Search the contract for flow-down language. Look for: "subprocessor obligations no less protective than," "flow-down of data commitments," "back-to-back terms," "Provider shall ensure that its subprocessors are bound by," "equivalent obligations."
- If present: Quote it, verify it covers the specific flagged term, and flag whether it's enforceable (who can enforce it — you, or only the intermediate vendor?).
- If absent: Produce a specific redline requiring it:
"Add to §[X]: Provider shall ensure that any third-party model providers, infrastructure providers, or subprocessors used in delivering the Services are bound by obligations with respect to [Customer Data / AI training / data retention / confidentiality] no less protective than those set forth in this Agreement, and shall be responsible for any breach of this Agreement caused by such third parties."
- Flag the gap with a severity: 🔴 if the term is training-on-data or liability and there's no flow-down; 🟡 if the term is less sensitive or there's partial flow-down.
"Escalate and check upstream" is where compliance dies. Produce the test and the redline.
Acceptable use policies flip the frame.
AUPs tell you what you can't do; they don't tell you what the vendor can do.
Don't let a clean AUP review substitute for reading the data use and liability terms.
Renewals are leverage points.
If the current agreement is unfavorable and the vendor won't renegotiate mid-term,
document the gaps now and flag them for the renewal. Flag to procurement:
"This renewal should not close without AI addendum addressing [list]."
Builder context adds a layer.
If the company is a builder using a vendor's model as a foundation, the vendor's terms
also govern what the company can offer its own customers. Some terms prohibit certain
downstream uses. Check use restrictions against the product roadmap, not just current
internal workflows.
数据训练条款是最容易被忽略的部分。
供应商AI条款在API输入是否可用于训练或改进模型方面历来差异很大——部分供应商默认允许,部分禁止,还有许多随时间改变立场。切勿仅凭声誉或过往经验假设特定供应商的当前立场,必须阅读眼前的具体协议。对于任何拥有机密或敏感数据的公司而言,这几乎总是最重要的条款,必须以书面形式确认,而非假设。
梳理AI技术栈。 现代AI部署是分层的。审查条款前,先梳理各层:
- 终端用户SaaS应用(如法律科技工具、带AI评分的CRM、文档助手)——您组织注册使用的工具
- API网关/编排层(如Azure OpenAI Service、AWS Bedrock、Google Vertex、LangChain-hosted)——通常不可见,但始终有自己的条款
- 模型提供商(如Anthropic、OpenAI、Google、Meta)——大语言模型(LLM)
- 托管知识库/RAG源(如向量数据库、第三方数据 corpus、检索服务)——Claude读取的数据来源
- 其他分包商——分析、日志、微调合作伙伴
询问:“请梳理技术栈——[SaaS工具]底层使用什么?它是基于云AI服务构建的吗?它是直接调用模型提供商还是通过网关?是否使用托管知识库?”然后审查每一层的条款,而非仅顶层。
各层之间的每次交接都存在传导风险。第一层的承诺(“我们不会使用您的数据进行训练”)如果第三层条款允许训练且第一层从未将承诺传导下去,则毫无意义。
传导测试。 对于每个标记的多层供应商条款——尤其是数据训练、数据保留、分包商变更和责任——不要仅标记“检查上游条款”。实际执行检查:
- 在合同中搜索传导条款。 查找:“分包商义务不低于”“数据承诺传导”“背靠背条款”“供应商应确保其分包商受约束”“同等义务”。
- 如果存在: 引用该条款,验证其是否涵盖标记的特定条款,并标记其是否可执行(谁可执行——您,还是仅中间供应商?)。
- 如果不存在: 生成具体的红线修订要求:
“在§[X]中添加:供应商应确保提供服务时使用的任何第三方模型提供商、基础设施提供商或分包商,在[客户数据/AI训练/数据保留/保密性]方面受约束的义务不低于本协议规定的义务,并应对此类第三方导致的本协议违约负责。”
- 标记缺口严重程度: 如果条款是数据训练或责任且无传导,则为🔴;如果条款敏感度较低或部分传导,则为🟡。
“升级并检查上游”是合规失效的起点。请执行测试并提出红线修订。
可接受使用政策转换了视角。
AUP说明我们不能做什么;但未说明供应商可以做什么。切勿以AUP审查通过替代对数据使用和责任条款的阅读。
续约是谈判杠杆点。
如果当前协议不利且供应商不愿中期重新谈判,请现在记录缺口并在续约时标记。向采购部门标记:“本次续约不得完成,需先解决[列表]中的AI补充条款问题。”
构建方背景增加额外层面。
如果公司是使用供应商模型作为基础的构建方,供应商条款还管辖公司可向自身客户提供的内容。部分条款禁止某些下游用途。请对照产品路线图检查使用限制,而非仅当前内部工作流程。
Close with the next-steps decision tree
以下一步决策树收尾
End with the next-steps decision tree per CLAUDE.md . Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.
## Outputs根据CLAUDE.md文件部分的下一步决策树收尾。根据本技能生成的内容自定义选项——五个默认分支(起草X、升级处理、获取更多事实、观察等待、其他)是起点,而非固定选项。决策树是输出内容;由律师做出选择。
## OutputsWhat this skill does not do
本技能不执行的操作
- It doesn't review the DPA provisions of the same agreement — run
, if the plugin is installed, for that.
/privacy-legal:dpa-review - It doesn't decide whether to accept terms outside the fallbacks. It routes those
per the escalation table in .
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - It doesn't evaluate vendor security posture beyond what's in the agreement — that's a security team function.
- 不审查同一协议中的DPA条款——如果已安装插件,请运行进行该审查。
/privacy-legal:dpa-review - 不决定是否接受超出fallback范围的条款。它会按照文件中的升级表处理此类情况。
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md - 不评估协议之外的供应商安全态势——这是安全团队的职能。