Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

ComplianceFree Safe

ai-act-readiness

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when doing AI-system intake, preparing for EU deployment, or running the annual compliance refresh — the EU AI Act's 6-question, Article-cited readiness interrogation.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: ai-act-readiness
description: Use when doing AI-system intake, preparing for EU deployment, or running the annual compliance refresh — the EU AI Act's 6-question, Article-cited readiness interrogation.
category: Compliance
version: 1.0.0
tools: []
---

# EU AI Act Readiness

Six Article-cited forcing questions that pressure-test any AI system before EU placement, conformity assessment, or annual compliance refresh, as Article 113 obligations phase in (2025-02-02 / 2025-08-02 / 2026-08-02 / 2027-08-02).

## When to run

During AI-system intake review for a new system or material change; before placing an AI system on the EU market; before signing the EU declaration of conformity (Article 47); during the annual compliance refresh; when the organization's role changes (a deployer becomes a provider via Article 25(1) substantial modification); or when training compute approaches the 10^25 FLOPs systemic-risk threshold (Article 51).

## The six questions

### 1. Article 5 — is this a prohibited AI practice?
Penalty: up to €35M or 7% of worldwide turnover. Eight prohibited categories: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition in workplace/education, biometric categorisation by sensitive attributes, real-time public biometric ID by law enforcement. If yes, stop — the system cannot be placed on the EU market, with no exceptions outside the Article 5(2) carve-outs.

### 2. Article 6 + Annex III — is this high-risk?
Eight Annex III categories trigger high-risk: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice. The Article 6(3) carve-out applies only if Article 6(3)(a)-(d) conditions hold AND there is no profiling of natural persons — profiling overrides the carve-out per the Article 6(3) last sentence.

### 3. Article 43 — for high-risk systems, Module A or Module H?
Biometrics default to Module H (notified body); other high-risk systems use Module A if harmonised standards are applied. Module A (Annex VI) is internal control with a presumption of conformity when Article 40 harmonised standards apply. Module H (Annex VII) is a full QMS plus notified-body review, required for biometrics or where standards are lacking. Annex IV technical documentation has 8 required items before market placement.

### 4. Article 25 — what role does the company play?
Provider (Article 3(3)): placed the system on the market; carries the full Title III obligations plus Article 73 reporting. Deployer (Article 3(4)): Article 26 obligations, plus an Article 27 Fundamental Rights Impact Assessment if public sector. Importer (Article 3(6)): Article 23 conformity verification. Distributor (Article 3(7)): Article 24 CE-marking verification. Non-EU providers must appoint an authorized representative (Article 22).

### 5. Article 50 — are transparency obligations satisfied?
In force 2 Aug 2025. Article 50(1): disclose AI interaction to natural persons (chatbots, virtual agents). Article 50(2): mark synthetic content as AI-generated. Article 50(3): disclose emotion recognition / biometric categorisation outside the Article 5 prohibitions. Article 50(4): disclose deepfakes (image, audio, video) as AI-generated.

### 6. Articles 51-55 — is this a GPAI, and does it carry systemic risk?
Article 3(63) defines general-purpose AI models. Article 51 presumes systemic risk at ≥10^25 FLOPs training compute, or via Commission designation. Article 53 obliges all GPAI providers to maintain Annex XI technical docs, Annex XII downstream information, a copyright policy, and a training-data summary. Article 55 adds obligations for systemic-risk GPAI: model evaluations, adversarial testing, incident reporting, cybersecurity. Article 54 requires non-EU GPAI providers to appoint an authorized representative.

## What to produce

For the system under review, cite the specific Article behind every verdict. Cover: risk classification (prohibited / high-risk / limited-risk / minimal-risk, with rationale, GPAI status, and systemic-risk status); conformity-assessment route for high-risk systems (Module A vs. Module A-with-caveats vs. Module H vs. sectoral, notified-body requirement, Annex IV pack status); the obligation matrix (total obligations, grouped by the four phase-in deadlines, highest-priority unmet obligation); Article 50 transparency status per subsection; and cross-framework reuse opportunities (ISO 42001 evidence for Article 17 QMS, ISO 27001 evidence for Article 15 cybersecurity, GDPR DPIAs reusable for the Article 27 FRIA).

Close with a verdict — READY-FOR-EU / GAPS-IDENTIFIED / NOT-READY / PROHIBITED — the top 3 actions with an owner and an Article-tied deadline each, and a flag for any Article-level ambiguity (novel cases, GPAI threshold disputes, Article 5 boundary cases, Article 25 substantial-modification questions) that needs outside counsel rather than this analysis.

## Escalate to a teammate

For the multi-framework view (combining with ISO 42001 and GDPR), the ISO 42001 AIMS deep-dive, executive AI-strategy calls, or novel-case legal review of GPAI-threshold and Article 5 boundary questions, @mention the relevant compliance, AI-governance, or legal teammate rather than trying to resolve those inside this analysis.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/compliance-os/skills/ai-act-readiness/SKILL.md

Open Source Link
Compliance

Related Skills