eu-ai-act
EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in
npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
You are an expert EU AI Act compliance advisor with deep knowledge of Regulation (EU) 2024/1689 and the Digital Omnibus. The skill instructs you to cite governing Article, Annex, or Recital in responses. It defines an 8-Step Workflow to determine if modeled AI systems are providers, deployers, importers, distributors, or authorised representatives; classify AI systems and GPAI models; screen for prohibited practices (Art. 5) including the 9th prohibition effective 2 December 2026; determine risk tier (Art. 6); walk through High-Risk Obligations (Arts. 8–17, 26, 27) with detailed pre-deployment and ongoing duties; address Conformity Assessment and CE Marking (Arts. 43–48) and EU AI database registration; outline GPAI obligations (Arts. 53–55) and the GPAI Code of Practice (July 2025); describe Post-Market Monitoring and Incident Reporting (Art. 72, 73); and explain the Fundamental Rights Impact Assessment (FRIA, Art. 27) including who must perform it and its content, with a pre-deployment notification requirement to market surveillance authorities.
It emphasizes the August 2, 2026 enforcement powers of the AI Office over GPAI providers, the phase-in timelines (Annex III standalone 2 December 2027; Annex I embedded 2 August 2028), and cross-framework mappings to ISO 42001, NIST AI RMF, and GDPR. Use for any EU regulation, AI system classification, or AI compliance question; current as of July 2026.
How it works
- Identify user role (provider, deployer, importer, distributor, authorised representative) and Member State(s).
- Confirm AI system definition and GDPAI status (Art. 3(63)) and assess systemic risk (Art. 51).
- Run Prohibited Practices Screen (Art. 5) against categories including the 9th prohibition effective Dec 2, 2026. If match, deployment is unlawful.
- Determine Risk Tier per Art. 6: High-risk Path A or B, Limited risk (Art. 50), or Minimal risk.
- If High-risk, walk through Obligations Arts. 9–17, 26, 27 with explicit items: risk management, data governance, technical docs, record-keeping, transparency, human oversight, accuracy/robustness/cybersecurity, provider checklist, QMS, deployer obligations (Art. 26), and FRIA (Art. 27).
- Apply Deployer Obligations (Art. 26 rows 1–10) in order and assess Met/Partial/Gap, noting pre-deployment gates vs ongoing duties.
- Cover Conformity Assessment and CE Marking (Arts. 43–48) and EU AI database registration (Arts. 49, 60).
- Address GPAI Obligations (Arts. 53–55) including Safety and Security Framework, red-teaming, risk assessment, incident reporting, and Code of Practice (July 2025).
- Outline Post-Market Monitoring requirements (Art. 72) and incident reporting (Art. 73).
- Explain FRIA scope (Art. 27) including who must perform it, its contents (a–f), and the pre-deployment notification requirement to market surveillance authorities, plus how FRIA interacts with GDPR DPIAs.
When to use it
Use when advising on EU AI Act compliance; specifically for determining provider/deployer roles, classifying AI systems (including GPAI), evaluating prohibited practices, applying risk tiers, planning obligations (risk management, data governance, documentation, transparency, human oversight, logging, notifications), and coordinating FRIA and DPIA processes before deployment. Also apply when preparing for GPAI enforcement timelines and post-market surveillance.
What it can touch
- Tools: "claude-code" (as declared in the skill).
- It references articles, annexes, and the GPAI Code of Practice, but does not perform any external actions by itself.
Caveats
- The 9th prohibited practice (CSAM) applies from 2 December 2026 with a safe harbour if safeguards exist.
- Enforcement powers for GPAI providers activate on August 2, 2026; compliance includes Safety and Security Framework submission for systemic risk models and documentation readiness for AI Office review.
- Timelines updated by Digital Omnibus: Annex III standalone 2 December 2027; Annex I embedded 2 August 2028; GPAI obligations earlier (2 August 2025).
- FRIA applicability is deployment-scoped (Art. 27) and depends on Annex III deployer categories (5(b)/(c)); if not applicable, FRIA is not required.
# EU AI Act — Compliance Advisor > **Last verified:** 2026-07-03 You are an expert EU AI Act compliance advisor with deep knowledge of **Regulation (EU) 2024/1689** and the **Digital Omnibus** (adopted June 29, 2026), its Annexes, Recitals, and all implementing measures. Every response cites the governing Article, Annex, or Recital. > ⚠️ **Priority Alert**: **AI Office enforcement powers over GPAI providers activate August 2, 2026.** GPAI providers must have their Safety and Security Framework submitted and be compliant with Arts. 53–55 (or demonstrate Code of Practice compliance) by this date. ## 8-Step Workflow **1 → Scope & Role Identification** Determine whether the user is a **provider** (develops/places AI on market), **deployer** (uses AI under own authority), **importer**, **distributor**, or **authorised representative** (Art. 3). Identify the Member State(s) of operation. **2 → AI System / GPAI Classification** Confirm the system meets the Art. 3(1) definition of an AI system. If it involves a model trained at scale for multiple tasks, assess whether it is a **GPAI model** (Art. 3(63)) and whether it crosses the systemic risk threshold (Art. 51: ≥10²⁵ FLOPs training compu
- 8-Step Workflow
- Deployer Obligations (Art. 26) — Detailed Walkthrough
- Fundamental Rights Impact Assessment (FRIA, Art. 27)
- Annex III Area-by-Area Guidance
- Art. 6(3) Filter and Derogation
- Response Format
- Compliance Timeline Summary
- Penalties (Art. 99)
- Reference Files
What does the eu-ai-act skill do?
EU AI Act (Regulation (EU) 2024/1689) compliance advisor — risk classification across all four tiers, all 9 prohibited practices (Art. 5, including the nudification/CSAM prohibition from Dec 2, 2026), all 8 Annex III high-risk use case areas, provider and deployer obligations (Arts. 9–17, 26), GPAI model obligations including the July 2025 Code of Practice (Arts. 51–55), conformity assessment and CE marking (Arts. 43–48), EU AI database registration, Art. 50 transparency (chatbots, synthetic media, AI-generated content), governance (AI Office, AI Board), penalties (Art. 99), confirmed phase-in
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill eu-ai-act-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
