Agent skill

AI Act Readiness

by alirezarezvani in alirezarezvani/claude-skills

/cs:ai-act-readiness <system — EU AI Act 6-question forcing interrogation.

MITAuto-check passedLegal & Compliance

Install AI Act Readiness

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill ai-act-readiness -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills ai-act-readiness --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/compliance-os/skills/ai-act-readiness .claude/skills/ai-act-readiness && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-act-readiness
GitHub stars
28k
Token cost
~1.8k tokens
SKILL.md length
542 words
Files
1
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

/cs:ai-act-readiness <system — EU AI Act 6-question forcing interrogation.

  • Works in 6 steps: Article 5: Is this a prohibited AI… → Article 6 + Annex III: Is this high-risk? → Article 43: For high-risk, Module A or… → …
  • Tasks that involve AI governance
  • SKILL.md covers When to Run, The Six EU AI Act Questions, Workflow and Output Format, plus 2 more sections
  • Calls python

What it does

AI Act Readiness is an agent skill from alirezarezvani/claude-skills. /cs:ai-act-readiness <system — EU AI Act 6-question forcing interrogation. Use during AI-system intake, before EU deployment, or during annual compliance refresh as Article 113 obligations phase in (2025-02-02 / 2025-08-02 / 2026-08-02 / 2027-08-02).

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering AI governance. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Tasks that involve AI governance

Example prompts

  • “/ai-act-readiness”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Article 5: Is this a prohibited AI practice?
  2. Article 6 + Annex III: Is this high-risk?
  3. Article 43: For high-risk, Module A or Module H?
  4. Article 25: What role does the company play?
  5. Article 50: Are transparency obligations satisfied?
  6. Articles 51-55: Is this a GPAI? Does it have systemic risk?

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AI Act Readiness loads about 1.8k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 542 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 542 words, ~1,774 tokens.

Download SKILL.mdSave it as .claude/skills/ai-act-readiness/SKILL.md (or your agent's skills folder).
name
ai-act-readiness
description
/cs:ai-act-readiness <system> — EU AI Act 6-question forcing interrogation. Use during AI-system intake, before EU deployment, or during annual compliance refresh as Article 113 obligations phase in (2025-02-02 / 2025-08-02 / 2026-08-02 / 2027-08-02).

/cs:ai-act-readiness — EU AI Act Forcing Questions

Command: /cs:ai-act-readiness <system>

The EU AI Act compliance operator pressure-tests any AI system before EU deployment. Six Article-cited questions before any EU placement, conformity assessment, or annual compliance refresh.

When to Run

  • During AI-system intake review (per new system or material change)
  • Before placing an AI system on the EU market
  • Before signing the EU declaration of conformity (Article 47)
  • During annual compliance refresh (Article 113 phasing brings new obligations)
  • When the organization's role changes (deployer becomes provider via Article 25(1) substantial modification)
  • When training compute approaches 10^25 FLOPs (Article 51 systemic-risk threshold)

The Six EU AI Act Questions

1. Article 5: Is this a prohibited AI practice?

Penalty: up to 35M EUR or 7% worldwide turnover.

  • 8 categories: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition in workplace/education, biometric categorisation by sensitive attributes, real-time public biometric ID by law enforcement
  • Run ai_system_risk_classifier.py
  • If yes → STOP. Cannot place on EU market. No exceptions outside Article 5(2) carve-outs.
2. Article 6 + Annex III: Is this high-risk?

Annex III triggers high-risk; Article 6(3) carve-out conditional.

  • 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice
  • Carve-out applies only if Article 6(3)(a)-(d) AND no profiling of natural persons
  • Profiling overrides carve-out (Article 6(3) last sentence)
  • Run ai_system_risk_classifier.py
3. Article 43: For high-risk, Module A or Module H?

Biometrics → Module H (notified body) by default; others → Module A if harmonised standards applied.

  • Run conformity_assessment_planner.py
  • Module A (Annex VI): internal control with presumption of conformity if Article 40 harmonised standards applied
  • Module H (Annex VII): full QMS + notified body for biometrics or where standards lacking
  • Annex IV technical documentation: 8 items required before placing on market
4. Article 25: What role does the company play?

Provider obligations are heaviest; substantial modification turns deployer into provider.

  • Provider (Article 3(3)): placed on market; full Title III + Article 73 reporting
  • Deployer (Article 3(4)): Article 26 obligations + Article 27 FRIA if public sector
  • Importer (Article 3(6)): Article 23 verification of conformity
  • Distributor (Article 3(7)): Article 24 CE marking verification
  • Authorized representative (Article 22): non-EU providers must appoint
  • Run ai_act_obligation_tracker.py
Show full SKILL.md (187 more words)Show less
5. Article 50: Are transparency obligations satisfied?

In force 2 Aug 2025.

  • Article 50(1): disclose AI interaction to natural persons (chatbots, virtual agents)
  • Article 50(2): mark synthetic content as AI-generated
  • Article 50(3): disclose emotion recognition / biometric categorisation (outside Article 5 prohibitions)
  • Article 50(4): disclose deepfakes (image, audio, video) as AI-generated
6. Articles 51-55: Is this a GPAI? Does it have systemic risk?

GPAI has parallel track; systemic risk above 10^25 FLOPs.

  • Article 3(63): general-purpose AI model definition
  • Article 51: systemic-risk presumption (≥ 10^25 FLOPs training compute) or Commission designation
  • Article 53: all GPAI providers — Annex XI technical docs, Annex XII downstream info, copyright policy, training-data summary
  • Article 55: systemic-risk GPAI additional obligations — model evaluations, adversarial testing, incident reporting, cybersecurity
  • Article 54: non-EU GPAI providers must appoint authorized representative

Workflow

bash
# 1. Risk classification
python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_system_risk_classifier.py systems.json

# 2. If high-risk: conformity assessment
python ra-qm-team/skills/eu-ai-act-specialist/scripts/conformity_assessment_planner.py system.json

# 3. Per-role obligation matrix
python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_act_obligation_tracker.py roles.json

# 4. Cross-framework reuse (ISO 42001 etc.)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json

Output Format

markdown
# EU AI Act Readiness: <system>
**Date:** YYYY-MM-DD
**Article Citations:** Every verdict below cites the specific Article.

## The Decision Being Made
[classify | conformity-route | obligation-scope | annual-refresh]

## Risk Classification
- Tier: prohibited | high_risk | limited_risk | minimal_risk
- Citation: Article X(Y) + Annex Z if applicable
- Rationale: <Article-cited rationale>
- GPAI: yes/no
- Systemic-risk GPAI: yes/no (per Article 51 10^25 FLOPs threshold)

## Conformity Assessment (if high-risk)
- Module: A | A_with_caveats | H | sectoral
- Citation: Article 43 + Annex VI/VII
- Notified body required: yes | no | optional
- Annex IV pack status: complete | in-progress | not-started

## Obligation Matrix
- Total obligations: N
- By deadline phase: 2025-02-02=A, 2025-08-02=B, 2026-08-02=C, 2027-08-02=D
- Highest-priority unmet obligation: <Article + description>

## Transparency (Article 50)
- 50(1) interaction disclosure: yes | no
- 50(2) synthetic content marking: yes | no | NA
- 50(3) emotion recognition disclosure: yes | no | NA
- 50(4) deepfake disclosure: yes | no | NA

## Cross-Framework Reuse
- ISO 42001 evidence applicable to Article 17 QMS: yes/no
- ISO 27001 evidence applicable to Article 15 cybersecurity: yes/no
- GDPR DPIA usable for Article 27 FRIA: yes/no

## Verdict
🟢 READY-FOR-EU | 🟡 GAPS-IDENTIFIED | 🔴 NOT-READY | 🚫 PROHIBITED

## Top 3 Actions
[3 concrete next steps with owner + Article-tied deadline]

## Legal Review Required
[Article-level ambiguities flagged for outside counsel: novel cases, GPAI threshold disputes, Article 5 boundary cases, Article 25 substantial-modification questions]

Routing

  • /cs:compliance-readiness — for multi-framework view (combine with ISO 42001 + GDPR)
  • /cs:aims-audit — for ISO 42001 deep-dive
  • /cs:caio-review — for executive AI strategy decisions
  • /cs:gc-review — for novel-case legal review (GPAI threshold, Article 5 boundary, substantial-modification)
  • /cs:decide — to log the verdict
  • /cs:freeze 30 — on EU launch commitments (regulatory exposure)

Version: 1.0.0

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in compliance-os/skills/ai-act-readiness of alirezarezvani/claude-skills.

Open the folder on GitHubat commit 19392f7

Compare with similar skills

AI Act Readiness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AI Act Readiness compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AI Act Readiness this skillalirezarezvani/claude-skills28k—~1.8kAutomated safety check: PassMIT
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.7kAutomated safety check: PassMIT
AI Risk Managementbriiirussell/cybersecurity-skills413—~3.7kAutomated safety check: NotesMIT
EU AI Act System Inventoryanthropics/claude-for-legal9.6k3 repos~2.8kAutomated safety check: PassApache-2.0
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
AI GovernanceHack23/cia239—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    946 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check: notes
  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    petrkindlmann/qa-skills

    Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…

    170 GitHub stars~4.6k tokensUpdated 4 mo ago
    Legal & ComplianceAuto-check passed

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Questions about AI Act Readiness

What does AI Act Readiness do?

/cs:ai-act-readiness <system — EU AI Act 6-question forcing interrogation. AI Act Readiness is an agent skill from alirezarezvani/claude-skills. /cs:ai-act-readiness <system — EU AI Act 6-question forcing interrogation.

When should I use AI Act Readiness?

AI Act Readiness fits situations like: tasks that involve AI governance.

How do I install AI Act Readiness in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill ai-act-readiness -a claude-code`. Or copy the skill folder (compliance-os/skills/ai-act-readiness in alirezarezvani/claude-skills) into .claude/skills/ai-act-readiness in your project. Claude Code loads it when a task matches its description.

How do I install AI Act Readiness in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill ai-act-readiness -a codex`. Or copy the skill folder (compliance-os/skills/ai-act-readiness in alirezarezvani/claude-skills) into .agents/skills/ai-act-readiness in your project. Codex loads it when a task matches its description.

Can I use AI Act Readiness in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill ai-act-readiness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-act-readiness, .gemini/skills/ai-act-readiness, .github/skills/ai-act-readiness and .opencode/skills/ai-act-readiness in your project.

What does AI Act Readiness need to run?

Going by SKILL.md and its folder, AI Act Readiness needs the command-line tools its instructions call (python). Our summary lists: Python 3.

Does AI Act Readiness access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AI Act Readiness safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does AI Act Readiness use?

AI Act Readiness is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AI Act Readiness use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AI Act Readiness?

Skills that share tags, products or a category with AI Act Readiness: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), EU AI Act System Inventory (anthropics/claude-for-legal, 9.6k stars) and Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AI Act Readiness?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,938 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.