Skip to content

lexbeam-software/eu-ai-governance

v1.1.3Apache-2.0

Source-grounded EU AI Act governance for European legal, compliance, privacy, security and AI governance teams: risk classification, DPIA and FRIA workflows, vendor and policy review, and evidence packs.

EU AI Governance Plugin

Version License EU AI Act Platform Validate

Source-grounded EU AI Act governance for European in-house legal, compliance, privacy, security, and AI governance teams. Classify systems, coordinate DPIA and FRIA workflows, review vendors and policies, and assemble traceable evidence packs.

Website · Lawve · Issues

Why it is useful

  • Six bounded commands for recurring governance work
  • Six reusable skills with role-specific workflows
  • Current enacted-law map for Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
  • Bundled connection to Lexbeam’s open EU AI Act MCP, when connected tools are supported and permitted, for versioned article summaries and official links, classification, deadlines, obligations, Article 6(3), and Annex IV checks
  • Embedded fallback for local-only work, with an explicit source-date warning
  • Fact-specific DACH escalation instead of treating Germany, Austria, and Switzerland as one legal regime
  • Deterministic validation of manifests, links, versions, legal anchors, and stale-law regressions

The project supports professional judgment. It does not certify compliance or replace legal advice. See LEGAL-DISCLAIMER.md.

Install in Claude Code

claude plugin marketplace add lexbeam-software/eu-ai-governance-plugin
claude plugin install eu-ai-governance@lexbeam

Then run:

/eu-ai-governance:ai-act-status
/eu-ai-governance:classify-ai-risk <system description>

Requires Claude Code or Cowork with plugin support. The embedded workflow content has no package dependency. Connected MCP services are optional and may process selected context under their own terms; see CONNECTORS.md.

Install in Cowork

  1. Download the validated release ZIP from GitHub or the matching Lawve release.
  2. In Claude, open Settings → Plugins → Add → Create plugin → Upload a plugin.
  3. Upload the ZIP and start with /eu-ai-governance:ai-act-status.

Verify that the uploaded package shows version 1.1.0, Apache 2.0, and the 6 August 2026 legal baseline. Do not upload the stale Lawve v1 package.

Commands

CommandOutcome
/eu-ai-governance:classify-ai-riskCited classification, actor-specific duties, deadlines, evidence gaps, and next actions
/eu-ai-governance:ai-act-statusEvidence-based readiness assessment by control domain and operative date
/eu-ai-governance:assess-ai-vendorRole map, evidence matrix, ranked risks, conditions, and contractual redlines
/eu-ai-governance:run-dpiaGDPR Article 35 DPIA with separate EU AI Act Article 27 FRIA scoping
/eu-ai-governance:review-ai-policySection-level policy findings or a versioned governance-policy draft
/eu-ai-governance:generate-evidence-packRequirement-to-evidence index and scoped review pack without false completeness claims

Skills

SkillUse it for
ai-act-classificationArticle 5, Article 6, Annex I/III, Article 6(3), Article 50, GPAI, roles, and dates
ai-act-complianceInventories, AI literacy, programme controls, gaps, and roadmaps
ai-vendor-assessmentProvider evidence, DPA and contract review, model changes, incidents, and exit
dpia-aiDPIA triggers, people-centred risks, DPO advice, Article 36, and FRIA coordination
governance-documentationAnnex IV, logs, conformity records, registrations, monitoring, and evidence indexes
risk-managementRisk registers, controls, metrics, monitoring, and incident escalation

Source-grounding model

The plugin follows a documented legal source protocol:

  1. Use the Lexbeam EU AI Act MCP when available.
  2. Use the MCP summary and official URL to locate the decisive provision, then read the complete official text before stating a prohibition, exception, duty, deadline, or negative legal conclusion.
  3. Prefer consolidated official text and verify amended wording against the amending act.
  4. Separate enacted law, guidance, national law, contractual controls, and recommended practice.
  5. Report the source mode and as-of date.

The connected server is also available independently:

Current legal baseline

Embedded content was reviewed on 6 August 2026 against CELEX 02024R1689-20260727 and Regulation (EU) 2026/1744.

DateMilestone
2 February 2025Article 4 and most Article 5 prohibitions apply
2 August 2025GPAI duties and most penalty provisions apply
27 July 2026Regulation (EU) 2026/1744 enters into force
2 August 2026Article 50 and Commission GPAI enforcement apply
2 December 2026New Article 5(1)(ba), (bb), 5(1a), and 5(1b) apply
2 August 2027Legacy GPAI transition date
2 December 2027Article 6(2)/Annex III high-risk rules apply
2 August 2028Article 6(1)/Annex I high-risk rules apply

The 2027 and 2028 dates are enacted, unconditional calendar dates. They are not proposal-era backstops.

Examples

The examples are fictional demonstrations, not current vendor findings or legal opinions:

Validate a contribution

npm run validate
claude plugin validate .

The local validator checks component structure, versions, links, license presence, MCP configuration, exact legal anchors, and known stale-law phrases. Legal review remains necessary for substantive changes; use the protected legal claim matrix. Maintainers should also complete the distribution checklist before publishing.

Distribution and version integrity

GitHub releases are the source of truth. Before using a Lawve or other third-party copy, compare its version, license, and legal baseline with this repository. Distribution packages should be produced from a validated release commit.

Data and privacy

What the plugin runs and sends:

  • Skills and commands are Markdown instructions for Claude. The plugin ships no hooks and runs no scripts on your machine; scripts/validate.mjs is a contributor check, not part of the plugin.
  • The one bundled connection is the Lexbeam EU AI Act MCP at https://mcp.lexbeam.com/mcp, with no login. When Claude calls one of its tools, the tool arguments (for example a description of the AI system to classify) and the request data (IP address, time, URL, user agent) reach that endpoint. It runs statelessly: it stores no tool arguments or results, sets no cookies and runs no analytics. It is hosted by Railway. Privacy policy: PRIVACY.md.
  • Nothing else leaves your session through the plugin. Organisational sources such as Slack or Microsoft 365 are never connected by the plugin; see CONNECTORS.md.
  • Keep personal, confidential and privileged information out of tool arguments; the tools do not need it. Without the connection the skills work from their embedded references, and nothing reaches Lexbeam.

License and attribution

Apache License 2.0. See LICENSE. Built and maintained by Lexbeam Software, led by Werner Plutat. See CONTRIBUTING.md and SECURITY.md.

The plugin can work standalone or alongside Anthropic’s public knowledge-work plugins. It is not affiliated with or endorsed by Anthropic.