Install any skill in seconds. Free to start, no credit card required.
Get Started Free →EU AI Act (Regulation EU 2024/1689) compliance specialist. Use for AI system risk classification, provider/deployer obligations, GPAI model compliance, conformity assessments, bias and fairness testing, and AI governance programs.
.claude/skills/borghei-eu-ai-act-specialist/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-18 | ✗→✓ | ▲ Improved | 334% | 0% |
| case-21 | ✗→✓ | ▲ Improved | 176% | 0% |
| case-09 | ✓→✓ | = Same ✓ | 365% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 170% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 211% | 0% |
Production-ready compliance patterns for Regulation (EU) 2024/1689 -- the EU Artificial Intelligence Act. Covers risk classification, provider/deployer obligations, GPAI model requirements, conformity assessment, and AI governance.
Before classifying or mapping obligations, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the classification.
The agent classifies AI systems under the EU AI Act's risk-based framework and maps applicable obligations.
scripts/ai_compliance_checker.py to identify compliance gaps.json{ "system_name": "Resume Screener v2.1", "provider": "Internal ML Team", "intended_purpose": "Screen job applications and rank candidates for recruiter review", "ai_act_classification": "HIGH-RISK", "classification_rationale": "Annex III Category 4 - Employment: AI for recruitment and screening of job applicants", "art_6_3_exception": false, "exception_rationale": "System directly influences which candidates proceed to interview stage - not a narrow procedural task", "applicable_obligations": [ "Risk management system (Art. 9)", "Data governance (Art. 10)", "Technical documentation (Art. 11)", "Record-keeping / automatic logging (Art. 12)", "Transparency and information to deployers (Art. 13)", "Human oversight (Art. 14)", "Accuracy, robustness, cybersecurity (Art. 15)", "Quality management system (Art. 17)", "Conformity assessment (Art. 43)", "CE marking (Art. 48)", "EU database registration (Art. 49)", "Post-market monitoring (Art. 72)" ], "compliance_deadline": "2026-08-02", "assigned_owner": "Head of AI Governance" }
The AI Act uses a risk-based approach with four tiers.
| Prohibited Practice | Article | |---------------------|---------| | Social scoring by public authorities | Art. 5(1)(c) | | Real-time remote biometric identification in public spaces (with narrow exceptions) | Art. 5(1)(h) | | Emotion recognition in workplace and education (except medical/safety) | Art. 5(1)(f) | | Individual predictive policing based solely on profiling | Art. 5(1)(d) | | Exploitation of vulnerabilities (age, disability, social/economic situation) | Art. 5(1)(b) | | Subliminal manipulation causing significant harm | Art. 5(1)(a) | | Untargeted facial image scraping for recognition databases | Art. 5(1)(e) | | Biometric categorization by sensitive attributes (race, religion, etc.) | Art. 5(1)(g) |
An AI system is high-risk if it falls under Annex III categories OR is a safety component of a product covered by Annex I harmonization legislation.
Annex III Categories:
| # | Category | Examples | |---|----------|----------| | 1 | Biometric identification and categorization | Remote biometric ID, emotion recognition | | 2 | Critical infrastructure management | Road traffic, water/gas/electricity supply, digital infrastructure | | 3 | Education and vocational training | Admissions, learning outcome evaluation, test monitoring | | 4 | Employment and workers management | Recruitment/screening, promotion/termination, performance monitoring | | 5 | Essential private and public services | Creditworthiness, insurance risk, public assistance eligibility | | 6 | Law enforcement | Polygraph, deepfake detection, crime analytics | | 7 | Migration, asylum, border control | Asylum risk assessment, visa/permit examination | | 8 | Administration of justice | Judicial fact-finding, election influence |
| System Type | Transparency Requirement | |-------------|------------------------| | Chatbots / AI interacting with persons | Inform person they are interacting with AI | | Emotion recognition / biometric categorization | Inform exposed persons of system operation | | Deepfakes / AI-generated content | Disclose AI generation; machine-readable labelling | | AI-generated text on public interest matters | Disclose AI generation unless editorially reviewed |
No mandatory requirements. Voluntary codes of conduct encouraged (Art. 95).
Providers of high-risk AI systems must comply with all of the following:
| # | Obligation | Article | Key Requirement | |---|-----------|---------|-----------------| | 1 | Risk Management System | Art. 9 | Continuous iterative process throughout lifecycle; test against defined metrics | | 2 | Data Governance | Art. 10 | Training/validation/testing datasets meet quality, representativeness, and bias criteria | | 3 | Technical Documentation | Art. 11 | Drawn up before market placement; kept up to date throughout lifecycle | | 4 | Record-Keeping / Logging | Art. 12 | Automatic recording of events enabling traceability | | 5 | Transparency | Art. 13 | Instructions for use with capabilities, limitations, and oversight measures | | 6 | Human Oversight | Art. 14 | Human-in-the-loop, on-the-loop, or in-command depending on risk | | 7 | Accuracy, Robustness, Cybersecurity | Art. 15 | Appropriate levels declared and maintained; adversarial resilience | | 8 | Quality Management System | Art. 17 | Documented QMS covering design, development, testing, data management, post-market | | 9 | Conformity Assessment | Art. 43 | Internal control (Annex VI) or third-party assessment (Annex VII) | | 10 | CE Marking | Art. 48 | Affix CE marking before market placement | | 11 | EU Database Registration | Art. 49 | Register in EU database before market placement | | 12 | Post-Market Monitoring | Art. 72 | Active systematic data collection; serious incident reporting within 15 days |
| Obligation | Detail | |-----------|--------| | Use per instructions | Operate per provider's instructions for use | | Human oversight | Assign competent, trained, authorized oversight personnel | | Input data relevance | Ensure input data is relevant and representative | | Monitoring | Monitor operation; inform provider of risks/incidents | | Record-keeping | Keep auto-generated logs (minimum 6 months) | | Inform workers | Notify workers/representatives before deployment of high-risk AI | | DPIA | Carry out GDPR Art. 35 data protection impact assessment when required | | Fundamental Rights Impact Assessment | Required for public bodies / private entities providing public services (Art. 27) |
| Obligation | Detail | |-----------|--------| | Technical documentation | Maintain documentation of model training/testing process | | Information for downstream | Provide sufficient info for downstream AI system providers | | Copyright compliance | Comply with EU copyright law; honor opt-out mechanisms | | Training data summary | Publish detailed summary of training content per AI Office template | | EU representative | Non-EU providers must appoint EU-based representative |
Classified as systemic risk if: high impact capabilities, AI Office designation, or trained with >10^25 FLOPs (rebuttable presumption).
Additional obligations: Model evaluation with adversarial testing, red-teaming proportionate to risk, systemic risk assessment and mitigation, incident tracking and reporting, cybersecurity protection, energy consumption reporting.
The agent guides organizations through conformity assessment for high-risk AI systems.
Required for biometric identification systems (Annex III point 1) and cases where harmonized standards are insufficient.
The agent performs bias detection per Art. 10 data governance requirements.
bash# Analyze dataset statistics for bias indicators python scripts/ai_bias_detector.py --input dataset_stats.json \ --protected-attributes gender,age_group,ethnicity # Output as JSON for integration with compliance documentation python scripts/ai_bias_detector.py --input dataset_stats.json --json
| Date | Milestone | Key Requirements | |------|-----------|-----------------| | 1 Aug 2024 | Entry into force | Regulation published | | 2 Feb 2025 | Prohibited practices + AI literacy | Art. 5 prohibitions; Art. 4 AI literacy | | 2 Aug 2025 | GPAI obligations + governance | Art. 53, 55 GPAI obligations; AI Office operational | | 2 Aug 2026 | Full application | All remaining: high-risk, deployer, transparency, conformity, CE marking | | 2 Aug 2027 | Extended deadline | Certain Annex I Section B high-risk safety components |
| Violation Type | Maximum Fine | % Global Turnover | |---------------|-------------|-------------------| | Prohibited AI practices | EUR 35 million | 7% (whichever higher) | | High-risk non-compliance | EUR 15 million | 3% (whichever higher) | | Misleading information to authorities | EUR 7.5 million | 1% (whichever higher) |
SMEs and startups receive proportionate treatment (lower of absolute or percentage).
AI SYSTEM DESCRIPTION
=====================
System Name:
Version:
Provider:
Date:
1. GENERAL INFORMATION
- Intended purpose:
- Target users (deployers):
- Affected persons:
- Geographic scope:
- AI Act classification:
- Annex III category (if applicable):
2. TECHNICAL ARCHITECTURE
- Model type:
- Input data modalities:
- Output description:
- Key design choices and rationale:
3. TRAINING AND DATA
- Training data sources:
- Data volume and characteristics:
- Data preparation methods:
- Bias examination results:
4. PERFORMANCE
- Accuracy metrics:
- Robustness testing results:
- Known limitations:
- Performance across demographic groups:
5. HUMAN OVERSIGHT
- Oversight level: [human-in-the-loop / on-the-loop / in-command]
- Override mechanism:
- Automation bias safeguards:RISK MANAGEMENT SYSTEM -- AI SYSTEM
====================================
System Name:
Version:
Risk Management Lead:
Date:
1. RISK IDENTIFICATION
| Risk ID | Description | Likelihood | Severity | Risk Level |
|---------|-------------|------------|----------|------------|
| R-001 | | | | |
2. RISK CONTROL MEASURES
| Risk ID | Measure | Type | Verification | Status |
|---------|---------|------|-------------|--------|
| R-001 | | | | |
3. RESIDUAL RISK ASSESSMENT
- Acceptability determination:
- Overall risk-benefit analysis:
4. POST-MARKET DATA INTEGRATION
- Review frequency:
- Trigger conditions for update:bash# Classify AI system from JSON description python scripts/ai_risk_classifier.py --input system_description.json # Classify from inline JSON python scripts/ai_risk_classifier.py --inline '{ "name": "Resume Screener", "description": "AI system that screens job applications and ranks candidates", "domain": "employment", "uses_biometrics": false, "decision_type": "automated_with_review", "affected_persons": "job applicants", "eu_deployment": true }' # JSON output for programmatic use python scripts/ai_risk_classifier.py --input system.json --json
bash# Full compliance check with gap analysis python scripts/ai_compliance_checker.py --input compliance_status.json # Check deployer obligations only python scripts/ai_compliance_checker.py --input compliance_status.json --role deployer # JSON output with remediation steps python scripts/ai_compliance_checker.py --input compliance_status.json --json
bash# Analyze dataset for bias indicators mapped to Art. 10 python scripts/ai_bias_detector.py --input dataset_stats.json # Specify protected attributes explicitly python scripts/ai_bias_detector.py --input dataset_stats.json \ --protected-attributes gender,age_group,ethnicity --json
| Document | Path | Description | |----------|------|-------------| | Classification Guide | references/ai-act-classification-guide.md | Complete Annex III categories, decision trees, prohibited practices, GPAI classification | | Governance Framework | references/ai-governance-framework.md | Organizational structure, ethics board, model lifecycle, conformity assessment procedures | | Documentation Templates | references/ai-technical-documentation-templates.md | Full templates for system description, risk management, data governance, testing, oversight, post-market monitoring, incident reporting, FRIA |
| Problem | Possible Cause | Resolution | |---------|---------------|------------| | AI system classified as HIGH-RISK but organization believes it qualifies for Art. 6(3) exception | Exception analysis incomplete or domain mapping incorrect | Re-evaluate against all Art. 6(3) exception criteria; the system must perform a narrow procedural task, improve the result of a previously completed human activity, or be purely preparatory; document rationale with legal review | | Bias detector reports disparate impact but model performs well overall | Aggregated metrics mask subgroup disparities; four-fifths rule violation on specific protected attributes | Analyze per-group positive outcome rates using --protected-attributes flag; implement targeted mitigation (re-sampling, threshold adjustment) for affected groups; document residual bias with justification | | Compliance checker returns low score despite extensive documentation | Documentation exists but key compliance fields marked as incomplete or not up to date | Verify each obligation field in the input JSON reflects current state; ensure kept_up_to_date and lifecycle_coverage flags are set; update technical documentation per Art. 11 before reassessment | | System falls under multiple Annex III categories simultaneously | AI system serves multiple domains (e.g., employment + education) | Classify under the highest-risk applicable category; apply the most stringent obligations; document classification rationale for each category | | GPAI model obligations unclear for downstream provider | Upstream GPAI provider has not supplied sufficient documentation per Art. 53 | Request technical documentation, training data summary, and copyright compliance information from the GPAI provider; if unavailable, document the gap and assess independent obligations | | Conformity assessment route uncertain (internal vs. third-party) | Biometric identification system or insufficient harmonized standards | Biometric ID systems (Annex III point 1) require third-party assessment (Annex VII); all others may use internal control (Annex VI) unless harmonized standards are unavailable; consult notified body | | Post-market monitoring shows model performance degradation | Data drift, concept drift, or deployment context changed since initial assessment | Trigger Art. 72 post-market monitoring procedures; report serious incidents within 15 days; update risk management system and technical documentation; consider re-running conformity assessment |
In Scope:
Out of Scope:
Important Notes:
| Skill | Integration | When to Use | |-------|-------------|-------------| | iso42001-ai-management | ISO 42001 AIMS provides organizational framework for EU AI Act compliance; certification demonstrates Art. 17 QMS | When building AI governance program that satisfies both ISO 42001 and EU AI Act | | gdpr-dsgvo-expert | Art. 10 data governance overlaps with GDPR; high-risk AI systems processing personal data require DPIA per GDPR Art. 35 | When AI system processes personal data and requires combined DPIA + conformity assessment | | mdr-745-specialist | AI medical devices fall under both EU AI Act and MDR; MDR conformity assessment may satisfy AI Act per Art. 120 | When AI-enabled medical device requires dual MDR and AI Act compliance | | fda-consultant-specialist | Cross-jurisdictional AI/ML SaMD compliance mapping between FDA PCCP and EU AI Act | When AI medical device is marketed in both US and EU | | infrastructure-compliance-auditor | Technical security controls supporting Art. 15 accuracy, robustness, and cybersecurity requirements | When validating infrastructure security for deployed high-risk AI systems |
Classifies AI systems into EU AI Act risk categories based on a JSON system description.
| Flag | Required | Description | |------|----------|-------------| | --input <file> | Yes (unless --inline) | Path to JSON file containing AI system description | | --inline '<json>' | No | Inline JSON system description for quick classification | | --json | No | Output results in JSON format for programmatic use | | --output <file> | No | Export classification report to specified file path |
Input Fields: name, description, domain, sub_domain, uses_biometrics, biometric_type, biometric_context, interacts_with_persons, generates_content, content_type, decision_type, affected_persons, is_safety_component, product_legislation, eu_deployment, social_scoring, manipulates_behavior, targets_vulnerable_groups, predictive_policing_individual, untargeted_scraping, is_gpai, training_compute_flops, critical_infrastructure, infrastructure_type.
Validates AI system compliance against all provider and deployer obligations with gap analysis.
| Flag | Required | Description | |------|----------|-------------| | --input <file> | Yes | Path to JSON compliance status file | | --role <role> | No | Check obligations for specific role: provider (default) or deployer | | --json | No | Output results in JSON format with remediation steps | | --output <file> | No | Export compliance report to specified file path |
Output: Overall compliance score (0-100), per-obligation status, gap analysis with Art. references, and prioritized remediation recommendations.
Analyzes dataset statistics for bias indicators mapped to Art. 10 data governance requirements.
| Flag | Required | Description | |------|----------|-------------| | --input <file> | Yes | Path to JSON file with dataset statistics (demographics, outcomes, correlations) | | --protected-attributes <attrs> | No | Comma-separated list of protected attributes to analyze (e.g., gender,age_group,ethnicity) | | --json | No | Output results in JSON format | | --output <file> | No | Export bias assessment report to specified file path |
Thresholds: Representation ratio 0.8-1.25 (within 20% of population), class imbalance >0.5, four-fifths rule (0.8) for disparate impact, proxy correlation >0.5 for proxy variable detection.
Regulation Reference: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Last Updated: March 2026 Version: 1.0.0
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-09 | pass→pass | 9,470 | 8,333 | -12% | 1 | 1 | 0% | 1,662 | 7,736 | +365% | 0 | 0 | — |
case-01 | pass→pass | 26,455 | 36,793 | +39% | 1 | 1 | 0% | 4,669 | 12,621 | +170% | 0 | 0 | — |
case-02 | pass→pass | 16,834 | 9,719 | -42% | 1 | 1 | 0% | 2,555 | 7,935 | +211% | 0 | 0 | — |
case-10 | pass→pass | 10,928 | 11,865 | +9% | 1 | 1 | 0% | 1,847 | 8,326 | +351% | 0 | 0 | — |
case-03 | pass→pass | 9,852 | 11,067 | +12% | 1 | 1 | 0% | 1,521 | 8,245 | +442% | 0 | 0 | — |
case-04 | pass→pass | 16,002 | 8,542 | -47% | 1 | 1 | 0% | 1,861 | 7,828 | +321% | 0 | 0 | — |
case-05 | pass→pass | 10,160 | 10,517 | +4% | 1 | 1 | 0% | 1,585 | 8,144 | +414% | 0 | 0 | — |
case-06 | pass→pass | 11,261 | 10,899 | -3% | 1 | 1 | 0% | 1,833 | 8,292 | +352% | 0 | 0 | — |
case-07 | pass→pass | 14,569 | 14,400 | -1% | 1 | 1 | 0% | 2,317 | 8,759 | +278% | 0 | 0 | — |
case-08 | pass→pass | 7,215 | 10,208 | +41% | 1 | 1 | 0% | 1,247 | 8,149 | +553% | 0 | 0 | — |
case-11 | pass→pass | 15,641 | 14,066 | -10% | 1 | 1 | 0% | 2,521 | 8,779 | +248% | 0 | 0 | — |
case-12 | pass→pass | 14,761 | 11,245 | -24% | 1 | 1 | 0% | 2,419 | 8,321 | +244% | 0 | 0 | — |
case-13 | pass→pass | 11,194 | 10,177 | -9% | 1 | 1 | 0% | 1,993 | 8,127 | +308% | 0 | 0 | — |
case-14 | pass→pass | 9,077 | 5,314 | -41% | 1 | 1 | 0% | 1,482 | 7,229 | +388% | 0 | 0 | — |
case-15 | pass→pass | 6,447 | 4,790 | -26% | 1 | 1 | 0% | 1,085 | 7,228 | +566% | 0 | 0 | — |
case-16 | pass→pass | 4,454 | 4,382 | -2% | 1 | 1 | 0% | 829 | 7,134 | +761% | 0 | 0 | — |
case-17 | pass→pass | 8,198 | 6,638 | -19% | 1 | 1 | 0% | 1,416 | 7,597 | +437% | 0 | 0 | — |
case-18 | fail→pass | 9,165 | 3,805 | -58% | 1 | 1 | 0% | 1,629 | 7,076 | +334% | 0 | 0 | — |
case-19 | pass→pass | 8,608 | 2,873 | -67% | 1 | 1 | 0% | 1,464 | 6,872 | +369% | 0 | 0 | — |
case-20 | fail→fail | 12,155 | 24,490 | +101% | 1 | 1 | 0% | 2,498 | 11,485 | +360% | 0 | 0 | — |
case-21 | fail→pass | 18,634 | 9,007 | -52% | 1 | 1 | 0% | 2,794 | 7,705 | +176% | 0 | 0 | — |
case-22 | fail→fail | 30,944 | 29,332 | -5% | 1 | 1 | 0% | 5,176 | 11,368 | +120% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.