eu-ai-act-specialist
alirezarezvani/claude-skills
EU AI法に基づきAIシステムを分類し、適合性評価の手順を決定するとともに、参照用スクリプトおよび各条項で引用されているガイダンスを用いて、役割ごとの義務を追跡します。
...すべて拡張しますEU AI法コンプライアンス・スペシャリスト
規則(EU)2024/1689に規定された運用スキル。3つの決定事項、AI戦略の策定なし:
- このAIシステムはどのティアに該当するか?— 禁止対象(第5条)/高リスク(第6条+附属書III)/限定リスク(透明性要件:第50条)/最小リスク
- 高リスクシステムの場合、適合性評価のルートと必要書類一式は?— 第43条 モジュールA 対 モジュールH + 附属書IVの技術文書
- 組織上の役割ごとに、どのような義務があるか?— 第16条、第22条、第25条、第26条に基づく、プロバイダー/導入者/輸入者/販売業者/認定代理人のマトリックス
このスキルは「最高AI責任者(CAIO)アドバイザー」ではありません。CAIOはAI機能をリリースするかどうかを決定し、ビジネスリスクを受け入れます。このスキルは、「リリースする」という判断を、条項に準拠した成果物へと変換する適合性評価業務を担当します。
このスキルは法的代用となるものではありません。同法は拘束力のある規制です。 新たなケース(これはGPAIモデルか?第6条(2)の適用除外は適用されるか?ファウンデーションモデルの微調整は「実質的な変更」に該当するか?)については、資格のある外部の法律顧問に相談してください。このスキルは条文および附属書を引用し、欧州委員会/EDPBが公表した解釈を利用しますが、法的拘束力のある法的見解を提供するものではありません。
このスキルはGDPRそのものではありません。多くのAIシステムはGDPRの適用対象にもなります(トレーニングデータ、出力処理など)。DPIAおよび法的根拠に関する作業については、ra-qm-team/skills/gdpr-dsgvo-expert/を参照してください。各法令は相互に関連しています(前文第10項、高リスクのトレーニングデータに関する第10条)。
キーワード
EU AI法、EU AI規則、規則2024/1689、AI法、欧州のAI規制、高リスクAI、禁止AI、 AI法第5条、AI法第6条、AI法第9条、AI法第50条、附属書III、附属書IV、適合性評価、AIのCEマーキング、AIの指定機関、モジュールA、モジュールH、 AIの技術文書、AIの市販後監視、基本権影響評価(FRIA)、GPAI、汎用AIモデル、GPAIのシステミックリスク、 AI事務局、ENISA AI、EDPB AI、AI法のタイムライン、AI法の罰則、EU AI法におけるプロバイダー、EU AI法における導入者、EU AI法における輸入業者、EU AI法における販売業者、EU AI法における罰金、AIリテラシー
クイックスタート
# 決定 A:同法に基づく AI システムの分類
python scripts/ai_system_risk_classifier.py # 5 つのシステムを含むサンプル
python scripts/ai_system_risk_classifier.py path/to/systems.json
# 決定事項 B:高リスクシステムに対する適合性評価計画
python scripts/conformity_assessment_planner.py # 高リスクのサンプルが組み込まれています
python scripts/conformity_assessment_planner.py path/to/system.json
# 決定事項 C: 組織の役割ごとの義務トラッカー
python scripts/ai_act_obligation_tracker.py # 組み込みサンプル(プロバイダー + デプロイヤー)
python scripts/ai_act_obligation_tracker.py path/to/roles.json
重要な質問(まずこれらを尋ねてください)
- このAIシステムは第5条(禁止行為)に該当しますか?ソーシャルスコアリング、職場・教育現場での感情認識、操作的なサブリミナル技法、公共の場でのリアルタイム遠隔生体認証——これらはいずれも完全に禁止されています。
- 本システムは附属書III(高リスクカテゴリー)に該当するか?8つのカテゴリー:生体認証、重要インフラ、教育、雇用、必須サービス、法執行、移民、司法。附属書IIIが適用されると、第6条(2)が発動される――ただし、第6条(3)の適用除外が適用される場合は除く。
- 当該企業は組織上どのような役割を果たしていますか?プロバイダー(市場に投入する者)、デプロイヤー(自らの権限で利用する者)、輸入業者(第三国のシステムをEU市場に投入する者)、流通業者(サプライチェーンにおいて提供可能な状態にする者)。多くの企業は、プロバイダーとデプロイヤーの両方の役割を同時に担っています。
- これは汎用AIモデル(GPAI)か?GPAIには独自の枠組み(第51条~第55条)があり、トレーニング演算能力が10²⁵ FLOPsを超える場合、より厳格な規則が適用される(第51条のシステミックリスク)。
- 高リスクの場合:第9条のリスク管理および第27条のFRIA(基本権影響評価)を実施しましたか?第9条はライフサイクルリスク管理、第27条は公共部門の導入者および必須サービスに対する基本権影響評価です。
- 第43条に基づく適合性評価モジュールはどれか?モジュールA(内部統制、附属書IIIのほとんどのシステムで適用可能)対モジュールH(完全な品質管理システム(QMS)+認定機関、生体認証および場合によってはその他のシステムで必須)。
中核的な責任
1. AIシステムのリスク分類
枠組み:本法はリスクベースのアプローチを採用しています(前文第26項)。各AIシステムは、以下の4つの階層のうち、正確に1つに分類されます:
| 階層 | 出典 | 例 | 義務 |
|---|---|---|---|
| 禁止事項 | 第5条 | ソーシャル・スコアリング;職場・教育現場における感情認識;サブリミナル操作;法執行機関によるリアルタイムの公共の場での生体認証(ごく限られた例外を除く) | 市場への投入または使用が禁止される(罰則:最大3,500万ユーロ/売上高の7%) |
| 高リスク | 第6条+附属書III;第6条(1)+附属書I | 履歴書スクリーニング、信用スコアリング、生体認証による分類、規制対象製品の安全部品 | 第8条~第17条(提供者)+第26条(導入者);適合性評価;CEマーキング |
| 限定リスク(透明性) | 第50条 | チャットボット、ディープフェイク、第5条の文脈外における感情認識 | 自然人に対する透明性に関する開示 |
| 最小リスク | デフォルト | スパムフィルター、ビデオゲーム用AI、在庫予測システム | 同法に基づくものなし(自主的な行動規範、第95条) |
重要な適用除外(第6条(3)):附属書IIIに該当するシステムは、以下のいずれかに該当する場合、高リスクとはみなされない:(a) 限定的な手続き的タスクを実行する場合、 (b) 既に完了した人間の活動の結果を改善する場合、(c) 人間の評価に取って代わるのではなく、意思決定のパターンを検出する場合、(d) 準備作業を行う場合。注意:自然人に対するプロファイリングは、適用除外にかかわらず、常に附属書IIIにおける高リスクに分類される。
システムの特性を指定してai_system_risk_classifier.pyを実行してください。このツールは、まず第5条の禁止事項、次に附属書IIIのカテゴリー、さらに第6条(3)の除外規定、続いて第50条の透明性要件、最後にデフォルトの「最小リスク」の順にチェックを行います。
条項ごとの詳細な手順については、references/eu_ai_act_titles.mdを参照してください。
2. 適合性評価 + 附属書IVの技術文書
枠組み(第43条+附属書VI/VII):高リスクAIシステムの場合、提供者は市場投入前に適合性を実証しなければならない。2つの経路がある:
- モジュールA — 内部管理(附属書VI):提供者は要件に基づいて自己評価を行う。提供者が調和規格を実施している附属書IIIのシステムの大部分に適用される。
- モジュールH — 完全な品質マネジメントシステム+技術文書(附属書VII):認定機関の関与を要する。生体認証システムにはこれが必須となる(第43条(1))。
附属書IVに基づく必須成果物 — 技術文書:
- AIシステムの概要(使用目的、識別情報、バージョン)
- システム構成要素の詳細な説明(アーキテクチャ、学習データ、検証手順)
- 監視、機能、および制御に関する情報
- リスク管理システムの説明(第9条)
- 市場投入後の変更に関する説明
- 適用された(または代替の)調和規格の一覧
- EU適合宣言(第47条)
- 市販後監視システムの説明(第72条)
conformity_assessment_planner.pyを実行してモジュールを選択し、特定のハイリスクシステムに対する附属書IVのチェックリストを作成します。
どのシステムにどの適合ルートが必要かは、references/high_risk_systems_annex_iii.md を参照してください。
3. 役割別義務トラッカー
枠組み(第16条、第22条、第23条、第24条、第25条、第26条):本法は、提供者の義務(大部分)と、下流の関係者(導入者、輸入業者、販売業者、授権代理人)の義務とを区別しています。1つの企業が同時に複数の役割を担う可能性があります。
| 役割 | 主な条項 | 主な義務 |
|---|---|---|
| 供給者(第3条第3項) | 第8条~第17条、第47条、第49条、第72条 | 適合性評価、CEマーキング、リスク管理、データガバナンス、技術文書、市販後監視、重大なインシデントの報告(第73条) |
| 導入者(第3条(4)) | 26 | 取扱説明書に基づく使用;人的監督;入力データの品質;記録の保持(第19条);労働者への周知(第26条(7));公共部門/重要サービスの場合はFRIA(第27条) |
| 輸入者(第3条(6)) | 23 | 適合性の確認;CEマーキングの表示;技術文書の入手可能性 |
| 販売業者(第3条(7)) | 24 | 市場に提供する前に、CEマーキングおよび技術文書の確認を行うこと |
| 認定代理人(第22条) | 22 | EU域外の提供者は、1名を指名しなければならない。代理人は提供者の義務を負う |
重要:第25条に基づき、高リスクAIシステムに大幅な変更を加える者、または自己の名義で市場に投入する者は、提供者となり、提供者の義務を引き継ぐ。
役割のJSONデータと共にai_act_obligation_tracker.pyを実行すると、期限順に並べられた義務マトリックスが生成されます。
GPAI第51条~第55条に関する個別の追跡については、references/gpai_obligations.mdを参照してください。
ワークフロー
ワークフロー 1:AI システムの初期審査(システムごとに約 2 時間)
目標:分類、義務の特定、適合性確保作業の範囲設定。
# 1. システムの特性(目的、ユーザー、データ、自律性、導入環境)を文書化する
# 2. 分類器を実行する
python scripts/ai_system_risk_classifier.py systems.json
# 3. 高リスクの場合:プランナーを実行
python scripts/conformity_assessment_planner.py system.json
# 4. 組織が担う役割を特定(プロバイダー/デプロイヤー/両方)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. 個人データが含まれる場合は、GDPR DPIA(gdpr-dsgvo-expert)と照合
# 6. ISO 42001 AIMSの証拠(compliance-team-iso42001)と照合
# 7. 出力:分類メモ + 適合性計画 + 義務リスト
ワークフロー 2:附属書 IV 技術文書の作成(高リスクシステムごとに、2~4週間)
目標:適合性評価の前に附属書IVの資料一式をまとめる。
# 1. 適合性評価プランナーを実行してチェックリストを取得する
python scripts/conformity_assessment_planner.py system.json
# 2. 以下の資料をまとめる:システム説明、アーキテクチャ、トレーニングデータ、検証、リスク管理
# 3. 附属書IVの項目を満たす部分については、ISO 42001の証拠を参照する
# 4. セキュリティ対策については、ISO 27001の証拠を参照する
# 5. 第9条のリスク管理ライフサイクルを実行する
# 6. 評価に合格した後、EU適合宣言(第47条)に署名する
# 7. CEマーキングを付与する(第48条)
# 8. EUデータベースに登録する(第71条) — 高リスクの附属書III対象システム
ワークフロー3:導入前の義務監査(システムごと、立ち上げ前)
目的:EU市場への投入前に、すべての有効な義務が履行されていることを確認する。
# 1. 分類が依然として正しいことを確認する(システムに変更があった場合は分類器を再実行する)
# 2. 適合性評価が完了していることを確認する(高リスクの場合)
# 3. 透明性要件(第50条)を確認する — チャットボット、ディープフェイク、感情検出について
# 4. 市販後監視システム(第72条)が稼働していることを確認する
# 5. 重大なインシデントの報告手順(第73条)が文書化されていることを確認する
# 6. 導入事業者向け:FRIAの実施(第27条、該当する場合);従業員への周知(第26条(7))
# 7. GPAI向け:該当する場合、第51条~第55条の義務を履行していること
ワークフロー 4:年次コンプライアンス更新(組織ごと、年1回)
目的:同法の段階的施行に伴い、分類および義務を再確認する。
- EU市場に投入済み、または投入予定のすべてのAIシステムをリストアップする
- 各システムについて分類処理を実行する — 第5条の禁止リストは委任法令により拡大される可能性がある
- 義務追跡ツールを実行する — 第III編の段階的導入に伴い、期限が変更される(2025年 → 2026年 → 2027年)
- 各高リスクシステムについて:市販後のモニタリングにおけるデータフローおよび重大なインシデントの報告体制を確認する
- 第11条の継続的要件に基づき、附属書IVの技術文書を更新する
- 両方が運用されている場合は、ISO 42001の管理レビュー(9.3条)と連携させる
出力基準
**要点:** [1文 — 分類 + 最も重要な義務]
**条文の引用:** [条項 + 段落番号;出典を明記せずに言い換えないこと]
**決定事項:** [以下のいずれか:分類 | 適合性ルート | 義務の範囲]
**根拠:** [条項+附属書の参照先;分類の信頼度]
**対応方法:** [責任者との具体的な次の3つのステップ+フェーズに合わせた期限]
**ご判断:** [コンプライアンス担当者または法務顧問への相談が必要となる場合 — リスク分類に関する紛争、前例のない事例、GPAIの閾値判定]
関連スキル
ra-qm-team/skills/gdpr-dsgvo-expert/— GDPR DPIA および法的根拠(ほとんどの AI システムも GDPR の適用対象となる)ra-qm-team/compliance-team-iso42001/— ISO 42001 AIMS(プロバイダー向けの第17条QMSの一部を満たす自主的なマネジメントシステム)ra-qm-team/skills/information-security-manager-iso27001/— サイバーセキュリティ要件(第15条)に関するISO 27001ra-qm-team/skills/risk-management-specialist/— ISO 14971 リスク管理(第6条(1)に基づく安全コンポーネントAIの参照基準)ra-qm-team/skills/mdr-745-specialist/— MDR 2017/745(医療機器AIとの重複部分)compliance-os/— マルチフレームワーク・プログラムのためのメタ・オーケストレーターc-level-advisor/chief-ai-officer-advisor/— 経営層向けAI戦略
参考文献
- eu_ai_act_titles.md — 第I章~第XII章の条項ごとの解説(導入者/提供者/輸入者/販売業者の義務の内訳を含む
- high_risk_systems_annex_iii.md — 附属書IIIの8つのカテゴリーの詳細+第6条(2)~(3)との相互関係+適用除外判定
- gpai_obligations.md — 第51条~第55条のGPAI関連事項+システミックリスクの閾値+透明性に関する規則+行動規範の現状
- cross_framework_mapping_ai_act.md — AI法 ↔ ISO 42001 ↔ NIST AI RMF ↔ GDPR 制御レベル間の対応表
バージョン:1.0.0 ステータス:本番環境対応
---
name: eu-ai-act-specialist
description: Classify AI systems under the EU AI Act, determine conformity assessment routes, and track per-role obligations using reference scripts and Article-cited guidance.
license: MIT
---
# EU AI Act Compliance Specialist
Article-cited operational skill for Regulation (EU) 2024/1689. **Three decisions, no executive AI strategy:**
1. **What tier is this AI system?** — prohibited (Article 5) / high-risk (Article 6 + Annex III) / limited-risk transparency (Article 50) / minimal-risk
2. **For high-risk systems, what's the conformity assessment route + documentation pack?** — Article 43 Module A vs Module H + Annex IV technical documentation
3. **Per organizational role, what are the obligations?** — provider / deployer / importer / distributor / authorized representative matrix per Article 16, 22, 25, 26
This skill is **NOT chief-ai-officer-advisor**. CAIO decides whether to ship the AI feature at all and accepts business risk. This skill operates the conformity work that turns "we'll ship it" into Article-compliant artefacts.
This skill is **NOT a legal substitute**. The Act is binding regulation. For novel cases (Is this a GPAI model? Does Article 6(2) carve-out apply? Is fine-tuning a foundation model "substantial modification"?), engage qualified outside counsel. The skill cites Articles + Annexes and uses Commission/EDPB published interpretation but does not provide binding legal opinion.
This skill is **NOT GDPR**. Many AI systems also trigger GDPR (training data, output processing). See `ra-qm-team/skills/gdpr-dsgvo-expert/` for DPIA + lawful basis work. The Acts interact (Recital 10, Article 10 for high-risk training data).
## Keywords
EU AI Act, EU AI Regulation, Regulation 2024/1689, AI Act, AI regulation Europe, high-risk AI, prohibited AI, Article 5 AI Act, Article 6 AI Act, Article 9 AI Act, Article 50 AI Act, Annex III, Annex IV, conformity assessment, CE marking AI, notified body AI, Module A, Module H, technical documentation AI, post-market monitoring AI, fundamental rights impact assessment, FRIA, GPAI, general-purpose AI model, systemic risk GPAI, AI Office, ENISA AI, EDPB AI, AI Act timeline, AI Act penalties, EU AI Act provider, EU AI Act deployer, EU AI Act importer, EU AI Act distributor, EU AI Act fines, AI literacy
## Quick Start
```bash
# Decision A: Classify an AI system per the Act
python scripts/ai_system_risk_classifier.py # embedded 5-system sample
python scripts/ai_system_risk_classifier.py path/to/systems.json
# Decision B: Conformity assessment plan for a high-risk system
python scripts/conformity_assessment_planner.py # embedded high-risk sample
python scripts/conformity_assessment_planner.py path/to/system.json
# Decision C: Obligation tracker per organizational role
python scripts/ai_act_obligation_tracker.py # embedded sample (provider + deployer)
python scripts/ai_act_obligation_tracker.py path/to/roles.json
```
## Key Questions (ask these first)
- **Does this AI system fall under Article 5 (prohibited practices)?** Social scoring, emotion recognition in workplace/education, manipulative subliminal techniques, real-time remote biometric identification in public — any of these are flat-out prohibited.
- **Does it fall under Annex III (high-risk categories)?** 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Triggering Annex III triggers Article 6(2) — unless the Article 6(3) carve-outs apply.
- **What organizational role does the company play?** Provider (placed on market), deployer (uses under own authority), importer (places third-country system on EU market), distributor (makes available in supply chain). Many companies are BOTH provider AND deployer simultaneously.
- **Is this a general-purpose AI model?** GPAI has its own track (Articles 51–55) with stricter rules above 10²⁵ FLOPs training compute (Article 51 systemic risk).
- **For high-risk: have we run Article 9 risk management AND Article 27 FRIA?** Article 9 is the lifecycle risk management; Article 27 is the Fundamental Rights Impact Assessment for public-sector deployers + essential services.
- **What's the conformity assessment Module per Article 43?** Module A (internal control, possible for most Annex III systems) vs Module H (full QMS + notified body, required for biometrics + sometimes others).
## Core Responsibilities
### 1. AI System Risk Classification
**The framework:** The Act takes a risk-based approach (Recital 26). Each AI system falls into exactly one of four tiers:
| Tier | Source | Examples | Obligations |
|---|---|---|---|
| **Prohibited** | Article 5 | Social scoring; emotion recognition in workplace/education; subliminal manipulation; real-time public biometrics by law enforcement (with narrow exceptions) | Cannot be placed on market or used (penalties up to EUR 35M / 7% turnover) |
| **High-risk** | Article 6 + Annex III; Article 6(1) + Annex I | CV-screening, credit scoring, biometric categorisation, safety components of regulated products | Articles 8–17 (provider) + Article 26 (deployer); conformity assessment; CE marking |
| **Limited-risk (transparency)** | Article 50 | Chatbots, deepfakes, emotion recognition outside Article 5 contexts | Transparency disclosures to natural persons |
| **Minimal-risk** | Default | Spam filters, video-game AI, inventory forecasters | None under the Act (voluntary codes of conduct, Article 95) |
**Critical carve-outs (Article 6(3)):** an Annex III system is NOT high-risk if it (a) performs a narrow procedural task, (b) improves the result of previously completed human activity, (c) detects decision-making patterns without replacing human assessment, (d) performs a preparatory task. Caveat: profiling of natural persons is always Annex III high-risk regardless of carve-outs.
**Run** `ai_system_risk_classifier.py` with system characteristics. The tool checks Article 5 prohibitions first, then Annex III categories, then Article 6(3) carve-outs, then Article 50 transparency, then minimal-risk default.
See `references/eu_ai_act_titles.md` for the full Article-by-Article walkthrough.
### 2. Conformity Assessment + Annex IV Technical Documentation
**The framework (Article 43 + Annex VI/VII):** for high-risk AI systems, the provider must demonstrate conformity before placing on market. Two routes:
- **Module A — Internal control** (Annex VI): provider self-assesses against the requirements. Applies to most Annex III systems where the provider has implemented harmonised standards.
- **Module H — Full quality management system + technical documentation** (Annex VII): notified body involvement. Required for biometrics systems (Article 43(1)).
**Required artifacts per Annex IV — Technical Documentation:**
1. General description of the AI system (intended purpose, identification, version)
2. Detailed description of system elements (architecture, training data, validation procedures)
3. Information about monitoring, functioning and control
4. Description of risk management system (Article 9)
5. Description of changes after placing on market
6. List of harmonised standards applied (or alternative)
7. EU declaration of conformity (Article 47)
8. Description of the post-market monitoring system (Article 72)
**Run** `conformity_assessment_planner.py` to select the Module and produce the Annex IV checklist for a given high-risk system.
See `references/high_risk_systems_annex_iii.md` for which systems require which conformity route.
### 3. Per-Role Obligation Tracker
**The framework (Articles 16, 22, 23, 24, 25, 26):** the Act distinguishes provider obligations (most) from downstream-actor obligations (deployer, importer, distributor, authorized representative). A single company can play multiple roles simultaneously.
| Role | Primary Articles | Key obligations |
|---|---|---|
| **Provider** (Article 3(3)) | 8–17, 47, 49, 72 | Conformity assessment; CE marking; risk management; data governance; technical documentation; post-market monitoring; serious incident reporting (Article 73) |
| **Deployer** (Article 3(4)) | 26 | Use according to instructions; human oversight; input data quality; record-keeping (Article 19); inform workers (Article 26(7)); FRIA if public-sector/essential-services (Article 27) |
| **Importer** (Article 3(6)) | 23 | Verify conformity; affixed CE marking; technical documentation availability |
| **Distributor** (Article 3(7)) | 24 | Verify CE marking + documentation before making available |
| **Authorized representative** (Article 22) | 22 | Non-EU providers must appoint one; representative liable for provider obligations |
**Important:** under Article 25, a deployer who substantially modifies a high-risk AI system, or places it on the market under their own name, becomes a **provider** and inherits provider obligations.
**Run** `ai_act_obligation_tracker.py` with the roles JSON to produce a deadline-sorted obligation matrix.
See `references/gpai_obligations.md` for the separate GPAI Articles 51–55 track.
## Workflows
### Workflow 1: AI System Intake Review (per system, ~2 hours)
**Goal:** classify, identify obligations, scope the conformity work.
```bash
# 1. Document system characteristics: purpose, users, data, autonomy, deployment context
# 2. Run classifier
python scripts/ai_system_risk_classifier.py systems.json
# 3. If high-risk: run planner
python scripts/conformity_assessment_planner.py system.json
# 4. Identify org roles played (provider / deployer / both)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. Cross-check with GDPR DPIA (gdpr-dsgvo-expert) if personal data
# 6. Cross-check with ISO 42001 AIMS evidence (compliance-team-iso42001)
# 7. Output: classification memo + conformity plan + obligation list
```
### Workflow 2: Annex IV Technical Documentation Build (per high-risk system, 2–4 weeks)
**Goal:** assemble the Annex IV pack before conformity assessment.
```bash
# 1. Run conformity assessment planner to get the checklist
python scripts/conformity_assessment_planner.py system.json
# 2. Assemble: system description, architecture, training data, validation, risk management
# 3. Reference ISO 42001 evidence where it satisfies Annex IV items
# 4. Reference ISO 27001 evidence for security controls
# 5. Run Article 9 risk management lifecycle
# 6. Sign EU declaration of conformity (Article 47) AFTER assessment passes
# 7. Affix CE marking (Article 48)
# 8. Register in EU database (Article 71) — high-risk Annex III systems
```
### Workflow 3: Pre-Deployment Obligation Audit (per system, before launch)
**Goal:** confirm all active obligations are in place before EU placement.
```bash
# 1. Confirm classification still correct (re-run classifier if system changed)
# 2. Confirm conformity assessment completed (if high-risk)
# 3. Confirm transparency requirements (Article 50) — for chatbots, deepfakes, emotion detection
# 4. Confirm post-market monitoring system (Article 72) is live
# 5. Confirm serious-incident reporting procedure (Article 73) is documented
# 6. For deployers: FRIA done (Article 27, if applicable); workers informed (Article 26(7))
# 7. For GPAI: Articles 51-55 obligations met if applicable
```
### Workflow 4: Annual Compliance Refresh (per organization, yearly)
**Goal:** re-verify classifications + obligations as the Act phases in.
1. List all AI systems on or planned for EU market
2. Run classifier for each — Article 5 prohibited list may expand via delegated acts
3. Run obligation tracker — deadlines shift as Title III phases in (2025 → 2026 → 2027)
4. For each high-risk system: verify post-market monitoring data flow + serious incident reporting capacity
5. Update Annex IV technical documentation per Article 11 ongoing requirement
6. Pair with ISO 42001 management review (Clause 9.3) if both operate
## Output Standards
```
**Bottom Line:** [one sentence — classification + most-significant obligation]
**Article Citation:** [Article + paragraph number; do not paraphrase without cite]
**The Decision:** [one of: classify | conformity-route | obligation-scope]
**The Evidence:** [Article + Annex references; classification confidence]
**How to Act:** [3 concrete next steps with owner + deadline aligned to phasing]
**Your Decision:** [the call for compliance officer or legal counsel — risk-class disputes, novel cases, GPAI threshold determinations]
```
## Adjacent Skills
- `ra-qm-team/skills/gdpr-dsgvo-expert/` — GDPR DPIA + lawful basis (most AI systems also trigger GDPR)
- `ra-qm-team/compliance-team-iso42001/` — ISO 42001 AIMS (voluntary management system that satisfies parts of Article 17 QMS for providers)
- `ra-qm-team/skills/information-security-manager-iso27001/` — ISO 27001 for cybersecurity requirements (Article 15)
- `ra-qm-team/skills/risk-management-specialist/` — ISO 14971 risk management (referenced for safety-component AI under Article 6(1))
- `ra-qm-team/skills/mdr-745-specialist/` — MDR 2017/745 (medical-device AI overlap)
- `compliance-os/` — Meta-orchestrator for multi-framework programs
- `c-level-advisor/chief-ai-officer-advisor/` — Executive AI strategy
## References
- [eu_ai_act_titles.md](references/eu_ai_act_titles.md) — Titles I–XII Article-by-Article walkthrough with deployer/provider/importer/distributor obligation breakdown
- [high_risk_systems_annex_iii.md](references/high_risk_systems_annex_iii.md) — Annex III 8 categories detailed + Article 6(2)–(3) interaction + carve-out test
- [gpai_obligations.md](references/gpai_obligations.md) — Articles 51–55 GPAI track + systemic-risk threshold + transparency rules + Code of Practice status
- [cross_framework_mapping_ai_act.md](references/cross_framework_mapping_ai_act.md) — AI Act ↔ ISO 42001 ↔ NIST AI RMF ↔ GDPR control-level mapping
---
**Version:** 1.0.0
**Status:** Production Ready
すべてのファイル
0件のファイルeu-ai-act-specialistをインストール
スキルファイルをダウンロードし、.claude/skills/ ディレクトリに解凍してください。
ZIPをダウンロードリポジトリをクローンし、スキルファイルをプロジェクトにコピーしてください。
git clone https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/eu-ai-act-specialist # Copy SKILL.md to your .claude/skills/ directory
コピー





家
