Agent skill · Databases

eu-ai-act

EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-ai-act --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 4
SKILL.md size: 27 KB
Bundled scripts: none
Path: plugins/eu-ai-act/skills/eu-ai-act/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

You are an expert EU AI Act compliance advisor with deep knowledge of Regulation (EU) 2024/1689 and the Digital Omnibus (adopted June 29, 2026), its Annexes, Recitals, and all implementing measures. Every response cites the governing Article, Annex, or Recital.

⚠️ Priority Alert: AI Office enforcement powers over GPAI providers activate August 2, 2026. GPAI providers must be fully compliant with Arts. 53–55 and have their required documentation ready for AI Office review. Systemic-risk providers must have their Safety and Security Framework already submitted.

How it works

The skill lays out an 8-step workflow to guide users through: identifying whether they are a provider, deployer, importer, distributor, or authorised representative; classifying the AI system and determining if it is a GPAI model; screening for Art. 5 prohibited practices (including the CSAM 9th prohibition from 2 December 2026); determining risk tier (High-risk Path A/B, Limited risk, or Minimal risk); detailing High-Risk obligations (Arts. 9–17, 26, 27) with explicit sub-steps for data governance, risk management, transparency, human oversight, and provider/deployer obligations; outlining conformity assessment and CE marking (Arts. 43–48) and GPAI obligations (Arts. 53–55); and closing with Post-Market Monitoring and FRIA where applicable.

The procedure emphasizes pre-deployment gates (Arts. 1–3, 6, 8–17, 26–27) and ongoing duties (monitoring, incident reporting). It includes a detailed Deployer Obligations table (Arts. 26) and notes timing discipline for gatekeeping and ongoing duties. It also specifies the GPAI Code of Practice (July 2025) and enforcement timelines.

When to use it

Use when determining compliance steps for EU AI Act deployment scenarios, especially for Annex III high-risk systems, GPAI models, or deployments involving high-risk decisions (e.g., credit scoring, life/health insurance risk assessment). Applicable triggers include deployment, data governance, risk management, transparency requirements, human oversight, and post-market monitoring.

What it can touch

The skill references tools and standards related to GPAI obligations (Arts. 53–55), Annexes, and the AI Office processes. It mentions the AI database registration (Arts. 49, 60) and public authority deployment registrations (Art. 60). It requires evaluating systems against Annex III use cases, data governance, and logging per Art. 12. It also instructs on post-market reporting (Art. 72) and incident notification (Art. 73).

Caveats

All guidance is tied to the stated Articles, Annexes, and Recitals. Enactment dates and scope are as described, including the Digital Omnibus timing for Annex III and GPAI obligations. The FRIA is described as a deployer-side obligation, distinct from GDPR DPIA, with pre-deployment notification requirements to the market surveillance authority. The Code of Practice requirements for GPAI are outlined, with the August 2, 2026 enforcement activation noted.

From the SKILL.md

# EU AI Act — Compliance Advisor > **Last verified:** 2026-07-03 You are an expert EU AI Act compliance advisor with deep knowledge of **Regulation (EU) 2024/1689** and the **Digital Omnibus** (adopted June 29, 2026), its Annexes, Recitals, and all implementing measures. Every response cites the governing Article, Annex, or Recital. > ⚠️ **Priority Alert**: **AI Office enforcement powers over GPAI providers activate August 2, 2026.** GPAI providers must have their Safety and Security Framework submitted and be compliant with Arts. 53–55 (or demonstrate Code of Practice compliance) by this date. ## 8-Step Workflow **1 → Scope & Role Identification** Determine whether the user is a **provider** (develops/places AI on market), **deployer** (uses AI under own authority), **importer**, **distributor**, or **authorised representative** (Art. 3). Identify the Member State(s) of operation. **2 → AI System / GPAI Classification** Confirm the system meets the Art. 3(1) definition of an AI system. If it involves a model trained at scale for multiple tasks, assess whether it is a **GPAI model** (Art. 3(63)) and whether it crosses the systemic risk threshold (Art. 51: ≥10²⁵ FLOPs training compu

What's inside
Steps it walks through
  1. 8-Step Workflow
  2. Deployer Obligations (Art. 26) — Detailed Walkthrough
  3. Fundamental Rights Impact Assessment (FRIA, Art. 27)
  4. Annex III Area-by-Area Guidance
  5. Art. 6(3) Filter and Derogation
  6. Response Format
  7. Compliance Timeline Summary
  8. Penalties (Art. 99)
  9. Reference Files
Ships with 3 files
  • references/gpai-governance.md
  • references/obligations-high-risk.md
  • references/risk-classification.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the eu-ai-act skill do?

EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill eu-ai-act --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going