Open source · CLI + GitHub Action · MIT
Find the AI in your codebase
Every AI Act programme starts with one question: which AI do we actually run? Most teams answer from memory and miss half of it. One command answers it from the code and gives you the inventory, with the article to check for each component.
View on GitHub →Run it in any repository (Node 18+)
npx github:jose-rdgz/ai-act-scan
7 AI components found (1 review first, 3 transparency, 2 classify, 1 info)
REVIEW FIRST Face recognition libraries
hiring-ml/requirements.txt
TRANSPARENCY Anthropic Claude API
support-bot/package.json, support-bot/.env.example
TRANSPARENCY ElevenLabs (voice synthesis)
support-bot/src/voice.ts
CLASSIFY scikit-learn
hiring-ml/rank.py, hiring-ml/requirements.txt
INFO Vector database
support-bot/package.jsonKeep the register
npx github:jose-rdgz/ai-act-scan --csv ai-inventory.csv
The CSV uses the columns of the AI system inventory template. Purpose and owner are left empty: code cannot know them, and they are what decides the tier.
Stop shadow AI in pull requests
Commit a baseline once, then fail any pull request that adds an AI component nobody has reviewed.
name: AI inventory
on: [pull_request]
permissions:
contents: read
jobs:
ai-act-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: jose-rdgz/ai-act-scan@v1
with:
baseline: .ai-inventory.json
fail-on: newThe report lands in the job summary. Without a baseline the action only reports and never fails.
How to read the result
Four labels, none of them a verdict
Review first
Face recognition, biometric analysis and emotion recognition libraries. Some uses are prohibited under Article 5; others are high-risk under Annex III point 1.
Transparency
Hosted and self-hosted generative models, agent frameworks, image and voice generation. Article 50 disclosure and marking duties apply when people interact with the system or you publish its output.
Classify
Your own models (PyTorch, TensorFlow, scikit-learn, gradient boosting, ONNX) and speech recognition. The tier depends entirely on what the model decides.
Info
Supporting components such as vector databases, which point to a retrieval-augmented feature worth listing.
From a list of libraries to a classification
The scanner finds components. The AI Act regulates systems and their intended purpose, so the next step is yours: group the components into the features they power, write down what each feature decides or produces and for whom, then classify it.
Classify a system in 7 questions (free, no account), see how common use cases are classified, or check which dates apply to you. Working inside an AI assistant? The MCP server exposes the same classifier.
FAQ
Frequently asked questions
Does my code leave my machine?
No. The scanner has zero dependencies and makes no network requests. It reads dependency manifests, source files and .env templates in the directory you point it at, and prints the result.
Does it read my secrets?
No. It only opens template files such as .env.example and only reads the variable names in them. A real .env file is never opened.
Can a scanner tell me if my system is high-risk?
No, and you should distrust any tool that claims it can. A library has no risk tier; a use does. The same scikit-learn model is minimal risk when it forecasts stock and high-risk when it ranks job applicants. The scanner tells you what you run and which articles to look at; the purpose decides the tier.
Which languages does it support?
JavaScript and TypeScript, Python, Go, Ruby, Java and Kotlin, Rust, .NET and PHP, through their dependency manifests, plus known AI API hostnames in any source file and model weight files committed to the repository.
What will it miss?
AI you buy as a feature of other software (the CV screener inside your recruiting tool, the chatbot inside your helpdesk) and anything outside the repository. Add those to the inventory by hand.
Is it free?
Yes. MIT licensed, on GitHub. Pull requests that add signatures are welcome.
General information about Regulation (EU) 2024/1689, updated 5 October 2026. Not legal advice.