选项
首页首页 Skill 文档 eu-ai-act-specialist

eu-ai-act-specialist

alirezarezvani/claude-skills alirezarezvani/claude-skills

根据《欧盟人工智能法案》对人工智能系统进行分类,确定符合性评估途径,并利用参考脚本和援引该法案条款的指南,追踪各角色应履行的义务。

...展开全部
1
更新时间 2026-08-30

欧盟《人工智能法案》合规专家

针对《欧盟法规(EU)2024/1689》的条文引用操作技能。三项决定,尚无执行性AI战略:

  1. 该AI系统属于哪一等级?——禁止类(第5条)/高风险类(第6条+附件III)/有限风险透明度类(第50条)/最低风险类
  2. 对于高风险系统,符合性评估路径及文件包应如何确定?——第43条A模块与H模块对比 + 附件IV技术文件
  3. 按组织角色划分,各自的义务是什么?——根据第16、22、25、26条规定的提供商/部署方/进口商/分销商/授权代表责任矩阵

本技能并非“首席人工智能官顾问”(CAIO)。CAIO负责决定是否发布AI功能,并承担业务风险。本技能负责执行符合性工作,将“我们将发布该功能”转化为符合法规要求的交付成果。

本技能并非法律替代品。该法案是具有约束力的法规。 对于新型案例(这是通用人工智能(GPAI)模型吗?第6条第2款的豁免条款是否适用?对基础模型进行微调是否属于“实质性修改”?),请聘请合格的外部法律顾问。本技能引用相关条款及附件,并采用欧盟委员会/欧洲数据保护委员会(EDPB)发布的解释,但不提供具有约束力的法律意见。

本技能并非《通用数据保护条例》(GDPR)。许多人工智能系统也会触发《通用数据保护条例》(涉及训练数据、输出处理等)。有关数据保护影响评估(DPIA)及合法依据的工作,请参阅ra-qm-team/skills/gdpr-dsgvo-expert/。各项法规之间存在相互关联(参见第10条序言、第10条关于高风险训练数据的规定)。

关键词

欧盟《人工智能法案》、欧盟《人工智能条例》、第2024/1689号条例、人工智能法案、欧洲人工智能条例、高风险人工智能、被禁止的人工智能, 《AI法》第5条、《AI法》第6条、《AI法》第9条、《AI法》第50条、附件III、附件IV、符合性评估、AI的CE标志、AI的指定机构、A模块、H模块、 AI技术文件、AI上市后监测、基本权利影响评估(FRIA)、通用人工智能(GPAI)、通用人工智能模型、GPAI系统性风险、 AI办公室,ENISA AI,EDPB AI,《AI法案》时间表,《AI法案》处罚,《欧盟AI法案》提供商,《欧盟AI法案》部署者,《欧盟AI法案》进口商,《欧盟AI法案》分销商,《欧盟AI法案》罚款,AI素养

快速入门

# 决策 A:根据该法案对人工智能系统进行分类
python scripts/ai_system_risk_classifier.py                       # 内嵌 5 个系统的示例
python scripts/ai_system_risk_classifier.py path/to/systems.json

# 决策 B:高风险系统的符合性评估计划
python scripts/conformity_assessment_planner.py                   # 内嵌高风险示例
python scripts/conformity_assessment_planner.py path/to/system.json

# 决策 C:按组织角色划分的义务追踪器
python scripts/ai_act_obligation_tracker.py                       # 内置示例(提供方 + 部署方)
python scripts/ai_act_obligation_tracker.py path/to/roles.json

关键问题(请首先询问这些问题)

  • 该人工智能系统是否属于第5条(禁止行为)的范畴?社会评分、工作场所/教育中的情绪识别、具有操纵性的潜意识技术、公共场所的实时远程生物特征识别——上述任何一种行为均被明确禁止。
  • 该系统是否属于附件三(高风险类别)?共8个类别:生物识别、关键基础设施、教育、就业、基本服务、执法、移民、司法。触发附件三即触发第6条第2款——除非第6条第3款的豁免条款适用。
  • 该公司扮演何种组织角色?提供商(将产品投放市场)、部署方(自主使用)、进口商(将第三国系统投放欧盟市场)、分销商(在供应链中提供产品)。许多公司同时兼具提供商和部署方的双重身份。
  • 这是通用人工智能模型吗?通用人工智能(GPAI)有其独立的监管路径(第51–55条),当训练计算能力超过10²⁵ FLOPs时,将适用更严格的规定(第51条系统性风险)。
  • 对于高风险系统:我们是否已执行第9条规定的风险管理以及第27条规定的基本权利影响评估(FRIA)?第9条涉及生命周期风险管理;第27条针对公共部门部署者及基本服务,要求进行基本权利影响评估。
  • 根据第43条,符合性评估模块应采用哪一种?模块A(内部控制,适用于大多数附件III系统)与模块H(完整质量管理体系+指定机构,生物识别技术及其他某些情况必须采用)。

核心职责

1. 人工智能系统风险分类

框架:该法案采用基于风险的方法(第26条考虑因素)。每个AI系统均确切归入以下四个等级中的一个:

等级 来源 示例 义务
禁止事项 第5条 社会评分;工作场所/教育中的情绪识别;潜意识操控;执法部门进行的实时公共生物识别(除极少数例外情况外) 不得投放市场或使用(最高可处以3500万欧元罚款或年营业额的7%)
高风险 第6条 + 附件三;第6条第(1)款 + 附件一 简历筛选、信用评分、生物特征分类、受监管产品中的安全组件 第8–17条(提供者)+第26条(部署者);符合性评估;CE标志
有限风险(透明度) 第50条 聊天机器人、深度伪造、第5条规定范围之外的情绪识别 向自然人披露透明度信息
最低风险 默认 垃圾邮件过滤器、电子游戏人工智能、库存预测工具 本法未作规定(自愿行为准则,第95条)

关键豁免条款(第6条第3款):若附件三所列系统符合以下条件,则不被视为高风险:(a) 执行范围狭窄的程序性任务, (b) 改进先前已完成的人类活动的结果,(c) 检测决策模式但不取代人类评估,(d) 执行准备性任务。注意事项:对自然人的画像分析无论是否符合豁免条件,均始终属于附件三所定义的高风险。

使用系统特征运行 ai_system_risk_classifier.py。该工具将首先检查第5条的禁止性规定,然后是附件三的类别,接着是第6(3)条的豁免条款,随后是第50条的透明度要求,最后是最低风险默认分类。

详见references/eu_ai_act_titles.md中的逐条指南。

2. 符合性评估 + 附件 IV 技术文件

框架(第43条 + 附件VI/VII):对于高风险AI系统,提供商必须在投放市场前证明其符合性。有两种途径:

  • A 模块——内部控制(附件 VI):服务提供商根据要求进行自我评估。适用于大多数已实施协调标准的附件 III 系统。
  • H 模块——完整质量管理体系 + 技术文件(附件 VII):需经指定机构参与。生物识别系统必须采用此途径(第 43 条第 1 款)。

根据附件IV——技术文件的要求,需提供的文件包括:

  1. 人工智能系统的总体描述(预期用途、标识、版本)
  2. 系统要素的详细描述(架构、训练数据、验证程序)
  3. 关于监测、运行和控制的信息
  4. 风险管理体系说明(第9条)
  5. 投放市场后的变更说明
  6. 所采用的协调标准清单(或替代标准)
  7. 欧盟符合性声明(第47条)
  8. 上市后监测系统的说明(第72条)

运行 conformity_assessment_planner.py脚本以选择模块,并为给定的高风险系统生成附件IV检查表。

请参阅references/high_risk_systems_annex_iii.md,了解哪些系统需要采用哪种符合性评估途径。

3. 按角色划分的义务追踪表

框架(第16、22、23、24、25、26条):该法案将提供者的义务(占大多数)与下游主体的义务(部署者、进口商、分销商、授权代表)区分开来。一家公司可以同时扮演多个角色。

角色 主要条款 主要义务
供应商(第3条第3款) 第8–17条、第47条、第49条、第72条 符合性评估;CE标志;风险管理;数据治理;技术文件;上市后监测;严重事件报告(第73条)
部署方(第3条第4款) 26 按说明使用;人工监督;输入数据质量;记录保存(第19条);告知工作人员(第26条第7款);若属于公共部门/基本服务,则需进行FRIA(第27条)
进口商(第3(6)条) 23 核实符合性;加贴CE标志;技术文件的提供
分销商(第3(7)条) 24 在产品投放市场前核查CE标志及技术文件
授权代表(第22条) 22 非欧盟供应商必须指定一名授权代表;该代表对供应商义务承担责任

重要提示:根据第25条规定,对高风险人工智能系统进行实质性修改,或以自身名义将其投放市场的部署者,即成为供应商并承担供应商义务。

运行 ai_act_obligation_tracker.py并传入角色 JSON 文件,即可生成按截止日期排序的义务矩阵。

有关GPAI第51–55条的单独跟踪内容,请参阅references/gpai_obligations.md

工作流程

工作流 1:AI 系统接案审查(按系统计算,约 2 小时)

目标:进行分类、确定义务、界定合规工作范围。

# 1. 记录系统特征:用途、用户、数据、自主性、部署环境
# 2. 运行分类器
python scripts/ai_system_risk_classifier.py systems.json
# 3. 若为高风险:运行规划器
python scripts/conformity_assessment_planner.py system.json
# 4. 确定所扮演的组织角色(提供方 / 部署方 / 兼具两者)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. 若涉及个人数据,则与 GDPR DPIA(gdpr-dsgvo-expert)交叉核对
# 6. 与 ISO 42001 AIMS 证据(compliance-team-iso42001)交叉核对
# 7. 输出:分类备忘录 + 合规计划 + 义务清单

工作流 2:附件 IV 技术文档编制(按高风险系统,2–4 周)

目标:在符合性评估前整理好附件IV文件包。

# 1. 运行符合性评估规划工具以获取检查清单
python scripts/conformity_assessment_planner.py system.json
# 2. 整理:系统描述、架构、训练数据、验证、风险管理
# 3. 引用满足附件 IV 要求的 ISO 42001 证据
# 4. 引用 ISO 27001 证据以证明安全控制措施
# 5. 运行第 9 条规定的风险管理生命周期
# 6. 评估通过后签署欧盟符合性声明(第47条)
# 7. 加贴CE标志(第48条)
# 8. 在欧盟数据库中注册(第71条)——高风险附件III系统

工作流 3:部署前义务审核(按系统进行,在发布前)

目标:确认在产品投放欧盟市场前,所有现行义务均已落实。

# 1. 确认分类仍正确(若系统发生变更,则重新运行分类器)
# 2. 确认符合性评估已完成(若为高风险系统)
# 3. 确认透明度要求(第50条)——适用于聊天机器人、深度伪造、情绪检测
# 4. 确认上市后监测系统(第72条)已投入运行
# 5. 确认严重事件报告程序(第73条)已形成书面记录
# 6. 针对部署方:已完成风险影响评估(第27条,如适用);已向员工告知(第26(7)条)
# 7. 针对通用人工智能(GPAI):如适用,已履行第51至55条规定的义务

工作流 4:年度合规更新(按组织,每年一次)

目标:随着法案的逐步实施,重新核查分类及义务。

  1. 列出所有已在欧盟市场投入使用或计划投放的AI系统
  2. 对每个系统运行分类器——第5条禁止清单可能通过授权法案进一步扩展
  3. 运行义务追踪器——随着第三篇的逐步实施,截止日期将相应调整(2025 → 2026 → 2027)
  4. 针对每个高风险系统:核实上市后监测数据流及严重事件报告能力
  5. 根据第11条的持续要求,更新附件IV的技术文件
  6. 若两者均在运行,则与ISO 42001管理评审(第9.3条)配合进行

输出标准

**结论:** [一句话 — 分类 + 最重要义务]
**条款引用:** [条款 + 段落编号;切勿在未注明出处的情况下进行改写]
**决定:** [选其一:分类 | 符合性路径 | 义务范围]
**依据:** [条款 + 附件引用;分类确定度]
**行动方案:** [3项具体后续措施,明确负责人 + 截止日期需与分阶段实施计划保持一致]
**您的决定:** [需咨询合规官或法律顾问的情况——风险等级争议、新类型案例、GPAI阈值判定]

相关技能

  • ra-qm-team/skills/gdpr-dsgvo-expert/— GDPR DPIA 及合法依据(大多数人工智能系统也会触发 GDPR)
  • ra-qm-team/compliance-team-iso42001/— ISO 42001 AIMS(满足第17条部分要求的供应商自愿管理体系)
  • ra-qm-team/skills/information-security-manager-iso27001/— 满足网络安全要求的 ISO 27001(第 15 条)
  • ra-qm-team/skills/risk-management-specialist/— ISO 14971 风险管理(作为第6(1)条下安全组件AI的参考依据)
  • ra-qm-team/skills/mdr-745-specialist/— MDR 2017/745(与医疗器械人工智能的重叠部分)
  • compliance-os/— 多框架项目的元协调器
  • c-level-advisor/chief-ai-officer-advisor/— 高管层人工智能战略

参考资料

  • eu_ai_act_titles.md — 第 I–XII 篇逐条解析,附部署方/提供方/进口商/分销商义务细则
  • high_risk_systems_annex_iii.md — 附件 III 8 大类详细说明 + 第 6(2) 至 (3) 条的关联性 + 豁免测试
  • gpai_obligations.md — 第51–55条GPAI路径 + 系统性风险阈值 + 透明度规则 + 行为准则现状
  • cross_framework_mapping_ai_act.md — 《人工智能法案》↔ ISO 42001 ↔ NIST 人工智能风险管理框架 ↔ 《通用数据保护条例》(GDPR)控制层级映射

版本:1.0.0 状态:已准备就绪

在 GitHub 上查看
---
name: eu-ai-act-specialist
description: Classify AI systems under the EU AI Act, determine conformity assessment routes, and track per-role obligations using reference scripts and Article-cited guidance.
license: MIT
---

# EU AI Act Compliance Specialist

Article-cited operational skill for Regulation (EU) 2024/1689. **Three decisions, no executive AI strategy:**

1. **What tier is this AI system?** — prohibited (Article 5) / high-risk (Article 6 + Annex III) / limited-risk transparency (Article 50) / minimal-risk
2. **For high-risk systems, what's the conformity assessment route + documentation pack?** — Article 43 Module A vs Module H + Annex IV technical documentation
3. **Per organizational role, what are the obligations?** — provider / deployer / importer / distributor / authorized representative matrix per Article 16, 22, 25, 26

This skill is **NOT chief-ai-officer-advisor**. CAIO decides whether to ship the AI feature at all and accepts business risk. This skill operates the conformity work that turns "we'll ship it" into Article-compliant artefacts.

This skill is **NOT a legal substitute**. The Act is binding regulation. For novel cases (Is this a GPAI model? Does Article 6(2) carve-out apply? Is fine-tuning a foundation model "substantial modification"?), engage qualified outside counsel. The skill cites Articles + Annexes and uses Commission/EDPB published interpretation but does not provide binding legal opinion.

This skill is **NOT GDPR**. Many AI systems also trigger GDPR (training data, output processing). See `ra-qm-team/skills/gdpr-dsgvo-expert/` for DPIA + lawful basis work. The Acts interact (Recital 10, Article 10 for high-risk training data).

## Keywords

EU AI Act, EU AI Regulation, Regulation 2024/1689, AI Act, AI regulation Europe, high-risk AI, prohibited AI, Article 5 AI Act, Article 6 AI Act, Article 9 AI Act, Article 50 AI Act, Annex III, Annex IV, conformity assessment, CE marking AI, notified body AI, Module A, Module H, technical documentation AI, post-market monitoring AI, fundamental rights impact assessment, FRIA, GPAI, general-purpose AI model, systemic risk GPAI, AI Office, ENISA AI, EDPB AI, AI Act timeline, AI Act penalties, EU AI Act provider, EU AI Act deployer, EU AI Act importer, EU AI Act distributor, EU AI Act fines, AI literacy

## Quick Start

```bash
# Decision A: Classify an AI system per the Act
python scripts/ai_system_risk_classifier.py                       # embedded 5-system sample
python scripts/ai_system_risk_classifier.py path/to/systems.json

# Decision B: Conformity assessment plan for a high-risk system
python scripts/conformity_assessment_planner.py                   # embedded high-risk sample
python scripts/conformity_assessment_planner.py path/to/system.json

# Decision C: Obligation tracker per organizational role
python scripts/ai_act_obligation_tracker.py                       # embedded sample (provider + deployer)
python scripts/ai_act_obligation_tracker.py path/to/roles.json
```

## Key Questions (ask these first)

- **Does this AI system fall under Article 5 (prohibited practices)?** Social scoring, emotion recognition in workplace/education, manipulative subliminal techniques, real-time remote biometric identification in public — any of these are flat-out prohibited.
- **Does it fall under Annex III (high-risk categories)?** 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. Triggering Annex III triggers Article 6(2) — unless the Article 6(3) carve-outs apply.
- **What organizational role does the company play?** Provider (placed on market), deployer (uses under own authority), importer (places third-country system on EU market), distributor (makes available in supply chain). Many companies are BOTH provider AND deployer simultaneously.
- **Is this a general-purpose AI model?** GPAI has its own track (Articles 51–55) with stricter rules above 10²⁵ FLOPs training compute (Article 51 systemic risk).
- **For high-risk: have we run Article 9 risk management AND Article 27 FRIA?** Article 9 is the lifecycle risk management; Article 27 is the Fundamental Rights Impact Assessment for public-sector deployers + essential services.
- **What's the conformity assessment Module per Article 43?** Module A (internal control, possible for most Annex III systems) vs Module H (full QMS + notified body, required for biometrics + sometimes others).

## Core Responsibilities

### 1. AI System Risk Classification

**The framework:** The Act takes a risk-based approach (Recital 26). Each AI system falls into exactly one of four tiers:

| Tier | Source | Examples | Obligations |
|---|---|---|---|
| **Prohibited** | Article 5 | Social scoring; emotion recognition in workplace/education; subliminal manipulation; real-time public biometrics by law enforcement (with narrow exceptions) | Cannot be placed on market or used (penalties up to EUR 35M / 7% turnover) |
| **High-risk** | Article 6 + Annex III; Article 6(1) + Annex I | CV-screening, credit scoring, biometric categorisation, safety components of regulated products | Articles 8–17 (provider) + Article 26 (deployer); conformity assessment; CE marking |
| **Limited-risk (transparency)** | Article 50 | Chatbots, deepfakes, emotion recognition outside Article 5 contexts | Transparency disclosures to natural persons |
| **Minimal-risk** | Default | Spam filters, video-game AI, inventory forecasters | None under the Act (voluntary codes of conduct, Article 95) |

**Critical carve-outs (Article 6(3)):** an Annex III system is NOT high-risk if it (a) performs a narrow procedural task, (b) improves the result of previously completed human activity, (c) detects decision-making patterns without replacing human assessment, (d) performs a preparatory task. Caveat: profiling of natural persons is always Annex III high-risk regardless of carve-outs.

**Run** `ai_system_risk_classifier.py` with system characteristics. The tool checks Article 5 prohibitions first, then Annex III categories, then Article 6(3) carve-outs, then Article 50 transparency, then minimal-risk default.

See `references/eu_ai_act_titles.md` for the full Article-by-Article walkthrough.

### 2. Conformity Assessment + Annex IV Technical Documentation

**The framework (Article 43 + Annex VI/VII):** for high-risk AI systems, the provider must demonstrate conformity before placing on market. Two routes:

- **Module A — Internal control** (Annex VI): provider self-assesses against the requirements. Applies to most Annex III systems where the provider has implemented harmonised standards.
- **Module H — Full quality management system + technical documentation** (Annex VII): notified body involvement. Required for biometrics systems (Article 43(1)).

**Required artifacts per Annex IV — Technical Documentation:**

1. General description of the AI system (intended purpose, identification, version)
2. Detailed description of system elements (architecture, training data, validation procedures)
3. Information about monitoring, functioning and control
4. Description of risk management system (Article 9)
5. Description of changes after placing on market
6. List of harmonised standards applied (or alternative)
7. EU declaration of conformity (Article 47)
8. Description of the post-market monitoring system (Article 72)

**Run** `conformity_assessment_planner.py` to select the Module and produce the Annex IV checklist for a given high-risk system.

See `references/high_risk_systems_annex_iii.md` for which systems require which conformity route.

### 3. Per-Role Obligation Tracker

**The framework (Articles 16, 22, 23, 24, 25, 26):** the Act distinguishes provider obligations (most) from downstream-actor obligations (deployer, importer, distributor, authorized representative). A single company can play multiple roles simultaneously.

| Role | Primary Articles | Key obligations |
|---|---|---|
| **Provider** (Article 3(3)) | 8–17, 47, 49, 72 | Conformity assessment; CE marking; risk management; data governance; technical documentation; post-market monitoring; serious incident reporting (Article 73) |
| **Deployer** (Article 3(4)) | 26 | Use according to instructions; human oversight; input data quality; record-keeping (Article 19); inform workers (Article 26(7)); FRIA if public-sector/essential-services (Article 27) |
| **Importer** (Article 3(6)) | 23 | Verify conformity; affixed CE marking; technical documentation availability |
| **Distributor** (Article 3(7)) | 24 | Verify CE marking + documentation before making available |
| **Authorized representative** (Article 22) | 22 | Non-EU providers must appoint one; representative liable for provider obligations |

**Important:** under Article 25, a deployer who substantially modifies a high-risk AI system, or places it on the market under their own name, becomes a **provider** and inherits provider obligations.

**Run** `ai_act_obligation_tracker.py` with the roles JSON to produce a deadline-sorted obligation matrix.

See `references/gpai_obligations.md` for the separate GPAI Articles 51–55 track.

## Workflows

### Workflow 1: AI System Intake Review (per system, ~2 hours)
**Goal:** classify, identify obligations, scope the conformity work.

```bash
# 1. Document system characteristics: purpose, users, data, autonomy, deployment context
# 2. Run classifier
python scripts/ai_system_risk_classifier.py systems.json
# 3. If high-risk: run planner
python scripts/conformity_assessment_planner.py system.json
# 4. Identify org roles played (provider / deployer / both)
python scripts/ai_act_obligation_tracker.py roles.json
# 5. Cross-check with GDPR DPIA (gdpr-dsgvo-expert) if personal data
# 6. Cross-check with ISO 42001 AIMS evidence (compliance-team-iso42001)
# 7. Output: classification memo + conformity plan + obligation list
```

### Workflow 2: Annex IV Technical Documentation Build (per high-risk system, 2–4 weeks)
**Goal:** assemble the Annex IV pack before conformity assessment.

```bash
# 1. Run conformity assessment planner to get the checklist
python scripts/conformity_assessment_planner.py system.json
# 2. Assemble: system description, architecture, training data, validation, risk management
# 3. Reference ISO 42001 evidence where it satisfies Annex IV items
# 4. Reference ISO 27001 evidence for security controls
# 5. Run Article 9 risk management lifecycle
# 6. Sign EU declaration of conformity (Article 47) AFTER assessment passes
# 7. Affix CE marking (Article 48)
# 8. Register in EU database (Article 71) — high-risk Annex III systems
```

### Workflow 3: Pre-Deployment Obligation Audit (per system, before launch)
**Goal:** confirm all active obligations are in place before EU placement.

```bash
# 1. Confirm classification still correct (re-run classifier if system changed)
# 2. Confirm conformity assessment completed (if high-risk)
# 3. Confirm transparency requirements (Article 50) — for chatbots, deepfakes, emotion detection
# 4. Confirm post-market monitoring system (Article 72) is live
# 5. Confirm serious-incident reporting procedure (Article 73) is documented
# 6. For deployers: FRIA done (Article 27, if applicable); workers informed (Article 26(7))
# 7. For GPAI: Articles 51-55 obligations met if applicable
```

### Workflow 4: Annual Compliance Refresh (per organization, yearly)
**Goal:** re-verify classifications + obligations as the Act phases in.

1. List all AI systems on or planned for EU market
2. Run classifier for each — Article 5 prohibited list may expand via delegated acts
3. Run obligation tracker — deadlines shift as Title III phases in (2025 → 2026 → 2027)
4. For each high-risk system: verify post-market monitoring data flow + serious incident reporting capacity
5. Update Annex IV technical documentation per Article 11 ongoing requirement
6. Pair with ISO 42001 management review (Clause 9.3) if both operate

## Output Standards

```
**Bottom Line:** [one sentence — classification + most-significant obligation]
**Article Citation:** [Article + paragraph number; do not paraphrase without cite]
**The Decision:** [one of: classify | conformity-route | obligation-scope]
**The Evidence:** [Article + Annex references; classification confidence]
**How to Act:** [3 concrete next steps with owner + deadline aligned to phasing]
**Your Decision:** [the call for compliance officer or legal counsel — risk-class disputes, novel cases, GPAI threshold determinations]
```

## Adjacent Skills

- `ra-qm-team/skills/gdpr-dsgvo-expert/` — GDPR DPIA + lawful basis (most AI systems also trigger GDPR)
- `ra-qm-team/compliance-team-iso42001/` — ISO 42001 AIMS (voluntary management system that satisfies parts of Article 17 QMS for providers)
- `ra-qm-team/skills/information-security-manager-iso27001/` — ISO 27001 for cybersecurity requirements (Article 15)
- `ra-qm-team/skills/risk-management-specialist/` — ISO 14971 risk management (referenced for safety-component AI under Article 6(1))
- `ra-qm-team/skills/mdr-745-specialist/` — MDR 2017/745 (medical-device AI overlap)
- `compliance-os/` — Meta-orchestrator for multi-framework programs
- `c-level-advisor/chief-ai-officer-advisor/` — Executive AI strategy

## References

- [eu_ai_act_titles.md](references/eu_ai_act_titles.md) — Titles I–XII Article-by-Article walkthrough with deployer/provider/importer/distributor obligation breakdown
- [high_risk_systems_annex_iii.md](references/high_risk_systems_annex_iii.md) — Annex III 8 categories detailed + Article 6(2)–(3) interaction + carve-out test
- [gpai_obligations.md](references/gpai_obligations.md) — Articles 51–55 GPAI track + systemic-risk threshold + transparency rules + Code of Practice status
- [cross_framework_mapping_ai_act.md](references/cross_framework_mapping_ai_act.md) — AI Act ↔ ISO 42001 ↔ NIST AI RMF ↔ GDPR control-level mapping

---

**Version:** 1.0.0
**Status:** Production Ready

所有文件

0 个文件

安装 eu-ai-act-specialist

下载技能文件并将其解压到 .claude/skills/ 目录下。

下载ZIP

克隆仓库并复制技能文件到您的项目中。

git clone https://github.com/alirezarezvani/claude-skills/tree/main/ra-qm-team/skills/eu-ai-act-specialist # Copy SKILL.md to your .claude/skills/ directory

复制 复制
快速设置: 将技能文件夹复制到 .claude/skills/ Claude 会自动检测并使用该技能

相关技能

golang-dependency-injection
更新时间 2026-06-29
nuxthub
更新时间 2026-08-23
tc-tracker
更新时间 2026-08-27
code-quality
更新时间 2026-08-22
OR