Classify your first AI system in 90 seconds.
A Claude plugin for in-house legal, compliance, and AI governance teams. The Annex III high-risk obligations apply from 2 August 2026 in current law (a 7 May 2026 provisional Council/Parliament agreement would shift this to 2 December 2027, but is not yet adopted; current law remains authoritative until formal adoption and OJ publication). This plugin gets you from "what AI do we actually have?" to a classified inventory, vendor redlines, and auditor-ready evidence, without another SaaS login.
See it live · 20-min intro call with Werner
# 1. Add the Lexbeam marketplace
claude plugin marketplace add lexbeam-software/eu-ai-governance-plugin
# 2. Install the plugin
claude plugin install eu-ai-governance@lexbeam
# 3. See where you stand
/ai-act-statusDisclaimer. This plugin is an orientation tool, not legal advice. Standardized, rule-based software run by the user in their own environment, keine Rechtsdienstleistung im Sinne des § 2 RDG. Lexbeam Software is not a Rechtsanwaltsgesellschaft and does not provide case-specific legal analysis. For concrete legal questions, consult a registered Rechtsanwältin or Rechtsanwalt. Full text: LEGAL-DISCLAIMER.md.
Legal Engineer · LL.M. Business Law · 10+ years in Big 4 & DAX compliance.
I use this plugin daily on paid client mandates. That's why the regulatory content stays current the day new guidance drops, and why the DACH specifics, Works Council under BetrVG, BaFin, BSI, are actually right.
LinkedIn · lexbeam.com · Intro call
The EU AI Act is live. Prohibited practices are already banned. GPAI transparency obligations are in effect. High-risk Annex III obligations apply from 2 August 2026 in current law (a 7 May 2026 provisional Council/Parliament agreement would shift this to 2 December 2027 if formally adopted; not yet adopted, current law authoritative). Anthropic's legal plugin handles generic GDPR and contract work. This plugin handles what it doesn't:
- AI Act risk classification (is your system high-risk?)
- Provider vs. deployer obligations (what's YOUR responsibility?)
- Fundamental rights impact assessments
- AI inventory and documentation requirements
- Works council considerations for AI systems (mandatory in DACH)
- Schrems II transfer impact assessments for AI model providers
Works standalone or alongside Anthropic's legal plugin.
The plugin uses a multi-gate decision framework aligned to the EU AI Act:
flowchart TD
A["AI System Description"] --> B{"Gate 1: Prohibited?<br/>(Article 5)"}
B -->|Yes| C["PROHIBITED<br/>Immediate escalation"]
B -->|No| D{"Gate 2A: Safety component<br/>of regulated product?<br/>(Annex I)"}
D -->|Yes| E["HIGH-RISK<br/>(Annex I)"]
D -->|No| F{"Gate 2B: High-risk<br/>use case?<br/>(Annex III)"}
F -->|Yes| G["HIGH-RISK<br/>(Annex III)"]
F -->|No| H{"Gate 2C: GPAI Model?<br/>(Articles 51-56)"}
H -->|Yes| I["GPAI OBLIGATIONS<br/>apply at model level"]
H -->|No| J{"Gate 3: Transparency<br/>duties?<br/>(Article 50)"}
J -->|Yes| K["LIMITED RISK<br/>Transparency obligations"]
J -->|No| L["MINIMAL RISK<br/>Voluntary codes of conduct"]
style C fill:#dc2626,color:#fff
style E fill:#ea580c,color:#fff
style G fill:#ea580c,color:#fff
style I fill:#7c3aed,color:#fff
style K fill:#2563eb,color:#fff
style L fill:#16a34a,color:#fff
Key enforcement deadlines, the plugin tracks where you stand against each. Dates shown are current-law dates. A 7 May 2026 provisional Council/Parliament agreement would shift Annex III to 2 Dec 2027 and Annex I to 2 Aug 2028 if formally adopted; not yet adopted, current law authoritative.
gantt
title EU AI Act Enforcement Timeline (current law)
dateFormat YYYY-MM-DD
axisFormat %b %Y
section Already in Force
Prohibited practices ban (Art. 5) :done, 2025-02-02, 1d
AI literacy obligations (Art. 4) :done, 2025-02-02, 1d
GPAI model obligations (Arts. 51-56) :done, 2025-08-02, 1d
section Upcoming
High-risk Annex III obligations :crit, 2026-08-02, 1d
section Future
High-risk Annex I obligations :2027-08-02, 1d
| Command | What it does |
|---|---|
/classify-ai-risk |
Determine if an AI system is high-risk under the EU AI Act. Step-by-step classification with regulatory citations. |
/assess-ai-vendor |
Review an AI vendor/provider contract against AI Act deployer obligations, GDPR requirements, and enterprise governance standards. |
/run-dpia |
Conduct a Data Protection Impact Assessment specifically designed for AI systems. Covers both GDPR Art. 35 and AI Act requirements. |
/ai-act-status |
Assess your organization's compliance posture against EU AI Act deadlines. Gap analysis with prioritized action items. |
/generate-evidence-pack |
Compile governance documentation for auditors, regulators, or internal review. Structured output ready for regulatory inspection. |
/review-ai-policy |
Review or draft an AI governance policy against EU AI Act requirements and industry best practices. |
| Skill | When it activates |
|---|---|
| AI Act Classification | Determining risk levels, prohibited practices, GPAI obligations |
| AI Vendor Assessment | Evaluating AI provider contracts and compliance posture |
| DPIA for AI Systems | Impact assessments combining GDPR and AI Act requirements |
| Governance Documentation | Creating audit trails, evidence packs, compliance records |
| EU Compliance (Extended) | GDPR, AI Act, works council, and cross-border transfer requirements |
| Risk Management | AI-specific risk assessment frameworks and controls |
| Anthropic Legal Plugin | EU AI Governance Plugin |
|---|---|
| GDPR/CCPA checklists | Full EU AI Act classification engine with regulatory citations |
| Generic contract review | AI vendor-specific assessment against deployer obligations |
| No AI Act awareness | Deadline-aware compliance (Feb 25, Aug 25, Aug 26, Aug 27) |
| US-centric defaults | DACH-first with German templates and works council integration |
| No audit trail guidance | Evidence pack generation for regulatory inspection |
| Manual playbook configuration | Pre-built EU governance playbooks, ready out of the box |
| No risk classification | Structured risk classification per Annex III |
- Run
/ai-act-statusto see where your organization stands - Use
/classify-ai-riskfor each AI system in your inventory - Run
/assess-ai-vendoron your AI provider contracts - Generate evidence packs with
/generate-evidence-pack
No configuration. No API keys. Works with what your team already has.
- English: Full support for all commands and outputs
- German (Deutsch): Templates, governance documents, and compliance reports available in German. Use
--lang dewith any command.
- Claude Cowork or Claude Code
- No external dependencies, no API keys, no infrastructure
- Works offline with local files
- EU AI Act (Regulation 2024/1689): Full classification, obligations, and timeline
- GDPR: Extended DPA review with AI-specific considerations
- German Works Constitution Act (BetrVG): Works council consultation requirements for AI systems
- Schrems II / EU-US DPF: Transfer impact assessments for AI model providers
- ISO 42001: AI management system alignment (optional)
See what the plugin actually produces, realistic, redacted sample outputs:
| Example | Command | Scenario |
|---|---|---|
| HR Resume Screening AI | /classify-ai-risk |
Classifying an automated recruitment tool as HIGH-RISK (Annex III) with Works Council obligations |
| ChatGPT Enterprise Deployment | /assess-ai-vendor |
Vendor assessment with RED/YELLOW flags, contract redlines, and Schrems II analysis |
| Customer Churn Prediction | /run-dpia |
Full DPIA for an ML model processing customer behavioral data |
| Version | Focus | Status |
|---|---|---|
| v1.0 | EU AI Act classification, DPIAs, vendor assessments, evidence packs, policy review | Released |
| v1.1 | ISO 42001 full alignment, control mapping and certification readiness workflows | Planned |
| v1.2 | NIS2 integration, cybersecurity obligations for AI in critical infrastructure | Planned |
| v1.3 | Multi-jurisdiction, French CNIL, Dutch AP, and Austrian DSB-specific guidance | Planned |
| v2.0 | Implementing acts and harmonised standards tracking, auto-update as EU AI Office publishes guidance | Planned |
Apache 2.0, Fork it, extend it, use it commercially.
Lexbeam Software, AI Governance and Legal Tech for European enterprises.
Live demo · Changelog · Legal disclaimer
Extends Anthropic's knowledge-work-plugins. Not affiliated with or endorsed by Anthropic.
This plugin extends and complements Anthropic's knowledge-work-plugins. It is not affiliated with or endorsed by Anthropic.