Agent skill

Eu AI Act Specialist

by borghei in borghei/Claude-Skills

EU AI Act (Regulation EU 2024/1689) compliance specialist. An agent skill from borghei/Claude-Skills.

MITAuto-check passedLegal & Compliance

Install Eu AI Act Specialist

skills CLI
$ npx skills add borghei/Claude-Skills --skill eu-ai-act-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills eu-ai-act-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/eu-ai-act-specialist .claude/skills/eu-ai-act-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eu-ai-act-specialist
GitHub stars
891
Token cost
~7k tokens
SKILL.md length
2,742 words
Files
7 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

EU AI Act (Regulation EU 2024/1689) compliance specialist. An agent skill from borghei/Claude-Skills.

  • Works in 6 steps: Inventory all AI systems -- for each… → Apply classification decision tree to… → Map obligations based on classification… → …
  • AI system risk classification
  • SKILL.md covers Clarify First, AI System Inventory and…, Risk Classification System and Provider Obligations for…, plus 7 more sections
  • Runs Python scripts from its folder; calls python

What it does

Eu AI Act Specialist is an agent skill from borghei/Claude-Skills. EU AI Act (Regulation EU 2024/1689) compliance specialist. Use for AI system risk classification, provider/deployer obligations, GPAI model compliance, conformity assessments, bias and fairness testing, and AI governance programs.

Its SKILL.md is about 7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/ai-act-classification-guide.md`, `references/ai-governance-framework.md` and `references/ai-technical-documentation-templates.md`).

It sits in Legal & Compliance, covering AI governance and Legal risk assessment. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • AI system risk classification
  • Provider/deployer obligations
  • GPAI model compliance
  • Conformity assessments

Example prompts

  • “/eu-ai-act-specialist”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Inventory all AI systems -- for each system, document: name, provider/developer, description, intended purpose, deployment status…
  2. Apply classification decision tree to each system
  3. Map obligations based on classification -- assign compliance owners for each obligation.
  4. Run gap analysis using scripts/ai_compliance_checker.py to identify compliance gaps.
  5. Prioritize remediation by deadline urgency, penalty severity, and number of affected persons.
  6. Validation checkpoint: Every AI system classified; prohibited practices flagged for immediate action; high-risk systems have assigned…

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eu AI Act Specialist loads about 7k tokens when it runs, and up to ~41k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 2,742 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~41k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 2,742 words, ~7,013 tokens.

Download SKILL.mdSave it as .claude/skills/eu-ai-act-specialist/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
eu-ai-act-specialist
description
EU AI Act (Regulation EU 2024/1689) compliance specialist. Use for AI system risk classification, provider/deployer obligations, GPAI model compliance, conformity assessments, bias and fairness testing, and AI governance programs.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
ai-governance
metadata.updated
2026-03-31
metadata.tags
eu-ai-act, ai-governance, risk-classification, gpai, conformity

EU AI Act Compliance Specialist

Production-ready compliance patterns for Regulation (EU) 2024/1689 -- the EU Artificial Intelligence Act. Covers risk classification, provider/deployer obligations, GPAI model requirements, conformity assessment, and AI governance.


Clarify First

Before classifying or mapping obligations, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Intended purpose and domain — what the system does and its Annex III area (drives the risk classification and which obligations apply)
  • Role — provider, deployer, GPAI provider, or importer (determines the obligation set)
  • Biometric / GPAI characteristics — uses biometrics, is a GPAI model, or trained with >10^25 FLOPs (drives the prohibited / high-risk / systemic-risk path and the conformity-assessment route)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the classification.

AI System Inventory and Classification Workflow

The agent classifies AI systems under the EU AI Act's risk-based framework and maps applicable obligations.

Workflow: Classify and Map Obligations
  1. Inventory all AI systems -- for each system, document: name, provider/developer, description, intended purpose, deployment status, affected persons, geographic scope, data processed, and decision impact level.
  2. Apply classification decision tree to each system:
    • Does it meet the Art. 3(1) definition of an AI system? If no, document exclusion.
    • Does it fall under a prohibited practice (Art. 5)? If yes, flag as UNACCEPTABLE RISK -- must be discontinued.
    • Is it a safety component of an Annex I product? If yes, HIGH-RISK (product legislation path).
    • Does it fall under an Annex III category? If yes, apply Art. 6(3) exception analysis. If exception does not apply, HIGH-RISK.
    • Does Art. 50 transparency obligation apply? If yes, LIMITED RISK. Otherwise, MINIMAL RISK.
  3. Map obligations based on classification -- assign compliance owners for each obligation.
  4. Run gap analysis using scripts/ai_compliance_checker.py to identify compliance gaps.
  5. Prioritize remediation by deadline urgency, penalty severity, and number of affected persons.
  6. Validation checkpoint: Every AI system classified; prohibited practices flagged for immediate action; high-risk systems have assigned compliance owners and remediation timelines.
Example: AI System Classification Output
json
{
  "system_name": "Resume Screener v2.1",
  "provider": "Internal ML Team",
  "intended_purpose": "Screen job applications and rank candidates for recruiter review",
  "ai_act_classification": "HIGH-RISK",
  "classification_rationale": "Annex III Category 4 - Employment: AI for recruitment and screening of job applicants",
  "art_6_3_exception": false,
  "exception_rationale": "System directly influences which candidates proceed to interview stage - not a narrow procedural task",
  "applicable_obligations": [
    "Risk management system (Art. 9)",
    "Data governance (Art. 10)",
    "Technical documentation (Art. 11)",
    "Record-keeping / automatic logging (Art. 12)",
    "Transparency and information to deployers (Art. 13)",
    "Human oversight (Art. 14)",
    "Accuracy, robustness, cybersecurity (Art. 15)",
    "Quality management system (Art. 17)",
    "Conformity assessment (Art. 43)",
    "CE marking (Art. 48)",
    "EU database registration (Art. 49)",
    "Post-market monitoring (Art. 72)"
  ],
  "compliance_deadline": "2026-08-02",
  "assigned_owner": "Head of AI Governance"
}

Risk Classification System

The AI Act uses a risk-based approach with four tiers.

Tier 1: Prohibited Practices (Art. 5) -- Banned from 2 February 2025
Prohibited PracticeArticle
Social scoring by public authoritiesArt. 5(1)(c)
Real-time remote biometric identification in public spaces (with narrow exceptions)Art. 5(1)(h)
Emotion recognition in workplace and education (except medical/safety)Art. 5(1)(f)
Individual predictive policing based solely on profilingArt. 5(1)(d)
Exploitation of vulnerabilities (age, disability, social/economic situation)Art. 5(1)(b)
Subliminal manipulation causing significant harmArt. 5(1)(a)
Untargeted facial image scraping for recognition databasesArt. 5(1)(e)
Biometric categorization by sensitive attributes (race, religion, etc.)Art. 5(1)(g)
Tier 2: High-Risk AI Systems (Art. 6, Annex III)

An AI system is high-risk if it falls under Annex III categories OR is a safety component of a product covered by Annex I harmonization legislation.

Annex III Categories:

#CategoryExamples
1Biometric identification and categorizationRemote biometric ID, emotion recognition
2Critical infrastructure managementRoad traffic, water/gas/electricity supply, digital infrastructure
3Education and vocational trainingAdmissions, learning outcome evaluation, test monitoring
4Employment and workers managementRecruitment/screening, promotion/termination, performance monitoring
5Essential private and public servicesCreditworthiness, insurance risk, public assistance eligibility
6Law enforcementPolygraph, deepfake detection, crime analytics
7Migration, asylum, border controlAsylum risk assessment, visa/permit examination
8Administration of justiceJudicial fact-finding, election influence
Tier 3: Limited Risk -- Transparency Obligations (Art. 50)
System TypeTransparency Requirement
Chatbots / AI interacting with personsInform person they are interacting with AI
Emotion recognition / biometric categorizationInform exposed persons of system operation
Deepfakes / AI-generated contentDisclose AI generation; machine-readable labelling
AI-generated text on public interest mattersDisclose AI generation unless editorially reviewed
Tier 4: Minimal Risk

No mandatory requirements. Voluntary codes of conduct encouraged (Art. 95).


Provider Obligations for High-Risk AI

Providers of high-risk AI systems must comply with all of the following:

#ObligationArticleKey Requirement
1Risk Management SystemArt. 9Continuous iterative process throughout lifecycle; test against defined metrics
2Data GovernanceArt. 10Training/validation/testing datasets meet quality, representativeness, and bias criteria
3Technical DocumentationArt. 11Drawn up before market placement; kept up to date throughout lifecycle
4Record-Keeping / LoggingArt. 12Automatic recording of events enabling traceability
5TransparencyArt. 13Instructions for use with capabilities, limitations, and oversight measures
6Human OversightArt. 14Human-in-the-loop, on-the-loop, or in-command depending on risk
7Accuracy, Robustness, CybersecurityArt. 15Appropriate levels declared and maintained; adversarial resilience
8Quality Management SystemArt. 17Documented QMS covering design, development, testing, data management, post-market
9Conformity AssessmentArt. 43Internal control (Annex VI) or third-party assessment (Annex VII)
10CE MarkingArt. 48Affix CE marking before market placement
11EU Database RegistrationArt. 49Register in EU database before market placement
12Post-Market MonitoringArt. 72Active systematic data collection; serious incident reporting within 15 days

Deployer Obligations (Art. 26)

ObligationDetail
Use per instructionsOperate per provider's instructions for use
Human oversightAssign competent, trained, authorized oversight personnel
Input data relevanceEnsure input data is relevant and representative
MonitoringMonitor operation; inform provider of risks/incidents
Record-keepingKeep auto-generated logs (minimum 6 months)
Inform workersNotify workers/representatives before deployment of high-risk AI
DPIACarry out GDPR Art. 35 data protection impact assessment when required
Fundamental Rights Impact AssessmentRequired for public bodies / private entities providing public services (Art. 27)

General-Purpose AI Models (GPAI)

GPAI Provider Obligations (Art. 53) -- Effective 2 August 2025
ObligationDetail
Technical documentationMaintain documentation of model training/testing process
Information for downstreamProvide sufficient info for downstream AI system providers
Copyright complianceComply with EU copyright law; honor opt-out mechanisms
Training data summaryPublish detailed summary of training content per AI Office template
EU representativeNon-EU providers must appoint EU-based representative
Systemic Risk GPAI Models (Art. 51, 55)

Classified as systemic risk if: high impact capabilities, AI Office designation, or trained with >10^25 FLOPs (rebuttable presumption).

Additional obligations: Model evaluation with adversarial testing, red-teaming proportionate to risk, systemic risk assessment and mitigation, incident tracking and reporting, cybersecurity protection, energy consumption reporting.


Conformity Assessment Workflow

The agent guides organizations through conformity assessment for high-risk AI systems.

Workflow: Internal Control (Annex VI)
  1. Establish QMS per Art. 17 -- document design, development, testing, data management, and post-market monitoring processes.
  2. Compile technical documentation per Art. 11 -- system description, development process, risk management, data governance, performance metrics.
  3. Implement all Chapter III Section 2 requirements -- verify each obligation is addressed.
  4. Conduct internal assessment:
    • Verify risk management system addresses all identified risks (Art. 9)
    • Verify data governance meets Art. 10 requirements
    • Verify technical documentation is complete and current (Art. 11)
    • Verify logging capability (Art. 12)
    • Verify transparency and instructions for use (Art. 13)
    • Verify human oversight design (Art. 14)
    • Verify accuracy, robustness, cybersecurity (Art. 15)
    • Confirm QMS covers all required elements (Art. 17)
  5. Sign EU Declaration of Conformity (Art. 47), affix CE marking (Art. 48), register in EU database (Art. 49).
  6. Implement post-market monitoring (Art. 72) and maintain documentation updates.
  7. Validation checkpoint: All 12 provider obligations verified; declaration signed; CE marking affixed; EU database registration complete; post-market monitoring operational.
Workflow: Third-Party Assessment (Annex VII)

Required for biometric identification systems (Annex III point 1) and cases where harmonized standards are insufficient.

  1. Complete all internal control steps above.
  2. Select and engage notified body with relevant AI system expertise.
  3. QMS assessment -- notified body reviews and assesses QMS; issues certificate or requires corrective action; annual surveillance.
  4. Technical documentation assessment -- notified body reviews documentation, tests system, issues type-examination certificate.
  5. Sign EU Declaration of Conformity with notified body identification number on CE marking.
  6. Maintain ongoing compliance -- notified body surveillance, notify of significant changes, maintain all documentation.
  7. Validation checkpoint: Notified body certificates issued; CE marking with NB number affixed; ongoing surveillance scheduled.

Bias Detection and Fairness Testing

The agent performs bias detection per Art. 10 data governance requirements.

Workflow: Bias Testing
  1. Define protected attributes -- age, gender, ethnicity, disability, religion, and other relevant characteristics for the system's context.
  2. Analyze data distribution -- check representation ratios (target: 0.8-1.25 vs. population), class imbalance ratios (>0.5), and coverage of all known groups.
  3. Evaluate outcome fairness using these metrics:
    • Demographic parity: P(positive outcome) equal across groups (within 80% / four-fifths rule)
    • Equalized odds: TPR and FPR equal across groups (within 80%)
    • Predictive parity: PPV equal across groups (within 80%)
    • Calibration: Predicted probabilities accurate for all groups (within 5pp)
  4. Identify proxy variables -- check for features correlated with protected attributes.
  5. Implement mitigation -- data augmentation, re-sampling, re-weighting, adversarial debiasing, threshold adjustment, or reject option classification as appropriate.
  6. Validate -- re-run analysis to confirm improvement.
  7. Document -- record all findings, measures taken, and residual bias levels in technical documentation.
  8. Validation checkpoint: All protected attributes tested; fairness metrics within thresholds or residual bias documented with justification; mitigation measures recorded.
Example: Bias Detection Command
bash
# Analyze dataset statistics for bias indicators
python scripts/ai_bias_detector.py --input dataset_stats.json \
  --protected-attributes gender,age_group,ethnicity

# Output as JSON for integration with compliance documentation
python scripts/ai_bias_detector.py --input dataset_stats.json --json

Implementation Timeline

DateMilestoneKey Requirements
1 Aug 2024Entry into forceRegulation published
2 Feb 2025Prohibited practices + AI literacyArt. 5 prohibitions; Art. 4 AI literacy
2 Aug 2025GPAI obligations + governanceArt. 53, 55 GPAI obligations; AI Office operational
2 Aug 2026Full applicationAll remaining: high-risk, deployer, transparency, conformity, CE marking
2 Aug 2027Extended deadlineCertain Annex I Section B high-risk safety components
Penalties (Art. 99)
Violation TypeMaximum Fine% Global Turnover
Prohibited AI practicesEUR 35 million7% (whichever higher)
High-risk non-complianceEUR 15 million3% (whichever higher)
Misleading information to authoritiesEUR 7.5 million1% (whichever higher)

SMEs and startups receive proportionate treatment (lower of absolute or percentage).


AI Model Documentation Templates

Template: AI System Description
AI SYSTEM DESCRIPTION
=====================
System Name:
Version:
Provider:
Date:

1. GENERAL INFORMATION
   - Intended purpose:
   - Target users (deployers):
   - Affected persons:
   - Geographic scope:
   - AI Act classification:
   - Annex III category (if applicable):

2. TECHNICAL ARCHITECTURE
   - Model type:
   - Input data modalities:
   - Output description:
   - Key design choices and rationale:

3. TRAINING AND DATA
   - Training data sources:
   - Data volume and characteristics:
   - Data preparation methods:
   - Bias examination results:

4. PERFORMANCE
   - Accuracy metrics:
   - Robustness testing results:
   - Known limitations:
   - Performance across demographic groups:

5. HUMAN OVERSIGHT
   - Oversight level: [human-in-the-loop / on-the-loop / in-command]
   - Override mechanism:
   - Automation bias safeguards:
Template: Risk Management Documentation
RISK MANAGEMENT SYSTEM -- AI SYSTEM
====================================
System Name:
Version:
Risk Management Lead:
Date:

1. RISK IDENTIFICATION
   | Risk ID | Description | Likelihood | Severity | Risk Level |
   |---------|-------------|------------|----------|------------|
   | R-001   |             |            |          |            |

2. RISK CONTROL MEASURES
   | Risk ID | Measure | Type | Verification | Status |
   |---------|---------|------|-------------|--------|
   | R-001   |         |      |             |        |

3. RESIDUAL RISK ASSESSMENT
   - Acceptability determination:
   - Overall risk-benefit analysis:

4. POST-MARKET DATA INTEGRATION
   - Review frequency:
   - Trigger conditions for update:

Tools

AI Risk Classifier
bash
# Classify AI system from JSON description
python scripts/ai_risk_classifier.py --input system_description.json

# Classify from inline JSON
python scripts/ai_risk_classifier.py --inline '{
  "name": "Resume Screener",
  "description": "AI system that screens job applications and ranks candidates",
  "domain": "employment",
  "uses_biometrics": false,
  "decision_type": "automated_with_review",
  "affected_persons": "job applicants",
  "eu_deployment": true
}'

# JSON output for programmatic use
python scripts/ai_risk_classifier.py --input system.json --json
AI Compliance Checker
bash
# Full compliance check with gap analysis
python scripts/ai_compliance_checker.py --input compliance_status.json

# Check deployer obligations only
python scripts/ai_compliance_checker.py --input compliance_status.json --role deployer

# JSON output with remediation steps
python scripts/ai_compliance_checker.py --input compliance_status.json --json
AI Bias Detector
bash
# Analyze dataset for bias indicators mapped to Art. 10
python scripts/ai_bias_detector.py --input dataset_stats.json

# Specify protected attributes explicitly
python scripts/ai_bias_detector.py --input dataset_stats.json \
  --protected-attributes gender,age_group,ethnicity --json

Reference Documentation

DocumentPathDescription
Classification Guidereferences/ai-act-classification-guide.mdComplete Annex III categories, decision trees, prohibited practices, GPAI classification
Governance Frameworkreferences/ai-governance-framework.mdOrganizational structure, ethics board, model lifecycle, conformity assessment procedures
Documentation Templatesreferences/ai-technical-documentation-templates.mdFull templates for system description, risk management, data governance, testing, oversight, post-market monitoring, incident reporting, FRIA


Show full SKILL.md (1,084 more words)Show less

Troubleshooting

ProblemPossible CauseResolution
AI system classified as HIGH-RISK but organization believes it qualifies for Art. 6(3) exceptionException analysis incomplete or domain mapping incorrectRe-evaluate against all Art. 6(3) exception criteria; the system must perform a narrow procedural task, improve the result of a previously completed human activity, or be purely preparatory; document rationale with legal review
Bias detector reports disparate impact but model performs well overallAggregated metrics mask subgroup disparities; four-fifths rule violation on specific protected attributesAnalyze per-group positive outcome rates using --protected-attributes flag; implement targeted mitigation (re-sampling, threshold adjustment) for affected groups; document residual bias with justification
Compliance checker returns low score despite extensive documentationDocumentation exists but key compliance fields marked as incomplete or not up to dateVerify each obligation field in the input JSON reflects current state; ensure kept_up_to_date and lifecycle_coverage flags are set; update technical documentation per Art. 11 before reassessment
System falls under multiple Annex III categories simultaneouslyAI system serves multiple domains (e.g., employment + education)Classify under the highest-risk applicable category; apply the most stringent obligations; document classification rationale for each category
GPAI model obligations unclear for downstream providerUpstream GPAI provider has not supplied sufficient documentation per Art. 53Request technical documentation, training data summary, and copyright compliance information from the GPAI provider; if unavailable, document the gap and assess independent obligations
Conformity assessment route uncertain (internal vs. third-party)Biometric identification system or insufficient harmonized standardsBiometric ID systems (Annex III point 1) require third-party assessment (Annex VII); all others may use internal control (Annex VI) unless harmonized standards are unavailable; consult notified body
Post-market monitoring shows model performance degradationData drift, concept drift, or deployment context changed since initial assessmentTrigger Art. 72 post-market monitoring procedures; report serious incidents within 15 days; update risk management system and technical documentation; consider re-running conformity assessment

Success Criteria

  • All AI systems inventoried and classified -- every system assessed against the risk-based framework with documented classification rationale, including Art. 6(3) exception analysis where applicable
  • Prohibited practices identified and discontinued -- all Art. 5 prohibited practices flagged by February 2, 2025, with documented evidence of discontinuation or lawful exception application
  • High-risk systems fully compliant by August 2, 2026 -- all 12 provider obligations verified, EU Declaration of Conformity signed, CE marking affixed, and EU database registration complete
  • Bias testing completed for all high-risk systems -- demographic parity, equalized odds, and predictive parity metrics within four-fifths threshold for all protected attributes, or residual bias documented with justification
  • GPAI model obligations met by August 2, 2025 -- technical documentation maintained, downstream provider information supplied, copyright compliance verified, and training data summary published
  • Conformity assessment completed per correct route -- internal control (Annex VI) or third-party assessment (Annex VII) selected based on system classification, with all certificates issued and filed

Scope & Limitations

In Scope:

  • AI system risk classification across all four tiers (Prohibited, High-Risk, Limited Risk, Minimal Risk)
  • Annex III category analysis and Art. 6(3) exception evaluation
  • Provider and deployer obligation mapping with compliance gap analysis
  • GPAI model classification including systemic risk determination (10^25 FLOPs threshold)
  • Bias detection and fairness testing mapped to Art. 10 data governance requirements
  • Conformity assessment workflow guidance (Annex VI internal control and Annex VII third-party)
  • Implementation timeline tracking with penalty exposure assessment

Out of Scope:

  • Actual ML model training, retraining, or adversarial testing -- this skill provides compliance frameworks, not ML engineering tools
  • Notified body selection, engagement, or audit execution
  • National regulatory sandbox applications or experimental AI system exemptions
  • Detailed GPAI Code of Practice implementation beyond obligation mapping
  • CE marking physical affixation or EU database registration system interaction
  • Legal advice on liability, insurance, or contractual allocation of AI Act obligations

Important Notes:

  • The EU AI Act compliance deadline of August 2, 2026 for high-risk systems is firm -- organizations should begin classification and gap analysis immediately
  • Penalties are severe: up to EUR 35 million or 7% of global turnover for prohibited practices, EUR 15 million or 3% for high-risk non-compliance
  • SMEs and startups receive proportionate penalty treatment (lower of absolute or percentage)

Integration Points

SkillIntegrationWhen to Use
iso42001-ai-managementISO 42001 AIMS provides organizational framework for EU AI Act compliance; certification demonstrates Art. 17 QMSWhen building AI governance program that satisfies both ISO 42001 and EU AI Act
gdpr-dsgvo-expertArt. 10 data governance overlaps with GDPR; high-risk AI systems processing personal data require DPIA per GDPR Art. 35When AI system processes personal data and requires combined DPIA + conformity assessment
mdr-745-specialistAI medical devices fall under both EU AI Act and MDR; MDR conformity assessment may satisfy AI Act per Art. 120When AI-enabled medical device requires dual MDR and AI Act compliance
fda-consultant-specialistCross-jurisdictional AI/ML SaMD compliance mapping between FDA PCCP and EU AI ActWhen AI medical device is marketed in both US and EU
infrastructure-compliance-auditorTechnical security controls supporting Art. 15 accuracy, robustness, and cybersecurity requirementsWhen validating infrastructure security for deployed high-risk AI systems

Tool Reference

ai_risk_classifier.py

Classifies AI systems into EU AI Act risk categories based on a JSON system description.

FlagRequiredDescription
--input <file>Yes (unless --inline)Path to JSON file containing AI system description
--inline '<json>'NoInline JSON system description for quick classification
--jsonNoOutput results in JSON format for programmatic use
--output <file>NoExport classification report to specified file path

Input Fields: name, description, domain, sub_domain, uses_biometrics, biometric_type, biometric_context, interacts_with_persons, generates_content, content_type, decision_type, affected_persons, is_safety_component, product_legislation, eu_deployment, social_scoring, manipulates_behavior, targets_vulnerable_groups, predictive_policing_individual, untargeted_scraping, is_gpai, training_compute_flops, critical_infrastructure, infrastructure_type.

ai_compliance_checker.py

Validates AI system compliance against all provider and deployer obligations with gap analysis.

FlagRequiredDescription
--input <file>YesPath to JSON compliance status file
--role <role>NoCheck obligations for specific role: provider (default) or deployer
--jsonNoOutput results in JSON format with remediation steps
--output <file>NoExport compliance report to specified file path

Output: Overall compliance score (0-100), per-obligation status, gap analysis with Art. references, and prioritized remediation recommendations.

ai_bias_detector.py

Analyzes dataset statistics for bias indicators mapped to Art. 10 data governance requirements.

FlagRequiredDescription
--input <file>YesPath to JSON file with dataset statistics (demographics, outcomes, correlations)
--protected-attributes <attrs>NoComma-separated list of protected attributes to analyze (e.g., gender,age_group,ethnicity)
--jsonNoOutput results in JSON format
--output <file>NoExport bias assessment report to specified file path

Thresholds: Representation ratio 0.8-1.25 (within 20% of population), class imbalance >0.5, four-fifths rule (0.8) for disparate impact, proxy correlation >0.5 for proxy variable detection.


Regulation Reference: Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Last Updated: March 2026 Version: 1.0.0

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in ra-qm-team/eu-ai-act-specialist of borghei/Claude-Skills.

  • SKILL.md
  • references/ai-act-classification-guide.md
  • references/ai-governance-framework.md
  • references/ai-technical-documentation-templates.md
  • scripts/ai_bias_detector.py
  • scripts/ai_compliance_checker.py
  • scripts/ai_risk_classifier.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Eu AI Act Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eu AI Act Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eu AI Act Specialist this skillborghei/Claude-Skills891—~7kAutomated safety check: PassMIT
EU AI Act System Inventoryanthropics/claude-for-legal9.6k3 repos~2.8kAutomated safety check: PassApache-2.0
Eu AI Act Readinessseb1n/awesome-ai-agent-skills206—~3.3kAutomated safety check: PassMIT
Caio Reviewalirezarezvani/claude-skills28k—~1.5kAutomated safety check: PassMIT
Gpai Code Of Practicelawve-ai/awesome-legal-skills847—~4.4kAutomated safety check: PassCustom licence
Product Launch Legal Reviewanthropics/claude-for-legal9.6k2 repos~5kAutomated safety check: PassApache-2.0

Similar skills

  • EU AI Act System Inventory

    anthropics/claude-for-legal

    Official

    Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.

    9.6k GitHub starsUsed in 3 repos~2.8k tokens
    Legal & ComplianceAuto-check passed
  • Eu AI Act Readiness

    seb1n/awesome-ai-agent-skills

    Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…

    206 GitHub stars~3.3k tokensUpdated 2 mo ago
    Legal & ComplianceAuto-check passed
  • Caio Review

    alirezarezvani/claude-skills

    /cs:caio-review <plan — Eval-demanding Chief AI Officer interrogation of any plan that involves AI: model selection, risk classification, cost economics, or AI hiring.

    28k GitHub stars~1.5k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gpai Code Of Practice

    lawve-ai/awesome-legal-skills

    Assess compliance with the EU General-Purpose AI (GPAI) Code of Practice under the AI Act (Regulation (EU) 2024/1689).

    847 GitHub stars~4.4k tokensUpdated 8 days ago
    Legal & ComplianceAuto-check passed
  • Product Launch Legal Review

    anthropics/claude-for-legal

    Official

    Runs a category-by-category legal review of a product launch from a PRD or tracker ticket, calibrated to your team's framework, and writes a review memo in house format.

    9.6k GitHub starsUsed in 2 repos~5k tokens
    Legal & ComplianceAuto-check passed
  • Legal Risk Visualization

    zh-xx/legal-assistant-skills

    法律风险结构化分析与可视化。基于法律分析文本,执行五步风险抽取模型, 生成四层可视化输出(雷达图数据、风险矩阵、影响路径图、决策树)。

    174 GitHub stars~2.4k tokensUpdated 5 mo ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 4 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 4 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 4 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 4 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 4 days ago
    Auto-check passed

Questions about Eu AI Act Specialist

What does Eu AI Act Specialist do?

EU AI Act (Regulation EU 2024/1689) compliance specialist. An agent skill from borghei/Claude-Skills. Eu AI Act Specialist is an agent skill from borghei/Claude-Skills. EU AI Act (Regulation EU 2024/1689) compliance specialist.

When should I use Eu AI Act Specialist?

Eu AI Act Specialist fits situations like: AI system risk classification; provider/deployer obligations; GPAI model compliance; conformity assessments.

How do I install Eu AI Act Specialist in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill eu-ai-act-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/eu-ai-act-specialist in borghei/Claude-Skills) into .claude/skills/eu-ai-act-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Eu AI Act Specialist in Codex?

Run `npx skills add borghei/Claude-Skills --skill eu-ai-act-specialist -a codex`. Or copy the skill folder (ra-qm-team/eu-ai-act-specialist in borghei/Claude-Skills) into .agents/skills/eu-ai-act-specialist in your project. Codex loads it when a task matches its description.

Can I use Eu AI Act Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill eu-ai-act-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eu-ai-act-specialist, .gemini/skills/eu-ai-act-specialist, .github/skills/eu-ai-act-specialist and .opencode/skills/eu-ai-act-specialist in your project.

What does Eu AI Act Specialist need to run?

Going by SKILL.md and its folder, Eu AI Act Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Eu AI Act Specialist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Eu AI Act Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Eu AI Act Specialist use?

Eu AI Act Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eu AI Act Specialist use?

About 7k tokens (SKILL.md is roughly 28k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 34k tokens, read only when the agent opens those files.

What are the alternatives to Eu AI Act Specialist?

Skills that share tags, products or a category with Eu AI Act Specialist: EU AI Act System Inventory (anthropics/claude-for-legal, 9.6k stars), Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars), Caio Review (alirezarezvani/claude-skills, 28k stars) and Gpai Code Of Practice (lawve-ai/awesome-legal-skills, 847 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eu AI Act Specialist?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.