eu-ai-act-specialist
alirezarezvani/claude-skills
EU AI법에 따라 AI 시스템을 분류하고, 적합성 평가 절차를 결정하며, 참조 스크립트와 조항별 지침을 활용하여 역할별 의무를 추적합니다.
...모든 것을 확장하십시오EU AI법 준수 전문가
규정 (EU) 2024/1689에 명시된 실무 역량. 세 가지 결정, AI 실행 전략 부재:
- 이 AI 시스템은 어떤 등급에 해당하나요? — 금지 대상(제5조) / 고위험(제6조 + 부속서 III) / 제한적 위험 투명성(제50조) / 최소 위험
- 고위험 시스템의 경우, 적합성 평가 절차 및 문서 패키지는 무엇인가? — 제43조 모듈 A 대 모듈 H + 부속서 IV 기술 문서
- 조직 내 역할별로 의무 사항은 무엇인가? — 제16조, 제22조, 제25조, 제26조에 따른 공급자 / 배포자 / 수입자 / 유통업자 / 권한을 위임받은 대리인 매트릭스
이 직무는 최고 AI 책임자(CAIO) 자문 역할이 아닙니다. CAIO는 AI 기능을 출시할지 여부를 결정하고 비즈니스 위험을 감수합니다. 이 직무는 “출시하겠다”는 결정을 조항을 준수하는 결과물로 전환하는 적합성 평가 업무를 수행합니다.
이 스킬은 법적 대안이 아닙니다. 해당 법은 구속력 있는 규정입니다. 새로운 사례(이것이 GPAI 모델인가? 제6조(2)의 예외 조항이 적용되는가? 파운데이션 모델의 파인 튜닝이 “실질적인 수정”에 해당하는가?)의 경우, 자격을 갖춘 외부 변호사와 협의하십시오. 이 스킬은 조문 및 부속서를 인용하고 유럽집행위원회/EDPB가 발표한 해석을 활용하지만, 구속력 있는 법적 견해를 제공하지는 않습니다.
이 스킬은 GDPR 그 자체가 아닙니다. 많은 AI 시스템은 GDPR의 적용 대상이기도 합니다(훈련 데이터, 출력 처리 등). DPIA 및 합법적 근거 관련 업무는 ra-qm-team/skills/gdpr-dsgvo-expert/를 참조하십시오. 관련 법률들은 상호 연관되어 있습니다(고위험 훈련 데이터에 대한 서문 10, 제10조).
키워드
EU AI법, EU AI 규정, 규정 2024/1689, AI법, 유럽 AI 규정, 고위험 AI, 금지된 AI, AI법 제5조, AI법 제6조, AI법 제9조, AI법 제50조, 부속서 III, 부속서 IV, 적합성 평가, AI CE 마킹, AI 지정 기관, 모듈 A, 모듈 H, AI 기술 문서, AI 시판 후 모니터링, 기본권 영향 평가(FRIA), GPAI, 범용 AI 모델, GPAI의 시스템적 위험, AI 사무국, ENISA AI, EDPB AI, AI법 시행 일정, AI법 제재, EU AI법 제공자, EU AI법 배포자, EU AI법 수입업자, EU AI법 유통업자, EU AI법 과징금, AI 리터러시
빠른 시작
# 결정 A: 법에 따라 AI 시스템 분류하기
python scripts/ai_system_risk_classifier.py # 5개 시스템 샘플 포함
python scripts/ai_system_risk_classifier.py path/to/systems.json
# 결정 B: 고위험 시스템에 대한 적합성 평가 계획
python scripts/conformity_assessment_planner.py # 포함된 고위험 샘플
python scripts/conformity_assessment_planner.py system.json의 경로
# 결정 C: 조직 역할별 의무 추적기
python scripts/ai_act_obligation_tracker.py # 포함된 예제 (제공자 + 배포자)
python scripts/ai_act_obligation_tracker.py path/to/roles.json
핵심 질문 (가장 먼저 물어봐야 할 사항)
- 이 AI 시스템이 제5조(금지된 관행)에 해당합니까? 사회적 점수 부여, 직장/교육 환경에서의 감정 인식, 조작적인 잠재의식 기법, 공공장소에서의 실시간 원격 생체 인식 — 이 중 어느 하나라도 명백히 금지됩니다.
- 이 시스템이 부속서 III(고위험 범주)에 해당합니까? 8가지 범주: 생체 인식, 중요 인프라, 교육, 고용, 필수 서비스, 법 집행, 이민, 사법. 부속서 III가 적용되면 제6조(2)가 발동됩니다 — 단, 제6조(3)의 예외 조항이 적용되는 경우는 제외됩니다.
- 해당 기업은 조직 내에서 어떤 역할을 수행합니까? 공급자(시장에 출시), 운영자(자체 권한 하에 사용), 수입업자(제3국 시스템을 EU 시장에 출시), 유통업자(공급망 내에서 제공)가 있습니다. 많은 기업이 공급자와 운영자 역할을 동시에 수행합니다.
- 이 모델은 범용 AI 모델( GPAI)입니까? GPAI는 별도의 규정(제51조~제55조)이 적용되며, 훈련 연산량이 10²⁵ FLOPs를 초과할 경우 더 엄격한 규칙이 적용됩니다(제51조 시스템적 위험).
- 고위험 시스템의 경우: 제9조에 따른 위험 관리와 제27조에 따른 기본권 영향평가(FRIA)를 모두 수행했습니까? 제9조는 수명 주기 위험 관리이며, 제27조는 공공 부문 운영자 및 필수 서비스에 대한 기본권 영향 평가입니다.
- 제43조에 따른 적합성 평가 모듈은 무엇입니까? 모듈 A(내부 통제, 대부분의 부속서 III 시스템에 적용 가능) 대 모듈 H(전체 QMS + 지정 기관, 생체 인식 및 경우에 따라 기타 시스템에 필수).
핵심 책임
1. AI 시스템 위험 분류
기본 틀: 이 법은 위험 기반 접근 방식을 채택합니다(서문 26항). 각 AI 시스템은 다음 네 단계 중 정확히 하나에 속합니다:
| 등급 | 출처 | 예시 | 의무 |
|---|---|---|---|
| 금지 사항 | 제5조 | 사회적 평가; 직장/교육 현장에서의 감정 인식; 잠재의식 조작; 법 집행 기관에 의한 실시간 공개 생체 인식 (극히 제한된 예외 사항 제외) | 시장에 출시하거나 사용할 수 없음(최대 3,500만 유로 또는 매출액의 7%에 해당하는 벌금) |
| 고위험 | 제6조 + 부속서 III; 제6조(1) + 부속서 I | 이력서 심사, 신용 점수 산정, 생체 인식 분류, 규제 대상 제품의 안전 구성 요소 | 제8조~제17조(제공자) + 제26조(배포자); 적합성 평가; CE 마킹 |
| 제한적 위험 (투명성) | 제50조 | 챗봇, 딥페이크, 제5조 적용 범위를 벗어난 감정 인식 | 자연인에 대한 투명성 공개 |
| 최소 위험 | 기본값 | 스팸 필터, 비디오 게임 AI, 재고 예측 시스템 | 법상 해당 사항 없음(자발적 행동 강령, 제95조) |
중대한 예외 사항(제6조(3)): 부속서 III에 해당하는 시스템은 다음의 경우 고위험으로 간주되지 않습니다. (a) 제한된 절차적 업무를 수행하는 경우, (b) 이전에 완료된 인간의 활동 결과를 개선하는 경우, (c) 인간의 평가를 대체하지 않고 의사결정 패턴을 탐지하는 경우, (d) 준비 작업을 수행하는 경우. 주의사항: 자연인에 대한 프로파일링은 예외 조항과 관계없이 항상 부속서 III의 고위험으로 분류됩니다.
시스템 특성을 입력하여 ai_system_risk_classifier.py를실행하십시오. 이 도구는 먼저 제5조의 금지 사항을 확인한 다음, 부속서 III의 범주, 제6조(3)의 예외 규정, 제50조의 투명성 요건, 마지막으로 최소 위험 기본 설정을 순서대로 확인합니다.
조항별 전체 안내 절차는 references/eu_ai_act_titles.md를 참조하십시오.
2. 적합성 평가 + 부속서 IV 기술 문서
프레임워크(제43조 + 부속서 VI/VII): 고위험 AI 시스템의 경우, 공급자는 시판 전에 적합성을 입증해야 합니다. 두 가지 경로가 있습니다:
- 모듈 A — 내부 통제 (부속서 VI): 공급자가 요구 사항에 따라 자체 평가합니다. 공급자가 조화 표준을 이행한 대부분의 부속서 III 시스템에 적용됩니다.
- 모듈 H — 완전한 품질 관리 시스템 + 기술 문서 (부속서 VII): 지정 기관의 참여가 필요합니다. 생체 인식 시스템에 필수적입니다(제43조(1)).
부속서 IV — 기술 문서에 따라 요구되는 자료:
- AI 시스템에 대한 일반적 설명(용도, 식별 정보, 버전)
- 시스템 구성 요소에 대한 상세 설명(아키텍처, 훈련 데이터, 검증 절차)
- 모니터링, 작동 및 제어에 관한 정보
- 위험 관리 시스템에 대한 설명(제9조)
- 시장 출시 후 변경 사항에 대한 설명
- 적용된 조화 표준 목록(또는 대체 표준)
- EU 적합성 선언(제47조)
- 시판 후 모니터링 시스템에 대한 설명 (제72조)
conformity_assessment_planner.py를실행하여 모듈을 선택하고, 주어진 고위험 시스템에 대한 부속서 IV 체크리스트를 생성하십시오.
어떤 시스템에 어떤 적합성 평가 경로가 필요한지는 references/high_risk_systems_annex_iii.md를 참조하십시오.
3. 역할별 의무 추적기
기본 틀(제16조, 제22조, 제23조, 제24조, 제25조, 제26조): 이 법은 공급자(대부분)의 의무와 하류 주체(배포자, 수입업자, 유통업자, 권한을 위임받은 대리인)의 의무를 구분합니다. 한 회사가 동시에 여러 역할을 수행할 수 있습니다.
| 역할 | 주요 조항 | 주요 의무 |
|---|---|---|
| 공급자 (제3조 제3항) | 제8조~제17조, 제47조, 제49조, 제72조 | 적합성 평가; CE 마킹; 위험 관리; 데이터 거버넌스; 기술 문서; 시판 후 모니터링; 중대한 사고 보고(제73조) |
| 배치자 (제3조 제4항) | 26 | 지침에 따른 사용; 인적 감독; 입력 데이터 품질; 기록 보관(제19조); 근로자 알림(제26조(7)); 공공 부문/필수 서비스인 경우 FRIA(제27조) |
| 수입업자 (제3조 제6항) | 23 | 적합성 검증; CE 마크 부착; 기술 문서 제공 |
| 유통업자 (제3조(7)) | 24 | 시판 전 CE 마킹 및 기술 문서 확인 |
| 지정 대리인 (제22조) | 22 | 비EU 공급자는 대리인을 1명 지정해야 하며, 대리인은 공급자의 의무를 이행할 책임이 있음 |
중요: 제25조에 따라, 고위험 AI 시스템을 실질적으로 수정하거나 자신의 이름으로 시장에 출시하는 배포자는 공급자가 되며, 공급자의 의무를 승계합니다.
역할 JSON 파일과 함께 ai_act_obligation_tracker.py를실행하여 마감일 순으로 정렬된 의무 매트릭스를 생성하십시오.
별도의 GPAI 제51조~제55조 관련 내용은 references/gpai_obligations.md를 참조하십시오.
워크플로우
워크플로우 1: AI 시스템 접수 검토 (시스템당, 약 2시간)
목표: 분류, 의무 사항 파악, 적합성 작업 범위 설정.
# 1. 시스템 특성 문서화: 목적, 사용자, 데이터, 자율성, 배포 환경
# 2. 분류기 실행
python scripts/ai_system_risk_classifier.py systems.json
# 3. 고위험인 경우: 플래너 실행
python scripts/conformity_assessment_planner.py system.json
# 4. 수행하는 조직 역할 파악 (제공자 / 배포자 / 둘 다)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. 개인 데이터인 경우 GDPR DPIA(gdpr-dsgvo-expert)와 교차 확인
# 6. ISO 42001 AIMS 증거(compliance-team-iso42001)와 교차 확인
# 7. 결과물: 분류 메모 + 적합성 계획 + 의무 목록
워크플로우 2: 부속서 IV 기술 문서 작성 (고위험 시스템당 2~4주 소요)
목표: 적합성 평가 전에 부속서 IV 문서 모음을 구성합니다.
# 1. 적합성 평가 플래너를 실행하여 체크리스트 확보
python scripts/conformity_assessment_planner.py system.json
# 2. 다음 항목 구성: 시스템 설명, 아키텍처, 훈련 데이터, 검증, 위험 관리
# 3. 부속서 IV 항목을 충족하는 경우 ISO 42001 증거 자료 참조
# 4. 보안 통제에 대해서는 ISO 27001 증거 자료 참조
# 5. 제9조 위험 관리 라이프사이클 실행
# 6. 평가 통과 후 EU 적합성 선언서(제47조)에 서명
# 7. CE 마크 부착(제48조)
# 8. EU 데이터베이스에 등록(제71조) — 고위험 부속서 III 시스템
워크플로우 3: 배포 전 의무 감사(시스템별, 출시 전)
목표: EU 내 유통 전 모든 유효한 의무 사항이 이행되었는지 확인.
# 1. 분류가 여전히 정확한지 확인 (시스템이 변경된 경우 분류기를 재실행)
# 2. 적합성 평가 완료 여부 확인 (고위험인 경우)
# 3. 투명성 요건(제50조) 확인 — 챗봇, 딥페이크, 감정 감지 기능의 경우
# 4. 시판 후 모니터링 시스템(제72조)이 가동 중인지 확인
# 5. 중대 사고 보고 절차(제73조)가 문서화되었는지 확인
# 6. 배포자의 경우: FRIA 완료(제27조, 해당되는 경우); 근로자 통지(제26조(7))
# 7. GPAI의 경우: 해당되는 경우 제51조~제55조의 의무 이행
워크플로우 4: 연간 규정 준수 재확인 (조직별, 매년)
목표: 법이 단계적으로 시행됨에 따라 분류 및 의무 사항 재확인.
- EU 시장에 출시되었거나 출시 예정인 모든 AI 시스템을 나열
- 각 시스템에 대해 분류기를 실행 — 위임법령을 통해 제5조에 명시된 금지 목록이 확대될 수 있음
- 의무 추적기를 실행 — 제3편의 단계적 시행에 따라 마감일이 변경됨(2025년 → 2026년 → 2027년)
- 각 고위험 시스템에 대해: 시판 후 모니터링 데이터 흐름 및 중대 사고 보고 역량을 검증
- 제11조에 따른 부속서 IV 기술 문서를 지속적으로 업데이트
- 두 가지가 모두 운영되는 경우, ISO 42001 경영 검토(9.3조)와 연계
출력 기준
**결론:** [한 문장 — 분류 + 가장 중요한 의무]
**조항 인용:** [조항 + 단락 번호; 인용 없이 의역하지 말 것]
**결정:** [다음 중 하나: 분류 | 적합성 경로 | 의무 범위]
**근거:** [조항 + 부속서 참조; 분류 신뢰도]
**조치 방법:** [책임자와 협의한 3가지 구체적인 후속 조치 + 단계별 일정에 맞춘 마감일]
**귀하의 결정:** [준법 담당자 또는 법률 고문과 상의해야 할 사항 — 위험 등급 관련 분쟁, 새로운 사례, GPAI 기준치 결정]
관련 역량
ra-qm-team/skills/gdpr-dsgvo-expert/— GDPR DPIA + 법적 근거 (대부분의 AI 시스템도 GDPR 적용 대상)ra-qm-team/compliance-team-iso42001/— ISO 42001 AIMS (서비스 제공업체를 위한 제17조 QMS의 일부 요건을 충족하는 자발적 관리 시스템)ra-qm-team/skills/information-security-manager-iso27001/— 사이버 보안 요건에 대한 ISO 27001 (제15조)ra-qm-team/skills/risk-management-specialist/— ISO 14971 위험 관리 (제6조(1)항에 따른 안전 구성 요소 AI에 참조됨)ra-qm-team/skills/mdr-745-specialist/— MDR 2017/745 (의료기기 AI와의 중복)compliance-os/— 다중 프레임워크 프로그램을 위한 메타 오케스트레이터c-level-advisor/chief-ai-officer-advisor/— AI 최고 전략 책임자(CAO) 자문
참고 문헌
- eu_ai_act_titles.md — 제I–XII장 조항별 해설 및 배포자/공급자/수입자/유통업자의 의무 분류
- high_risk_systems_annex_iii.md — 부속서 III의 8개 범주 상세 설명 + 제6조(2)~(3) 상호작용 + 예외 적용 테스트
- gpai_obligations.md — 제51조–제55조 GPAI 추적 + 시스템적 위험 기준치 + 투명성 규칙 + 실천 규범 현황
- cross_framework_mapping_ai_act.md — AI 법 ↔ ISO 42001 ↔ NIST AI RMF ↔ GDPR 통제 수준 매핑
버전: 1.0.0 상태: 본 운영 준비 완료
---
name: eu-ai-act-specialist
description: Classify AI systems under the EU AI Act, determine conformity assessment routes, and track per-role obligations using reference scripts and Article-cited guidance.
license: MIT
---
# EU AI Act Compliance Specialist
Article-cited operational skill for Regulation (EU) 2024/1689. **Three decisions, no executive AI strategy:**
1. **What tier is this AI system?** — prohibited (Article 5) / high-risk (Article 6 + Annex III) / limited-risk transparency (Article 50) / minimal-risk
2. **For high-risk systems, what's the conformity assessment route + documentation pack?** — Article 43 Module A vs Module H + Annex IV technical documentation
3. **Per organizational role, what are the obligations?** — provider / deployer / importer / distributor / authorized representative matrix per Article 16, 22, 25, 26
This skill is **NOT chief-ai-officer-advisor**. CAIO decides whether to ship the AI feature at all and accepts business risk. This skill operates the conformity work that turns "we'll ship it" into Article-compliant artefacts.
This skill is **NOT a legal substitute**. The Act is binding regulation. For novel cases (Is this a GPAI model? Does Article 6(2) carve-out apply? Is fine-tuning a foundation model "substantial modification"?), engage qualified outside counsel. The skill cites Articles + Annexes and uses Commission/EDPB published interpretation but does not provide binding legal opinion.
This skill is **NOT GDPR**. Many AI systems also trigger GDPR (training data, output processing). See `ra-qm-team/skills/gdpr-dsgvo-expert/` for DPIA + lawful basis work. The Acts interact (Recital 10, Article 10 for high-risk training data).
## Keywords
EU AI Act, EU AI Regulation, Regulation 2024/1689, AI Act, AI regulation Europe, high-risk AI, prohibited AI, Article 5 AI Act, Article 6 AI Act, Article 9 AI Act, Article 50 AI Act, Annex III, Annex IV, conformity assessment, CE marking AI, notified body AI, Module A, Module H, technical documentation AI, post-market monitoring AI, fundamental rights impact assessment, FRIA, GPAI, general-purpose AI model, systemic risk GPAI, AI Office, ENISA AI, EDPB AI, AI Act timeline, AI Act penalties, EU AI Act provider, EU AI Act deployer, EU AI Act importer, EU AI Act distributor, EU AI Act fines, AI literacy
## Quick Start
```bash
# Decision A: Classify an AI system per the Act
python scripts/ai_system_risk_classifier.py # embedded 5-system sample
python scripts/ai_system_risk_classifier.py path/to/systems.json
# Decision B: Conformity assessment plan for a high-risk system
python scripts/conformity_assessment_planner.py # embedded high-risk sample
python scripts/conformity_assessment_planner.py path/to/system.json
# Decision C: Obligation tracker per organizational role
python scripts/ai_act_obligation_tracker.py # embedded sample (provider + deployer)
python scripts/ai_act_obligation_tracker.py path/to/roles.json
```
## Key Questions (ask these first)
- **Does this AI system fall under Article 5 (prohibited practices)?** Social scoring, emotion recognition in workplace/education, manipulative subliminal techniques, real-time remote biometric identification in public — any of these are flat-out prohibited.
- **Does it fall under Annex III (high-risk categories)?** 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Triggering Annex III triggers Article 6(2) — unless the Article 6(3) carve-outs apply.
- **What organizational role does the company play?** Provider (placed on market), deployer (uses under own authority), importer (places third-country system on EU market), distributor (makes available in supply chain). Many companies are BOTH provider AND deployer simultaneously.
- **Is this a general-purpose AI model?** GPAI has its own track (Articles 51–55) with stricter rules above 10²⁵ FLOPs training compute (Article 51 systemic risk).
- **For high-risk: have we run Article 9 risk management AND Article 27 FRIA?** Article 9 is the lifecycle risk management; Article 27 is the Fundamental Rights Impact Assessment for public-sector deployers + essential services.
- **What's the conformity assessment Module per Article 43?** Module A (internal control, possible for most Annex III systems) vs Module H (full QMS + notified body, required for biometrics + sometimes others).
## Core Responsibilities
### 1. AI System Risk Classification
**The framework:** The Act takes a risk-based approach (Recital 26). Each AI system falls into exactly one of four tiers:
| Tier | Source | Examples | Obligations |
|---|---|---|---|
| **Prohibited** | Article 5 | Social scoring; emotion recognition in workplace/education; subliminal manipulation; real-time public biometrics by law enforcement (with narrow exceptions) | Cannot be placed on market or used (penalties up to EUR 35M / 7% turnover) |
| **High-risk** | Article 6 + Annex III; Article 6(1) + Annex I | CV-screening, credit scoring, biometric categorisation, safety components of regulated products | Articles 8–17 (provider) + Article 26 (deployer); conformity assessment; CE marking |
| **Limited-risk (transparency)** | Article 50 | Chatbots, deepfakes, emotion recognition outside Article 5 contexts | Transparency disclosures to natural persons |
| **Minimal-risk** | Default | Spam filters, video-game AI, inventory forecasters | None under the Act (voluntary codes of conduct, Article 95) |
**Critical carve-outs (Article 6(3)):** an Annex III system is NOT high-risk if it (a) performs a narrow procedural task, (b) improves the result of previously completed human activity, (c) detects decision-making patterns without replacing human assessment, (d) performs a preparatory task. Caveat: profiling of natural persons is always Annex III high-risk regardless of carve-outs.
**Run** `ai_system_risk_classifier.py` with system characteristics. The tool checks Article 5 prohibitions first, then Annex III categories, then Article 6(3) carve-outs, then Article 50 transparency, then minimal-risk default.
See `references/eu_ai_act_titles.md` for the full Article-by-Article walkthrough.
### 2. Conformity Assessment + Annex IV Technical Documentation
**The framework (Article 43 + Annex VI/VII):** for high-risk AI systems, the provider must demonstrate conformity before placing on market. Two routes:
- **Module A — Internal control** (Annex VI): provider self-assesses against the requirements. Applies to most Annex III systems where the provider has implemented harmonised standards.
- **Module H — Full quality management system + technical documentation** (Annex VII): notified body involvement. Required for biometrics systems (Article 43(1)).
**Required artifacts per Annex IV — Technical Documentation:**
1. General description of the AI system (intended purpose, identification, version)
2. Detailed description of system elements (architecture, training data, validation procedures)
3. Information about monitoring, functioning and control
4. Description of risk management system (Article 9)
5. Description of changes after placing on market
6. List of harmonised standards applied (or alternative)
7. EU declaration of conformity (Article 47)
8. Description of the post-market monitoring system (Article 72)
**Run** `conformity_assessment_planner.py` to select the Module and produce the Annex IV checklist for a given high-risk system.
See `references/high_risk_systems_annex_iii.md` for which systems require which conformity route.
### 3. Per-Role Obligation Tracker
**The framework (Articles 16, 22, 23, 24, 25, 26):** the Act distinguishes provider obligations (most) from downstream-actor obligations (deployer, importer, distributor, authorized representative). A single company can play multiple roles simultaneously.
| Role | Primary Articles | Key obligations |
|---|---|---|
| **Provider** (Article 3(3)) | 8–17, 47, 49, 72 | Conformity assessment; CE marking; risk management; data governance; technical documentation; post-market monitoring; serious incident reporting (Article 73) |
| **Deployer** (Article 3(4)) | 26 | Use according to instructions; human oversight; input data quality; record-keeping (Article 19); inform workers (Article 26(7)); FRIA if public-sector/essential-services (Article 27) |
| **Importer** (Article 3(6)) | 23 | Verify conformity; affixed CE marking; technical documentation availability |
| **Distributor** (Article 3(7)) | 24 | Verify CE marking + documentation before making available |
| **Authorized representative** (Article 22) | 22 | Non-EU providers must appoint one; representative liable for provider obligations |
**Important:** under Article 25, a deployer who substantially modifies a high-risk AI system, or places it on the market under their own name, becomes a **provider** and inherits provider obligations.
**Run** `ai_act_obligation_tracker.py` with the roles JSON to produce a deadline-sorted obligation matrix.
See `references/gpai_obligations.md` for the separate GPAI Articles 51–55 track.
## Workflows
### Workflow 1: AI System Intake Review (per system, ~2 hours)
**Goal:** classify, identify obligations, scope the conformity work.
```bash
# 1. Document system characteristics: purpose, users, data, autonomy, deployment context
# 2. Run classifier
python scripts/ai_system_risk_classifier.py systems.json
# 3. If high-risk: run planner
python scripts/conformity_assessment_planner.py system.json
# 4. Identify org roles played (provider / deployer / both)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. Cross-check with GDPR DPIA (gdpr-dsgvo-expert) if personal data
# 6. Cross-check with ISO 42001 AIMS evidence (compliance-team-iso42001)
# 7. Output: classification memo + conformity plan + obligation list
```
### Workflow 2: Annex IV Technical Documentation Build (per high-risk system, 2–4 weeks)
**Goal:** assemble the Annex IV pack before conformity assessment.
```bash
# 1. Run conformity assessment planner to get the checklist
python scripts/conformity_assessment_planner.py system.json
# 2. Assemble: system description, architecture, training data, validation, risk management
# 3. Reference ISO 42001 evidence where it satisfies Annex IV items
# 4. Reference ISO 27001 evidence for security controls
# 5. Run Article 9 risk management lifecycle
# 6. Sign EU declaration of conformity (Article 47) AFTER assessment passes
# 7. Affix CE marking (Article 48)
# 8. Register in EU database (Article 71) — high-risk Annex III systems
```
### Workflow 3: Pre-Deployment Obligation Audit (per system, before launch)
**Goal:** confirm all active obligations are in place before EU placement.
```bash
# 1. Confirm classification still correct (re-run classifier if system changed)
# 2. Confirm conformity assessment completed (if high-risk)
# 3. Confirm transparency requirements (Article 50) — for chatbots, deepfakes, emotion detection
# 4. Confirm post-market monitoring system (Article 72) is live
# 5. Confirm serious-incident reporting procedure (Article 73) is documented
# 6. For deployers: FRIA done (Article 27, if applicable); workers informed (Article 26(7))
# 7. For GPAI: Articles 51-55 obligations met if applicable
```
### Workflow 4: Annual Compliance Refresh (per organization, yearly)
**Goal:** re-verify classifications + obligations as the Act phases in.
1. List all AI systems on or planned for EU market
2. Run classifier for each — Article 5 prohibited list may expand via delegated acts
3. Run obligation tracker — deadlines shift as Title III phases in (2025 → 2026 → 2027)
4. For each high-risk system: verify post-market monitoring data flow + serious incident reporting capacity
5. Update Annex IV technical documentation per Article 11 ongoing requirement
6. Pair with ISO 42001 management review (Clause 9.3) if both operate
## Output Standards
```
**Bottom Line:** [one sentence — classification + most-significant obligation]
**Article Citation:** [Article + paragraph number; do not paraphrase without cite]
**The Decision:** [one of: classify | conformity-route | obligation-scope]
**The Evidence:** [Article + Annex references; classification confidence]
**How to Act:** [3 concrete next steps with owner + deadline aligned to phasing]
**Your Decision:** [the call for compliance officer or legal counsel — risk-class disputes, novel cases, GPAI threshold determinations]
```
## Adjacent Skills
- `ra-qm-team/skills/gdpr-dsgvo-expert/` — GDPR DPIA + lawful basis (most AI systems also trigger GDPR)
- `ra-qm-team/compliance-team-iso42001/` — ISO 42001 AIMS (voluntary management system that satisfies parts of Article 17 QMS for providers)
- `ra-qm-team/skills/information-security-manager-iso27001/` — ISO 27001 for cybersecurity requirements (Article 15)
- `ra-qm-team/skills/risk-management-specialist/` — ISO 14971 risk management (referenced for safety-component AI under Article 6(1))
- `ra-qm-team/skills/mdr-745-specialist/` — MDR 2017/745 (medical-device AI overlap)
- `compliance-os/` — Meta-orchestrator for multi-framework programs
- `c-level-advisor/chief-ai-officer-advisor/` — Executive AI strategy
## References
- [eu_ai_act_titles.md](references/eu_ai_act_titles.md) — Titles I–XII Article-by-Article walkthrough with deployer/provider/importer/distributor obligation breakdown
- [high_risk_systems_annex_iii.md](references/high_risk_systems_annex_iii.md) — Annex III 8 categories detailed + Article 6(2)–(3) interaction + carve-out test
- [gpai_obligations.md](references/gpai_obligations.md) — Articles 51–55 GPAI track + systemic-risk threshold + transparency rules + Code of Practice status
- [cross_framework_mapping_ai_act.md](references/cross_framework_mapping_ai_act.md) — AI Act ↔ ISO 42001 ↔ NIST AI RMF ↔ GDPR control-level mapping
---
**Version:** 1.0.0
**Status:** Production Ready
모든 파일
0개 파일eu-ai-act-specialist 설치
스킬 파일을 다운로드하여 .claude/skills/ 디렉터리에 압축을 풀어 주세요.
ZIP 다운로드저장소를 클론하고 스킬 파일을 프로젝트에 복사하세요.
git clone https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/eu-ai-act-specialist # Copy SKILL.md to your .claude/skills/ directory
복사





집
