Skip to main content
Glama

Classify an AI system under the EU AI Act

classify_ai_system

Classifies an AI system into the EU AI Act risk tiers (prohibited, high, limited, minimal) from 9 facts about it. Returns the tier, a compliance score, findings with the legal article, the documents the tier requires, and a link to the saved report. Ask the user for any fact you do not know instead of guessing.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
industryYesSector where it is used.
companyNameNoOptional, shown on the saved report.
disclosesAiYesHow users are told it is AI.
aiSystemTypeYesWhat the system does.
consumerFacingYesPeople interact with it directly.
euJurisdictionYesWhether it is offered or its output used in the EU ("spain" if Spain specifically).
hasTechnicalDocsYesTechnical documentation of the system exists.
hasHumanOversightYesA person can review and override its output.
processesBiometricYesProcesses biometric data (face, voice, fingerprint, emotion).
makesConsequentialDecisionsYesEffect on people: binding decisions, influences a human decision, or none.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observed

TDQS

A4.1/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations are minimal (readOnlyHint=false, openWorldHint=false, destructiveHint=false) and do not explain why a classifier is not read-only; the description resolves this by disclosing that a report is saved and a link returned. It also describes the return payload (tier, compliance score, findings with legal article, required documents), adding real context beyond the annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Two sentences, front-loaded with what the tool does and its outputs, followed by a single actionable instruction; no filler or repetition of schema content.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

With no output schema and a 9-required-parameter input, the description covers the missing pieces: it summarizes the returned fields, notes the persisted report side effect, and tells the agent how to handle unknown facts.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100% with enum descriptions for all 10 parameters, so the schema carries the semantic burden; the description only says the input is '9 facts about it' without adding meaning to any individual fact. Baseline 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

Names a specific verb (classifies) and resource (AI system), enumerates the four EU AI Act risk tiers it outputs, and is clearly distinct from siblings like estimate_ai_act_fine and list_ai_act_deadlines.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Provides an interaction rule ('ask the user for any fact you do not know instead of guessing'), which is useful, but gives no guidance on when to choose this tool over siblings such as estimate_ai_act_fine or generate_ai_disclosure_notice, nor any prerequisite about what inputs are needed.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.

Resources