Metadata-Version: 2.5
Name: litmus-screener
Version: 1.0.1
Summary: LitmusAI — free, deterministic CLI screener for Article 5 of the EU AI Act (Regulation (EU) 2024/1689).
Project-URL: Homepage, https://aiexponent.com/products/litmusai
Project-URL: Documentation, https://aiexponent.com/docs/litmusai
Project-URL: Repository, https://github.com/aiexponent/litmusai
Project-URL: Issues, https://github.com/aiexponent/litmusai/issues
Project-URL: Changelog, https://github.com/aiexponent/litmusai/blob/main/CHANGELOG.md
Author-email: AI Exponent LLC <hello@aiexponent.com>
License: Apache-2.0
License-File: LICENSE
License-File: NOTICE
Keywords: ai-governance,article-5,cli,compliance,eu-ai-act,prohibited-ai-practices,screening
Classifier: Development Status :: 5 - Production/Stable
Classifier: Environment :: Console
Classifier: Intended Audience :: Developers
Classifier: Intended Audience :: Legal Industry
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Operating System :: OS Independent
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Topic :: Software Development :: Quality Assurance
Classifier: Typing :: Typed
Requires-Python: >=3.11
Requires-Dist: click<9.0,>=8.1
Requires-Dist: jinja2<4.0,>=3.1
Requires-Dist: jsonschema<5.0,>=4.0
Requires-Dist: pydantic[email]<3.0,>=2.5
Requires-Dist: pyyaml<7.0,>=6.0
Requires-Dist: rich<14.0,>=13.0
Requires-Dist: structlog<26.0,>=24.0
Requires-Dist: typer<1.0,>=0.12
Provides-Extra: dev
Requires-Dist: hypothesis<7.0,>=6.100; extra == 'dev'
Requires-Dist: licensecheck>=2024.2; extra == 'dev'
Requires-Dist: mypy<2.0,>=1.10; extra == 'dev'
Requires-Dist: pre-commit<5.0,>=3.7; extra == 'dev'
Requires-Dist: pytest-cov<7.0,>=5.0; extra == 'dev'
Requires-Dist: pytest-socket<1.0,>=0.7; extra == 'dev'
Requires-Dist: pytest<9.0,>=8.0; extra == 'dev'
Requires-Dist: ruff<1.0,>=0.5; extra == 'dev'
Requires-Dist: types-jsonschema; extra == 'dev'
Requires-Dist: types-pyyaml; extra == 'dev'
Description-Content-Type: text/markdown

<p align="center">
  <a href="https://aiexponent.com"><img src=".github/brand/logo-full-light.png" alt="AiExponent — Building AI that deserves to be trusted" width="560"></a>
</p>

<h1 align="center">LitmusAI</h1>
<p align="center"><em>Free, deterministic Article 5 screener for the EU AI Act.</em></p>

<p align="center">
  <a href="https://pypi.org/project/litmus-screener/"><img src="https://img.shields.io/pypi/v/litmus-screener.svg?style=flat-square&color=0D5463" alt="PyPI"></a>
  <a href="https://github.com/aiexponent/litmusai/actions"><img src="https://img.shields.io/github/actions/workflow/status/aiexponent/litmusai/ci.yml?branch=main&style=flat-square&label=CI" alt="CI"></a>
  <a href="LICENSE"><img src="https://img.shields.io/badge/License-Apache_2.0-0D5463.svg?style=flat-square" alt="License: Apache 2.0"></a>
  <a href="https://www.python.org/downloads/"><img src="https://img.shields.io/badge/python-3.11%2B-0D5463.svg?style=flat-square" alt="Python 3.11+"></a>
  <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689"><img src="https://img.shields.io/badge/EU%20AI%20Act-Article%205-0D5463.svg?style=flat-square" alt="EU AI Act Article 5"></a>
  <a href="#privacy"><img src="https://img.shields.io/badge/telemetry-zero-0B7A4B.svg?style=flat-square" alt="Zero telemetry"></a>
  <a href="#legal-review-status"><img src="https://img.shields.io/badge/ruleset_legal_status-UNREVIEWED-B68A2E.svg?style=flat-square" alt="Ruleset legal status: UNREVIEWED"></a>
</p>

---

> **LitmusAI 1.0.0 ships with the AiExponent reference ruleset (UNREVIEWED — internal panel authored, no external lawyer review). Apache 2.0, AS IS.**
>
> The package's CLI surface, JSON/SARIF schema, and BYO-ruleset contract are stable for production integration. The reference ruleset has been authored and reviewed by an internal AiExponent panel (six engineering + governance roles) but has **not** been reviewed by a qualified EU AI Act practising lawyer. Every screening report carries this disclosure prominently. Customers who require lawyer-reviewed output can supply their own signed ruleset via the BYO mechanism — see [`docs/ruleset-authoring.md`](docs/ruleset-authoring.md).
>
> A full external legal review will land in a `ruleset-2024-1689-v1.1` release with `legal_status: REVIEWED`. Tracked under [Legal review status](#legal-review-status) below.

---

Screen your AI system against the **eight prohibited-practice categories** of [Article 5](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689) of the EU AI Act (Regulation (EU) 2024/1689). Get a per-category **Red / Amber / Clear** verdict with regulatory citations, confidence levels, and remediation guidance — in under 60 seconds, without a sales call, without a paywall, and without uploading data to any server.

Built by [AI Exponent LLC](https://aiexponent.com). Apache 2.0. Runs entirely offline after `pip install`.

## Quick Start

```bash
pip install litmus-screener   # the brand is "LitmusAI"; the PyPI distribution is "litmus-screener"
```

```bash
# Quick screen from a text description
litmus screen --describe "a chatbot for mental health support for teenagers"

# Or from a structured YAML file
litmus init                                         # creates system.yaml template
litmus screen system.yaml --output report.json      # full screening with all 8 categories
litmus export report.json -o report.sarif --format sarif
```

## How It Works

```mermaid
graph LR
    A["system.yaml<br/>or --describe"] --> B["Parse +<br/>Validate"]
    B --> C["Rule Engine<br/>(22 rules)"]
    C --> D{"Per-category<br/>verdict"}
    D -->|RED| E["Prohibition<br/>likely"]
    D -->|AMBER| F["Legal review<br/>required"]
    D -->|CLEAR| G["No indicators<br/>found"]

    style A fill:#FCFCFA,color:#0F1419,stroke:#E4E2DC
    style B fill:#FCFCFA,color:#0F1419,stroke:#E4E2DC
    style C fill:#0D5463,color:#FCFCFA,stroke:#0D5463
    style D fill:#F5F4EF,color:#0F1419,stroke:#E4E2DC
    style E fill:#9D2929,color:#FCFCFA,stroke:#9D2929
    style F fill:#B8791C,color:#FCFCFA,stroke:#B8791C
    style G fill:#0B7A4B,color:#FCFCFA,stroke:#0B7A4B
```

## What LitmusAI Does

- Screens AI systems against all 8 categories of Article 5(1)(a)-(h)
- Produces **deterministic** verdicts: same input = same output, always
- Generates audit-ready reports (JSON, SARIF, Markdown)
- Runs in CI/CD as a pre-merge gate ([GitHub Action](.github/actions/litmusai-screen/) included)
- Works **fully offline** — zero network calls, zero telemetry
- Supports **[Bring-Your-Own-Ruleset](docs/ruleset-authoring.md)** — plug in your lawyer's signed interpretation

## Article 5 Categories Covered

| Category | Prohibition | Verdict logic |
|----------|------------|---------------|
| 5.1.a | Harmful manipulation | RED if subliminal + behaviour change |
| 5.1.b | Exploitation of vulnerabilities | RED if targeting minors/vulnerable + behaviour predictions |
| 5.1.c | Social scoring | RED if individual scores + behaviour history |
| 5.1.d | Criminal risk prediction | RED if profiling-based criminal risk output |
| 5.1.e | Untargeted facial scraping | RED if facial images + scraped data |
| 5.1.f | Emotion inference (work/education) | RED in workplace/education; AMBER in healthcare |
| 5.1.g | Biometric categorisation | RED if biometric + sensitive attribute classification |
| 5.1.h | Real-time remote biometric ID | RED if biometric + public space + real-time |

## CI/CD Integration

```yaml
# .github/workflows/article5.yml
- uses: aiexponent/litmusai/.github/actions/litmusai-screen@v1
  with:
    path: system.yaml
    fail-on: amber
```

## Commands

| Command | Description |
|---------|-------------|
| `litmus init` | Create starter system.yaml |
| `litmus screen` | Screen a system (YAML or `--describe`) |
| `litmus verify` | Check report hash integrity |
| `litmus portfolio` | Batch screen a directory |
| `litmus export` | Export to JSON, Markdown, or SARIF |
| `litmus debug` | Show rule-firing trace |
| `litmus use-ruleset` | Set a custom BYO ruleset |
| `litmus verify-ruleset` | Validate a ruleset file |
| `litmus ruleset-info` | Show active ruleset provenance |

## Documentation

- [Getting Started](docs/getting-started.md)
- [Article 5 Coverage](docs/article-5-coverage.md)
- [Bring Your Own Ruleset](docs/ruleset-authoring.md)
- [CI Integration](docs/ci-integration.md)

## Important Disclaimers

<a name="legal-review-status"></a>

### Legal review status

> **UNREVIEWED REFERENCE RULESET**
>
> The default LitmusAI ruleset (`ruleset-2024-1689-v1.0`) is a good-faith engineering interpretation of Article 5, authored by AiExponent's internal compliance panel. **It has not been reviewed or signed by a qualified EU AI Act lawyer and is not legal advice.**
>
> A full external legal review will land in a future `ruleset-2024-1689-v1.1` release with `legal_status: REVIEWED` and a SIGNED provenance header. The package version (`litmusai 1.0.0`) reflects API stability — the legal-review status rides on the ruleset version + the explicit `ruleset_legal_status: UNREVIEWED` line printed by `litmus version`.
>
> If your organisation needs a lawyer-signed ruleset today, see [docs/ruleset-authoring.md](docs/ruleset-authoring.md) for the BYO-ruleset path. A complete dummy-signed example ships in `tests/fixtures/rulesets/acme-corp-signed-v1.0.json`.
>
> Every screening is a screening, not a certification. **Not legal advice. Not a notified body.**

## Privacy

<a name="privacy"></a>

LitmusAI makes **zero network calls** during screening. No telemetry, no usage metrics, no crash reports. Your system descriptions never leave your machine. Enforced in CI via `pytest-socket --disable-socket`.

## License

Apache 2.0 — see [LICENSE](LICENSE).

---

*Part of the AiExponent open-source AI governance toolchain:*  
**litmusai** (Art. 5) · 
[license-compliance-checker](https://github.com/aiexponent/license-compliance-checker) (Art. 53) · 
[rag-benchmarking](https://github.com/aiexponent/rag-benchmarking) (Art. 15) · 
[riskforge](https://github.com/aiexponent/riskforge) (Art. 9) · 
[agentic-document-analyser](https://github.com/aiexponent/agentic-document-analyser) (Art. 9 / Annex IV)

---

<div align="center">
  <sub>
    <a href="https://aiexponent.com">aiexponent.com</a> ·
    <a href="mailto:hello@aiexponent.com">hello@aiexponent.com</a> ·
    Built in the open · Apache 2.0
  </sub>
</div>
