Skip to main content

AiExponent — Building AI that deserves to be trusted

LitmusAI

Free, deterministic Article 5 screener for the EU AI Act.

PyPI CI License: Apache 2.0 Python 3.11+ EU AI Act Article 5 Zero telemetry Ruleset legal status: UNREVIEWED


LitmusAI 1.0.0 ships with the AiExponent reference ruleset (UNREVIEWED — internal panel authored, no external lawyer review). Apache 2.0, AS IS.

The package's CLI surface, JSON/SARIF schema, and BYO-ruleset contract are stable for production integration. The reference ruleset has been authored and reviewed by an internal AiExponent panel (six engineering + governance roles) but has not been reviewed by a qualified EU AI Act practising lawyer. Every screening report carries this disclosure prominently. Customers who require lawyer-reviewed output can supply their own signed ruleset via the BYO mechanism — see docs/ruleset-authoring.md.

A full external legal review will land in a ruleset-2024-1689-v1.1 release with legal_status: REVIEWED. Tracked under Legal review status below.


Screen your AI system against the eight prohibited-practice categories of Article 5 of the EU AI Act (Regulation (EU) 2024/1689). Get a per-category Red / Amber / Clear verdict with regulatory citations, confidence levels, and remediation guidance — in under 60 seconds, without a sales call, without a paywall, and without uploading data to any server.

Built by AI Exponent LLC. Apache 2.0. Runs entirely offline after pip install.

Quick Start

pip install litmus-screener   # the brand is "LitmusAI"; the PyPI distribution is "litmus-screener"
# Quick screen from a text description
litmus screen --describe "a chatbot for mental health support for teenagers"

# Or from a structured YAML file
litmus init                                         # creates system.yaml template
litmus screen system.yaml --output report.json      # full screening with all 8 categories
litmus export report.json -o report.sarif --format sarif

How It Works

graph LR
    A["system.yaml<br/>or --describe"] --> B["Parse +<br/>Validate"]
    B --> C["Rule Engine<br/>(22 rules)"]
    C --> D{"Per-category<br/>verdict"}
    D -->|RED| E["Prohibition<br/>likely"]
    D -->|AMBER| F["Legal review<br/>required"]
    D -->|CLEAR| G["No indicators<br/>found"]

    style A fill:#FCFCFA,color:#0F1419,stroke:#E4E2DC
    style B fill:#FCFCFA,color:#0F1419,stroke:#E4E2DC
    style C fill:#0D5463,color:#FCFCFA,stroke:#0D5463
    style D fill:#F5F4EF,color:#0F1419,stroke:#E4E2DC
    style E fill:#9D2929,color:#FCFCFA,stroke:#9D2929
    style F fill:#B8791C,color:#FCFCFA,stroke:#B8791C
    style G fill:#0B7A4B,color:#FCFCFA,stroke:#0B7A4B

What LitmusAI Does

  • Screens AI systems against all 8 categories of Article 5(1)(a)-(h)
  • Produces deterministic verdicts: same input = same output, always
  • Generates audit-ready reports (JSON, SARIF, Markdown)
  • Runs in CI/CD as a pre-merge gate (GitHub Action included)
  • Works fully offline — zero network calls, zero telemetry
  • Supports Bring-Your-Own-Ruleset — plug in your lawyer's signed interpretation

Article 5 Categories Covered

Category Prohibition Verdict logic
5.1.a Harmful manipulation RED if subliminal + behaviour change
5.1.b Exploitation of vulnerabilities RED if targeting minors/vulnerable + behaviour predictions
5.1.c Social scoring RED if individual scores + behaviour history
5.1.d Criminal risk prediction RED if profiling-based criminal risk output
5.1.e Untargeted facial scraping RED if facial images + scraped data
5.1.f Emotion inference (work/education) RED in workplace/education; AMBER in healthcare
5.1.g Biometric categorisation RED if biometric + sensitive attribute classification
5.1.h Real-time remote biometric ID RED if biometric + public space + real-time

CI/CD Integration

# .github/workflows/article5.yml
- uses: aiexponent/litmusai/.github/actions/litmusai-screen@v1
  with:
    path: system.yaml
    fail-on: amber

Commands

Command Description
litmus init Create starter system.yaml
litmus screen Screen a system (YAML or --describe)
litmus verify Check report hash integrity
litmus portfolio Batch screen a directory
litmus export Export to JSON, Markdown, or SARIF
litmus debug Show rule-firing trace
litmus use-ruleset Set a custom BYO ruleset
litmus verify-ruleset Validate a ruleset file
litmus ruleset-info Show active ruleset provenance

Documentation

Important Disclaimers

UNREVIEWED REFERENCE RULESET

The default LitmusAI ruleset (ruleset-2024-1689-v1.0) is a good-faith engineering interpretation of Article 5, authored by AiExponent's internal compliance panel. It has not been reviewed or signed by a qualified EU AI Act lawyer and is not legal advice.

A full external legal review will land in a future ruleset-2024-1689-v1.1 release with legal_status: REVIEWED and a SIGNED provenance header. The package version (litmusai 1.0.0) reflects API stability — the legal-review status rides on the ruleset version + the explicit ruleset_legal_status: UNREVIEWED line printed by litmus version.

If your organisation needs a lawyer-signed ruleset today, see docs/ruleset-authoring.md for the BYO-ruleset path. A complete dummy-signed example ships in tests/fixtures/rulesets/acme-corp-signed-v1.0.json.

Every screening is a screening, not a certification. Not legal advice. Not a notified body.

Privacy

LitmusAI makes zero network calls during screening. No telemetry, no usage metrics, no crash reports. Your system descriptions never leave your machine. Enforced in CI via pytest-socket --disable-socket.

License

Apache 2.0 — see LICENSE.


Part of the AiExponent open-source AI governance toolchain:
litmusai (Art. 5) · license-compliance-checker (Art. 53) · rag-benchmarking (Art. 15) · riskforge (Art. 9) · agentic-document-analyser (Art. 9 / Annex IV)


aiexponent.com · hello@aiexponent.com · Built in the open · Apache 2.0

Metadata

Release files for litmus-screener 1.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for litmus-screener 1.0.1
File Size Uploaded
litmus_screener-1.0.1.tar.gz 66.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for litmus-screener 1.0.1
File Interpreter ABI Platform
litmus_screener-1.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 113.6 kB

Release files / litmus_screener-1.0.1.tar.gz

Download URL litmus_screener-1.0.1.tar.gz
Size 66.1 kB
Tags Source
SHA-256 checksum
How to use checksums
06f25a86ad529def34b4dd2c75971506d9e5faa08f4001cbaae66367d3dfadcb
BLAKE2b-256 checksum
How to use checksums
30591381430be0024c9b98c3ad1d0afe4587d46ea40abf8b99084972088ec860
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release files / litmus_screener-1.0.1-py3-none-any.whl

Download URL litmus_screener-1.0.1-py3-none-any.whl
Size 47.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
6c65c2e087ccf03b151286b32a18032a0794a07a6c113a64e1a4a326041f0844
BLAKE2b-256 checksum
How to use checksums
06e64458a3577e3f2b00897b25a3b915be4645d7d5b476d5a5fc22cb5e7a7159
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.1 This release

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page