skills/arckit-eu-ai-act/SKILL.md
[COMMUNITY] Assess EU AI Act (Regulation 2024/1689) compliance obligations, risk classification, and conformity requirements for AI systems
npx skillsauth add tractorjuice/arckit-codex arckit-eu-ai-actInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
⚠️ Community-contributed command — not part of the officially-maintained ArcKit baseline. Output should be reviewed by qualified DPO / RSSI / legal counsel before reliance. Citations to ANSSI / CNIL / EU regulations may lag the current text — verify against the source.
You are helping an enterprise architect generate an EU AI Act Compliance Assessment (Regulation EU 2024/1689) for an AI system deployed in the European Union. The AI Act is the world's first binding horizontal AI regulation, with phased application through 2027.
$ARGUMENTS
Note: Before generating, scan
projects/for existing project directories. For each project, list allARC-*.mdartifacts, checkexternal/for reference documents, and check000-global/for cross-project policies. If no external docs exist but they would improve output, ask the user.
MANDATORY (warn if missing):
RECOMMENDED (read if available, note if missing):
OPTIONAL (read if available, skip silently):
external/ — extract AI ethics assessments, algorithmic impact assessments, existing conformity documentation, ANSSI or ARCOM correspondence000-global/policies/ — extract responsible AI policy, model governance policy, human oversight policyIdentify the target project from the hook context. If the project doesn't exist:
projects/*/ directories and find the highest NNN-* numberprojects/{NNN}-{slug}/README.mdPROJECT_ID and PROJECT_PATHRead all documents from Step 0. Identify:
Read the template (with user override support):
.arckit/templates-custom/eu-ai-act-template.md exists in the project root.arckit/templates/eu-ai-act-template.mdBefore generating the assessment, determine risk classification:
PROHIBITED (Article 5 — applicable February 2025):
If ANY prohibited practice applies → STOP and flag: the AI system cannot be placed on the EU market.
HIGH RISK — Annex I (safety components of products covered by sector legislation): Machinery, toys, recreational craft, lifts, ATEX, medical devices, in vitro diagnostics, aviation, agricultural vehicles, railway
HIGH RISK — Annex III (standalone AI systems):
LIMITED RISK (transparency obligations only): Chatbots, emotion recognition disclosure, synthetic content labelling, biometric categorisation disclosure
MINIMAL RISK: All other AI systems — no mandatory obligations, voluntary codes encouraged
Show the classification clearly before proceeding.
CRITICAL: Use the Write tool to create the assessment document.
Detect version: Check for existing ARC-{PROJECT_ID}-AIACT-v*.md files:
Auto-populate Document Control:
ARC-{PROJECT_ID}-AIACT-v{VERSION}Section 1: AI System Classification
Section 2: Prohibited Practices Check (Article 5)
Section 3: High-Risk AI Requirements (Articles 8–17) (if High Risk)
Section 4: Transparency Obligations (Article 50) (Limited Risk)
Section 5: GPAI Model Obligations (Articles 53–55) (if GPAI)
Section 6: Conformity Assessment and Registration
Section 7: French Market Context
Section 8: Gap Analysis and Application Timeline
Before writing the file, read .arckit/references/quality-checklist.md and verify all Common Checks pass.
Write the document to:
projects/{project_id}/ARC-{PROJECT_ID}-AIACT-v{VERSION}.md
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
✅ EU AI Act Assessment Generated
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📄 Document: projects/{project_id}/ARC-{PROJECT_ID}-AIACT-v{VERSION}.md
📋 Document ID: {document_id}
📅 Assessment Date: {date}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
🤖 AI System Classification
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Risk Class: {PROHIBITED ⛔ / HIGH RISK 🔴 / LIMITED RISK 🟡 / MINIMAL RISK 🟢}
GPAI Model: {Yes / No}
Role: {Provider / Deployer}
{If PROHIBITED: ⛔ SYSTEM CANNOT BE DEPLOYED ON EU MARKET — see Section 2}
{If HIGH RISK: Full conformity assessment required before market placement}
{If LIMITED RISK: Transparency obligations apply}
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
📋 Conformity Requirements
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{Summary of applicable requirements with status}
Total Gaps: {N} ({N} high, {N} medium)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⏰ Critical Deadlines
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
{Application dates relevant to this classification}
Next steps:
1. {If personal data: Run $arckit-eu-rgpd for GDPR obligations}
2. {If high-risk: Initiate conformity assessment process}
3. Run $arckit-risk to register AI Act gaps
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
| Document | Publisher | URL | |----------|-----------|-----| | EU AI Act (Regulation 2024/1689) — full text | EUR-Lex | https://eur-lex.europa.eu/eli/reg/2024/1689/oj | | EU AI Office — implementation guidance and GPAI codes of practice | European Commission | https://digital-strategy.ec.europa.eu/en/policies/ai-office | | AI Act application timeline and obligations summary | European Commission | https://digital-strategy.ec.europa.eu/en/policies/european-approach-artificial-intelligence | | ENISA — AI cybersecurity guidance | ENISA | https://www.enisa.europa.eu/topics/artificial-intelligence | | MITRE ATLAS — adversarial ML threat matrix | MITRE | https://atlas.mitre.org/ | | ANSSI — AI security guidance (French context) | ANSSI | https://cyber.gouv.fr/publications |
Note for reviewers: The EU AI Act is the world's first comprehensive AI regulation, applying to providers and deployers of AI systems in the EU regardless of where the provider is based. It uses a risk-based approach: prohibited practices (e.g. social scoring, real-time biometric surveillance) are banned outright; high-risk systems (Annex III — employment, education, essential services, law enforcement, migration, justice) face strict conformity requirements before market placement; GPAI models (general-purpose AI, e.g. large language models) have separate transparency and safety obligations. Application dates are phased: prohibited practices from February 2025, high-risk from August 2026.
projects/{project_id}/ARC-{PROJECT_ID}-AIACT-v{VERSION}.md$arckit-eu-ai-act Assess AI Act compliance for an automated CV screening tool used by a French public employment service (France Travail), processing personal data, making pre-selection recommendations to human recruiters
$arckit-eu-ai-act AI Act classification for 001 — chatbot for citizen service portal, built on GPT-4, providing information about public benefits eligibility
$arckit-eu-ai-act Assess a real-time emotion detection system to be deployed in a retail environment to monitor customer satisfaction
After completing this command, consider running:
$arckit-eu-rgpd -- Assess GDPR obligations for personal data used in AI training or inference (when AI system processes personal data)$arckit-risk -- Integrate AI Act compliance gaps and prohibited practice findings into the risk register$arckit-traceability -- Link AI Act conformity requirements back to functional requirements (when High-risk AI system classification confirmed)tools
Procurement market intelligence — award-value benchmarks, top suppliers, incumbency and concentration, from the UK Tenders MCP
tools
Competitor landscape — rival suppliers, awarded-value market share, head-to-head and concentration, from the UK Tenders MCP
development
[COMMUNITY] Generate a SOCI Act Critical Infrastructure Risk Management Program (CIRMP) governance and evidence pack for Australian critical infrastructure assets.
development
[COMMUNITY] Generate an ASD operational technology cyber security assessment for Australian Government and critical-infrastructure projects with connected OT environments.