Praxikon
Server Details
EU AI Act and GDPR checks with sources: classify an AI system, trace each duty, find the supervisor.
- Status
- Healthy
- Last Tested
- Transport
- Streamable HTTP ยท MCP 2025-11-25
- URL
TDQS
Score is being calculated.
Available Tools
9 toolsanswer_questionAnswer a short general question about the AI Act or the GDPRRead-onlyInspect
Use this for a short, general question about the EU AI Act or the GDPR (AVG), such as whether a customer service chatbot has to say that it is AI or when a DPIA is required. It looks the question up in the published Praxikon answers: deterministic, no language model, and with the articles and sources. Before you call it, rewrite the question in general terms in at most 200 characters: no names of people or organisations, no contact details, no numbers that identify a person or a case. A question that looks like it contains personal data is refused. The question is not stored, logged or counted; only the use of the tool is counted per day. An unrecognised question returns no answer rather than a constructed one. For one concrete system or case, the coded assessment tools give a fuller answer.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the answer. Dutch is the default. | nl |
| question | Yes | The question in general terms, without names, contact details or identifying numbers. |
Output Schema
| Name | Required | Description |
|---|---|---|
| lang | Yes | |
| mode | No | scenario, semantic, gdpr, koppeling or none. |
| view | Yes | |
| answer | No | The compact answer, as the published answer endpoint returns it, without the question. |
| stored | No | |
| message | No | |
| answered | Yes | |
| provenance | Yes | |
| alternatives | No |
check_caseCasus-check AVG en AI ActRead-onlyInspect
Use this when the user describes a concrete, intended use of AI or of personal data (a system, a project, a supplier) and wants to know whether a DPIA, a FRIA or duties under the GDPR (AVG) and the EU AI Act come into play. It runs the Praxikon case check: fixed rules over fixed answers, the same rules as the case check on the site. It returns per law (GDPR, AI Act, and where the two meet) each test with its outcome, the article and a source link, the DPIA and FRIA signal, the next steps and the facts that are still open. Fill in the answers yourself from what the user said, and ask the user for a fact that decides a test rather than guessing it. Leave out what is not known: it counts as unknown, never as no. Send only these coded answers and never the case text, names or other personal data; there is no field for them. Show the notice with the result. It does not build the implementation graph or the obligation list of one AI system.
| Name | Required | Description | Default |
|---|---|---|---|
| org | No | What kind of organisation uses the system? Values: public = Government or public body (municipality, implementing agency); public_service = Private organisation providing a public service (e.g. education, healthcare, housing association); company = Company or other private organisation. | unknown |
| lang | No | Language of the result. Dutch is the default. | nl |
| role | No | What is the role of that organisation with regard to the AI system? Values: deployer = Uses a system from a supplier (deployer); provider = Develops it itself and places it on the market under its own name (provider); both = Develops it itself and also uses it itself (provider and deployer); gpai = Makes a general-purpose AI model, such as a language model, for others. | unknown |
| scale | No | Does it involve many people, or are people systematically monitored or observed? For example thousands of data subjects, all residents or customers, or continuous monitoring with cameras, location or software. | unknown |
| domain | No | What is the system used for? These areas are listed in Annex III or Annex I of the AI Act. For other insurance than life or health, or for fraud detection, choose none. Values: public_benefits = Granting, reducing or recovering benefits, allowances or other public services; credit = Creditworthiness or credit score of natural persons; life_health_insurance = Risk assessment and pricing in life or health insurance only; emergency = Classifying emergency calls or emergency healthcare; employment = Recruitment, selection, evaluation or task allocation of staff; education = Admission, evaluation or monitoring of tests in education; biometrics = Biometric identification or categorisation of people; law_enforcement = Police and criminal investigation; migration = Migration, asylum or border control; justice = Administration of justice or elections; critical_infra = Safety component of critical infrastructure (energy, water, traffic); product = Part of a product with CE marking, such as a medical device; none = None of these. | unknown |
| effect | No | Does the outcome have legal effects or affect people significantly (benefit, job, loan, investigation, exam)? | unknown |
| special | No | Does it involve special categories of personal data (health, genetic, biometric, racial or ethnic origin, religion or belief, political opinion, trade union membership, sex life or sexual orientation)? | unknown |
| aiSystem | No | Is it an AI system: does it infer the outcome from data itself (machine learning, language model), rather than only applying fixed rules written by a human? A system that only applies fixed rules drawn up by people, such as a calculation rule or a written-out decision tree, is not an AI system. A model trained on examples is, even if it does not keep learning after it is put into use. An expert system that draws conclusions by itself from encoded knowledge can be an AI system too. | unknown |
| criminal | No | Does it involve personal data relating to criminal convictions or offences, including a suspicion? Art. 10 GDPR: for example a criminal record, a criminal case, or a suspicion or report of an offence. | unknown |
| transfer | No | Do the data go to a country outside the European Economic Area, including via the supplier or a cloud? | unknown |
| automated | No | Is the decision about a person taken without a human assessing the case on its merits? Also yes if a human only sees part of it, such as the top ten, and the rest get a decision, such as a rejection, without human review. Merely not being selected for closer checks is no decision. | unknown |
| frequency | No | For how long and how often is the system used? Values: continuous = Continuously, with no end date: for every application or case, or every day; periodic = Periodically, with no end date: in fixed rounds, for example monthly or yearly; limited = For a limited period, such as a pilot or a one-off project. | unknown |
| inService | No | Was the system put into service or placed on the market before 2 December 2027? Also yes if it is in use now, or goes into use before that date. This concerns this system in its current form: if its design changes significantly afterwards, it counts as new. | unknown |
| profiling | No | Does the system produce a score, ranking or prediction about persons (profiling)? | unknown |
| interaction | No | Does the system do one or more of these things? Values: chatbot = People talk or chat with it directly; generated = It creates text, images, audio or video; deepfake = It creates images, audio or video that look real (deepfake); emotion = It recognises the emotions or mood of people. | |
| apCategories | No | Categories of the Dutch Data Protection Authority list of processing that requires a DPIA (Stcrt. 2019, 64418) that the facts of the case confirm. Leave out any category the facts do not show. | |
| personalData | No | Are personal data processed (data about identifiable people)? | unknown |
| interactionKnown | No | Whether the answer to interaction is settled, so that an empty list means none of these. Defaults to true when interaction is sent and to false when it is left out; never false when interaction lists items. |
Output Schema
| Name | Required | Description |
|---|---|---|
| dpia | Yes | |
| fria | Yes | |
| lang | No | |
| laws | Yes | |
| view | Yes | |
| notice | Yes | |
| sources | No | |
| headline | Yes | |
| law_date | No | |
| left_out | No | |
| provenance | Yes | |
| answers_used | No | |
| expert_review | Yes | |
| full_check_url | Yes | |
| open_questions | Yes | |
| recommendations | No | |
| transition_note | No |
classify_systemClassify one AI system against the routes of the RegulationRead-onlyInspect
Use this as the first step when you hold a concrete AI system and need to know which routes of the EU AI Act come into view: prohibited practice screening, Annex III high risk, transparency, FRIA and the general purpose model route, and with a version 2 profile the wider set of duties, such as Article 26 for a deployer. It runs the deterministic decision engine over coded answers and returns one applicability status per assessed obligation, with the timing and what is still open. It is not meant for a general question about the law. An obligation the engine did not assess is listed in assessment_scope.not_assessed with the reason; it was not found inapplicable. It does not return a single coded classification label.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the labels and explanations. Dutch is the default. | nl |
| detail | No | Amount of data to return. brief keeps the outcome, the dates, the reasons, the open questions and the source with its locator; full adds the complete objects, every statement text and every hash, for re-computation or archiving. | brief |
| profile | Yes | The coded answers about one system. The fifteen version 1 fields are required. A field that does not bear on this case takes not_relevant, and unsure is a real answer that leads to insufficient_context rather than to a guess. A version 1 profile has five obligations assessed. To have the wider set assessed, including Article 26 for a deployer of a high risk system, also send profile_version 2.0.0, chain_roles (consistent with actor_role) and the twelve other version 2 scope facts: ai_system_scope, jurisdiction_established_in_eu, jurisdiction_market_in_eu, jurisdiction_output_in_eu, scope_exclusion, annex_i_product, annex_i_third_party_conformity, article_25_role_change, provider_outside_eu, sandbox_participation, real_world_testing and adverse_significant_decision. The remaining version 2 facts are optional: an unanswered fact is unknown and leads to insufficient_context, never to a silent no. The backend rejects a profile whose answers contradict each other. |
Output Schema
| Name | Required | Description |
|---|---|---|
| view | No | |
| notes | No | |
| dataset | Yes | |
| privacy | No | |
| profile | No | |
| sources | No | |
| summary | Yes | |
| disclaimer | No | |
| provenance | Yes | Which published endpoints produced this result. Every call is listed with its full URL, so a reader can re-issue it and check the answer rather than trust it. |
| obligations | Yes | |
| snapshot_id | No | |
| blocking_flags | No | |
| deadline_notes | No | |
| open_questions | No | |
| assessment_scope | No | What this assessment did and did not assess, from the engine itself. not_assessed groups the obligations that were not assessed by reason (for example profile_version_below_2), with the facts that would have them assessed. Not assessed is not the same as not applying. |
| evaluation_scope | No | |
| payload_hash_sha256 | No | |
| decision_engine_version | No | |
| snapshot_schema_version | No | |
| evaluated_obligation_ids | No | |
| not_indicated_obligation_ids | No |
explain_applicabilityThe legal path behind one obligation, not only the outcomeRead-onlyInspect
Use this whenever you have to justify why an obligation does or does not bear on a case, and an outcome on its own is not enough. It returns the legal path: the conditions under which the rule is about a situation, the exceptions under which it is not despite those conditions, and the statements of the obligation split by kind, each with the primary source, the locator inside that source and the source record behind it. Supply a profile as well and the deterministic rule trace is added: which rule was met, not met or unknown for this case, plus the assumptions and the questions the engine could not settle. Use this rather than paraphrasing an obligation yourself: the conditions, the exceptions and the citations are published data and are not to be reconstructed from prose.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the labels and explanations. Dutch is the default. | nl |
| detail | No | Amount of data to return. brief keeps the outcome, the dates, the reasons, the open questions and the source with its locator; full adds the complete objects, every statement text and every hash, for re-computation or archiving. | brief |
| profile | No | The same coded profile that classify_system takes, with the same fields and codes: see the profile schema of classify_system. Send a version 2 profile to have the wider set assessed, including Article 26 for a deployer. The server validates the profile against that full schema. | |
| known_at | No | Knowledge time pin, a date or an ISO instant. Defaults to the release default. | |
| effective_at | No | Legal time pin, a date or an ISO instant. Defaults to the release default. | |
| obligation_id | Yes | The stable identifier, for example praxikon:eu:ai-act:obligation:article-50-transparency. |
Output Schema
| Name | Required | Description |
|---|---|---|
| pin | No | The release and the two time axes this answer resolved against. Store it next to anything you keep: an unpinned query is not reproducible, because the defaults move with each release. |
| view | No | |
| caveats | No | |
| sources | Yes | |
| assessment | Yes | Present only when a profile was supplied and the decision engine assessed this obligation for it. Null otherwise, with the reason in assessment_absent_reason and, when the engine said why, the detail in not_assessed. |
| legal_path | Yes | |
| obligation | Yes | |
| provenance | Yes | Which published endpoints produced this result. Every call is listed with its full URL, so a reader can re-issue it and check the answer rather than trust it. |
| not_assessed | No | Why the engine did not assess this obligation for this profile, as the engine reported it, with the facts that would have it assessed. For example profile_version_below_2: send a version 2 profile. |
| assessment_absent_reason | No |
export_dpia_intakeDPIA intake as a Word fileRead-onlyInspect
Use this when the user wants the DPIA intake of a concrete, intended use of AI or of personal data as a Word file to work on, and, where the FRIA comes into play, the FRIA draft too. It takes the same fixed fact answers as the case check of Praxikon, as coded choices, and gives the same documents as the download on the site: the four parts of Article 35(7) GDPR with the seventeen points of the Dutch government model DPIA, each point filled from the facts given, partly filled, or left as an open question, with articles and source links. Leave out what is not known: it counts as unknown and becomes an open question, never a no. Send only the coded answers and never the case text, names or other personal data; there is no field for them. The answer gives a download_url: the case check on the site with the answers in the part after #, which the browser never sends to the server; opening it shows the outcome and builds the Word file in the user's browser. Give the user that link, the explanation and the summary, and show the notice. Nothing is stored.
| Name | Required | Description | Default |
|---|---|---|---|
| org | No | ||
| lang | No | Language of the document. Dutch is the default. | nl |
| role | No | ||
| scale | No | ||
| domain | No | ||
| effect | No | ||
| special | No | ||
| aiSystem | No | ||
| criminal | No | ||
| transfer | No | ||
| automated | No | ||
| frequency | No | ||
| inService | No | ||
| profiling | No | ||
| interaction | No | ||
| apCategories | No | ||
| personalData | No | ||
| interactionKnown | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| date | No | |
| dpia | Yes | |
| fria | Yes | |
| lang | No | |
| view | Yes | |
| title | Yes | |
| notice | Yes | |
| stored | Yes | |
| summary | Yes | What the intake holds, point by point, as plain text to show in the chat. |
| documents | Yes | |
| provenance | Yes | |
| explanation | Yes | |
| fria_reason | No | |
| download_url | Yes | The case check with the answers in the URL fragment; the browser builds the Word file. |
| fria_included | Yes | |
| rules_version | No | |
| full_check_url | Yes |
get_applicable_obligationsWhich obligations the decision engine indicates for one systemRead-onlyInspect
Use this when you need the obligations themselves for one assessed system rather than the classification picture: which obligations apply, which possibly apply, from when, why, and on which source and locator. Returns one entry per assessed obligation, filtered by applicability. A version 2 profile has the wider set assessed, including Article 26 for a deployer of a high risk system, with one sub result per paragraph. This is the assessed route, not a catalogue of all obligations in the dataset.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the labels and explanations. Dutch is the default. | nl |
| detail | No | Amount of data to return. brief keeps the outcome, the dates, the reasons, the open questions and the source with its locator; full adds the complete objects, every statement text and every hash, for re-computation or archiving. | brief |
| profile | Yes | The same coded profile that classify_system takes, with the same fields and codes: see the profile schema of classify_system. Send a version 2 profile to have the wider set assessed, including Article 26 for a deployer. The server validates the profile against that full schema. | |
| applicability | No | Which applicability statuses to return. Defaults to applies and possibly_applies. The counters and evaluated_obligation_ids stay complete whatever you filter on, so a filtered list can never be read as the whole assessment. |
Output Schema
| Name | Required | Description |
|---|---|---|
| view | No | |
| dataset | No | |
| sources | No | |
| summary | Yes | |
| disclaimer | No | |
| provenance | Yes | Which published endpoints produced this result. Every call is listed with its full URL, so a reader can re-issue it and check the answer rather than trust it. |
| filtered_on | No | |
| obligations | Yes | |
| snapshot_id | No | |
| deadline_notes | No | |
| assessment_scope | No | What this assessment did and did not assess, from the engine itself. not_assessed groups the obligations that were not assessed by reason (for example profile_version_below_2), with the facts that would have them assessed. Not assessed is not the same as not applying. |
| evaluation_scope | No | |
| decision_engine_version | No | |
| evaluated_obligation_ids | Yes |
get_national_enforcementWho supervises, per member stateRead-onlyInspect
Use this for the national layer: which authority is designated in a member state, how far the implementing law has come, and which dated enforcement signals are recorded, each with a primary source. The authority is recorded as free text per member state and is deliberately not a graph identifier, because which national body fills the market surveillance role differs per member state. The same call returns the ruling register: judgments and supervisory decisions with the relation they bear to a provision (interprets, narrows, broadens, confirms, contradicts, or illustrates for context). An event says what happened, a ruling says what we know a provision means. Never present a related_gdpr ruling as AI Act case law: it rests on the GDPR and carries the illustrates relation only. This tool takes no lang: the tracker carries both languages on every record, in the fields that end in _nl and _en.
| Name | Required | Description | Default |
|---|---|---|---|
| type | No | Narrow to one event type, for example implementing_law. | |
| detail | No | Amount of data to return. brief keeps the outcome, the dates, the reasons, the open questions and the source with its locator; full adds the complete objects, every statement text and every hash, for re-computation or archiving. | brief |
| country | No | ISO 3166-1 alpha-2 country code, for example NL. Omit for all member states. | |
| known_at | No | Knowledge axis of the ruling register, as YYYY-MM-DD: returns the rulings we had recorded on that date and nothing that arrived afterwards. A provision keeps its own effective_at; only the reading moves. | |
| obligation | No | Slug of an obligation, for example article-50-transparency. Returns the rulings that bear on it. An empty result on an existing obligation means no ruling is recorded, not that the slug is wrong. |
Output Schema
| Name | Required | Description |
|---|---|---|
| view | No | |
| stats | No | |
| events | Yes | |
| filters | No | |
| rulings | Yes | |
| version | No | |
| countries | Yes | |
| provenance | Yes | Which published endpoints produced this result. Every call is listed with its full URL, so a reader can re-issue it and check the answer rather than trust it. |
| verified_at | No | |
| events_total | No | |
| ruling_register | No | |
| empty_result_note | No |
get_source_provenanceWhere a published statement comes fromRead-onlyInspect
Use this before you quote, cite or hand on anything from this graph, and whenever a reader asks on what authority a statement rests. It returns, for one object, every statement with its kind, its primary source, the locator inside that source and the review metadata, plus the source records behind those citations and a ready made citation block with the identifier, the object version, the payload hash and the release. Works for any object type, not only obligations.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the labels and explanations. Dutch is the default. | nl |
| detail | No | Amount of data to return. brief keeps the outcome, the dates, the reasons, the open questions and the source with its locator; full adds the complete objects, every statement text and every hash, for re-computation or archiving. | brief |
| known_at | No | Knowledge time pin. | |
| entity_id | Yes | The stable identifier of any object, for example praxikon:eu:ai-act:guidance:... or praxikon:eu:ai-act:obligation:... . An identifier in the flat raip:<type>:<slug> form published up to dataset 1.1.0 resolves to the same object. | |
| effective_at | No | Legal time pin. |
Output Schema
| Name | Required | Description |
|---|---|---|
| pin | No | The release and the two time axes this answer resolved against. Store it next to anything you keep: an unpinned query is not reproducible, because the defaults move with each release. |
| view | No | |
| found | Yes | |
| entity | No | |
| review | No | |
| caveats | No | |
| sources | Yes | |
| citation | No | |
| provenance | Yes | Which published endpoints produced this result. Every call is listed with its full URL, so a reader can re-issue it and check the answer rather than trust it. |
| statements | Yes | |
| source_review | No | |
| statement_counts | No |
request_expert_reviewTalk to a person about this questionRead-onlyInspect
Use this only when the user asks for it in their own words: they want to talk to a person, ask for a human expert, or ask how to get in touch about their situation. Never call it on your own initiative, never as a closing suggestion, and never because an answer seems uncertain. It returns a link to book a 30 minute introductory call with Zahed Ashkara, an independent AI and privacy consultant behind Praxikon. Send no part of the conversation: the tool takes only a language and, optionally, a topic from a fixed list, and nothing about the user. Show the title, the sentence and the link to the user as they are, and let the user decide whether to book.
| Name | Required | Description | Default |
|---|---|---|---|
| lang | No | Language of the text and of the booking page. Dutch is the default. | nl |
| topic | No | Optional subject of the question, from this fixed list only. It travels in the link as a campaign label (utm_content) to the booking page, so the booking can be traced to this tool. It is the only thing from the conversation that does; it names no person. |
Output Schema
| Name | Required | Description |
|---|---|---|
| url | Yes | |
| lang | Yes | |
| note | No | |
| text | Yes | |
| title | Yes | |
| topic | No | |
| provenance | Yes | |
| duration_minutes | Yes |
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
9 tool updates
- First observed
answer_question - First observed
check_case - First observed
classify_system - First observed
explain_applicability - First observed
export_dpia_intake - First observed
get_applicable_obligations - First observed
get_national_enforcement - First observed
get_source_provenance - First observed
request_expert_review
Related MCP Connectors
AI inventory and EU AI Act compliance. Find AI tools and use cases, check new AI uses before launch.
Classify any AI system under the EU AI Act: risk tier + binding Articles, verbatim from the law.
Classify AI systems by EU AI Act risk tier, estimate fines, write Art. 50 notices, list deadlines.
EU AI Act sovereignty scanning. Provider residency, registration status, audit trail support.
Related MCP Servers
- AlicenseAqualityCmaintenanceProvides comprehensive GDPR compliance assessment tools for AI/ML systems, including lawful basis determination, DPIA generation, and data subject rights handling. It also crosswalks GDPR requirements to EU AI Act obligations with AI-specific considerations throughout.64 npm45 PyPIMIT
- AlicenseAqualityDmaintenanceEnables EU AI Act compliance assessment by classifying AI systems, listing obligations, computing deadlines, and scanning repos for required documentation, all running locally.42MIT
- FlicenseNot gradedqualityDmaintenanceProvides an AI agent with regulatory compliance tools for the French/European market based on the AI Act and GDPR, including system classification, obligation listing, deadline schedules, legal reference lookup, and GDPR crosschecks.-
- AlicenseAqualityCmaintenanceScans codebases for AI frameworks, checks EU AI Act compliance, and generates compliance reports, roadmaps, and audit-ready packages.1611MIT
Glama MCP Gateway
Add one secure layer between your agents and this server.