Syntic

Skills may execute instructions and code that could affect your environment. Marketplace scans reduce risk but do not guarantee safety. Always review files, run your own security checks, and use at your own risk.

Regulatory & QualityFree Safe

eu-ai-act-specialist

Security Scan Summary

Status: Safe

Source: Syntic Skills registry

Automated security scan completed with no high-risk patterns detected. Manual review is still required.

About This Skill

Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a high-risk system, or scoping provider/deployer/importer/distributor obligations.

Downloadable SKILL.md

Download SKILL.md and place it in your Syntic skills folder. For Syntic Code, install in your local skills directory, review contents, and run in a controlled environment first. Acknowledge the risk notice above to enable the download.

SKILL.md
---
name: eu-ai-act-specialist
description: Use when classifying an AI system's EU AI Act risk tier, planning Article 43 conformity assessment for a high-risk system, or scoping provider/deployer/importer/distributor obligations.
category: Regulatory & Quality
version: 1.0.0
tools: []
---

# EU AI Act Compliance Specialist

Article-cited operational compliance for Regulation (EU) 2024/1689. **Three decisions, not executive AI strategy:**

1. **What tier is this AI system?** Prohibited (Article 5) / high-risk (Article 6 + Annex III) / limited-risk transparency (Article 50) / minimal-risk.
2. **For high-risk systems, what's the conformity-assessment route and documentation pack?** Article 43 Module A vs. Module H, plus Annex IV technical documentation.
3. **Per organizational role, what are the obligations?** Provider / deployer / importer / distributor / authorized representative, per Articles 16, 22, 25, 26.

This is **not** an executive-strategy skill — deciding whether to ship the AI feature at all, and accepting the business risk, is a separate call; this skill operates the conformity work that turns "we'll ship it" into Article-compliant artefacts. It is **not a legal substitute** — for novel cases (is this a GPAI model? does the Article 6(2) carve-out apply? is fine-tuning a foundation model "substantial modification"?) engage qualified outside counsel; the skill cites Articles and Annexes and uses published Commission/EDPB interpretation, not binding legal opinion. It is **not GDPR** — many AI systems trigger GDPR too (training data, output processing; the Acts interact via Recital 10 and Article 10 for high-risk training data) — route that DPIA/lawful-basis work to a GDPR specialist.

## Key questions to ask first

- Does the system fall under Article 5 prohibited practices — social scoring, emotion recognition in workplace/education, manipulative subliminal techniques, or real-time remote biometric identification in public? Any of these are flat-out prohibited.
- Does it fall under one of the 8 Annex III high-risk categories — biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice? That triggers Article 6(2) unless an Article 6(3) carve-out applies.
- What organizational role does the company play — provider (placed on market), deployer (uses under own authority), importer (places a third-country system on the EU market), distributor (makes it available in the supply chain)? Many companies are both provider and deployer at once, and under Article 25 a deployer who substantially modifies a high-risk system, or rebrands it under their own name, becomes a provider and inherits provider obligations.
- Is this a general-purpose AI model? GPAI has its own track (Articles 51–55) with stricter rules once training compute exceeds 10²⁵ FLOPs (Article 51 systemic risk).
- For high-risk systems, has Article 9 lifecycle risk management run, and — for public-sector or essential-services deployers — has the Article 27 Fundamental Rights Impact Assessment (FRIA) been done?
- What conformity module applies under Article 43 — Module A (internal control, viable for most Annex III systems) or Module H (full QMS plus notified body, required for biometrics and sometimes others)?

## Decision 1: Risk tier classification

The Act is risk-based (Recital 26); every system falls into exactly one of four tiers.

| Tier | Source | Examples | Obligations |
|---|---|---|---|
| Prohibited | Article 5 | Social scoring; workplace/education emotion recognition; subliminal manipulation; real-time public biometrics by law enforcement (narrow exceptions) | Cannot be placed on market or used — penalties up to EUR 35M / 7% of global turnover |
| High-risk | Article 6 + Annex III, or Article 6(1) + Annex I | CV-screening, credit scoring, biometric categorisation, safety components of regulated products | Articles 8–17 (provider) + Article 26 (deployer); conformity assessment; CE marking |
| Limited-risk (transparency) | Article 50 | Chatbots, deepfakes, emotion recognition outside Article 5 | Transparency disclosure to natural persons |
| Minimal-risk | Default | Spam filters, game AI, inventory forecasters | None under the Act — voluntary codes of conduct (Article 95) |

Article 6(3) carve-outs take an Annex III system out of high-risk if it performs a narrow procedural task, improves the result of previously completed human activity, detects decision-making patterns without replacing human assessment, or performs a preparatory task — except that profiling of natural persons is always high-risk regardless of carve-outs. Check prohibitions first, then Annex III categories, then the 6(3) carve-outs, then Article 50 transparency, and default to minimal-risk otherwise.

## Decision 2: Conformity assessment and Annex IV documentation

For high-risk systems, the provider must demonstrate conformity before placing the system on market, via one of two routes (Article 43 + Annex VI/VII): **Module A — internal control** (Annex VI), where the provider self-assesses against harmonised standards; or **Module H — full QMS plus notified-body involvement** (Annex VII), required for biometrics systems under Article 43(1).

Annex IV technical documentation requires: a general description of the system (intended purpose, identification, version); a detailed description of its elements (architecture, training data, validation procedures); information on monitoring, functioning, and control; a description of the Article 9 risk-management system; a record of changes after placing on market; the list of harmonised standards applied (or the alternative); the EU declaration of conformity (Article 47); and a description of the Article 72 post-market monitoring system. Sign the declaration of conformity only after assessment passes, then affix CE marking (Article 48) and register high-risk Annex III systems in the EU database (Article 71).

## Decision 3: Per-role obligation tracker

A single company can hold multiple roles simultaneously.

| Role | Key articles | Key obligations |
|---|---|---|
| Provider (Art. 3(3)) | 8–17, 47, 49, 72 | Conformity assessment; CE marking; risk management; data governance; technical documentation; post-market monitoring; serious-incident reporting (Art. 73) |
| Deployer (Art. 3(4)) | 26 | Use per instructions; human oversight; input-data quality; record-keeping (Art. 19); inform workers (Art. 26(7)); FRIA if public-sector/essential-services (Art. 27) |
| Importer (Art. 3(6)) | 23 | Verify conformity; verify CE marking; ensure documentation availability |
| Distributor (Art. 3(7)) | 24 | Verify CE marking and documentation before making available |
| Authorized representative (Art. 22) | 22 | Non-EU providers must appoint one; the representative is liable for provider obligations |

## Workflows

**AI system intake review (~2 hours per system):** document purpose, users, data, autonomy, and deployment context; classify it; if high-risk, scope the conformity route; identify which organizational roles apply; cross-check with GDPR DPIA and ISO 42001 AIMS evidence if relevant; produce a classification memo, conformity plan, and obligation list.

**Annex IV documentation build (2–4 weeks, high-risk systems):** get the conformity checklist; assemble system description, architecture, training data, validation, and risk-management sections, reusing ISO 42001 and ISO 27001 evidence wherever it already satisfies an Annex IV item; run the Article 9 risk-management lifecycle; sign the declaration of conformity after assessment passes; affix CE marking; register in the EU database.

**Pre-deployment obligation audit (before launch):** reconfirm classification if the system changed; confirm conformity assessment completion for high-risk systems; confirm Article 50 transparency requirements for chatbots/deepfakes/emotion detection; confirm the post-market monitoring system (Art. 72) and serious-incident reporting procedure (Art. 73) are live; for deployers, confirm FRIA and worker notification; for GPAI, confirm Articles 51–55 obligations.

**Annual compliance refresh:** list every AI system on or planned for the EU market; re-run classification (the Article 5 prohibited list may expand via delegated acts); re-run the obligation tracker as Title III deadlines phase in across 2025 → 2026 → 2027; verify post-market monitoring and incident-reporting capacity for each high-risk system; update Annex IV per the Article 11 ongoing-maintenance requirement.

## Output format

State the bottom line (classification plus the most significant obligation) in one sentence, cite the specific Article and paragraph, name the decision type (classify / conformity-route / obligation-scope), give the Article/Annex evidence with a confidence note, list 3 concrete next steps with owner and deadline aligned to the phase-in schedule, and flag what's reserved for the compliance officer or legal counsel — risk-class disputes, novel cases, GPAI threshold determinations.

## Adjacent work

Route personal-data questions (most AI systems also trigger GDPR) to GDPR DPIA work; route AI-management-system evidence to ISO 42001 AIMS work (it satisfies part of the Article 17 QMS requirement for providers); route cybersecurity-control questions to ISO 27001 work (Article 15); route safety-component risk questions to ISO 14971; route medical-device AI overlap to MDR 2017/745 work; and escalate executive AI strategy and risk acceptance to the appropriate leadership advisor, not this skill.

Bundle Download

Includes SKILL.md and bundled support files where provided. Risk acknowledgement is required.

Install Targets

Syntic App

  1. 1. Create a dedicated folder for this skill in your local skills library.
  2. 2. Place SKILL.md into that folder.
  3. 3. Restart Syntic and invoke this skill on matching tasks.

Syntic Code (CLI)

  1. 1. Save SKILL.md in your local Syntic Code skills directory.
  2. 2. Keep related files in the same skill folder.
  3. 3. Run in a safe environment and validate outputs.

Source

https://github.com/alirezarezvani/claude-skills/blob/main/ra-qm-team/compliance-team-eu-ai-act/skills/eu-ai-act-specialist/SKILL.md

Open Source Link
Regulatory & Quality

Related Skills