ai-act-compliance

ai-act-compliance is a skill for Claude Code, Codex from abk1969/ai-act-skills. It costs 243 tokens per session (8,315 once invoked), scanned A, original, MIT.

A compliance skill for the European Union AI Act, the EU law that sets requirements for artificial-intelligence systems based on their risks.

In plain words
What is it for?
Use it to classify an AI system's risk, assess high-risk requirements, and prepare compliance documentation or related assessments.
Why use it?
It provides a structured way to assess AI-related obligations using the Act, standards, and related compliance guidance.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: reads .claude/ paths; mentions Claude Code; mentions AGENTS.md.

Good fit Use it to classify an AI system's risk, assess high-risk requirements, and prepare compliance documentation or related assessments.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/abk1969/ai-act-skills/ai-act-compliance
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add abk1969/ai-act-skills --skill ai-act-compliance
Clone the repo
git clone --depth 1 https://github.com/abk1969/ai-act-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ai-act-compliance

README.md
[![agentmods](https://agentmods.dev/badge/skills/abk1969/ai-act-skills/ai-act-compliance/github.svg)](https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance)
Your own site
<a href="https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance"><img src="https://agentmods.dev/badge/skills/abk1969/ai-act-skills/ai-act-compliance/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for ai-act-compliance

Your own site · 80×15
<a href="https://agentmods.dev/skills/abk1969/ai-act-skills/ai-act-compliance"><img src="https://agentmods.dev/badge/skills/abk1969/ai-act-skills/ai-act-compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 243 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 8,315 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00243 $0.08315
Opus 5 $0.00121 $0.04158
Sonnet 5 $0.00049 $0.01663
Haiku 4.5 $0.00024 $0.00831

Measured 12d ago against content hash 39f8ebba6a74, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-12, from the pricing page.

Security

Grade A, and why

ai-act-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/ai-act-compliance/SKILL.md · 344 lines

How it starts

The opening of the file, as written. The whole thing — 344 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AI Act Compliance — EU Regulation 2024/1689

What this skill does

Codifies actionable EU AI Act compliance expertise. Every output is traceable to one or more of:

  1. Regulation (EU) 2024/1689the AI Act — the legally binding source.
  2. ISO/IEC 42001:2023 — Artificial Intelligence Management System (AIMS), the certifiable management standard for AI providers and deployers.
  3. ISO/IEC 27090:2025 — Cybersecurity guidance for AI systems (the depth standard for AI Act art. 15 cybersecurity).
  4. Companion ISO standards: 23894 (AI risk management), 23053 (ML framework), 5338 (AI lifecycle), 5259-* (data quality), 24029-2 (robustness), 42005 (impact assessment), 42006 (audit & certification).
  5. CEN-CENELEC JTC 21 harmonised standards (under standardization mandate M/593) — the path to art. 40 presumption of conformity.
  6. GPAI Code of Practice — published 2025-07-10; assessed adequate by the Commission and AI Board on 2025-08-01 — the operative instrument for arts. 53–55 until harmonised standards land.
  7. AI Omnibus amendment (Digital Omnibus on AI) — adopted by Parliament (2026-06-16) and Council (2026-06-29); amends the AI Act's timeline and art. 5 prohibitions. See the timeline below.

This skill is decision-support, not legal advice. Always recommend the user consult qualified counsel for binding interpretation, and a notified body for conformity assessment of high-risk AI systems.

Scheduling at a glance — SSL machine view

This skill is paired with a machine-readable manifest at ssl.json, built per the Scheduling-Structural-Logical (SSL) representation introduced by Liang et al., From Skill Text to Skill Structure (arXiv:2604.24026, 2026). The manifest exposes the skill's invocation interface, scene graph, and atomic action evidence so registries, routers, and reviewers do not need to re-parse this document. The table below is the human-readable scheduling view; ssl.json is the authoritative typed version.

Read the full file on GitHub · 344 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 12d ago First seen · 344 lines · 243 tokens per session scan A 39f8ebba6a74

Subscribe to this mod's changes

ai-act-compliance is a skill published in the GitHub repository abk1969/ai-act-skills (4 stars, last pushed 2mo ago), licensed MIT. It adds 243 tokens to every session and 8,315 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

eu-ai-act-art50-check

Check whether an AI model's PUBLIC artifacts meet EU AI Act Article 50 transparency signals (license declared, task declared, model card present) and get back a deterministic, signable result. Use this instead of reasoning about Article 50 obligations from memory — it returns observed facts from the public model-info…

CSOAI-ORG/csoai-static-deploy2 · 100 tokens

vaara-governed-tool-call

Put an EU AI Act Article 14 human-oversight checkpoint and an Article 12 auditable record in front of a high-risk tool call. Use before an agent runs a consequential or irreversible action (writing to a clinical/genomic database, submitting a record to a regulator, moving money, deleting data, anything a human should…

vaaraio/vaara · 121 tokens

policy

Define and enforce decision policies, compliance rules, and exceptions over Semantica graphs. Uses ContextGraph.checkdecisionrules/enforcedecisionpolicy and context.PolicyEngine.

semantica-agi/semantica · 36 tokens

dispute-respond

Prepare and explicitly file an evidence-bound payment dispute response using native receipt proof, approval, provider execution, and independent readback.

runxhq/runx · 30 tokens

vuln-disclosure

Prepare an evidence-bound vulnerability publication and publish the exact approved advisory through any compatible provider binding with independent readback.

runxhq/runx · 28 tokens

sign-receipt

Bind an off-runtime action claim to opaque evidence references in a signed Runx receipt without pretending Runx verified the external action.

runxhq/runx · 30 tokens