From eu-ai-act-compliance
EU AI Act compliance knowledge base (Regulation 2024/1689). Use this skill EVERY TIME the conversation involves: AI regulation, AI Act, risk classification, prohibited AI practices, high-risk AI, GPAI models, AI transparency, deepfakes, emotion recognition, biometric AI, AI in recruitment/HR/education/credit/insurance, AI literacy, human oversight, CE marking, FRIA, or building/deploying AI in the EU. Also trigger on Art. 5 prohibitions, Art. 6 high-risk, Art. 14 human oversight, Art. 26 deployer, Art. 50 transparency, Art. 53 GPAI, Annex III, provider or deployer obligations, AI fines, or whether an AI system is legal in the EU. ALWAYS trigger when the user types "/euaiact". Covers the full regulation with Danish supervisory specifics as a reference example.
How this skill is triggered — by the user, by Claude, or both
Slash command
/eu-ai-act-compliance:eu-ai-act-complianceThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
> **Regulation (EU) 2024/1689 · Skill version 2.0.0**
Regulation (EU) 2024/1689 · Skill version 2.0.0 Does NOT replace individual legal advice. State this to the user when relevant.
When the user types /euaiact, respond with a status card:
EU AI Act Compliance Skill — active
Knowledge base last updated: [read status_date from JSON]
Days since update: [calculate from today's date]
Coverage: Regulation (EU) 2024/1689 + Commission Art. 5 guidelines + GPAI Code of Practice
Companion: GDPR skill (/gdpr)
Current enforcement status:
✅ IN EFFECT: Art. 5 prohibitions, GPAI obligations, fines
⏳ UPCOMING (Aug 2026): High-risk, deployer obligations, Art. 50 transparency
⏳ FUTURE (Aug 2027): AI in regulated products (Annex I)
How can I help? Examples:
• Screen a project against Art. 5 prohibited practices
• Classify an AI system's risk level
• Check GPAI obligations for model providers
• Walk through the combined AI Act + GDPR screening sequence
If the knowledge base is older than 180 days, add a warning:
⚠️ This knowledge base is [X] months old. The AI Act is in active rollout — new guidance may exist.
Searching for recent regulatory changes...
Then use web search to check for recent Commission guidelines, delegated acts, enforcement actions, or updates to the GPAI Code of Practice.
Every time this skill is loaded, compare the status_date field in the JSON
against today's date:
Also re-evaluate the timeline table: dates that were "UPCOMING" may now be "IN EFFECT".
The AI Act is NOT a single start date. Different provisions apply at different times. Always check the timeline before advising:
| Date | Status | What applies |
|---|---|---|
| 2025-02-02 | IN EFFECT | Art. 1-4: definitions, scope, AI literacy |
| 2025-08-02 | IN EFFECT | Art. 5 prohibitions, GPAI (Ch. V), governance, fines |
| 2026-08-02 | UPCOMING | High-risk obligations, deployer obligations, Art. 50 transparency |
| 2027-08-02 | FUTURE | Art. 6(1) – AI in regulated products (Annex I) |
When advising users, always clarify which phase their obligations fall in. "From August 2026" is not the same as "applies now".
ALWAYS load the full knowledge base before responding to any AI Act question. Do not rely on this summary alone — the JSON contains the complete decision tree, all 8 prohibited practices with detail, Annex III categories, high-risk requirements, GPAI obligations, fine tiers, and GDPR interplay mapping.
view references/eu_ai_act_en.json
Every AI project starts with a prohibited practices check. This is non-negotiable and applies NOW:
If ANY answer is yes → investigate the specific prohibition's cumulative conditions. If conditions are met → the project is prohibited. Stop, document, escalate.
After Art. 5 is cleared, classify the system:
Key rule: Profiling of natural persons = ALWAYS high-risk (Art. 6(3)), regardless of other exemptions.
Flag these when the user's AI system touches any of these domains:
React with a clear warning if you spot:
The AI Act and GDPR apply cumulatively. When both are relevant, use this screening order:
For detailed GDPR guidance, see the companion skill: gdpr-compliance.
| Abbreviation | Meaning |
|---|---|
| GPAI | General-Purpose AI (e.g. LLMs) |
| FRIA | Fundamental Rights Impact Assessment |
| DPIA | Data Protection Impact Assessment (GDPR) |
| CE mark | Mandatory mark on high-risk AI systems |
Creates, edits, and optimizes skills for Claude Code, including drafting, evaluating with test prompts, iterating on performance, and improving skill descriptions for better triggering accuracy.
npx claudepluginhub sm4rtenheimer/eu-ai-act-compliance