lexbeam-software/eu-ai-governance
v1.1.3Apache-2.0
Source-grounded EU AI Act governance for European legal, compliance, privacy, security and AI governance teams: risk classification, DPIA and FRIA workflows, vendor and policy review, and evidence packs.
Changelog
All notable changes are documented here.
[1.1.3] - 2026-10-01
Changed
- CONNECTORS.md names the checked service version 1.7.0: every tool rejects arguments its schema does not name,
FAQ answers state whether they matched, and
Artikel 4resolves. Every tool the skills reference is live under the same name
[1.1.2] - 2026-09-29
Added
- Impressum and Datenschutz links in the plugin site's footer (lexbeam.com legal pages)
- CONNECTORS.md names the checked service version 1.6.2 (tool results without links, the Art. 50(2) transition answer); every tool the skills reference is live
Changed
- ChatGPT and Codex packaging follows OpenAI's portable layout:
plugin.json(agent-plugins 1.0.0) andmcp.jsonat the plugin root, the interface block underextensions.com.openai;.codex-plugin/is removed, since the root manifest supersedes that compatibility fallback
[1.1.1] - 2026-09-28
Added
- Data and privacy section in the README: what the plugin runs and what reaches the connected server
- Display name "Lexbeam EU AI Governance", homepage, repository and keywords in the plugin manifest
.codex-plugin/plugin.jsonand.codex-plugin/mcp.json, so the same skills and server install in ChatGPT and Codex- Plugin logo and icon under
assets/
Changed
- CONNECTORS.md names the checked service version (1.6.0) and links the server's privacy policy
[1.1.0] - 2026-08-06
Added
- Lexbeam EU AI Act MCP connection in Claude’s documented plugin
.mcp.jsonformat, plus connector-use protocol - Enacted-law decision map and negative-claim source discipline
- Apache 2.0 license file
- Deterministic repository validator and CI workflow
- Version and distribution-integrity guidance for Lawve and other mirrors
Corrected
- Complete Article 5 list, including points 5(1)(ba) and (bb) and their 2 December 2026 application date
- Article 6(1a) to (1c), Article 6(3), profiling override, documentation, and registration boundaries
- Annex III biometric-verification, essential-services, housing, insurance, and FRIA boundaries
- Article 18 documentation keeping, Article 19 logs, Article 43 conformity assessment, and Article 47 declaration mapping
- GDPR DPO consultation language; DPO approval is no longer presented as a universal statutory condition
- Actor-specific serious-incident routing and Article 4a paragraph 2 scope
- DACH wording to avoid treating three jurisdictions as one works-council regime
Changed
- Replaced static vendor profiles with evidence-driven assessment
- Limited bundled MCP configuration to Lexbeam’s legal source; organisational connectors remain user-configured and read-only by default
- Replaced categorical RDG and product-liability conclusions with a neutral use notice
- Replaced “auditor-ready” and guaranteed-current claims with traceability and source-date language
- Removed the undeclared dependency on Anthropic’s legal plugin
[1.0.0] - 2026-02-04
- Initial release with six commands, six skills, three fictional examples, and a static GitHub Pages site