Reference · plugin fact sheet

ai-governance-legal

The ground-truth summary behind Module 6. Every line below was read from the plugin's actual files (version 1.0.2, checked 2026-07-17) — paths cite the live repo. (Accuracy note: the plugin's own README lists only 8 of the 10 skills — it omits ai-inventory and customize — and calls policy-monitor an “agent”; it is a skill. The table below reflects what's on disk.)

Identity

From .claude-plugin/plugin.json: “Triages proposed AI use cases against your registry, runs impact assessments across the regimes in scope, reviews vendor AI terms for training-on-data and liability gaps, and keeps your AI policy current with practice.”

The 10 skills, by job

JobSkills
Set up & tune the profilecold-start-interview (regimes in scope; refuses a company-level AI role when the EU is in footprint — roles are per-system; shadow-AI discovery writes unapproved tools into the registry as [UNDOCUMENTED — NEEDS TRIAGE]), customize (one change at a time; refuses to drop load-bearing verification tags), matter-workspace (multi-client only — off for in-house)
The two registries — the front dooruse-case-triage (APPROVED / CONDITIONAL / NOT APPROVED against the use-case registry + red lines; no-match → CONDITIONAL pending an AIA; batch mode; a “provisional” escape on an unconfigured profile), ai-inventory (ai-systems.yaml: one record per AI system with role, tier, and basis — Article 5 prohibited screen → Annex III high-risk → GPAI → limited/minimal; never classifies silently)
The deep paperworkaia-generation (AI impact assessment per regime in scope; an AIA is not a PIA; provider-vs-deployer split table when the company wears both hats; risk-quality bar — “2-5 real risks, not 12 padded ones”), vendor-ai-review (13-term review of vendor AI terms — training-on-data is “the one most people miss”; the AI-addendum gap check; stacked-vendor/flow-down test when your vendor wraps someone else's model)
Keeping current — two directions of changereg-gap-analysis (outside-in: a new AI law vs. your posture — scope first, prohibited-practice gaps outrank everything, “accepted gaps” documented as first-class output), policy-monitor (inside-out: practice vs. your written policy — sweep or direct-query; the canonical catch: a policy that says “we do not use AI in employment decisions” after an AIA approved exactly that)
Day zeropolicy-starter (first-cut AI policy sourced from published model policies — NIST, bar guidance, peers — never invented; scope interview first; every judgment call flagged [review])

No subagents, no hooks — and no research connector

Nothing scheduled runs here: no agents/, no hooks. The “monitor” is a skill you run. From .mcp.json: Slack and Google Drive only — no research/statute tool, in the practice area that moves fastest. The plugin compensates with graduated source tags ([settled] / [verify] / [verify-pinpoint] — pinpoints are the highest fabrication risk: “EU AI Act article numbers in particular shifted during consolidation”), the no-silent-supplement stop (research thin → the skill asks you which source to accept), and references/currency-watch.md — which distrusts itself: “If the last-verified date above is more than 90 days old, treat this file as stale.”

State it keeps on your machine

Conventions worth knowing

Sources: the plugin's CLAUDE.md, .mcp.json, references/currency-watch.md, and the skill files — all under ai-governance-legal/ on GitHub.

← Back to Module 6