/801-regulations-eu-ai-act
Use when reviewing, designing, or modifying Java enterprise systems that use AI, LLMs, AI agents, RAG, tool calling, workflow automation, or model-based decision support and need EU AI Act regulatory awareness. This should trigger for requests such as Review a Java AI system for
$ npx -y skills add jabrena/plinth --skill 801-regulations-eu-ai-act --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/801-regulations-eu-ai-act
Context preview
The summary Claude sees to decide when to auto-load this skill.
Use when reviewing, designing, or modifying Java enterprise systems that use AI, LLMs, AI agents, RAG, tool calling, workflow automation, or model-based decision support and need EU AI Act regulatory awareness. This should trigger for requests such as Review a Java AI system for
SKILL.md
801-regulations-eu-ai-act.SKILL.mdname: 801-regulations-eu-ai-act
description: Use when reviewing, designing, or modifying Java enterprise systems that use AI, LLMs, AI agents, RAG, tool calling, workflow automation, or model-based decision support and need EU AI Act regulatory awareness. This should trigger for requests such as Review a Java AI system for EU AI Act controls; Design governance for an AI agent with enterprise tools; Add human oversight and auditability to LLM workflows; Assess RAG or model-driven decision support before production release. Part of Plinth Toolkit
license: Apache-2.0
metadata:
author: Juan Antonio Breña Moral
version: 0.18.0
EU AI Act Regulation for Java Enterprise Development with AI Systems and AI Agents
Use this Skill to review Java enterprise applications that include AI capabilities, AI agents, tool-calling workflows, RAG systems, workflow automation, or model-driven decision support.
Apply this Skill to determine what engineering controls are required before the system is released, deployed, or connected to corporate systems of record.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when EU AI Act concerns may apply and how to translate policy expectations into enterprise architecture controls such as policy gates, human oversight, least privilege, audit evidence, monitoring, escalation workflows, and approval processes.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.
The main question is:
> When does a Java application or AI agent require EU AI Act-aware engineering controls, and what should developers build differently?
External reference: [European Parliament legislative resolution TA-9-2024-0138](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689).
EU AI Act chapters summary reference: [EU AI Act chapters summary](references/801-regulations-eu-ai-act-chapters-summary.md).
Java engineering examples reference: [EU AI Act engineering examples](references/801-regulations-eu-ai-act-engineering-examples.md).
Questionnaire asset: [EU AI Act engineering review questionnaire](assets/questions/801-eu-ai-act-risk-questionnaire.md).
Report template asset: [EU AI Act engineering review report template](assets/reports/801-eu-ai-act-engineering-review-report-template.md).
Scope
This Skill applies to:
- Java applications embedding AI models or LLMs
- Spring AI, LangChain4j, Quarkus AI, and custom AI integrations
- RAG applications and enterprise knowledge assistants
- AI agents capable of calling enterprise tools
- Workflow automation driven by AI decisions or recommendations
- AI systems interacting with databases, APIs, message brokers, filesystems, IAM platforms, CI/CD pipelines, cloud resources, or external services
- AI-generated code, SQL, Flyway migrations, Liquibase changelogs, infrastructure definitions, operational runbooks, or deployment actions
AI System vs AI Agent
An AI System generates information, recommendations, classifications, rankings, predictions, or content.
Examples:
- Customer support assistant
- Knowledge search assistant
- Internal chatbot
- Document summarization service
- Code-generation assistant
An AI Agent can execute actions through tools.
Examples:
- Database maintenance agent
- Migration generation agent
- CI/CD deployment agent
- Procurement automation agent
- Incident response agent
For enterprise governance purposes, AI Agents require additional review because they can directly modify systems, data, infrastructure, permissions, or business processes.
The engineering risk increases significantly when an AI system becomes an AI agent capable of executing actions through enterprise tools.
Even when a use case is not classified as EU AI Act High-Risk, organizations should implement human oversight, approval workflows, auditability, least privilege, monitoring, and operational controls before granting AI agents access to corporate systems of record.
Constraints
Translate EU AI Act concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by counsel, compliance, privacy, security, or risk owners.
- **NOT LEGAL ADVICE**: Frame findings as engineering risk controls and escalation points; recommend legal or compliance review for classification, jurisdiction, and regulatory interpretation
- **SCOPE**: Apply this skill to AI systems, LLM integrations, RAG, AI agents, tool calling, automated workflow decisions, and model-driven decision support in Java enterprise systems
- **CLASSIFICATION FIRST**: Distinguish AI system, AI agent, decision-support system, and fully automated action before recommending controls
- **HIGH-RISK SIGNALS**: Escalate use cases involving employment, education, credit, essential services, biometric identification, law enforcement, migration, justice, or safety-critical decisions
- **PROHIBITED OR SENSITIVE USES**: Flag manipulative, exploitative, social scoring, unlawful biometric, or surveillance-like patterns for immediate governance review
- **HUMAN OVERSIGHT**: Require explicit approval workflows for AI outputs or agent actions that can affect rights, access, money, employment, safety, production systems, or regulated records
- **LEAST PRIVILEGE**: Do not grant AI agents broad credentials, write access, production permissions, or unrestricted tools without scoped authorization, policy checks, and revocation paths
- **AUDITABILITY**: Preserve prompts, model versions, retrieved sources, tool calls, approvals, decisions, outputs, and operator overrides as reviewable evidence where policy requires it
- **DATA GOVERNANCE**: Validate data lineage, retention, privacy, access control, source attribution, and RAG corpus quality before using enterprise da
Read more
name: 801-regulations-eu-ai-act description: Use when reviewing, designing, or modifying Java enterprise systems that use AI, LLMs, AI agents, RAG, tool calling, workflow automation, or model-based decision support and need EU AI Act regulatory awareness. This should trigger for requests such as Review a Java AI system for EU AI Act controls; Design governance for an AI agent with enterprise tools; Add human oversight and auditability to LLM workflows; Assess RAG or model-driven decision support before production release. Part of Plinth Toolkit license: Apache-2.0 metadata: author: Juan Antonio Breña Moral version: 0.18.0
EU AI Act Regulation for Java Enterprise Development with AI Systems and AI Agents
Use this Skill to review Java enterprise applications that include AI capabilities, AI agents, tool-calling workflows, RAG systems, workflow automation, or model-driven decision support.
Apply this Skill to determine what engineering controls are required before the system is released, deployed, or connected to corporate systems of record.
This Skill is not legal advice. It helps Java engineers, architects, tech leads, platform teams, and reviewers identify when EU AI Act concerns may apply and how to translate policy expectations into enterprise architecture controls such as policy gates, human oversight, least privilege, audit evidence, monitoring, escalation workflows, and approval processes.
The purpose of this Skill is to increase awareness of potential gaps in the system and create engineering evidence for qualified review. The response produced by this Skill does not represent legal advice, a legal opinion, or a final regulatory determination.
The main question is:
> When does a Java application or AI agent require EU AI Act-aware engineering controls, and what should developers build differently?
External reference: [European Parliament legislative resolution TA-9-2024-0138](https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202401689).
EU AI Act chapters summary reference: [EU AI Act chapters summary](references/801-regulations-eu-ai-act-chapters-summary.md).
Java engineering examples reference: [EU AI Act engineering examples](references/801-regulations-eu-ai-act-engineering-examples.md).
Questionnaire asset: [EU AI Act engineering review questionnaire](assets/questions/801-eu-ai-act-risk-questionnaire.md).
Report template asset: [EU AI Act engineering review report template](assets/reports/801-eu-ai-act-engineering-review-report-template.md).
Scope
This Skill applies to:
- Java applications embedding AI models or LLMs
- Spring AI, LangChain4j, Quarkus AI, and custom AI integrations
- RAG applications and enterprise knowledge assistants
- AI agents capable of calling enterprise tools
- Workflow automation driven by AI decisions or recommendations
- AI systems interacting with databases, APIs, message brokers, filesystems, IAM platforms, CI/CD pipelines, cloud resources, or external services
- AI-generated code, SQL, Flyway migrations, Liquibase changelogs, infrastructure definitions, operational runbooks, or deployment actions
AI System vs AI Agent
An AI System generates information, recommendations, classifications, rankings, predictions, or content.
Examples:
- Customer support assistant
- Knowledge search assistant
- Internal chatbot
- Document summarization service
- Code-generation assistant
An AI Agent can execute actions through tools.
Examples:
- Database maintenance agent
- Migration generation agent
- CI/CD deployment agent
- Procurement automation agent
- Incident response agent
For enterprise governance purposes, AI Agents require additional review because they can directly modify systems, data, infrastructure, permissions, or business processes.
The engineering risk increases significantly when an AI system becomes an AI agent capable of executing actions through enterprise tools.
Even when a use case is not classified as EU AI Act High-Risk, organizations should implement human oversight, approval workflows, auditability, least privilege, monitoring, and operational controls before granting AI agents access to corporate systems of record.
Constraints
Translate EU AI Act concerns into engineering controls for Java enterprise systems. Do not provide legal advice or replace review by counsel, compliance, privacy, security, or risk owners.
- **NOT LEGAL ADVICE**: Frame findings as engineering risk controls and escalation points; recommend legal or compliance review for classification, jurisdiction, and regulatory interpretation
- **SCOPE**: Apply this skill to AI systems, LLM integrations, RAG, AI agents, tool calling, automated workflow decisions, and model-driven decision support in Java enterprise systems
- **CLASSIFICATION FIRST**: Distinguish AI system, AI agent, decision-support system, and fully automated action before recommending controls
- **HIGH-RISK SIGNALS**: Escalate use cases involving employment, education, credit, essential services, biometric identification, law enforcement, migration, justice, or safety-critical decisions
- **PROHIBITED OR SENSITIVE USES**: Flag manipulative, exploitative, social scoring, unlawful biometric, or surveillance-like patterns for immediate governance review
- **HUMAN OVERSIGHT**: Require explicit approval workflows for AI outputs or agent actions that can affect rights, access, money, employment, safety, production systems, or regulated records
- **LEAST PRIVILEGE**: Do not grant AI agents broad credentials, write access, production permissions, or unrestricted tools without scoped authorization, policy checks, and revocation paths
- **AUDITABILITY**: Preserve prompts, model versions, retrieved sources, tool calls, approvals, decisions, outputs, and operator overrides as reviewable evidence where policy requires it
- **DATA GOVERNANCE**: Validate data lineage, retention, privacy, access control, source attribution, and RAG corpus quality before using enterprise da
Languages: Español · 中文 Help this project grow: Become a sponsor
Other skills on plinth.
- /001-commands-inventory
Use when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the project root. This should trigger for requests such as Create embedded commands inventory checklist;
Open skill - /002-agents-inventory
Use when you need to generate a checklist document with embedded agents inventory, following the embedded template exactly and producing INVENTORY-AGENTS-JAVA.md in the project root. This should trigger for requests such as Create embedded agents inventory checklist; Generate
Open skill - /003-skills-inventory
Use when you need to generate a checklist document with Java system prompts from skills.xml, following the embedded section template and producing INVENTORY-SKILLS-JAVA.md. This should trigger for requests such as Create Java system prompts checklist; Generate
Open skill - /004-commands-installation
Use when you need to install the embedded project commands into command directories (.github/commands, .claude/commands, .cursor/command, .codex/commands), selecting the destination interactively and copying the embedded command definitions from project assets. This should
Open skill - /005-agents-installation
Use when you need to install the embedded robot agents into .github/agents, .claude/agents, .cursor/agents, or .codex/agents, selecting the destination interactively and copying the embedded agent definitions from project assets. This should trigger for requests such as Install
Open skill - /012-agile-epic
Guides the creation of agile epics with comprehensive definition including business value, success criteria, and breakdown into user stories. Use when the user wants to create an agile epic, define large bodies of work, break down features into user stories, or document
Open skill

