Official agent skill

Aia Generation

by anthropics in anthropics/claude-for-legal

Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions.

OfficialApache-2.0Auto-check passedLegal & Compliance

Install Aia Generation

skills CLI
$ npx skills add anthropics/claude-for-legal --skill aia-generation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal aia-generation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/aia-generation .claude/skills/aia-generation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aia-generation
GitHub stars
9.6k
Used in
3 other repos
Token cost
~6.6k tokens
SKILL.md length
2,866 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions.

  • Works in 5 steps: Is an impact assessment needed? → Risk track → Intake → …
  • User says impact assessment for
  • SKILL.md covers Matter context, Purpose, Load house style and Step 0: Is an impact…, plus 9 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Aia Generation is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Use when user says "impact assessment for", "assess this AI use case", "run an AIA", "generate an AIA", "we need to document this AI system", "AI risk assessment for X", or follows a conditional…

Its SKILL.md is about 6.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering AI governance and Agent instruction files. The repository describes itself as: A suite of plugins for legal workflows. The licence is Apache-2.0.

When your agent uses it

  • User says impact assessment for
  • Assess this AI use case
  • Generate an AIA
  • We need to document this AI system

Example prompts

  • “impact assessment for”
  • “assess this AI use case”
  • “run an AIA”
  • “/aia-generation”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Is an impact assessment needed?
  2. Risk track
  3. Intake
  4. Regulatory classification
  5. Write the assessment

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aia Generation loads about 6.6k tokens when it runs. Until then it costs about 136 tokens; SKILL.md has 2,866 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~136
When it runs · the whole SKILL.md, loaded when a task matches
~6.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 2,866 words, ~6,568 tokens.

Download SKILL.mdSave it as .claude/skills/aia-generation/SKILL.md (or your agent's skills folder).
name
aia-generation
description
Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Uses the house-style structure learned from the seed impact assessment in `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md`. Use when user says "impact assessment for", "assess this AI use case", "run an AIA", "generate an AIA", "we need to document this AI system", "AI risk assessment for X", or follows a conditional triage result.
argument-hint
[describe the use case or system, or pass a triage result]

/aia-generation

  1. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Confirm impact assessment house style is populated.
  2. Determine risk track (fast or full) from governance tier and use case characteristics, using the framework below.
  3. Run intake — conversational, not a form.
  4. Regulatory classification for each regime in the footprint — research tier, prohibited-practice exposure, and applicable obligations; cite primary sources.
  5. Write assessment in house style (from seed doc, or default if none captured).
  6. Policy diff against ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md AI policy commitments.
  7. Output: assessment doc + conditions list + handoff flags (privacy PIA, vendor review if needed).
/ai-governance-legal:aia-generation "AI résumé screening for HR"

Matter context

Matter context. Check ## Matter workspaces in the practice-level CLAUDE.md. If Enabled is ✗ (the default for in-house users), skip the rest of this paragraph — skills use practice-level context and the matter machinery is invisible. If enabled and there is no active matter, ask: "Which matter is this for? Run /ai-governance-legal:matter-workspace switch <slug> or say practice-level." Load the active matter's matter.md for matter-specific context and overrides. Write outputs to the matter folder at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/matters/<matter-slug>/. Never read another matter's files unless Cross-matter context is on.


Purpose

An AI impact assessment is a documented decision, not a form. It answers: what does this AI system do, how does it reach its outputs, who's affected if it's wrong, what's the oversight, and is it okay to deploy. This skill structures that conversation and writes the output in this team's format — the one learned from the seed impact assessment during cold-start.

An AI impact assessment is not the same as a PIA. A PIA asks whether personal data is handled lawfully. An AIA asks whether the AI system is designed and deployed responsibly. They often need to happen in parallel; they're not substitutes.

Load house style

Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Impact assessment house style. That has:

  • What triggers an impact assessment at this company
  • The structure template extracted from the seed assessment
  • Typical depth
  • Who signs off

If the seed structure is in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md, use it. The point is that this assessment looks like the other assessments this team produces.

Jurisdictional scope. This assessment applies the regulatory regimes listed in ## Regulatory footprint in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. AI legal rules, risk classifications, and deployment obligations vary materially by jurisdiction and are moving fast. If this system is (or will be) deployed outside that footprint, or if a choice-of-law question is in play, this analysis may not apply as written — re-run or expand the footprint.


Step 0: Is an impact assessment needed?

Check the trigger criteria in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.

Also check these regardless:

  • Does this AI make or materially influence a decision affecting a person (employment, credit, access, pricing, content moderation)?
  • Does this AI process personal data about individuals?
  • Is this a customer-facing AI system rather than purely internal?
  • Does this AI use a third-party model where the company is the deployer?
  • Is the use case in the elevated or high governance tier per ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md?

If none of the above and the house trigger isn't met:

"Doesn't look like this needs a full impact assessment. Here's a one-paragraph record for the file explaining why — in case anyone asks later."


Step 1: Risk track

Before intake, determine which track to run. The tier definitions and the fast-track criteria come from ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md (## Use case registry and ## Governance tiers), not from any hardcoded regime-specific framework.

Research the applicable risk classification framework for each regime in the user's regulatory footprint. Many regimes distinguish by risk tier, affected population, and decision consequentiality — research the specific criteria. Note that most regimes treat employee data as personal data and employee monitoring as consequential; don't assume internal-only systems are out of scope.

No silent supplement. If a research query to the configured legal research tool (Westlaw, EUR-Lex, regulator sites, or firm platform) returns few or no results for a regime's risk tiers or triggers, report what was found and stop. Do NOT fill the gap from web search or model knowledge without asking. Say: "The search returned [N] results from [tool]. Coverage appears thin for [regime / topic]. Options: (1) broaden the search query, (2) try a different research tool, (3) search the web — results will be tagged [web search — verify] and should be checked against the issuing authority before relying, or (4) flag as unverified and stop. Which would you like?" A lawyer decides whether to accept lower-confidence sources.

Source attribution tiering. Tag every citation in the AIA — regulatory text, delegated acts, guidance, standards — with its source. For model-knowledge citations, use one of three tiers rather than a single blanket "verify" tag:

  • [settled] — stable, well-known statutory and regulatory references unlikely to have changed (e.g., GDPR Art. 22 as a concept, the existence of Regulation (EU) 2024/1689 as the EU AI Act). Still verify before certifying, but lower priority.
  • [verify] — model-knowledge citations that are real but should be verified: specific delegated / implementing acts, regulator guidance, NYC DCWP rules, Colorado AI Act provisions, harmonized standards, effective dates, EEOC guidance, and anything post-2023.
  • [verify-pinpoint] — pinpoint citations (specific EU AI Act article numbers, annex references, Colorado AI Act subsections, NYC LL 144 rule sections, sub-paragraph letters) carry the highest fabrication risk and should ALWAYS be verified against a primary source. EU AI Act article numbers in particular shifted during consolidation; every pinpoint cite to the Act should be verified against the Official Journal text.

Tool-retrieved citations keep their source tag ([Westlaw], [EUR-Lex], [regulator site], or the MCP tool name); web-search citations remain [web search — verify]; user-supplied citations remain [user provided]. The tiering surfaces the real verification work — a reader who verifies everything verifies nothing. Never strip or collapse the tags.

For non-lawyer users, uncertain dates go in a confirm-list, not inline. A [verify] tag on "effective February 1, 2026" reads as "effective February 1, 2026" to a CISO who doesn't know what [verify] means. Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If Role is Non-lawyer and a date, deadline, phase-in, threshold, or effective-date assertion is uncertain (would carry [verify] or [verify-pinpoint] if inline), replace the inline assertion with "effective date: confirm with counsel" (or "threshold: confirm with counsel", etc.) and collect all uncertain assertions in a final AIA section titled:

Things I'm not certain about — ask your attorney to confirm before relying on this:

List each uncertain item there with (1) what I said, (2) what I'm uncertain about, (3) why it matters to the assessment. This prevents a non-lawyer reader from mistaking a flagged best-guess for a checked fact. Lawyer-role users get the inline [verify] treatment — they know what the tag means.

Fast track vs. full assessment: ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md defines what qualifies for abbreviated treatment. If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md doesn't define fast-track criteria, default to full assessment and ask the user what criteria they want captured for next time.

If in doubt, run the full assessment. A fast track that turns out to be wrong is worse than a thorough assessment on something low-risk.


Step 2: Intake

Before writing anything, get answers to these. Conversational is fine — this is not a form to send them.

The system
  • What does the AI do? Describe it in plain language, not marketing copy.
  • Which model or vendor is powering it? Fine-tuned or off-the-shelf?
  • Where does it sit in the workflow — is it assistive (human reviews output), augmentative (human can override but usually doesn't), or automated (no human in the loop)?
  • What's the output — generated text, a score, a classification, a recommendation, an action?
Who's affected
  • Who does the AI's output act on — employees, customers, third parties?
  • If the AI produces an error (false positive, false negative, hallucination), who bears the harm and what's the worst realistic case?
  • Are any vulnerable groups disproportionately in scope — minors, job applicants, people in financial distress, patients?
Inputs and data
  • What data does the AI take in?
  • Does it take in personal data? Whose?
  • Was the model trained on data from this company, or is it a foundation model with no company-specific training?
  • Where does input data go — does it leave the perimeter to a third-party model API?
Decisions and oversight
  • Does the AI output trigger an action automatically, or does a human decide what to do with the output?
  • If there's human review: how often does the human actually change the AI's output? (If the answer is "rarely" — the human isn't really reviewing; they're rubber-stamping.)
  • Is there an appeals or correction process for people affected by the AI's outputs?
  • Who is accountable for the AI system's outputs — is there a named owner?
Accuracy and failure
  • What's the known or estimated error rate? What testing has been done?
  • What happens when the AI is wrong — is the error surfaced, logged, corrected?
  • Has bias testing been done? Against what demographic groups?
Deployment stage and scale

Ask:

  • Stage: "Is this system (a) proposed and not yet built, (b) in pilot, (c) live in production, or (d) live and scaled?"
  • Scale: "Roughly how many individuals are affected per [month/year]? How long has it been running?"
  • History: "Has it been assessed before? Has it produced decisions that were challenged, appealed, or reversed?"

Stage changes the assessment: a proposed system gets a design review (can we build it safely?). A pilot gets a design review plus a "before you scale" gate. A live system gets a retrospective impact check (has it caused harm?) AND a go-forward review. A live-and-scaled system gets all of the above plus a remediation plan if issues are found, because you can't just turn it off.


Show full SKILL.md (1,314 more words)Show less

Step 3: Regulatory classification

Step 3 pre-check — footprint freshness. Before iterating over the captured ## Regulatory footprint, compare the use case's affected population and decision type (from Step 2) against the footprint as written. The footprint was set at cold-start, based on the company's operating posture at that moment. If the use case introduces an affected population (e.g., children, employees in a new state, EU data subjects) or a decision type (e.g., hiring, creditworthiness, health diagnosis, law enforcement, critical infrastructure) that the footprint does not contemplate, re-derive the applicable regimes rather than iterating over the stale list.

Say to the user:

"The practice profile's regulatory footprint was set for [affected populations / decision types captured at cold-start]. This use case affects [new population or decision type — e.g., employees in Colorado, minors under 13, credit decisions, biometric identification], which is not in the captured footprint. I'm going to re-derive the applicable regimes from the company's operating jurisdictions ([list from ## Company profile]) and this use case's decision type ([Y]), rather than use the stale footprint. If this use case is representative of work you expect to see more of, update ## Regulatory footprint at the end of this run so the next AIA doesn't have to re-derive."

A common failure mode: the footprint lists EU AI Act + GDPR + NYC Local Law 144, and the use case is a hiring system being deployed into Illinois and Colorado. The footprint has no Illinois or Colorado entry, so iterating over it silently misses IL AIVIA, the new Colorado AI Act deployer obligations, and BIPA implications of any biometric component. Re-derive.

A second failure mode: the footprint was set before a regime that now matters existed (or took effect). If re-derivation surfaces a regime not in the footprint, flag it in the output's recommendation section, cite the authority, and recommend updating the footprint.

For each regime in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Regulatory footprint that applies to this system — plus any regime surfaced by the re-derivation above — research the currently operative risk classification framework and determine where the system lands.

Research tasks:

  • What is the regime's own tier taxonomy (e.g., prohibited / high-risk / limited / minimal, or the regime's equivalent)?
  • What are the criteria for each tier? Cite primary sources with pinpoint references.
  • Which tier does this system fall into given its function, affected parties, and decision consequentiality?
  • Are there prohibited practices the system might touch? Treat any possible match as critical — flag immediately.
  • Are there transparency obligations that apply regardless of tier (disclosure that a user is interacting with AI, labeling of AI-generated content, notice to people subject to automated decisions)?
  • If the company is a builder providing a general-purpose or foundation model, what provider-level obligations apply (technical documentation, training data transparency, copyright compliance, systemic-risk testing)?
  • Does any regime in the footprint require a separate fundamental-rights impact assessment (FRIA)? EU AI Act Art. 27 requires a FRIA for certain deployers of high-risk AI systems (public bodies and private entities providing public services, plus certain creditworthiness and insurance-risk-assessment use cases). Check each regime for an equivalent fundamental-rights or human-rights impact assessment that is a distinct deliverable from this AIA. If a FRIA (or regime equivalent) is required, flag it as a separate deliverable in the recommendation and conditions — do not treat this AIA as a substitute.

Don't assume internal-only systems are out of scope — most regimes treat employee data as personal data and employee monitoring as consequential. Verify the specific rule.

Provider-vs-deployer split (when AI role: Both). If ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md → ## Company profile → AI role is Both (the company is both a provider/builder and a deployer), Section 6 MUST include a provider-vs-deployer mapping table per regime. Most regimes impose materially different obligations on providers (or builders) versus deployers (or users) — collapsing them into one undifferentiated list misses obligations and conflates risks. Do not combine provider and deployer obligations into a single section. Produce, per regime:

ObligationAs providerAs deployer
[specific obligation, pinpoint cite][what applies / does not apply / with what carve-outs][what applies / does not apply / with what carve-outs]

If a high-risk or equivalent classification applies: Flag in the assessment, citing the specific provision and regime. Note that this AIA documents the internal review but does not substitute for any formal conformity assessment the regime requires. Recommend external legal review before deployment in the affected jurisdiction.

Capture the classification and the cited authority in the assessment output.


Step 4: Write the assessment

Use the seed structure from ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If none was captured, use this default:

markdown
[WORK-PRODUCT HEADER — per plugin config ## Outputs — differs by role; see `## Who's using this`]

# AI Impact Assessment: [System/Feature Name]

**Prepared by:** [name] | **Date:** [date] | **Status:** DRAFT / APPROVED
**System owner:** [name] | **AI governance reviewer:** [name]
**Governance tier:** [Standard / Elevated / High]
**Track:** [Fast track / Full assessment]

---

## Executive summary

[Two sentences: what this AI does and whether it's okay to deploy. E.g., "This
system uses a third-party LLM to draft initial responses to customer support tickets
before human agent review. Processing is consistent with the company's AI policy;
three conditions required before production deployment."]

**Overall risk:** 🟢 Low / 🟡 Medium / 🟠 High / 🔴 Very high

---

## 1. System description

**What it does:** [plain English — not marketing]
**Model / vendor:** [who's providing the AI]
**Deployment mode:** [Assistive / Augmentative / Automated]
**Output type:** [text / score / classification / recommendation / action]
**Status:** [Not started / Pilot / Production]

---

## 2. Affected parties

**Who it acts on:** [employees / customers / third parties]
**Scale:** [how many people, how often]
**Harm if wrong:** [most realistic worst case — specific, not generic]
**Vulnerable groups in scope:** [yes — [who] / no]

---

## 3. Data inputs

**Data categories used:** [specific fields, not "user data"]
**Personal data:** [yes — [whose] / no]
**Data leaves perimeter?** [yes — to [vendor] / no]
**Model training:** [company data used / foundation model / fine-tuned on [dataset]]

---

## 4. Decision-making and oversight

**Human in the loop:** [Always / Nominally (rubber-stamp risk) / No]
**Override mechanism:** [how a human can intervene or correct]
**Appeals / correction for affected parties:** [yes — [how] / no]
**Named owner:** [name or role]

---

## 5. Accuracy and bias

**Error rate:** [known / estimated / untested]
**Failure mode:** [what happens when it's wrong — surfaced? logged? corrected?]
**Bias testing:** [done — [results] / not done / not applicable]

---

## 6. Regulatory classification

*[One subsection per regime in the regulatory footprint that applies to this system.]*

**Regime:** [name]
**Classification under this regime:** [tier, with pinpoint citation to the controlling provision]
**Prohibited practices triggered:** [none identified / [specific provision and why]]
**Applicable obligations:** [researched list with citations — transparency, documentation, human oversight, testing, registration, etc.]
**Fundamental-rights impact assessment required?** [Yes — e.g., EU AI Act Art. 27 FRIA applies / regime equivalent / No / Not applicable. If yes, this is a separate deliverable, not subsumed by this AIA.]
**Effective / enforcement date:** [date(s)]
**Ambiguity or open interpretation:** [flag anything not yet settled]

**Provider-vs-deployer obligation split (required if `AI role: Both`):**

| Obligation | As provider | As deployer |
|---|---|---|
| [specific obligation + pinpoint cite] | [what applies / does not apply] | [what applies / does not apply] |

---

## 7. AI policy consistency

| Policy commitment | Consistent? | Notes |
|---|---|---|
| [commitment from `~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md` AI policy section] | 🟢 / 🟡 / 🟠 / 🔴 | |

[If any item is 🟡 or worse: policy update needed before deployment, or design needs to change.
One of them has to change — not both flagged and left open.]

---

## 8. Risks and mitigations

| # | Risk | Likelihood | Impact | Mitigation | Status | Owner |
|---|---|---|---|---|---|---|
| 1 | [specific risk tied to this design — not "AI hallucination" generically] | L/M/H | L/M/H | [specific control] | Done / Planned / Gap | [name] |

**Residual risk after mitigations:** [assessment]

---

## 9. Recommendation

**[APPROVED / APPROVED WITH CONDITIONS / CHANGES REQUIRED / NOT APPROVED]**

**Conditions (if any):**
- [ ] [specific action before deployment — owner, deadline]

**Privacy review required?** [Yes — run `/privacy-legal:pia-generation`, if the plugin is installed /
No]

**Sign-off:** [name, date]

---

## Cite check

Regulatory citations in Section 6 (and anywhere else) were generated by an AI model and have not been verified against primary sources. Before the assessment is certified or relied on, run a verification pass against a legal research tool (Westlaw, EUR-Lex, or your firm's platform) for each cited provision — confirm the pinpoint, currency, and any delegated or implementing acts. The AI regulatory landscape shifts quickly; verify before advising. Source tags on each citation (e.g., `[EUR-Lex]`, `[web search — verify]`) show where it came from; `verify` tags carry higher fabrication risk and should be checked first.

Before certifying the AIA (the Sign-off step, marking Status: APPROVED): Read ## Who's using this in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If the Role is Non-lawyer:

Certifying this AIA has legal consequences — it becomes the record the company relies on if a regulator or affected party asks how this use case was assessed. Have you reviewed this with an attorney? If yes, proceed. If no, here's a brief to bring to them:

[Generate a 1-page summary: the system, the regulatory classification, the risks identified, the mitigations in place, residual risk, open questions, what to ask the attorney before certifying.]

If you need to find an attorney, solicitor, barrister, or other authorised legal professional: your professional regulator's referral service is the fastest starting point (state bar in the US, SRA/Bar Standards Board in England & Wales, Law Society in Scotland/NI/Ireland/Canada/Australia, or your jurisdiction's equivalent).

Do not proceed past this gate without an explicit yes. DRAFT assessments for attorney review do not require the gate — certification does.


Risk quality standards

Same standard as the PIA skill — risks must be specific and tied to the design.

Bad riskWhy badBetter
"AI hallucination"Applies to every LLM; says nothing"Model may generate plausible but incorrect legal citations — support agents have no current verification step before sending to customers"
"Bias"Too vague"Résumé scoring model trained on historical hires; if historical cohort was demographically homogeneous, underrepresented candidates may be systematically scored lower"
"Vendor risk"Circular"OpenAI's terms permit training on API inputs by default; unless the opt-out is confirmed in the agreement, customer support messages may be used to train the model"

Aim for 2-5 real risks, not 12 padded ones.


AI policy diff

Every assessment should cross-check against the AI policy commitments in ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. Common drift:

  • Policy prohibits AI use in [category] — this use case is that category. Stop.
  • Policy requires human review — this deployment has no human step. Design needs to change.
  • Policy requires disclosure to affected parties — disclosure mechanism hasn't been built.
  • Approved vendor list exists — this vendor isn't on it. Procurement step required.

Flag every mismatch. One of them has to change before deployment.


Handoffs

  • To product / engineering: Conditions list with owners and deadlines. Not "add oversight" — "add a human review step before any automated email is sent, owner: [product lead], before launch."
  • To privacy: If personal data is involved, flag: "Run /privacy-legal:pia-generation [system name] in parallel, if the plugin is installed — the AIA doesn't substitute for a PIA."
  • To vendor-ai-review: If a new vendor is involved, flag: "If there's no AI addendum reviewed for [vendor], run /ai-governance-legal:vendor-ai-review before production."
  • To reg-gap-analysis: If new regulatory obligations emerged (EU AI Act high-risk, new sector rule), that skill tracks the gap.

Close with the next-steps decision tree

End with the next-steps decision tree per CLAUDE.md ## Outputs. Customize the options to what this skill just produced — the five default branches (draft the X, escalate, get more facts, watch and wait, something else) are a starting point, not a lock-in. The tree is the output; the lawyer picks.

What this skill does not do

  • It doesn't approve the deployment. A human signs the assessment.
  • It doesn't constitute any regulatory conformity assessment — where a regime (e.g., EU AI Act) requires a formal conformity assessment, that is a separate exercise requiring external legal review and technical documentation beyond what's here.
  • It doesn't design the mitigations. It describes what needs mitigating; engineering designs the fix.
  • It doesn't substitute for a PIA when personal data is involved. Run both.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/aia-generation of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Aia Generation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aia Generation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aia Generation this skillanthropics/claude-for-legal9.6k3 repos~6.6kAutomated safety check: PassApache-2.0
Legal Harness Initializercat-xierluo/legal-skills717—~2.3kAutomated safety check: PassMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.7kAutomated safety check: PassMIT
AI Risk Managementbriiirussell/cybersecurity-skills413—~3.7kAutomated safety check: NotesMIT
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
AI GovernanceHack23/cia239—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Legal Harness Initializer

    cat-xierluo/legal-skills

    Sets up or incrementally updates AGENTS.md and CLAUDE.md for legal professionals, with a minimal safety baseline and a check that a new session loads and follows the rules.

    717 GitHub stars~2.3k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    petrkindlmann/qa-skills

    Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…

    168 GitHub stars~4.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about Aia Generation

What does Aia Generation do?

Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions. Aia Generation is an agent skill from anthropics/claude-for-legal, published by the product's own GitHub organization. Run an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with conditions.

When should I use Aia Generation?

Aia Generation fits situations like: user says impact assessment for; assess this AI use case; generate an AIA; we need to document this AI system.

How do I install Aia Generation in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill aia-generation -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/aia-generation in anthropics/claude-for-legal) into .claude/skills/aia-generation in your project. Claude Code loads it when a task matches its description.

How do I install Aia Generation in Codex?

Run `npx skills add anthropics/claude-for-legal --skill aia-generation -a codex`. Or copy the skill folder (ai-governance-legal/skills/aia-generation in anthropics/claude-for-legal) into .agents/skills/aia-generation in your project. Codex loads it when a task matches its description.

Can I use Aia Generation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill aia-generation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aia-generation, .gemini/skills/aia-generation, .github/skills/aia-generation and .opencode/skills/aia-generation in your project.

What does Aia Generation need to run?

SKILL.md names no scripts, command-line tools or credentials: Aia Generation is instructions for the agent only.

Does Aia Generation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Aia Generation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aia Generation use?

Aia Generation is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aia Generation use?

About 6.6k tokens (SKILL.md is roughly 26k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aia Generation?

Skills that share tags, products or a category with Aia Generation: Legal Harness Initializer (cat-xierluo/legal-skills, 717 stars), Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars) and Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aia Generation?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,629 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.