Module 6 · AI-governance tour

Can we use AI for this? ai-governance-legal

What it does

Every legal team now fields the same question weekly: “can we use AI for this?” This plugin turns that from a fresh gut call each time into a system. In its own words, it “triages proposed AI use cases against your registry, runs impact assessments across the regimes in scope, reviews vendor AI terms for training-on-data and liability gaps, and keeps your AI policy current with practice.”

One thing to notice before the story starts: most legal crises arrive — a letter lands, a request comes in, a clock starts running. Governance is the opposite: it starts with something trying to leave the building. The business wants to ship, the facts are already moving, and the pressure isn't a statute's deadline — it's momentum.

Source: plugin.json · ai-governance-legal/ on GitHub

Under the hood

Ten skills — the full inventory is in the ai-governance-legal fact sheet. Three ideas define the plugin:

The registry is the answer — and the deliverable

When you ask use-case-triage whether a proposed AI use is okay, it doesn't reason from general AI ethics — it checks your company's own use-case registry and red lines: “Generic AI ethics reasoning is not a substitute for what this company has actually decided.” A use case with no registry match doesn't get waved through — it comes back CONDITIONAL, pending an impact assessment, and the result gets written back into the registry so the next answer is consistent with this one. Red lines are absolute: “Do not soften red line outcomes. If it's a no, it's a no.” The real output of this plugin isn't any single memo — it's the registry that makes your organization's answers add up.

Under the EU AI Act, roles belong to systems — not companies

Ask “are we a provider or a deployer?” and the plugin refuses the premise: “role and risk tier are assessed per AI system, not per company… A single organization can be a provider of System A, a deployer of System B, and an importer of System C.” That's why it keeps a second register — the ai-inventory (ai-systems.yaml) — one record per AI system, each with its own role and risk tier. And a deliberate refusal worth noticing: the inventory “does NOT auto-derive obligations… a hardcoded role × tier → obligations table is exactly the kind of confident-and-wrong artifact that ends up in a board memo.” The registry is for the lawyer; the obligation analysis stays yours.

AI law moves faster than the model — and the plugin knows it

Like the privacy plugin, this one bundles no research connector (just Slack and Google Drive) — for a practice area where effective dates slip and article numbers shift. So it makes its uncertainty loud: cites carry graduated tags ([settled] / [verify] / [verify-pinpoint]“EU AI Act article numbers in particular shifted during consolidation”), a references/currency-watch.md file lists the rules most likely to have moved — and even distrusts itself (“If the last-verified date above is more than 90 days old, treat this file as stale”). And when research comes back thin, the skill stops and asks you which lower-confidence source to accept rather than quietly filling the gap. The lawyer chooses the downgrade; the tool never does it silently.
Source: .mcp.json · references/currency-watch.md · ai-governance-legal/CLAUDE.md

№ The story — HR didn't ask permission

A proposal lands from Sablefield's People Operations team. They started a free trial of an AI resume screenerMarrowick Talent Systems — three weeks ago. Real candidate CVs are already in it. It auto-rejects the bottom 40% before any recruiter looks. The fall hiring push covers Texas and the EU team, the vendor swears it's “independently bias-audited, fully EEOC and GDPR compliant,” and the trial terms let Marrowick train on the uploaded CVs. They'd like a green light — and they'd rather not turn it off while you think. Go.

Guided — triage the screener, then write the assessment

Guided · from “can we?” to a documented decision

You'll need the plugin installed. No setup handy? Read along — the exhibits show what you'd see.

1. Install and set up — two steps, not one (the marketplace was added back in Module 1). First, install:

/plugin install ai-governance-legal@claude-for-legal

Then load the plugin — type /reload-plugins (or close and reopen Claude Code). It isn't live until you do. Now run the setup interview and take the 2-minute quick version (who you are, your practice setting, what's connected, and which AI regulations are on your radar):

/ai-governance-legal:cold-start-interview

No AI-governance practice of your own? Play the part — answer as Sablefield's lawyer:

Quick version, please. I'm a lawyer, in-house — the only one at Sablefield Robotics (Series-B industrial robotics, Delaware corp, Nashville HQ; ~150 staff in CA/TX/MI plus a small EU team). We're on both sides of AI: our robots ship with machine-learning grip control and camera perception (sold to US and EU customers), and we buy AI too — a computer-vision vendor, plus internal teams pitching new tools. Regulations on my radar: the EU AI Act, the state AI laws (Colorado and Texas), and general FTC consumer-protection exposure.

Quick setup captures who you are and which regimes apply, and writes working defaults for everything else — your use-case registry, red lines, and vendor positions start generic and sharpen as you use the skills (each output tells you which default it leaned on). Want red lines on record from day one? After setup, run customize and give it two or three — e.g. no fully automated adverse employment decisions; no emotion recognition; no biometric categorization.

2. Get the proposal — the one People Ops just sent:

⬇ Marrowick screening proposal (Word) or plain text (.md)

3. Run the triage. Send the command on its own:

/ai-governance-legal:use-case-triage

Then attach the proposal and tell it: “Triage this — we're Sablefield. HR wants a green light, and the pilot is already running.” (If it mentions your registry is still generic, or calls the run “provisional,” carry on — the triage works, and its proposed registry entry is how your registry stops being generic.)

4. Watch what it refuses to let slide — here's the verdict, shortened for the page:

Exhibit — the triage verdict (abridged illustration)

PRIVILEGED & CONFIDENTIAL — ATTORNEY WORK PRODUCT — PREPARED AT THE DIRECTION OF COUNSEL

⚠️ Reviewer note: no research connector — regime references are from training knowledge, tagged for verification · registry is early-stage (quick-setup defaults) · 4 items flagged [review].

USE CASE: AI resume screening (Marrowick Talent Systems) — scoring + auto-rejection of the bottom tranche, US (TX) + EU candidates.

CLASSIFICATION: CONDITIONAL — registry match: no match (first AI-in-hiring use case). Not approvable as proposed; not a hard no. Conditions below.

Three findings a hurried read would miss:

The pilot is retroactive triage. Real candidate data has been processed for three weeks without review — “a gap to document, not to wave through.” The gap itself goes in the record [review].
“The bottom 40% is auto-rejected” before any human looks. That is an automated adverse employment decision — the classic red-line pattern. Condition: a human reviews every rejection, or this becomes NOT APPROVED [review].
“The vendor says it's safe” is not an assessment. Marrowick's bias-audit and compliance claims are the vendor's position — and the trial terms let Marrowick train on uploaded CVs, which is a data question the assurance doesn't touch. Route the terms to a vendor AI review [review].

Regimes implicated: EU candidates → EU AI Act employment context — high-risk category for the deployer [verify]; TX + CO state AI laws [verify — effective dates move]; EEOC/Title VII exposure on disparate impact [review].

Governance tier: Elevated — impact assessment required before rollout.

Proposed registry entry (so the next “can HR use AI?” starts from a decision, not a shrug) — and: “Want me to start the impact assessment now? I can carry everything above straight into it.”

Condensed for the page; the steps are the skill's own — classification → conditions with owners → governance tier → proposed registry entry → handoff offer: use-case-triage. Your run's judgments will differ — that's what the [review] flags are for.

5. Say yes to that closing offer — and watch two skills chain in one conversation. The aia-generation skill picks up the use case and the triage's risk tier (which carries forward as a floor — it can't quietly soften) and interviews you toward a written AI impact assessment. Abridged excerpt of the part that matters most:

Exhibit — inside the impact assessment (the honesty is the point)

Regulatory classification (per regime in scope)

EU AI Act: AI used in “employment, workers management and access to self-employment” is a high-risk category — Sablefield sits in the deployer role for this system [verify-pinpoint: Annex III employment provision — article numbering shifted during consolidation; verify against the Official Journal]. Deployer duties (human oversight, monitoring, candidate transparency) apply on the EU roles [verify].

US: disparate-impact exposure under Title VII if the model's scoring skews against protected classes — the vendor's “bias-audited” claim must be replaced by audit documentation we can read [review]. State AI laws: Texas and Colorado enacted obligations for consequential-decision AI — effective dates and scope verified before relying [verify — check currency-watch].

⏸ The stop, mid-assessment: “I need the current text of the state-law obligations to finish this section, and no research tool is connected. Options: (1) you paste the statute text, (2) I search the web — results tagged [web search — verify], (3) leave the section flagged and finish the rest. Which would you like?” — the skill won't fill the gap silently; you choose the source.

Risks (specific, not padded): ① historical-hiring training data may encode the demographics of past cohorts — underrepresented candidates systematically scored lower; ② auto-rejection removes the human check exactly where error costs the most; ③ vendor training-on-CVs creates a data obligation to candidates who never agreed to it.

Recommendation: conditional approval — human review of every rejection; pilot data handling remediated; Marrowick's terms through vendor AI review before contract; candidate notice added. The policy conflict: the current AI policy says “Sablefield does not use AI in employment decisions” — the policy or the rollout has to change before launch [review].

Cite check. Regulatory references in this assessment were generated without a connected research tool. Verify each tagged item against a primary source before relying on it.

The format is the skill's own: aia-generation. Note what the tags are doing: [verify-pinpoint] marks the highest-fabrication-risk cites, and the mid-assessment stop hands the source decision to the lawyer. A draft for attorney review — always.

6. The quiet payoff: the triage's proposed registry entry plus the finished assessment mean the next “can we use AI in hiring?” gets answered from a documented decision — same conditions, same red line — instead of whoever's gut is on duty that day.

Stretch — the vendor's terms, and the two-hats inventory

Stretch · three pushes, three skills

Stretch 1 — read your AI vendor's paper with new eyes. Back in Module 3 you reviewed Wickline's vendor agreement as a commercial lawyer — is this a fair deal? Now run the same contract through vendor-ai-review and ask the AI-governance question instead: what can they do with our data and our models?

⬇ Wickline vendor agreement (Word) or .md

/ai-governance-legal:vendor-ai-review

Then attach it: “Review Wickline's terms — we're the deployer.” Watch it catch §4.4's perpetual train-on-our-data license and §5.1's vendor-owns-improvements — and, just as telling, the silences: no model-change notice, no incident notification, no human-review rights. When it asks for a playbook position your quick profile doesn't have, give it one (“no training on our data”) and watch it get recorded for next time. One more wrinkle worth asking about: “Is Wickline the model's builder, or a wrapper on someone else's?” — if there's a vendor behind the vendor, “there are TWO vendors' terms in play.”

Stretch 2 — one company, two hats. Put two systems on the AI inventory and watch the EU AI Act's per-system logic land:

/ai-governance-legal:ai-inventory

Then: “Add and classify two systems. First: FloorSight, an always-on camera-and-location feature we build on a vendor's vision platform and ship in our own product. Second: the Marrowick resume screener we just assessed.” The first makes Sablefield a provider (it ships the system under its own name — and fine-tuning a vendor's model can make you the provider of the modified system); the second makes it a deployer. Run “list the inventory” at the end: one table, one company, two roles — the whole EU-AI-Act lesson in five rows. Notice every classification carries its basis and a [verify] tag: “They are not hedging — they are the point.”

Stretch 3 — Sablefield has no real AI policy. Draft one. The 2024 policy is one page and already wrong. Run policy-starter:

/ai-governance-legal:policy-starter

Take its scope interview (it will talk you out of covering everything: “A policy that tries to cover everything covers nothing”) and watch two disciplines: every rule is sourced from published model policies — NIST, bar guidance, peer policies — not invented (“don't generate policy language out of thin air”), and every judgment call comes back flagged [review] for you, not decided for you. The draft's header says what it is: DRAFT FOR INTERNAL LEGAL REVIEW — NOT FOR DISTRIBUTION.

Free play

Free play · break it on purpose
  • Catch the policy lying. Grab the 2024 AI policy (.md) and run /ai-governance-legal:policy-monitor: “Does our policy cover the Marrowick screener we just approved with conditions?” — “Sablefield does not use AI in employment decisions” is no longer true, and “all AI output is reviewed by a human” broke the day anything automated shipped. REQUIRED changes, drafted for your review.
  • Point it at a law that moves. /ai-governance-legal:reg-gap-analysis on the Texas or Colorado AI act. Watch it scope first (“does this even apply to us?”), then open the plugin's own references/currency-watch.md — and note the file's self-distrust rule. The lesson is the check, not the entries.
  • Try to make it misbehave. Via customize, ask it to stop adding the verification tags to citations — and watch it refuse: they're “load-bearing, don't remove.”
  • Triage a whole backlog. Give use-case-triage three at once — a sales-call transcription tool nobody approved, a customer-support chatbot, and something that walks into a red line — and get the one-screen 🟢🟡🔴 summary.
  • Off the menu, on purpose. /ai-governance-legal:matter-workspace does nothing for Sablefield — matter workspaces are for multi-client firms, off for in-house. Correct, not broken.

Check your understanding

Lab notebook

Governance note — the registry, the clock, and the no

Three things to carry out of this module. First, the registry is the deliverable — and the plugin deliberately refuses to auto-derive legal obligations from it: “a hardcoded role × tier → obligations table is exactly the kind of confident-and-wrong artifact that ends up in a board memo.” The tool keeps the record; the obligation analysis stays with the lawyer. Second, AI law is moving faster than any model's training, and with no research connector bundled, every effective date and article number in these outputs is tagged for verification — with a currency-watch file that even flags its own staleness. The verification habit isn't a disclaimer; it's the practice. Third, red lines don't negotiate — and the no is gated too: the plugin won't soften a red-line outcome to be agreeable, and for non-lawyer users it holds a hard no for attorney review exactly as it holds a hard yes“wrongly rejecting a use case is also a consequential error.” It won't let you be confidently wrong in either direction.

And the rule that never goes away: the triage, the assessment, the policy draft — every one is a draft for attorney review.
Source: ai-governance-legal/CLAUDE.md · use-case-triage skill

Going deeper: the ai-governance-legal fact sheet has the full ten-skill inventory, the two registries it keeps on your machine, and the connector picture.