Iso42001
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
Classify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations.
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classification --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .claude/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .claude/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutatType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classification --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .agents/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .agents/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classification --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .cursor/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .cursor/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/lawve-ai/awesome-legal-skills.git --path skills/eu-ai-act-system-classifier-werner-plutat--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classification --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .gemini/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .gemini/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classificationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .github/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .github/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install lawve-ai/awesome-legal-skills eu-ai-act-classification --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/lawve-ai/awesome-legal-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/eu-ai-act-system-classifier-werner-plutat .opencode/skills/eu-ai-act-classification && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "eu-ai-act-classification" agent skill from https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/eu-ai-act-system-classifier-werner-plutat into .opencode/skills/eu-ai-act-classification/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "eu-ai-act-classification", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
eu-ai-act-classificationClassify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations.
Eu AI Act Classification is an agent skill from lawve-ai/awesome-legal-skills. Classify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations. Use when asked to assess AI risk level, check if an AI system is prohibited, determine high-risk status, identify GPAI model obligations, map provider/deployer responsibilities, or build an AI Act compliance roadmap. Covers the full classification decision tree (Prohibited → High-Risk → Limited → Minimal → GPAI), obligations by role (provider, deployer, importer, distributor), compliance timelines, and…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including reference files (for example `README.md`, `references/dach-specific.md` and `references/gpai-obligations.md`).
It sits in Legal & Compliance, covering AI governance. The repository describes itself as: A curated list of awesome Agent Skills for automating legal work. The licence is AGPL-3.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 045f738. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Eu AI Act Classification loads about 3.4k tokens when it runs, and up to ~28k if it reads all its reference files. Until then it costs about 204 tokens; SKILL.md has 1,668 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from lawve-ai/awesome-legal-skills at commit 045f738, republished under its AGPL-3.0 licence (© lawve-ai). 1,668 words, ~3,416 tokens.
.claude/skills/eu-ai-act-classification/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.Classify AI systems under Regulation (EU) 2024/1689 and determine obligations by role.
Important: This skill provides compliance workflow support, not legal advice. Always cite specific EU AI Act articles. Where facts are incomplete, state assumptions explicitly and ask targeted follow-up questions.
Follow this decision tree strictly in order. Stop at the first match.
Confirm the AI system falls within scope:
If out of scope, document why and stop.
Check every Article 5 category. If any match → PROHIBITED. Stop unless a narrow law enforcement exception applies.
Categories (check all ten: the original eight, plus Art. 5(1)(ba) non-consensual intimate material and (bb) CSAM, both applying from 2 December 2026):
→ For the complete checklist with examples and edge cases, read references/prohibited-practices.md.
Annex I path: Is the AI a product or safety component under EU harmonisation legislation (e.g., MDR, IVDR) subject to third-party conformity assessment? → HIGH-RISK
Annex I Section A vs Section B. For products covered by Section B, Regulation (EU) 2024/1689 applies only to the extent set out in its Article 2(2), so the full Chapter III regime does not attach. Regulation (EU) 2026/1744 moved the Machinery Regulation (EU) 2023/1230 from Section A to Section B with effect from 27 July 2026, so AI-enabled machinery now follows the sectoral route. Note that Article 2(2) was itself rewritten by the same act: for Section B products only Article 6(1), the new Article 60a and Articles 102 to 112 apply, with Articles 57 to 59 applying only in so far as the high-risk requirements have been integrated into that sectoral legislation.
The safety-component gateway narrowed on 27 July 2026. Before concluding HIGH-RISK on the Annex I path, apply the new Article 6(1a) to (1c) and the amended Article 3(14):
- Article 3(14) now ties "safety component" to intended purpose: a component fulfils a safety function where its intended purpose is to prevent or mitigate risks to the health and safety of persons or property. Mere integration into a regulated product does not make it one.
- Article 6(1a): systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control do not qualify as safety components.
- Article 6(1b): despite 1a, a system whose failure or malfunctioning would endanger health and safety does qualify.
- Article 6(1c): a product required to undergo third-party conformity assessment solely for risks other than health and safety, for example radio spectrum or electromagnetic interference, does not satisfy Article 6(1)(b).
Practical effect: several systems that previously classified as high-risk by virtue of sitting inside a regulated product now fall outside Article 6(1). Document which limb you relied on.
Annex III path: Does the intended purpose fall within one of the eight high-risk use-case categories?
| # | Category | Quick examples |
|---|---|---|
| 1 | Biometrics | Remote identification (1:1 verification of a claimed identity is expressly excluded), categorisation by sensitive attributes, emotion recognition |
| 2 | Critical infrastructure | Energy grid control, water systems, traffic management |
| 3 | Education | Admissions, grading, learning access decisions |
| 4 | Employment | CV screening, promotion, termination, task allocation |
| 5 | Essential services | Public-benefit eligibility, credit scoring (fraud detection excluded), life and health insurance pricing, emergency triage |
| 6 | Law enforcement | Risk assessment, evidence evaluation, profiling |
| 7 | Migration & border | Border risk assessment, examination of asylum/visa/residence applications (travel-document verification excluded) |
| 8 | Justice & democracy | Judicial assistance, electoral process systems |
→ For all categories with examples and edge cases, read references/high-risk-annex-iii.md.
Article 6(3) exception: Even if an Annex III use case matches, a system is NOT high-risk if it does not pose a significant risk of harm to health, safety or fundamental rights, including by not materially influencing the outcome of decision making, and one of these conditions is met:
Profiling override, check this FIRST: notwithstanding those conditions, an Annex III system is always high-risk where it performs profiling of natural persons (Art. 6(3), third subparagraph). If the system profiles people, the exception is unavailable and the analysis stops here.
If claiming this exception, document the reasoning thoroughly (Art. 6(4)), and note the Art. 49(2) registration duty for systems relying on it.
Independent of system-level risk. A minimal-risk app can use a GPAI model with its own obligations. Downstream providers/deployers must still verify vendor evidence and ensure documentation is sufficient for their specific use case and risk profile.
Check:
→ For GPAI obligations and systemic risk details, read references/gpai-obligations.md.
If not prohibited or high-risk, check Article 50 transparency duties. Who owes each duty differs by paragraph:
No AI Act-specific obligations. Recommend:
Use these questions at the start (and whenever facts are missing) to gather the information needed for classification. For borderline cases or uncertainty, escalate early to qualified legal counsel and document assumptions.
System & Purpose
Impact & Context 3. Does it make or materially influence decisions about individuals in education, employment, essential services, law enforcement, migration, or justice? 4. Who is affected — customers, employees, citizens, patients? 5. Is it customer-facing? Is there meaningful human oversight in practice?
Technical 6. Does it use biometrics, emotion recognition, or infer sensitive attributes? 7. What data categories are processed, including special category data? 8. Is a GPAI model used? Which provider? What compliance evidence is available?
Organisational 9. Who is the provider vs. deployer? Where is it deployed? 10. Is it a product or safety component under EU harmonisation legislation?
If answers are incomplete, state assumptions explicitly and flag gaps.
Load these as needed based on the classification result:
| File | When to read |
|---|---|
| references/prohibited-practices.md | Evaluating Article 5 — complete checklist with examples and edge cases |
| references/high-risk-annex-iii.md | Evaluating Annex III — all 8 categories with examples, edge cases, and the Article 6(3) exception |
| references/gpai-obligations.md | System uses a GPAI model — Articles 51–56, systemic risk thresholds, downstream duties |
| references/obligations-matrix.md | After classification — provider/deployer/importer/distributor responsibilities by risk level |
| references/timeline.md | Building a compliance roadmap — all deadlines with practical planning guidance |
| references/dach-specific.md | Deployer is in Germany/Austria/Switzerland — works council, BaFin, BSI, BNetzA, sector-specific overlaps |
| references/templates.md | Producing deliverables — classification memo, risk register entry, executive summary templates |
Every classification produces three deliverables:
Classification Memo — Formal assessment documenting the decision tree walkthrough, classification result, cited articles, and key assumptions. This is the primary legal record.
Risk Register Entry — Structured entry for the organisation's AI risk register with system name, classification, key obligations, deadlines, and responsible parties.
Executive Summary — One-page summary for leadership with classification result, key obligations, timeline, and recommended next steps.
Always consider horizontal obligations such as AI literacy/training (Article 4) as part of the compliance roadmap, even for minimal-risk systems.
→ For complete templates, read references/templates.md.
Flag these in every assessment to ensure appropriate escalation:
| Violation | Maximum fine |
|---|---|
| Prohibited practices | €35M or 7% global annual turnover, whichever is higher for an undertaking |
| High-risk system obligations | €15M or 3% global annual turnover, whichever is higher for an undertaking |
| Incorrect/misleading information | €7.5M or 1% global annual turnover, whichever is higher for an undertaking |
For SMEs, including startups, the lower of the amount or percentage applies to each Article 99 fine. For SMCs, that lower-of rule applies only to the fines in Article 99(4) and (5), not to prohibited-practice fines under Article 99(3).
This skill provides structured compliance workflow support based on Regulation (EU) 2024/1689. It does not constitute legal advice. Classification outcomes should be reviewed by qualified legal counsel before being relied upon for compliance decisions. The EU AI Act is subject to delegated acts, implementing acts, and guidance from the EU AI Office that may affect interpretation.
© lawve-ai, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 9 other files (references) in skills/eu-ai-act-system-classifier-werner-plutat of lawve-ai/awesome-legal-skills.
Open the folder on GitHubat commit 045f738
Eu AI Act Classification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Eu AI Act Classification this skilllawve-ai/awesome-legal-skills | 847 | — | ~3.4k | Automated safety check: Pass | AGPL-3.0 | |
| Iso42001Sushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~3.7k | Automated safety check: Pass | MIT | |
| AI Risk Managementbriiirussell/cybersecurity-skills | 413 | — | ~3.7k | Automated safety check: Notes | MIT | |
| EU AI Act System Inventoryanthropics/claude-for-legal | 9.6k | 3 repos | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Eu AI Act Readinessseb1n/awesome-ai-agent-skills | 206 | — | ~3.3k | Automated safety check: Pass | MIT | |
| AI GovernanceHack23/cia | 239 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert ISO 42001 AI Management System (AIMS) compliance advisor.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
anthropics/claude-for-legal
Maintains a register of AI systems under the EU AI Act, recording each system's role and risk tier separately, because both can differ from one system to the next.
seb1n/awesome-ai-agent-skills
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency…
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
petrkindlmann/qa-skills
Test for regulatory compliance: GDPR/CMP consent verification, Google Consent Mode v2, Global Privacy Control (GPC), CCPA/US state opt-out, EU AI Act Article 50 transparency, Better Ads Standards…
lawve-ai/awesome-legal-skills
U.S. An agent skill from lawve-ai/awesome-legal-skills.
lawve-ai/awesome-legal-skills
Practitioner skill for advising on EU Regulation 2023/2854 (Data Act).
lawve-ai/awesome-legal-skills
Calendar litigation and arbitration deadlines from a scheduling order.
lawve-ai/awesome-legal-skills
Read, search, and download emails and attachments from Microsoft Outlook via OAuth2.
lawve-ai/awesome-legal-skills
Turn an interpretive-ambiguity audit of a legal text — contract, statute, regulation, or judicial opinion — into a polished deliverable.
lawve-ai/awesome-legal-skills
Audits a website for compliance with Azerbaijan's Law on Personal Data No.
Categories
Classify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations. Eu AI Act Classification is an agent skill from lawve-ai/awesome-legal-skills. Classify AI systems under the EU AI Act (Regulation (EU) 2024/1689) and determine compliance obligations.
Eu AI Act Classification fits situations like: asked to assess AI risk level; check if an AI system is prohibited; determine high-risk status; identify GPAI model obligations.
Run `npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a claude-code`. Or copy the skill folder (skills/eu-ai-act-system-classifier-werner-plutat in lawve-ai/awesome-legal-skills) into .claude/skills/eu-ai-act-classification in your project. Claude Code loads it when a task matches its description.
Run `npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a codex`. Or copy the skill folder (skills/eu-ai-act-system-classifier-werner-plutat in lawve-ai/awesome-legal-skills) into .agents/skills/eu-ai-act-classification in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-classification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eu-ai-act-classification, .gemini/skills/eu-ai-act-classification, .github/skills/eu-ai-act-classification and .opencode/skills/eu-ai-act-classification in your project.
SKILL.md names no scripts, command-line tools or credentials: Eu AI Act Classification is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Eu AI Act Classification is published under the AGPL-3.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 24k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Eu AI Act Classification: Iso42001 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars), AI Risk Management (briiirussell/cybersecurity-skills, 413 stars), EU AI Act System Inventory (anthropics/claude-for-legal, 9.6k stars) and Eu AI Act Readiness (seb1n/awesome-ai-agent-skills, 206 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
lawve-ai (a GitHub organization) maintains it in lawve-ai/awesome-legal-skills, which has 847 GitHub stars. The repository holds 154 skills in this directory. The repository was last updated on October 2, 2026.
Source: lawve-ai/awesome-legal-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.