Official agent skill

EU AI Act System Inventory

by anthropics in anthropics/claude-for-legal

Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

OfficialApache-2.0Auto-check passedLegal & Compliance

Install EU AI Act System Inventory

skills CLI
$ npx skills add anthropics/claude-for-legal --skill ai-inventory -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install anthropics/claude-for-legal ai-inventory --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/anthropics/claude-for-legal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-governance-legal/skills/ai-inventory .claude/skills/ai-inventory && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ai-inventory
GitHub stars
9.6k
Used in
3 other repos
Token cost
~2.8k tokens
SKILL.md length
1,310 words
Files
1
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

  • Works in 3 steps: Role → Tier → Recommendations
  • Registering a new AI system and classifying its role and risk tier
  • SKILL.md covers When this runs, What to do, List format and Add flow (interview), plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The core idea is that role and risk tier belong to the system, not the company: one organization can be provider of one system, deployer of another and importer of a third. The skill keeps those assessments in an ai-systems.yaml file so they can be found later, and it reads a plugin CLAUDE.md config first, sending you to the cold-start interview if that config is missing or still has placeholders.

It dispatches on the argument: list shows a table with ID, name, owner, status, EU nexus, role, tier and next review, plus counts by tier and systems due for review within 30 days; add runs an interview; edit changes one field after confirmation; classify walks through role and tier and records the basis for each; show prints a full record. After any write it offers to discuss obligations in conversation and flags where the AI Act article mapping needs a lawyer's verification, since it does not derive obligations from a table.

When your agent uses it

  • Registering a new AI system and classifying its role and risk tier
  • Reviewing which systems are high-risk or due for review
  • Reclassifying a system after its use changes

Example prompts

  • “Add our resume-screening tool to the AI inventory and classify it under the EU AI Act.”
  • “List every AI system we deploy and show the counts by risk tier.”

Requirements

  • The ai-governance-legal plugin config in the claude-for-legal setup
  • Write access to the ai-systems.yaml inventory file

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Role
  2. Tier
  3. Recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit 4a6c651. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

EU AI Act System Inventory loads about 2.8k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 1,310 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from anthropics/claude-for-legal at commit 4a6c651, republished under its Apache-2.0 licence (© anthropics). 1,310 words, ~2,809 tokens.

Download SKILL.mdSave it as .claude/skills/ai-inventory/SKILL.md (or your agent's skills folder).
name
ai-inventory
description
EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says "ai inventory", "add an ai system", "what systems do we have", "classify this ai system", "eu ai act register", or "ai system registry".
argument-hint
[list | add | edit <id> | classify <id> | show <id>]

/ai-inventory

When this runs

The user wants to manage their AI system inventory under the EU AI Act. The core idea the skill exists to enforce: role and tier are per-system, not per-company. A single organization can be a provider of System A, a deployer of System B, and an importer of System C. Each combination triggers a different set of obligations under the AI Act. The inventory exists so those assessments are tracked where you can find them — the obligations themselves are derived in conversation, not from a table.

What to do

  1. Read the config. Read ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md. If it doesn't exist or still has [PLACEHOLDER] markers, direct the user to /ai-governance-legal:cold-start-interview first.

  2. Read the inventory. Inventory lives at ~/.claude/plugins/config/claude-for-legal/ai-governance-legal/ai-systems.yaml. If it doesn't exist, create it with an empty systems: list when the first add runs.

  3. Dispatch on the argument:

    • No argument, or list → show the inventory table (see List below).
    • add → run the Add flow.
    • edit <id> → show the current record, ask what to change, update one field, confirm, write.
    • classify <id> → run the Classification walk-through on an existing record, updating role, tier, role_basis, and tier_basis.
    • show <id> → show the full record.
  4. On list, offer the dashboard: "Want the full dashboard? Filter by status / tier / EU nexus / owner. Say the word."

  5. Close every action with a hook into the lawyer's work. After any write, say:

    Recorded. When you're ready to walk through obligations for this system, just ask — I'll do it in-conversation and flag where the AI Act article mapping needs your verification. I don't derive obligations from a table because the mapping is complex and changing.

List format

Render as a compact table:

IDNameOwnerStatusEU nexusRoleTierNext review
sys-001Resume screeningHR / Jamiein_productionyesdeployerhigh_risk2026-08-01
sys-002Email drafting assistantIT / Priyain_productionnodeployerlimited2026-12-01

Under the table, show counts by tier and a line: "N systems flagged for review within 30 days."

Add flow (interview)

Ask, one field at a time (or accept a paste). The required fields are name, owner, description, status, eu_nexus. The rest can be deferred — say so explicitly: "you can come back to classification with /ai-governance-legal:ai-inventory classify <id>."

  1. Name. Short label for the system.
  2. Owner. Person or team accountable for it day-to-day.
  3. Description. One or two sentences. What does it do, and against what data?
  4. Status. planned | in_development | in_production | deprecated.
  5. EU nexus. Is the system deployed in the EU/EEA, offered to users in the EU/EEA, or used to produce outputs that affect people in the EU/EEA? If any of these are true, EU AI Act analysis applies.
  6. Proceed to classification? Offer to run the walk-through now, or skip and come back later.

Assign an ID: sys-NNN where NNN is the next integer in the file.

Classification walk-through

The walk-through produces role, role_basis, tier, tier_basis. Both bases are tagged [verify against current AI Act text] — not because the skill is hedging, but because the article mapping is complex and the AI Act is still phasing in. The lawyer owns verification.

Step 1: Role

Who does what to this system?

Options, with the distinguishing test:

  • Provider — you develop it (or have it developed) and place it on the EU market or put it into service under your own name or trademark.
  • Deployer — you use it under your own authority, not for personal non-professional use. (Most common inside companies.)
  • Importer — you bring an AI system into the EU from a provider established outside the EU.
  • Distributor — you make an AI system available on the EU market without being the provider or importer.
  • Authorized representative — you act on behalf of a non-EU provider and are established in the EU.
  • Product manufacturer — you put a general-purpose AI system (or another AI system) into a product under your own name/trademark. Treated as provider for the product.

Dual-role flag. If the user substantially modifies a vendor system (fine-tunes on their own data, changes the intended purpose, rebrands), they may become a provider of the modified system even if they started as a deployer. Call this out when they describe any modification beyond configuration. [verify against current AI Act text — Article 25, provider obligations and substantial modification]

Write the role. Write role_basis in one sentence.

Show full SKILL.md (596 more words)Show less
Step 2: Tier

What does the system do, and does the use case fall into a regulated category?

Check in order:

A. Article 5 prohibited practices. [verify against current AI Act text — Article 5]

Summaries, not definitive text:

  • Subliminal or deceptive techniques materially distorting behavior
  • Exploiting vulnerabilities (age, disability, socio-economic status) to materially distort behavior
  • Social scoring by public authorities leading to detrimental treatment
  • Real-time remote biometric ID in publicly accessible spaces for law enforcement (narrow exceptions)
  • Biometric categorization inferring race, political opinions, union membership, religious or philosophical beliefs, sex life, or sexual orientation
  • Emotion recognition in the workplace or education (medical and safety exceptions)
  • Facial image database scraping from the internet or CCTV
  • Predictive policing based solely on personality traits

If matched → tier is prohibited. Flag the use case as stop and route to the governance team's prohibited-practice workflow.

B. Annex III high-risk areas. [verify against current AI Act text — Annex III]

Summaries:

  1. Biometric identification and categorization
  2. Critical infrastructure (digital infrastructure, road traffic, supply of water / gas / heating / electricity)
  3. Education and vocational training (access, evaluation, proctoring, monitoring prohibited behavior)
  4. Employment, worker management, self-employment access — recruitment, selection, promotion, termination, task allocation, monitoring, performance
  5. Essential private and public services (public benefits, credit scoring for individuals, risk assessment and pricing for life/health insurance, emergency dispatch)
  6. Law enforcement (risk assessment, polygraphs, deepfake detection, reliability of evidence, profiling)
  7. Migration, asylum, border control (risk assessment, travel document verification, examination of applications)
  8. Administration of justice and democratic processes (research and interpretation, influencing elections)

If matched → tier is high_risk. Note the Annex III area and subsection.

C. GPAI. [verify against current AI Act text — Article 51 and surrounding]

  • GPAI: model trained on broad data at scale, designed for generality, capable of competently performing a wide range of distinct tasks.
  • GPAI + systemic risk: cumulative compute > 10^25 FLOPs, or designated by the Commission.

D. Limited risk. Chatbots interacting with natural persons, deepfakes, emotion recognition and biometric categorization systems outside Article 5 scope — transparency obligations apply.

E. Minimal risk. Everything else.

Write the tier. Write tier_basis in one sentence, citing the article or Annex entry that matched, tagged [verify against current AI Act text].

Step 3: Recommendations

Offer three next steps:

  1. "Want me to walk through obligations for this system? I'll do it in conversation — I don't derive them from a table."
  2. "Want to run /ai-governance-legal:aia-generation to produce a full impact assessment?"
  3. "Want to set a next review date? I'll add it to the inventory."

Record format

yaml
systems:
  - id: sys-001
    name: "Resume screening tool"
    owner: "HR / Jamie"
    description: "Filters inbound CVs against job criteria"
    status: in_production          # planned | in_development | in_production | deprecated
    eu_nexus: true                 # deployed, offered, or affects people in the EU/EEA
    role: deployer                 # provider | deployer | importer | distributor | authorized_rep | product_manufacturer
    role_basis: "We license from VendorX and deploy internally [verify against current AI Act text]"
    tier: high_risk                # prohibited | high_risk | limited | minimal | gpai | gpai_systemic
    tier_basis: "Annex III(4)(a) — employment, recruitment selection [verify against current AI Act text]"
    obligations_assessed: false
    obligations_note: "To assess: as deployer of a high-risk system — human oversight, input data quality, monitoring, record-keeping, informing workers, FRIA if public body/service — see Article 26 [verify against current AI Act text]"
    next_review: "2026-08-01"
    review_trigger: "on substantial modification or annually"
    created: "2026-05-11"
    updated: "2026-05-11"

Why this skill does NOT auto-derive obligations

The inventory stores role, tier, and the basis for each. It does NOT contain a hardcoded role × tier → obligations table.

When the user asks "what are my obligations for System X?", the skill does the analysis in conversation, tagged [verify], and routes to /ai-governance-legal:aia-generation for the formal impact assessment if needed.

This is deliberate:

  • Article mapping is complex and the AI Act is phasing in through 2027.
  • Confident-and-wrong on a compliance obligation ends up in a board memo.
  • The inventory is a registry for the lawyer. The lawyer owns the obligation analysis.

Guardrails

  • Never classify silently. The classification walk-through must be visible; do not auto-classify from a system description.
  • [verify] tags stay. They are not hedging — they are the point. Do not strip them in outputs.
  • Flag substantial modification. Whenever a system is modified beyond configuration, prompt the user to re-run /ai-inventory classify — modification can change role.
  • Don't declare obligations from a table. If asked, do the analysis in conversation and route to /aia-generation for anything that needs a formal record.

© anthropics, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ai-governance-legal/skills/ai-inventory of anthropics/claude-for-legal.

Open the folder on GitHubat commit 4a6c651

Used in 3 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in anthropics/claude-for-legal, which our catalogue first saw on October 7, 2026.

Compare with similar skills

EU AI Act System Inventory next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

EU AI Act System Inventory compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
EU AI Act System Inventory this skillanthropics/claude-for-legal9.6k3 repos~2.8kAutomated safety check: PassApache-2.0
Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9431 repos~3.7kAutomated safety check: PassMIT
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
Caio Reviewalirezarezvani/claude-skills28k—~1.5kAutomated safety check: PassMIT
Ra Qm Skillsalirezarezvani/claude-skills28k—~833Automated safety check: PassMIT
Legal Risk AssessmentTHUYRan/Legal-Skills-Chinese873—~3.1kAutomated safety check: PassNone

Similar skills

  • Iso42001

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert ISO 42001 AI Management System (AIMS) compliance advisor.

    943 GitHub starsUsed in 1 repo~3.7k tokens
    Legal & ComplianceAuto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Caio Review

    alirezarezvani/claude-skills

    /cs:caio-review <plan — Eval-demanding Chief AI Officer interrogation of any plan that involves AI: model selection, risk classification, cost economics, or AI hiring.

    28k GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Ra Qm Skills

    alirezarezvani/claude-skills

    Router/index for the 15 regulatory & quality-management skills bundled in this plugin (ISO 13485 QMS, EU MDR 2017/745, FDA submissions under QMSR, ISO 14971 risk, CAPA, document control, ISO…

    28k GitHub stars~833 tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Legal Risk Assessment

    THUYRan/Legal-Skills-Chinese

    Assess an enterprise’s regulatory penalty risk across four dimensions: licensing/qualifications, compliance with regulatory rules, and historical penalty/credit records.

    873 GitHub stars~3.1k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Omh Legal Compliance Review

    rlaope/oh-my-hermes

    [omh] Business contract, NDA, or policy with legal risk: surface contract and compliance risks, questions, and escalation points before a legal decision or action.

    3.2k GitHub stars~1.9k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from anthropics/claude-for-legal

All 147 skills in this repo
  • Legal Clinic Client Intake

    anthropics/claude-for-legal

    Official

    Structures a legal clinic client intake interview and produces a case summary with cross-area issue spotting, conflict flags and triage classification.

    9.6k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Supervisor Review Queue

    anthropics/claude-for-legal

    Official

    Holds student work in a queue for a legal clinic professor to approve, edit-then-approve or return before anything reaches clients or courts.

    9.6k GitHub starsUsed in 3 repos~1.1k tokens
    Auto-check passed
  • Tabular Document Review

    anthropics/claude-for-legal

    Official

    Builds a review grid with one row per document and one column per data point, each cell cited to a verbatim quote, built for M&A diligence and other batch reviews.

    9.6k GitHub starsUsed in 3 repos~4.3k tokens
    Auto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Auto-check passed
  • Legal Skills Registry Browser

    anthropics/claude-for-legal

    Official

    Searches watched registries for community legal skills, shows matches with descriptions and offers the full SKILL.md before anything is installed.

    9.6k GitHub starsUsed in 2 repos~620 tokens
    Auto-check passed
  • Contract Renewal Tracker

    anthropics/claude-for-legal

    Official

    Shows which contracts renew soon and when notice must be sent by, working from a maintained renewal register, and warns about missed cancellation windows.

    9.6k GitHub starsUsed in 2 repos~3.1k tokens
    Auto-check passed

Questions about EU AI Act System Inventory

What does EU AI Act System Inventory do?

Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next. The core idea is that role and risk tier belong to the system, not the company: one organization can be provider of one system, deployer of another and importer of a third.md config first, sending you to the cold-start interview if that config is missing or still has placeholders.

When should I use EU AI Act System Inventory?

EU AI Act System Inventory fits situations like: registering a new AI system and classifying its role and risk tier; reviewing which systems are high-risk or due for review; reclassifying a system after its use changes.

How do I install EU AI Act System Inventory in Claude Code?

Run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a claude-code`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in anthropics/claude-for-legal) into .claude/skills/ai-inventory in your project. Claude Code loads it when a task matches its description.

How do I install EU AI Act System Inventory in Codex?

Run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a codex`. Or copy the skill folder (ai-governance-legal/skills/ai-inventory in anthropics/claude-for-legal) into .agents/skills/ai-inventory in your project. Codex loads it when a task matches its description.

Can I use EU AI Act System Inventory in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add anthropics/claude-for-legal --skill ai-inventory -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ai-inventory, .gemini/skills/ai-inventory, .github/skills/ai-inventory and .opencode/skills/ai-inventory in your project.

What does EU AI Act System Inventory need to run?

SKILL.md names no scripts, command-line tools or credentials: EU AI Act System Inventory is instructions for the agent only. Our summary lists: The ai-governance-legal plugin config in the claude-for-legal setup; Write access to the ai-systems.yaml inventory file.

Does EU AI Act System Inventory access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is EU AI Act System Inventory safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does EU AI Act System Inventory use?

EU AI Act System Inventory is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does EU AI Act System Inventory use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to EU AI Act System Inventory?

Skills that share tags, products or a category with EU AI Act System Inventory: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 943 stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars), Caio Review (alirezarezvani/claude-skills, 28k stars) and Ra Qm Skills (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains EU AI Act System Inventory?

anthropics (a GitHub organization, an official publisher) maintains it in anthropics/claude-for-legal, which has 9,629 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on September 29, 2026.

Source: anthropics/claude-for-legal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.