Skip to content

lexbeam-software/eu-ai-governance

v1.1.3Apache-2.0

Source-grounded EU AI Act governance for European legal, compliance, privacy, security and AI governance teams: risk classification, DPIA and FRIA workflows, vendor and policy review, and evidence packs.

Changelog

All notable changes are documented here.

[1.1.3] - 2026-10-01

Changed

  • CONNECTORS.md names the checked service version 1.7.0: every tool rejects arguments its schema does not name, FAQ answers state whether they matched, and Artikel 4 resolves. Every tool the skills reference is live under the same name

[1.1.2] - 2026-09-29

Added

  • Impressum and Datenschutz links in the plugin site's footer (lexbeam.com legal pages)
  • CONNECTORS.md names the checked service version 1.6.2 (tool results without links, the Art. 50(2) transition answer); every tool the skills reference is live

Changed

  • ChatGPT and Codex packaging follows OpenAI's portable layout: plugin.json (agent-plugins 1.0.0) and mcp.json at the plugin root, the interface block under extensions.com.openai; .codex-plugin/ is removed, since the root manifest supersedes that compatibility fallback

[1.1.1] - 2026-09-28

Added

  • Data and privacy section in the README: what the plugin runs and what reaches the connected server
  • Display name "Lexbeam EU AI Governance", homepage, repository and keywords in the plugin manifest
  • .codex-plugin/plugin.json and .codex-plugin/mcp.json, so the same skills and server install in ChatGPT and Codex
  • Plugin logo and icon under assets/

Changed

  • CONNECTORS.md names the checked service version (1.6.0) and links the server's privacy policy

[1.1.0] - 2026-08-06

Added

  • Lexbeam EU AI Act MCP connection in Claude’s documented plugin .mcp.json format, plus connector-use protocol
  • Enacted-law decision map and negative-claim source discipline
  • Apache 2.0 license file
  • Deterministic repository validator and CI workflow
  • Version and distribution-integrity guidance for Lawve and other mirrors

Corrected

  • Complete Article 5 list, including points 5(1)(ba) and (bb) and their 2 December 2026 application date
  • Article 6(1a) to (1c), Article 6(3), profiling override, documentation, and registration boundaries
  • Annex III biometric-verification, essential-services, housing, insurance, and FRIA boundaries
  • Article 18 documentation keeping, Article 19 logs, Article 43 conformity assessment, and Article 47 declaration mapping
  • GDPR DPO consultation language; DPO approval is no longer presented as a universal statutory condition
  • Actor-specific serious-incident routing and Article 4a paragraph 2 scope
  • DACH wording to avoid treating three jurisdictions as one works-council regime

Changed

  • Replaced static vendor profiles with evidence-driven assessment
  • Limited bundled MCP configuration to Lexbeam’s legal source; organisational connectors remain user-configured and read-only by default
  • Replaced categorical RDG and product-liability conclusions with a neutral use notice
  • Replaced “auditor-ready” and guaranteed-current claims with traceability and source-date language
  • Removed the undeclared dependency on Anthropic’s legal plugin

[1.0.0] - 2026-02-04

  • Initial release with six commands, six skills, three fictional examples, and a static GitHub Pages site