Best for
- Use when an organization needs to triage an AI use case, vendor, model, product, or portfolio for Regulation (EU) 2024/1689; prepare an AI inventory, gap register, implementation roadmap, or counsel briefing;
seb1n/awesome-ai-agent-skills/legal-and-compliance/eu-ai-act-readiness/SKILL.md
Build a preliminary, evidence-based EU AI Act readiness assessment across AI-system inventory, territorial scope, operator roles, prohibited-practice screening, risk classification, transparency, high-risk controls, general-purpose AI obligations, governance, and implementation milestones. Use when an organization needs to triage an AI use case, vendor, model, product, or portfolio for Regulation (EU) 2024/1689; prepare an AI inventory, gap register, implementation roadmap, or counsel briefing;
Decision brief
Produce operational triage, not a legal opinion. The AI Act changes through amendments, delegated/implementing acts, guidance, standards, and national enforcement practice; verify the law and dates at the start of every assessment.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/seb1n/awesome-ai-agent-skills --skill "legal-and-compliance/eu-ai-act-readiness"Inspect the Agent Skill "eu-ai-act-readiness" from https://github.com/seb1n/awesome-ai-agent-skills/blob/75865a5d037a4cdaa7f409a4ec14ab9b0292920b/legal-and-compliance/eu-ai-act-readiness/SKILL.md at commit 75865a5d037a4cdaa7f409a4ec14ab9b0292920b. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
Open current-law-and-sources.md, then check the linked EUR-Lex legislation and European Commission/AI Act Service Desk pages for changes since 2026-08-09. Read Regulation (EU) 2024/1689 together with Regulation (EU) 2026/1744 and any later amendments or consolidated text.
Re-open every cited official source and capture the access date.
Use the blank AI system inventory template when no reliable inventory exists.
1. Assessment date, last-verified legal-source date, jurisdictions, official sources, assumptions, and limitations. 2. An inventory with jurisdiction, system/model version, preliminary EU nexus, operator role, use-case screen, foreseeable misuse, material modifications, automati…
Open current-law-and-sources.md, then check the linked EUR-Lex legislation and European Commission/AI Act Service Desk pages for changes since 2026-08-09. Read Regulation (EU) 2024/1689 together with Regulation (EU) 2026/1744 and any later amendments or consolidated text.
Permission review
The documentation asks the agent to run terminal commands or scripts.
python3 scripts/check_ai_inventory.py assets/ai-system-inventory-template.csv --as-of 2026-08-09 --prettyThe documentation asks the agent to run terminal commands or scripts.
python3 scripts/check_ai_inventory.py /path/to/populated-inventory.csv --as-of YYYY-MM-DD --prettyEvidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 91/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 161 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Produce operational triage, not a legal opinion. The AI Act changes through amendments, delegated/implementing acts, guidance, standards, and national enforcement practice; verify the law and dates at the start of every assessment.
Collect or state:
Use the blank AI system inventory template when no reliable inventory exists.
Return:
Use preliminary, potential, or counsel review required; do not label an organization “compliant,” provide a definitive legal classification, or promise regulator acceptance.
Open current-law-and-sources.md, then check the linked EUR-Lex legislation and European Commission/AI Act Service Desk pages for changes since 2026-08-09. Read Regulation (EU) 2024/1689 together with Regulation (EU) 2026/1744 and any later amendments or consolidated text.
Record the access date and governing language/version. Confirm whether later delegated acts, implementing acts, Commission guidelines, harmonised standards, common specifications, codes, court decisions, or national rules affect the issue. If current official sources cannot be checked, mark the legal timeline stale and stop before making a deadline or classification conclusion.
Determine the relevant EU nexus and role under Articles 2 and 3. Consider EU market placement, EU-based deployment, and outputs used in the EU, as well as exclusions and sector-specific law. Territorial scope and exemptions are legal questions; route uncertainty to counsel.
Create one record per materially distinct system/model/use. Run the bundled completeness checker from this skill directory:
python3 scripts/check_ai_inventory.py assets/ai-system-inventory-template.csv --as-of 2026-08-09 --pretty
python3 scripts/check_ai_inventory.py /path/to/populated-inventory.csv --as-of YYYY-MM-DD --pretty
python3 scripts/check_ai_inventory.py /path/to/populated-inventory.csv --as-of YYYY-MM-DD --output /path/to/check.json --pretty
The checker uses standard-library heuristics, emits no legal classification, and labels its output structural/completeness screening only—not semantic fact verification or legal verification. It reports system IDs, missing fields, invalid controlled-vocabulary values, date issues, age/event status, and keyword-derived signals; it does not copy other source row values. With --output, it refuses inventory aliases and non-regular destinations, then atomically creates or replaces the report via a sibling temporary file. Use its controlled values for article_50_status and counsel_status; manually verify every source fact and signal. Include shadow AI, pilots, employee tools, vendor features, embedded models, legacy systems, and retired systems with continuing effects.
The default 365-day staleness flag is an administrative prompt, not a statutory deadline. Reassess sooner whenever a recorded trigger occurs, including a new use, system/model version, vendor, geography, role, material modification, incident, or legal update. A recent assessment can therefore still be due immediately.
First confirm whether the item is an AI system or GPAI model within the Act's definitions. Screen intended use and foreseeable operation against Article 5, including amendments. If a potential prohibited practice appears, stop routine scoring, preserve evidence, recommend a pause on deployment/expansion, and escalate to qualified counsel and the accountable owner. Do not pause or alter a live system unless the agent has explicit authority to do so. Do not attempt to redesign or conceal the use to evade scope.
Separately identify employment, education, biometrics, critical infrastructure, essential services, law enforcement, migration/border, justice, elections, health/safety, minors, and vulnerable-person contexts. These are escalation signals, not automatic classifications.
For each system, document the facts supporting:
Roles can overlap and can change through rebranding, placing on the market, substantial modification, or changing intended purpose. Do not rely solely on a vendor's label or contract.
Read assessment-checklist.md. Map only duties supported by a preliminary scope/role analysis, and cite the relevant article/annex. At minimum assess:
Use the applicable date from verified current law, not a remembered deadline or an undated checklist.
For each control, request an existing artifact and test whether it covers the exact system, version, role, purpose, jurisdiction, and lifecycle stage. Examples include approved inventory entries, risk records, dataset provenance, evaluation reports, logs, model/system cards, user instructions, human-oversight tests, security evidence, change records, contracts, transparency notices, incident exercises, training records, and decision/appeal procedures.
Mark implemented only when evidence is current and tested. Otherwise use partial, planned, missing, not assessed, or not applicable—basis pending counsel.
Prioritize potential prohibitions, already-applicable duties, live high-impact systems, misleading transparency, missing monitoring, and material incidents. Build a 30/60/90-day plan with accountable owners, dependencies, acceptance evidence, and legal decision gates.
Give counsel a concise fact pattern and explicit questions rather than asking for a generic review. Use exact intended use, role, affected people, dates, change history, and disputed provisions.
If an assessment used stale law, wrong jurisdiction, wrong system version, or an unsupported classification, withdraw the affected conclusion, identify downstream plans/notices/filings that relied on it, preserve the prior report, and issue a dated correction after counsel review. Do not silently rewrite the record. If potential prohibited use or a serious incident emerges, stop further rollout where authorized, preserve evidence, and escalate through the organization's legal and incident-response process.
Request: “Assess our résumé-ranking assistant before EU rollout.”
Document provider/deployer roles and EU nexus, screen Article 5 and Annex III employment use, verify current application dates, map high-risk and transparency evidence, identify human-oversight and worker-notice gaps, and send classification and rollout gates to counsel rather than declaring compliance.
Request: “What must change in our support bot now that Article 50 applies?”
Verify the current Article 50 text and guidance, determine provider/deployer roles and whether users are already clearly informed, test disclosure timing and accessibility, document synthetic-content features separately, and produce evidence requirements plus counsel questions.
Request: “Create a 90-day AI Act readiness plan for our 60 vendor and in-house systems.”
Structurally check the inventory, manually verify its facts, triage urgent/prohibited and already-applicable duties first, group systems by role/use/risk hypothesis, sample evidence, assign owners, and create a risk-based roadmap with legal gates and reassessment triggers.
Frequently asked questions
Produce operational triage, not a legal opinion. The AI Act changes through amendments, delegated/implementing acts, guidance, standards, and national enforcement practice; verify the law and dates at the start of every assessment.
The source record exposes this install command: npx skills add https://github.com/seb1n/awesome-ai-agent-skills --skill "legal-and-compliance/eu-ai-act-readiness". Inspect the command and pinned source before running it.
Static rules flagged exec-script in the source; the page lists the matching lines and excerpts.
Alternatives
garrytan/gbrain
End-to-end discipline for turning any large data source (audio libraries, email takeouts, document corpora, chat exports, API dumps) into brain pages at scale. The lifecycle spine: SCHEMA → ACCESS → TRIAL → EVALUATE → IMPROVE → CODIFY → TEST → SKILLIFY → BULK → MONITOR. State is tracked in a durable JSON manifest (see MANIFEST-PATTERN.md) so any crash, session boundary, or subagent fan-out resumes from ground truth instead of memory.
alirezarezvani/claude-skills
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store. Use when the user asks about ASO, app store rankings, app metadata, app titles and descriptions, app store listings, app visibility, or mobile app marketing on iOS or Android. Supports keyword research and scoring, competitor keyword analysis, metadata optimization, A/B test planning, launch checklist
wanshuiyin/Auto-claude-code-research-in-sleep
Use it for operations and research tasks; the detail page covers purpose, installation, and practical steps.
prowler-cloud/prowler
PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing index usage statistics, reindexing, dropping indexes, or working with partitioned table indexes. Also trigger when discussing index strategies, partial indexes, or index maintenance