EU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and risk tier (prohibited, high-risk, limited, minimal, GPAI, GPAI+systemic). Role and tier are assessed per system, not per company. Use when the user says "ai inventory", "add an ai system", "what systems do we have", "classify this ai system", "eu ai act register", or "ai system registry".
复制安装指令,让 AI 自动完成配置 · 推荐新手
请帮我安装 askskill 上的 "ai-inventory" 技能: 1. 下载 https://raw.githubusercontent.com/anthropics/claude-for-legal/main/ai-governance-legal/skills/ai-inventory/SKILL.md 2. 保存为 ~/.claude/skills/ai-inventory/SKILL.md 3. 装好后重载技能,告诉我可以用了
The user wants to manage their AI system inventory under the EU AI Act. The core idea the skill exists to enforce: role and tier are per-system, not per-company. A single organization can be a provider of System A, a deployer of System B, and an importer of System C. Each combination triggers a different set of obligations under the AI Act. The inventory exists so those assessments are tracked where you can find them — the obligations themselves are derived in conversation, not from a table.
Read the config. Read
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/CLAUDE.md.
If it doesn't exist or still has [PLACEHOLDER] markers, direct the user
to /ai-governance-legal:cold-start-interview first.
Read the inventory. Inventory lives at
~/.claude/plugins/config/claude-for-legal/ai-governance-legal/ai-systems.yaml.
If it doesn't exist, create it with an empty systems: list when the
first add runs.
Dispatch on the argument:
list → show the inventory table (see List below).add → run the Add flow.edit <id> → show the current record, ask what to change, update one
field, confirm, write.classify <id> → run the Classification walk-through on an
existing record, updating role, tier, role_basis, and tier_basis.show <id> → show the full record.On list, offer the dashboard: "Want the full dashboard? Filter by status / tier / EU nexus / owner. Say the word."
Close every action with a hook into the lawyer's work. After any write, say:
Recorded. When you're ready to walk through obligations for this system, just ask — I'll do it in-conversation and flag where the AI Act article mapping needs your verification. I don't derive obligations from a table because the mapping is complex and changing.
Render as a compact table:
| ID | Name | Owner | Status | EU nexus | Role | Tier | Next review |
|---|---|---|---|---|---|---|---|
| sys-001 | Resume screening | HR / Jamie | in_production | yes | deployer | high_risk | 2026-08-01 |
| sys-002 | Email drafting assistant | IT / Priya | in_production | no | deployer | limited | 2026-12-01 |
Under the table, show counts by tier and a line: "N systems flagged for review within 30 days."
Ask, one field at a time (or accept a paste). The required fields are
name, owner, description, status, eu_nexus. The rest can be
deferred — say so explicitly: "you can come back to classification with
/ai-governance-legal:ai-inventory classify <id>."
planned | in_development | in_production | deprecated.Assign an ID: sys-NNN where NNN is the next integer in the file.
The walk-through produces role, role_basis, tier, tier_basis. Both
bases are tagged [verify against current AI Act text] — not because the
skill is hedging, but because the article mapping is complex and the AI
Act is still phasing in. The lawyer owns verification.
Who does what to this system?
Options, with the distinguishing test:
…
帮助法律诊所进行结构化客户接案访谈、分流并生成案件摘要。
根据课程笔记与案例资料搭建或扩展课程提纲骨架,帮助学生自己完成复习大纲。
管理 Matter 工作区的创建、切换、归档与上下文隔离。
安全卸载通过 hub 安装的社区技能,并在删除前确认与记录审计日志
临时禁用或重新启用已安装社区技能,并保留其配置与文件。
根据日历、议程和材料起草符合内部格式的董事会或委员会会议纪要