EU AI Act Quick Assessment — fast 15-25 minute triage for preliminary classification and compliance assessment.
Library skill — the default version is maintained in GitHub; edits you make live in your own clone.
Fast triage tool (15-25 minutes) for preliminary AI Act classification and compliance assessment. Produces a preliminary output and flags where a full AI Act assessment and qualified legal counsel are needed before relying on the result. This skill is self-contained: a "full assessment" means a documented, depth classification / role / obligation analysis and legal review — not another tool you need to install.
Important: This is a preliminary AI Act assessment based on Regulation (EU) 2024/1689, designed for rapid triage. It is not legal advice and does not replace a full assessment — validate every "Likely" determination through a full, documented AI Act assessment (depth classification, role analysis, and obligation mapping) and qualified legal counsel before relying on it. Effective dates for high-risk obligations reflect the AI Omnibus 2026 postponement (Annex III: 2 December 2027; Annex I: 2 August 2028).
Operator. This triage can be run by a non-lawyer — a product owner, compliance manager, or founder scoping AI Act exposure — as well as by counsel. That is exactly why the output is preliminary by construction: if you are not a lawyer, your job is to route the resulting card to qualified counsel, not to treat "Likely Minimal" as an all-clear. No special AI fluency is assumed beyond describing the system in plain language.
Work shape. This is bounded-transactional triage: a single system run once through a fixed 6-gate sequence to produce a directional classification card — fast, pattern-matched, and deliberately shallow. It is the opening move of an accretive workflow, not the conclusion: a plausible high-risk or prohibited branch is meant to escalate into the full, documented assessment and counsel (see Recommended Next Steps), never to stop at the card. The speed is bought by narrowing scope, and the skill stays inside that narrow scope.
On activation — search for:
EU AI Act latest enforcement updates [current year]
EU AI Act Commission guidelines status [current year]
Gather context through a conversational 2-batch approach. Maximum 2 interaction turns — 1 if the user is detailed, 2 if gaps remain.
Present these three questions with a natural, conversational welcome:
Let's get started with a quick EU AI Act assessment.
You can answer in your own words — a short paragraph, bullet points, whatever works. I'll ask follow-up questions only if I need more detail.
1. What does the AI system do? (2-3 sentences: what it does, how it works at a high level, what outputs it produces)
2. Where is the system deployed? (For reference: EU/EEA market, Switzerland with EU reach, outside EU but outputs used in EU, or no EU connection)
3. What is your organization's relationship to it? (For reference: developed in-house, purchased/licensed, modified/finetuned, distribute/import, or evaluating for acquisition)
After the user responds to Batch 1, silently check whether their answer covers each of the 8 required fields. Be generous with extraction — e.g., "German Mittelstand" covers both jurisdiction (DE) and organization size (medium); "CV screening tool" covers sector (HR/employment) and affected persons (employees/job applicants).
| # | Field | Extract from |
|---|---|---|
| 1 | System description | Batch 1 Q1 |
| 2 | Deployment context | Batch 1 Q2 |
| 3 | Organization role | Batch 1 Q3 |
| 4 | Sector | Often inferable from system description |
| 5 | Affected persons | Often inferable from system description + sector |
| 6 | Modifications | Often inferable from organization role |
| 7 | Organization size | Sometimes mentioned in context |
| 8 | Jurisdiction(s) | Often inferable from deployment context |
Mark each field: Covered / Partially covered / Not covered.
[UNCLEAR — proceeding with cautious assumptions] and note the assumption made.Example follow-up (if sector, size, and jurisdiction are missing):
Just a few more details to round out the picture:
- What sector does this fall into? (e.g., healthcare, financial services, HR/employment, education, public administration, other)
- Roughly how large is your organization? (e.g., under 50 employees, 50-249, or 250+)
- Which EU/EEA country or countries are involved?
Before proceeding to Phase 2, normalize all gathered information into the structured 8-field format so the Phase 2 gate sequence can reference fields consistently:
Read references/quick-decision-tree.md for the condensed classification logic.
Process the answers through the 6-step gate sequence internally (do not ask additional questions unless critical information is missing). Output the result as a single assessment.
Gate 1: Scope Check (Art. 2) - If deployment context is "No EU connection" → likely out of scope → note and proceed cautiously - Check for military, personal use, pure R&D exclusions based on system description
Gate 2: AI System Test (Art. 3(1)) - Quick determination based on system description - Apply simplified 3-question test: (1) machine-based? (2) infers/generates beyond rules? (3) influences environment?
Gate 3: Prohibited Practice Screen (Art. 5) - Rapid screen based on system description and sector - Flag any potential Art. 5 concern for detailed review
Gate 4: High-Risk Assessment (Annex I + III) - Map sector + use case to Annex I/III categories - Use sector answer as primary trigger indicator - If Annex III triggered: quick Art. 6(3) exception check - If the high-risk branch is plausible, flag that a full Art. 6 high-risk assessment — grounded in the Commission's Art. 6(3) / Annex III guidelines and the classification's documented reasoning — is needed before treating the system as in or out of the high-risk tier.
Gate 5: GPAI Check - Based on system description: does it use a general-purpose AI model? - If yes: note GPAI obligations
Gate 6: Transparency Triggers (Art. 50) - Check for direct human interaction, synthetic content generation, emotion recognition, deep fakes
The Confidence field in the output is not decorative. Each level changes what you do with the determination, so an ambiguous call never reads the same as a clear one:
When in doubt between two bands, pick the lower one.
Generate a consolidated preliminary assessment using the following structure:
## AI Act Quick Assessment — PRELIMINARY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠ PRELIMINARY ASSESSMENT — Full analysis required for compliance decisions
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
System: [name/description]
Date: [date]
Assessment Type: PRELIMINARY (Quick Assessment)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
CLASSIFICATION SUMMARY
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
AI System (Art. 3(1)): [Likely YES / Likely NO / Unclear — full test needed]
Scope (Art. 2): [In scope / Likely excluded — Art. 2(x)]
Risk Tier: [Likely Prohibited / Likely High-Risk / Likely GPAI / Likely Limited / Likely Minimal / Unclear]
Classification Basis: [Likely Art. 5(1)(x) / Likely Annex III Nr. X / Likely Art. 50 / Likely minimal]
Confidence: [High / Medium / Low]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ROLE ASSESSMENT
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Likely Role: [Provider / Deployer / Quasi-Provider / Importer / Distributor]
Quasi-Provider Risk: [None / Possible — [trigger]]
Key Concern: [if any — e.g., finetuning may trigger Art. 25]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
TOP OBLIGATIONS (if high-risk or GPAI)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
| # | Obligation | Article | Urgency | Effort Estimate |
|---|-----------|---------|---------|-----------------|
| 1 | [top obligation] | [Art. X] | [Immediate/Short-term/Ongoing] | [Low/Medium/High] |
| 2 | [second obligation] | [Art. X] | [Immediate/Short-term/Ongoing] | [Low/Medium/High] |
| 3 | [third obligation] | [Art. X] | [Immediate/Short-term/Ongoing] | [Low/Medium/High] |
| 4 | [fourth obligation] | [Art. X] | [Immediate/Short-term/Ongoing] | [Low/Medium/High] |
| 5 | [fifth obligation] | [Art. X] | [Immediate/Short-term/Ongoing] | [Low/Medium/High] |
For ALL risk tiers:
| - | AI competence (Art. 4) | Art. 4 | Immediate (since Feb 2025) | Low-Medium |
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
COMPLIANCE TIMELINE
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Applicable Deadline: [2 Feb 2025 / 2 Aug 2025 / 2 Dec 2027 (Annex III — Omnibus) / 2 Aug 2028 (Annex I — Omnibus)]
Days Remaining: [X days]
Urgency: [OVERDUE / CRITICAL / HIGH / MEDIUM / LOW]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
JURISDICTION FLAGS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[Jurisdiction-specific flags based on deployment country, e.g.:]
[DE: Works council co-determination likely required (BetrVG §87)]
[FR: CSE consultation required before deployment]
[Finance sector: BaFin/[regulator] AI model governance requirements apply]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
FINANCIAL EXPOSURE (PRELIMINARY)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Maximum penalty: [EUR XM or X% turnover — Art. 99(X)]
SME proportionality: [Applies / Does not apply]
Penalty tier: [Tier 1/2/3]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
FLAGS & WARNINGS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[List any flags, e.g.:]
[PROHIBITED PRACTICE RISK — Art. 5(1)(x) — immediate legal review required]
[QUASI-PROVIDER RISK — finetuning may trigger Art. 25]
[PROFILING DETECTED — may affect Art. 6(3) exception]
[GDPR OVERLAP — DPIA likely required under Art. 35 GDPR]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
ASSESSMENT CONTEXT (carry forward to the full assessment / counsel)
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
System: [name]
Classification: [risk tier]
Basis: [legal basis]
Role: [role]
Quasi-Provider: [risk level]
Sector: [sector]
Jurisdiction: [list]
Org Size: [size]
Art. 50: [applicable triggers]
GPAI: [yes/no, systemic risk]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
RECOMMENDED NEXT STEPS
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
1. Full classification with documented reasoning — re-run every gate at depth
(Art. 2 scope, Art. 3(1) AI-system test, Art. 5 prohibited screen, Annex I/III
high-risk with the Art. 6(3) exception analysis, GPAI, Art. 50), recording the
legal basis for each determination.
[Priority: HIGH / MEDIUM — based on preliminary findings]
2. Detailed role determination — confirm provider / deployer / quasi-provider /
importer / distributor, including any Art. 25 quasi-provider trigger from
fine-tuning, substantial modification, or own-branding.
[Priority: HIGH if quasi-provider risk detected / MEDIUM otherwise]
3. Complete obligation mapping with owners (RACI) for the confirmed risk tier and role.
[Priority: HIGH if high-risk / MEDIUM if limited risk]
4. Formal assessment documentation for the file — classification record
(Prüfprotokoll), obligation/compliance register, and management briefing
(Entscheidungsvorlage).
[Priority: HIGH for regulatory files / MEDIUM for internal tracking]
5. Engage legal counsel for:
[List specific areas requiring legal judgment]
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠ This preliminary assessment provides directional guidance only. Every
determination marked "Likely" requires validation through a full, documented
AI Act assessment (steps 1–4 above) and legal review before it is relied on.
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
After presenting the preliminary assessment, offer:
"Would you like me to generate a preliminary version of any of the following templates? These will be marked as preliminary and should be finalized after a full assessment."
- Classification Record (Prüfprotokoll) — preliminary audit trail
- Compliance Register Entry — preliminary obligation tracker
- Management Briefing (Entscheidungsvorlage) — preliminary decision document
If requested, generate the chosen template from the assessment fields above using a standard structure — Classification Record: system, role, risk tier, legal basis per gate, confidence, open questions; Compliance Register Entry: obligation, article, owner, urgency, deadline, status; Management Briefing: one-paragraph summary, risk tier + exposure, decision asked of management, recommended next steps. Mark every output prominently as "PRELIMINARY — Full assessment recommended."
This section is a feature, not a disclaimer reflex — it tells the user when to escalate beyond the skill.
[UNCLEAR] and proceeds on stated cautious assumptions rather than guessing.This skill is provided "as is" under the Apache License 2.0 — without warranties of any kind, and subject to the limitation of liability in §§ 7–8 of that license. It is not legal advice and creates no attorney–client relationship. To the fullest extent permitted by law, the author (Oliver Schmidt-Prietz, Rechtsanwalt, Germany) accepts no liability for any use of, or reliance on, this skill or its output; users use it at their own responsibility and are solely responsible for validating results and for their own compliance decisions.