/cs:ai-act-readiness — EU AI Act Forcing Questions
Command: /cs:ai-act-readiness <system>
The EU AI Act compliance operator pressure-tests any AI system before EU deployment. Six Article-cited questions before any EU placement, conformity assessment, or annual compliance refresh.
When to Run
- During AI-system intake review (per new system or material change)
- Before placing an AI system on the EU market
- Before signing the EU declaration of conformity (Article 47)
- During annual compliance refresh (Article 113 phasing brings new obligations)
- When the organization's role changes (deployer becomes provider via Article 25(1) substantial modification)
- When training compute approaches 10^25 FLOPs (Article 51 systemic-risk threshold)
The Six EU AI Act Questions
1. Article 5: Is this a prohibited AI practice?
Penalty: up to 35M EUR or 7% worldwide turnover.
- 8 categories: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition in workplace/education, biometric categorisation by sensitive attributes, real-time public biometric ID by law enforcement
- Run
ai_system_risk_classifier.py
- If yes → STOP. Cannot place on EU market. No exceptions outside Article 5(2) carve-outs.
2. Article 6 + Annex III: Is this high-risk?
Annex III triggers high-risk; Article 6(3) carve-out conditional.
- 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice
- Carve-out applies only if Article 6(3)(a)-(d) AND no profiling of natural persons
- Profiling overrides carve-out (Article 6(3) last sentence)
- Run
ai_system_risk_classifier.py
3. Article 43: For high-risk, Module A or Module H?
Biometrics → Module H (notified body) by default; others → Module A if harmonised standards applied.
- Run
conformity_assessment_planner.py
- Module A (Annex VI): internal control with presumption of conformity if Article 40 harmonised standards applied
- Module H (Annex VII): full QMS + notified body for biometrics or where standards lacking
- Annex IV technical documentation: 8 items required before placing on market
4. Article 25: What role does the company play?
Provider obligations are heaviest; substantial modification turns deployer into provider.
- Provider (Article 3(3)): placed on market; full Title III + Article 73 reporting
- Deployer (Article 3(4)): Article 26 obligations + Article 27 FRIA if public sector
- Importer (Article 3(6)): Article 23 verification of conformity
- Distributor (Article 3(7)): Article 24 CE marking verification
- Authorized representative (Article 22): non-EU providers must appoint
- Run
ai_act_obligation_tracker.py
5. Article 50: Are transparency obligations satisfied?
In force 2 Aug 2025.
- Article 50(1): disclose AI interaction to natural persons (chatbots, virtual agents)
- Article 50(2): mark synthetic content as AI-generated
- Article 50(3): disclose emotion recognition / biometric categorisation (outside Article 5 prohibitions)
- Article 50(4): disclose deepfakes (image, audio, video) as AI-generated
6. Articles 51-55: Is this a GPAI? Does it have systemic risk?
GPAI has parallel track; systemic risk above 10^25 FLOPs.
- Article 3(63): general-purpose AI model definition
- Article 51: systemic-risk presumption (≥ 10^25 FLOPs training compute) or Commission designation
- Article 53: all GPAI providers — Annex XI technical docs, Annex XII downstream info, copyright policy, training-data summary
- Article 55: systemic-risk GPAI additional obligations — model evaluations, adversarial testing, incident reporting, cybersecurity
- Article 54: non-EU GPAI providers must appoint authorized representative
Workflow
# 1. Risk classification
python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_system_risk_classifier.py systems.json
# 2. If high-risk: conformity assessment
python ra-qm-team/skills/eu-ai-act-specialist/scripts/conformity_assessment_planner.py system.json
# 3. Per-role obligation matrix
python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_act_obligation_tracker.py roles.json
# 4. Cross-framework reuse (ISO 42001 etc.)
python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json
Output Format
# EU AI Act Readiness: <system>
**Date:** YYYY-MM-DD
**Article Citations:** Every verdict below cites the specific Article.
## The Decision Being Made
[classify | conformity-route | obligation-scope | annual-refresh]
## Risk Classification
- Tier: prohibited | high_risk | limited_risk | minimal_risk
- Citation: Article X(Y) + Annex Z if applicable
- Rationale: <Article-cited rationale>
- GPAI: yes/no
- Systemic-risk GPAI: yes/no (per Article 51 10^25 FLOPs threshold)
## Conformity Assessment (if high-risk)
- Module: A | A_with_caveats | H | sectoral
- Citation: Article 43 + Annex VI/VII
- Notified body required: yes | no | optional
- Annex IV pack status: complete | in-progress | not-started
## Obligation Matrix
- Total obligations: N
- By deadline phase: 2025-02-02=A, 2025-08-02=B, 2026-08-02=C, 2027-08-02=D
- Highest-priority unmet obligation: <Article + description>
## Transparency (Article 50)
- 50(1) interaction disclosure: yes | no
- 50(2) synthetic content marking: yes | no | NA
- 50(3) emotion recognition disclosure: yes | no | NA
- 50(4) deepfake disclosure: yes | no | NA
## Cross-Framework Reuse
- ISO 42001 evidence applicable to Article 17 QMS: yes/no
- ISO 27001 evidence applicable to Article 15 cybersecurity: yes/no
- GDPR DPIA usable for Article 27 FRIA: yes/no
## Verdict
🟢 READY-FOR-EU | 🟡 GAPS-IDENTIFIED | 🔴 NOT-READY | 🚫 PROHIBITED
## Top 3 Actions
[3 concrete next steps with owner + Article-tied deadline]
## Legal Review Required
[Article-level ambiguities flagged for outside counsel: novel cases, GPAI threshold disputes, Article 5 boundary cases, Article 25 substantial-modification questions]
Routing
/cs:compliance-readiness — for multi-framework view (combine with ISO 42001 + GDPR)
/cs:aims-audit — for ISO 42001 deep-dive
/cs:caio-review — for executive AI strategy decisions
/cs:gc-review — for novel-case legal review (GPAI threshold, Article 5 boundary, substantial-modification)
/cs:decide — to log the verdict
/cs:freeze 30 — on EU launch commitments (regulatory exposure)
Related
Version: 1.0.0
1---2name: ai-act-readiness3description: Ai Act Readiness4license: MIT5---67# /cs:ai-act-readiness — EU AI Act Forcing Questions89**Command:** `/cs:ai-act-readiness <system>`1011The EU AI Act compliance operator pressure-tests any AI system before EU deployment. Six Article-cited questions before any EU placement, conformity assessment, or annual compliance refresh.1213## When to Run1415- During AI-system intake review (per new system or material change)16- Before placing an AI system on the EU market17- Before signing the EU declaration of conformity (Article 47)18- During annual compliance refresh (Article 113 phasing brings new obligations)19- When the organization's role changes (deployer becomes provider via Article 25(1) substantial modification)20- When training compute approaches 10^25 FLOPs (Article 51 systemic-risk threshold)2122## The Six EU AI Act Questions2324### 1. Article 5: Is this a prohibited AI practice?25**Penalty: up to 35M EUR or 7% worldwide turnover.**26- 8 categories: subliminal manipulation, exploitation of vulnerabilities, social scoring, predictive policing, untargeted facial scraping, emotion recognition in workplace/education, biometric categorisation by sensitive attributes, real-time public biometric ID by law enforcement27- Run `ai_system_risk_classifier.py`28- If yes → STOP. Cannot place on EU market. No exceptions outside Article 5(2) carve-outs.2930### 2. Article 6 + Annex III: Is this high-risk?31**Annex III triggers high-risk; Article 6(3) carve-out conditional.**32- 8 categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice33- Carve-out applies only if Article 6(3)(a)-(d) AND no profiling of natural persons34- Profiling overrides carve-out (Article 6(3) last sentence)35- Run `ai_system_risk_classifier.py`3637### 3. Article 43: For high-risk, Module A or Module H?38**Biometrics → Module H (notified body) by default; others → Module A if harmonised standards applied.**39- Run `conformity_assessment_planner.py`40- Module A (Annex VI): internal control with presumption of conformity if Article 40 harmonised standards applied41- Module H (Annex VII): full QMS + notified body for biometrics or where standards lacking42- Annex IV technical documentation: 8 items required before placing on market4344### 4. Article 25: What role does the company play?45**Provider obligations are heaviest; substantial modification turns deployer into provider.**46- Provider (Article 3(3)): placed on market; full Title III + Article 73 reporting47- Deployer (Article 3(4)): Article 26 obligations + Article 27 FRIA if public sector48- Importer (Article 3(6)): Article 23 verification of conformity49- Distributor (Article 3(7)): Article 24 CE marking verification50- Authorized representative (Article 22): non-EU providers must appoint51- Run `ai_act_obligation_tracker.py`5253### 5. Article 50: Are transparency obligations satisfied?54**In force 2 Aug 2025.**55- Article 50(1): disclose AI interaction to natural persons (chatbots, virtual agents)56- Article 50(2): mark synthetic content as AI-generated57- Article 50(3): disclose emotion recognition / biometric categorisation (outside Article 5 prohibitions)58- Article 50(4): disclose deepfakes (image, audio, video) as AI-generated5960### 6. Articles 51-55: Is this a GPAI? Does it have systemic risk?61**GPAI has parallel track; systemic risk above 10^25 FLOPs.**62- Article 3(63): general-purpose AI model definition63- Article 51: systemic-risk presumption (≥ 10^25 FLOPs training compute) or Commission designation64- Article 53: all GPAI providers — Annex XI technical docs, Annex XII downstream info, copyright policy, training-data summary65- Article 55: systemic-risk GPAI additional obligations — model evaluations, adversarial testing, incident reporting, cybersecurity66- Article 54: non-EU GPAI providers must appoint authorized representative6768## Workflow6970```bash71# 1. Risk classification72python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_system_risk_classifier.py systems.json7374# 2. If high-risk: conformity assessment75python ra-qm-team/skills/eu-ai-act-specialist/scripts/conformity_assessment_planner.py system.json7677# 3. Per-role obligation matrix78python ra-qm-team/skills/eu-ai-act-specialist/scripts/ai_act_obligation_tracker.py roles.json7980# 4. Cross-framework reuse (ISO 42001 etc.)81python ../../skills/compliance-os/scripts/cross_framework_mapper.py program.json82```8384## Output Format8586```markdown87# EU AI Act Readiness: <system>88**Date:** YYYY-MM-DD89**Article Citations:** Every verdict below cites the specific Article.9091## The Decision Being Made92[classify | conformity-route | obligation-scope | annual-refresh]9394## Risk Classification95- Tier: prohibited | high_risk | limited_risk | minimal_risk96- Citation: Article X(Y) + Annex Z if applicable97- Rationale: <Article-cited rationale>98- GPAI: yes/no99- Systemic-risk GPAI: yes/no (per Article 51 10^25 FLOPs threshold)100101## Conformity Assessment (if high-risk)102- Module: A | A_with_caveats | H | sectoral103- Citation: Article 43 + Annex VI/VII104- Notified body required: yes | no | optional105- Annex IV pack status: complete | in-progress | not-started106107## Obligation Matrix108- Total obligations: N109- By deadline phase: 2025-02-02=A, 2025-08-02=B, 2026-08-02=C, 2027-08-02=D110- Highest-priority unmet obligation: <Article + description>111112## Transparency (Article 50)113- 50(1) interaction disclosure: yes | no114- 50(2) synthetic content marking: yes | no | NA115- 50(3) emotion recognition disclosure: yes | no | NA116- 50(4) deepfake disclosure: yes | no | NA117118## Cross-Framework Reuse119- ISO 42001 evidence applicable to Article 17 QMS: yes/no120- ISO 27001 evidence applicable to Article 15 cybersecurity: yes/no121- GDPR DPIA usable for Article 27 FRIA: yes/no122123## Verdict124🟢 READY-FOR-EU | 🟡 GAPS-IDENTIFIED | 🔴 NOT-READY | 🚫 PROHIBITED125126## Top 3 Actions127[3 concrete next steps with owner + Article-tied deadline]128129## Legal Review Required130[Article-level ambiguities flagged for outside counsel: novel cases, GPAI threshold disputes, Article 5 boundary cases, Article 25 substantial-modification questions]131```132133## Routing134135- `/cs:compliance-readiness` — for multi-framework view (combine with ISO 42001 + GDPR)136- `/cs:aims-audit` — for ISO 42001 deep-dive137- `/cs:caio-review` — for executive AI strategy decisions138- `/cs:gc-review` — for novel-case legal review (GPAI threshold, Article 5 boundary, substantial-modification)139- `/cs:decide` — to log the verdict140- `/cs:freeze 30` — on EU launch commitments (regulatory exposure)141142## Related143144- Agent: [`cs-ai-act-compliance`](../../agents/cs-ai-act-compliance.md)145- Skill: [`eu-ai-act-specialist`](../../../ra-qm-team/skills/eu-ai-act-specialist/SKILL.md)146- Adjacent: `../../skills/compliance-os/`, `../aims-audit/`, `../compliance-readiness/`, `../../../ra-qm-team/skills/gdpr-dsgvo-expert/`147148---149150**Version:** 1.0.0