EU AI Act governance work, grounded at the point of decision.

An open-source Claude plugin for classification, DPIA and FRIA coordination, vendor and policy review, and traceable evidence packs. Embedded guidance is reviewed against enacted law; the Lexbeam MCP returns versioned legal summaries, obligations, deadlines, and official source links.

claude plugin marketplace add lexbeam-software/eu-ai-governance-plugin
→ see a worked example
v1.1.0 · Apache 2.0 Source dated · 6 Aug 2026 EN / DE · bilingual output
EU AI Act · Annex III high-risk rules today · target · Dec 2, 2027 days remaining

Six bounded workflows, each with evidence and a source note.

The commands separate supplied facts, legal duties, national-law questions, contractual controls, and recommended practice.

/eu-ai-governance:classify-ai-risk

Tests scope, every Article 5 prohibition, Article 6 and Annex I/III, Article 50, GPAI duties, roles, and dates.

art. 5 · art. 6 · annex i/iii
/eu-ai-governance:run-dpia

Runs a structured Data Protection Impact Assessment with GDPR Art. 35 scaffolding and AI-specific risk prompts.

gdpr art. 35
/eu-ai-governance:assess-ai-vendor

Builds a role map and evidence matrix, then ranks contractual, data-protection, security, change, and incident gaps.

roles · evidence · redlines
/eu-ai-governance:generate-evidence-pack

Maps requirements to approved artifacts and assembles a scoped review pack without claiming false completeness.

art. 11 · annex iv
/eu-ai-governance:review-ai-policy

Maps an internal AI policy to applicable controls and returns section-level gaps, owners, and proposed edits.

internal policy
/eu-ai-governance:ai-act-status

Snapshot of your organisation's readiness across classifications, DPIAs, vendors, and evidence, with the things that are still open.

readiness dashboard

A fictional classification, shown with its decisive boundary.

The example demonstrates output structure. It is not a current vendor finding or legal opinion.

example · fictional system · eu-ai-gov v1.1.0 legal baseline · 6 aug 2026
you
/eu-ai-governance:classify-ai-risk
system: "CV-Screen", an applicant tracking tool we are procuring from a German vendor. It ranks incoming CVs for role fit and filters out the bottom 40% before a recruiter sees them. Used across DE, FR, NL entities.
lexbeam · eu-ai-gov
RiskHigh CitationAnnex III § 4(a) ProviderThird-party (DE) DeployerYou · Art. 26 DPIARequired · Art. 35 GDPR FRIAConsider · Art. 27 Evidence packReady to generate

CV-Screen matches Annex III point 4(a) because it analyses and filters applications. Profiling defeats the Article 6(3) exception on these facts. Deployer duties under Article 26 attach when the high-risk rules apply. Article 27 does not make a FRIA mandatory for every private employer, so scope must be established separately. Automated rejection makes a GDPR Article 35 DPIA highly likely, subject to the controller’s documented test.

NextRun /eu-ai-governance:run-dpia
ThenRun /eu-ai-governance:assess-ai-vendor
Output/eu-ai-governance:generate-evidence-pack
fictional example · verify current law and facts install to run this yourself →

Built in public by a legal engineer.

Werner Plutat
Legal Engineer · LL.M. Business Law
Legal engineering · EU AI governance

This plugin is shaped around recurring in-house governance tasks: classification, vendor evidence, impact assessment, policy, and review packs. It is open source because compliance workflows should be inspectable and reusable.

"I did not want another dashboard. I wanted the Act itself at the cursor, cited, structured, and defensible to the partner on the other side of the table." · Werner Plutat, on why the plugin exists

Two commands, then start with your inventory.

Use the two commands below in Claude Code. In Cowork, upload the validated release ZIP from Settings → Plugins → Add → Create plugin. The Lexbeam MCP connects when the plugin is enabled and receives tool arguments when invoked.

$claude plugin marketplace add lexbeam-software/eu-ai-governance-plugin
$claude plugin install eu-ai-governance@lexbeam
You getsix commands, six skills, source discipline, and optional current-law retrieval. You controlwhich documents and connected sources are placed in scope.

Shipped recently.

v1.1.006 Aug 2026
source-groundedConnected Lexbeam’s EU AI Act MCP, corrected Article 5, Article 6, Annex III, FRIA, documentation and DPO boundaries, added deterministic validation, completed Apache licensing, and removed categorical liability and currency claims.
see CHANGELOG.md →