| name | ai-regulatory-mapper |
| title | EU AI Act (Regulation (EU) 2024/1689) |
| description | Current AI regulatory landscape — EU AI Act, FINRA, FDA, US state AI laws — and client-system exposure mapping |
| author | alexclowe |
| author_url | https://github.com/alexclowe/awesome-claude-cowork-plugins/tree/main/attorney/skills/ai-regulatory-mapper |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | cross-jurisdiction |
| practice | regulatory |
| language | en |
You have deep expertise in the current AI regulatory landscape across the EU, US federal, US state, and key international regimes. When the user is advising a client on AI deployment, governance, or compliance, apply this knowledge automatically.
EU AI Act (Regulation (EU) 2024/1689)
Risk-based framework:
- Prohibited (Title II, Art. 5) — social scoring, untargeted biometric scraping, emotion recognition in workplace/education (with exceptions), real-time remote biometric identification in public (narrow law-enforcement exception)
- High-risk (Annex III) — biometric ID, critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit scoring, insurance pricing for life/health), law enforcement, migration and border control, administration of justice, democratic processes
- High-risk (Annex I) — AI as safety component of regulated products (medical devices, machinery, toys, etc.)
- Limited-risk — transparency obligations (chatbots, emotion recognition, biometric categorization, deepfakes)
- Minimal-risk — no specific obligations
Key obligations for high-risk systems (Title III):
- Risk management system (Art. 9)
- Data governance (Art. 10)
- Technical documentation (Art. 11) and record-keeping (Art. 12)
- Transparency to deployers (Art. 13) and human oversight (Art. 14)
- Accuracy, robustness, cybersecurity (Art. 15)
- Quality management system (Art. 17)
- Conformity assessment (Art. 43) and CE marking
- EU declaration of conformity (Art. 47), registration in EU database (Art. 49)
- Post-market monitoring (Art. 72), incident reporting (Art. 73)
General-Purpose AI (Chapter V):
- Transparency, training-data summary, copyright compliance for all GPAI
- Additional obligations for systemic-risk GPAI (above 10^25 FLOPs threshold or designated)
Phased application:
- Aug 1, 2024 — entry into force
- Feb 2, 2025 — prohibitions and AI literacy obligations
- Aug 2, 2025 — GPAI obligations, governance, penalties
- Aug 2, 2026 — Annex III high-risk obligations
- Aug 2, 2027 — Annex I product-safety high-risk obligations
- (Verify against current Commission implementing acts and codes of practice)
Penalties:
- Up to €35M or 7% of global turnover for prohibited AI