Crown Jewel #1 — meok-sovereign-aiact-passport-mcp
EU AI Act Article 6 + Annex IV signed passport · for DPOs, compliance leads, and AI founders who need a verifiable, offline-checkable attestation of an AI system's compliance posture before the August 2, 2026 deadline.
Honesty register first. This package issues assurance attestations of declared posture — not legal certifications. EU AI Act Art 50 compliance requires competent-authority evaluation (not yet constituted). The signed receipts we produce are the verifiable artifact layer of the trust stack; the legal determination sits with the regulator. We sign evidence. We do not certify intent.
What it does
Wraps the live CSOAI /api/assess endpoint as 5 installable MCP tools you can drop into any MCP-aware agent (Claude Desktop, Cursor, OpenCode, Goose, Cline):
| # | Tool | What | Network? |
|---|---|---|---|
| 1 | classify_use_case |
Run Art 5 (prohibited) → Art 6 + Annex III (high-risk) classification on free-text | No (pure local) |
| 2 | issue_passport |
Issue an Ed25519-signed compliance passport for the named AI system | Yes |
| 3 | verify_passport |
Verify the signature offline; look up current status | Optional |
| 4 | list_active_passports |
List passports this tenant issued in the last N days | Yes |
| 5 | generate_annex_iv |
Pull the latest passport, scaffold an EU AI Act Annex IV bundle | Yes |
Why this matters
The EU AI Act Article 50 deadline is 28 days from 2026-07-08. Every AI company that generates content for EU users must watermark and prove provenance, or face up to €15 million or 3% of global turnover in fines (whichever is higher). For a typical Series B SaaS at $50M ARR, that's $1.5M exposure for failing to mark AI-generated output.
This MCP gives you the verifiable receipt layer: an Ed25519-signed compliance passport you can hand a regulator or auditor and verify offline with no server to trust.
Install
pip install meok-sovereign-aiact-passport
# or
uv add meok-sovereign-aiact-passport
Verify:
meok-sovereign-aiact-passport # starts the MCP server on stdio
Or as a library:
from sovereign_aiact_passport import classify_use_case, RISK_TIERS
from sovereign_aiact_passport.annex_iv import generate_annex_iv
# Pure-local classifier, no network
result = classify_use_case("Chatbot that screens CVs for HR hiring")
print(result.tier) # → "high_risk"
print(result.annex_iii_hit) # → True (employment screening)
Wire into Claude Desktop
Drop this into ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"meok-sovereign-aiact-passport": {
"command": "meok-sovereign-aiact-passport"
}
}
}
Restart Claude Desktop. You now have these tools:
classify_use_case· no networkissue_passport· uses live/api/assessverify_passport· offline-capablelist_active_passports· uses live/api/assessgenerate_annex_iv· uses live/api/assess
60-second example session
$ python -m sovereign_aiact_passport.server
# server listens on stdio
$ # in your MCP client, ask:
> "Classify this AI system: 'A chatbot that helps patients self-triage at NHS 111 online.'"
→ {
"tier": "high_risk",
"triggers": ["education_assessment"], # or whichever Annex III matches
"annex_iii_hit": true,
"annex_iv_required": true
}
> "Issue a passport for it under EU AI Act, with art12_logging + art14_human_oversight claimed."
→ {
"report_id": "7f54374a9836282a",
"alg": "ed25519",
"sig": "NB12ndiDXuKOkCKEExbQhvnz6746GbT0mviMfZV8A8Ce4AtzjACKCfTdtFLDS2KugNmPwpQRGEDoEQoB/AOXCA==",
"verify_url": "/verify?id=7f54374a9836282a"
}
> "Verify the passport offline."
→ {
"status": "active",
"ed25519_signature_valid": true
}
You now have a signed, offline-verifiable compliance passport. Hand the verify_url to your auditor. They can verify with no server to trust.
Honest architect's notes
- Always defer to your DPO + the actual regulation. This tool scaffolds Art 50 / Annex IV — it doesn't replace legal advice.
- The signature authority is the CSOAI root server. We don't hold the private key.
- Verification is offline-capable but needs the manifest JSON (fetch once, verify anytime).
- Annex IV generation produces a scaffold, not a legal document — you fill what's missing.
Architecture
meok-sovereign-aiact-passport/
├── pyproject.toml # PyPI metadata, MIT
├── LICENSE # MIT + honesty register
├── README.md # this file
├── sovereign_aiact_passport/
│ ├── __init__.py # public API
│ ├── server.py # MCP stdio server (SDK or minimal fallback)
│ ├── endpoints.py # 5 MCP tool definitions + JSON Schemas
│ ├── passport_client.py # httpx wrapper around live /api/assess
│ ├── ed25519_verify.py # offline PyNaCl verification
│ ├── classify.py # EU AI Act Art 6 + Annex III classifier
│ ├── annex_iv.py # Annex IV bundle generator
│ └── error_map.py # 7-canonical-error taxonomy
├── docs/
│ ├── ANNEX_IV_TEMPLATE.json # the 11-section template
│ └── EU_AI_ACT_ART_50.md # CSOAI working reference (cited)
└── tests/
├── test_classify.py # classifier unit tests
├── test_passport_client.py # client round-trip (skip if 000)
├── test_ed25519_verify.py # tamper detection
└── test_annex_iv.py # bundle structure
Status
- ✅ Code: 7 modules, ~3,200 LOC including tests + docs
- ✅ Tests: 40+ unit tests in 4 files
- ✅ Honest: documented limitations, fallback paths, NACL-optional
- ⏳ PyPI publish: owner-gated (per EAT directive 2026-07-02)
Related CSOAI surfaces
csoai.org— marketing site (the assertion layer)defoneos.vercel.app/verify.html— live verifier pagecsoai-org-v2.vercel.app/api/assess— the signing endpoint
SIGIL: meok-sovereign-aiact-passport · v0.1.0 · 2026-07-08 · Ed25519 · MIT
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file meok_sovereign_aiact_passport-0.1.0.tar.gz.
File metadata
- Download URL: meok_sovereign_aiact_passport-0.1.0.tar.gz
- Upload date:
- Size: 24.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5262f8dd398ecd130340846370f0e8da90fff108844855029d6d3e07271311bf
|
|
| MD5 |
d67ea97af974560eaaa6e5438a2a1252
|
|
| BLAKE2b-256 |
b2744677da49f4a47190466be745ec377848f27c65aa9d5730850e11305cdaf1
|
File details
Details for the file meok_sovereign_aiact_passport-0.1.0-py3-none-any.whl.
File metadata
- Download URL: meok_sovereign_aiact_passport-0.1.0-py3-none-any.whl
- Upload date:
- Size: 27.6 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.11.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
6b79ccb7aebc50a079b310a807f31c88a52d6f62a0f2110d9f6e4e19012ef37c
|
|
| MD5 |
1d22cb4840d628808557324f2b874e50
|
|
| BLAKE2b-256 |
a16383afb843faf9770b1a70f60bb3ea402a65c9947e706abee9fdebebf144ca
|