Tests scope, every Article 5 prohibition, Article 6 and Annex I/III, Article 50, GPAI duties, roles, and dates.
An open-source Claude plugin for classification, DPIA and FRIA coordination, vendor and policy review, and traceable evidence packs. Embedded guidance is reviewed against enacted law; the Lexbeam MCP returns versioned legal summaries, obligations, deadlines, and official source links.
claude plugin marketplace add lexbeam-software/eu-ai-governance-plugin
The commands separate supplied facts, legal duties, national-law questions, contractual controls, and recommended practice.
Tests scope, every Article 5 prohibition, Article 6 and Annex I/III, Article 50, GPAI duties, roles, and dates.
Runs a structured Data Protection Impact Assessment with GDPR Art. 35 scaffolding and AI-specific risk prompts.
Builds a role map and evidence matrix, then ranks contractual, data-protection, security, change, and incident gaps.
Maps requirements to approved artifacts and assembles a scoped review pack without claiming false completeness.
Maps an internal AI policy to applicable controls and returns section-level gaps, owners, and proposed edits.
Snapshot of your organisation's readiness across classifications, DPIAs, vendors, and evidence, with the things that are still open.
The example demonstrates output structure. It is not a current vendor finding or legal opinion.
CV-Screen matches Annex III point 4(a) because it analyses and filters applications. Profiling defeats the Article 6(3) exception on these facts. Deployer duties under Article 26 attach when the high-risk rules apply. Article 27 does not make a FRIA mandatory for every private employer, so scope must be established separately. Automated rejection makes a GDPR Article 35 DPIA highly likely, subject to the controller’s documented test.
This plugin is shaped around recurring in-house governance tasks: classification, vendor evidence, impact assessment, policy, and review packs. It is open source because compliance workflows should be inspectable and reusable.
"I did not want another dashboard. I wanted the Act itself at the cursor, cited, structured, and defensible to the partner on the other side of the table." · Werner Plutat, on why the plugin exists
Use the two commands below in Claude Code. In Cowork, upload the validated release ZIP from Settings → Plugins → Add → Create plugin. The Lexbeam MCP connects when the plugin is enabled and receives tool arguments when invoked.
This plugin supports professional governance work. It does not replace legal advice, and it is published under the limitations set out below in full.
Whether a particular use is a legal service depends on the facts, user, workflow, and degree of individual assessment. Outputs require appropriate professional review before consequential use.
Read full disclaimer →The license applies according to its terms and only to the extent permitted by law. The project does not predetermine which liability rules apply to a distribution or use.
Read full disclaimer →