arize-compliance-audit
INVOKE THIS SKILL when auditing an AI agent or LLM app for regulatory compliance. Covers EU AI Act, GPAI Code of Practice, GDPR, NIST AI RMF, Colorado AI Act, HIPAA, and ISO 42001. Scans the codebase for compliance gaps, cross-references Arize instrumentation for audit trail coverage, and produces an actionable remediation checklist tailored to the selected frameworks.
Security Assessment
About arize-compliance-audit
This skill audits an AI agent or LLM application for regulatory compliance across a broad set of frameworks: the EU AI Act, the GPAI Code of Practice, GDPR, NIST AI RMF, the Colorado AI Act, NYC Local Law 144, HIPAA, and ISO 42001. It solves the problem of teams not knowing where their AI system falls short of documentation, logging, transparency, and governance expectations, and it cross-references Arize instrumentation to check whether tracing captures the audit-trail evidence regulators expect.
The workflow opens with a mandatory legal disclaimer presented verbatim, then asks the user which framework families apply and what the use case category is, rather than auto-selecting. It favors inspection over mutation, scanning the codebase for compliance gaps and tailoring findings to the specific jurisdiction and use case instead of dumping the entire regulatory text. Detailed reference files translate the EU AI Act risk tiers, high-risk obligations (risk management, data governance, technical documentation, record-keeping, human oversight, accuracy and cybersecurity), GPAI commitments, GDPR intersections, US frameworks, and ISO 42001 controls into developer-actionable items. It produces a remediation checklist and offers to implement fixes only after explicit user confirmation, and it emphasizes never embedding literal credential values, always referencing environment variables instead.
Target users are AI engineers, compliance and risk teams, and product owners building LLM applications who need a technical, developer-focused first pass at regulatory readiness. It is explicitly guidance, not legal advice, and is best used before engaging qualified legal counsel.
FAQ
Which compliance frameworks does it cover?
The EU AI Act, GPAI Code of Practice, GDPR, NIST AI RMF, Colorado AI Act, NYC LL144, HIPAA, and ISO 42001, grouped into EU, US, and ISO selections.
Is this a substitute for legal advice?
No. It presents a disclaimer stating the audit is guidance only, identifies common technical patterns and gaps, and cannot replace qualified legal counsel.
Will it change my code automatically?
No. It prefers inspection over mutation, presents a checklist first, and only implements specific fixes after explicit user confirmation.
How does it decide which requirements apply?
It asks the user which framework families apply and what the use case category is rather than inferring, so a chatbot is not held to the same obligations as a hiring tool.
How does it handle secrets during the audit?
It never embeds literal credential values, always references environment variables, and never asks the user to paste secrets into the chat.
Install arize-compliance-audit
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
arize-ai/arize-skills