eu-ai-act

Classifies AI systems under EU AI Act risk tiers and maps provider and deployer obligations.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill eu-ai-act-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: eu-ai-act
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/eu-ai-act
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill eu-ai-act-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Navigating Regulation (EU) 2024/1689 requires interpreting hundreds of articles, annexes, and shifting deadlines. This Skill turns any AI system description into a structured compliance assessment — risk tier, applicable obligations, and gap analysis — with citations to the governing Article, Annex, or Recital. ## Core Features & Use Cases - Risk Classification: Screens systems against all 9 prohibited practices (Art. 5), the 8 Annex III high-risk areas, the Art. 6(3) exceptions, and the profiling override, with area-by-area misclassification traps. - Obligation Walkthroughs: Covers provider duties (Arts. 9–17), the 10 deployer duties (Art. 26), FRIA requirements (Art. 27), conformity assessment and CE marking (Arts. 43–48), and GPAI model obligations including the Code of Practice (Arts. 51–55). - Timeline & Penalty Guidance: Tracks the confirmed phase-in schedule under the Digital Omnibus (Annex III to Dec 2027, Annex I to Aug 2028) and Art. 99 penalty tiers. - Use Case: A bank deploying a credit-scoring tool asks whether it is high-risk; the Skill applies the Annex III Area 5(b) match, the Art. 6(3) exceptions test, the profiling override, and the Art. 6(4) documentation duty, then lists the deployer's pre-deployment obligations. ## Quick Start Ask the assistant to classify your AI system under the EU AI Act and list the obligations that apply to your role as provider or deployer.

Frequently Asked Questions about eu-ai-act

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I classify an AI system under the EU AI Act?

Classification follows a sequence: confirm the Art. 3(1) AI system definition, screen against the 9 prohibited practices in Art. 5, then determine the risk tier under Art. 6. Annex III-listed systems are high-risk unless a narrow Art. 6(3) exception applies, but any profiling of natural persons overrides those exceptions.

What are the deployer obligations under Article 26 of the EU AI Act?

Article 26 imposes ten duties including following provider instructions, assigning competent human oversight, controlling input data, monitoring and suspending on risk, retaining logs for at least 6 months, notifying workers before deployment, and informing individuals subject to Annex III decisions. Pre-deployment duties must be satisfied before go-live.

When do EU AI Act high-risk obligations take effect?

Under the Digital Omnibus adopted June 29, 2026, Annex III standalone high-risk systems must comply by December 2, 2027, and Annex I embedded product safety components by August 2, 2028. GPAI obligations have been in force since August 2, 2025, and Art. 50 transparency applies from August 2, 2026.

Does the EU AI Act apply to general-purpose AI models?

Yes, GPAI models trained with at least 10^23 FLOPs face Art. 53 obligations including technical documentation, a copyright policy, and a public training summary. Models at or above 10^25 FLOPs are presumed to have systemic risk and face additional Art. 55 duties such as red-teaming and incident reporting to the AI Office.

Who must perform a Fundamental Rights Impact Assessment under Article 27?

A FRIA is required for public-law bodies and private entities providing public services deploying Annex III systems, plus any deployer of credit-scoring systems under point 5(b) or life and health insurance pricing under point 5(c). Results must be notified to the market surveillance authority before the system goes live.

What are the penalties for violating the EU AI Act?

Article 99 sets fines up to 35 million euros or 7 percent of global turnover for prohibited practices, 15 million euros or 3 percent for provider and deployer violations, and 7.5 million euros or 1 percent for misleading information to authorities. For SMEs and startups, the lower of the fixed amount or percentage applies.