AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Israeli Ai Compliance Kit

skill-skills-il-security-compliance-israeli-ai-compliance-kit · by skills-il

Guide Israeli ML teams through the AI governance and compliance stack: Ministry of Innovation December 2023 AI policy principles, Privacy Protection Law (PPL) and Amendment 13 applied to ML training data, sector-specific rules (Bank of Israel Directive 364, Ministry of Health AMAR medical-device AI), and EU AI Act exposure for Israeli exporters. Generates model cards, data statements, and DPIA te…

No reviews yet
0 installs
24 views
0.0% view→install

Install

$ agentstack add skill-skills-il-security-compliance-israeli-ai-compliance-kit

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-skills-il-security-compliance-israeli-ai-compliance-kit)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Israeli Ai Compliance Kit? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Israeli AI Compliance Kit

Problem

Israeli ML teams shipping AI products face a fragmented compliance landscape: voluntary principles from the Ministry of Innovation, the Privacy Protection Law with Amendment 13 in force since August 14, 2025, sector regulators each drafting their own AI guidance, and the EU AI Act rolling out in staggered phases through 2027 that reach anyone selling into Europe. Most teams discover these requirements mid-procurement when an enterprise customer demands a model card, data statement, and DPIA. There is no unified checklist or template set tailored to the Israeli regulatory context.

Instructions

Step 1: Scope Your AI System

Before any compliance work, classify the system across four axes. The classification determines which regimes apply.

| Axis | Options | Why it matters | |------|---------|----------------| | System type | GenAI (LLM, image, audio), Predictive ML, Rule-based | EU AI Act GPAI obligations target GenAI. Predictive models fall under Annex III if used in high-risk domains | | Personal data | Yes (training or inference), No | Triggers PPL, Amendment 13 obligations, Data Security Regulations 2017 | | EU market exposure | Placed on EU market, Output used in EU, Neither | Determines EU AI Act applicability under Article 2 | | Israeli sector regulator | Banking (BoI), Health (MoH AMAR), Insurance (CMISA), Transport (MoT), Defense (MoD), None | Each regulator has distinct obligations; some predate AI-specific rules |

Output a one-page scoping memo with these four answers before continuing. This memo is the first artifact the customer's AI risk review will ask for.

Step 2: Israel's Ministry of Innovation AI Policy (December 2023)

The authoritative document is "Policy, Regulation and Ethics Principles in the Field of Artificial Intelligence", published December 14, 2023 jointly by the Ministry of Innovation, Science and Technology and the Ministry of Justice. It establishes Israel's "Responsible Innovation" approach: a voluntary, sector-based, risk-proportional framework rather than a horizontal law like the EU AI Act.

The policy contains 12 principles total, organized into two groups.

6 Regulatory Principles (governance-focused, how government should regulate):

  1. Whole-of-government approach
  2. Sector-based, risk-based regulation
  3. International alignment (OECD principles)
  4. Balanced and proportionate intervention
  5. Soft-law tools first (voluntary standards, guidance, sandboxes)
  6. Regular review and evolution

6 Ethical Principles (values-focused, how AI should be developed and used):

  1. Human-centric AI and respect for fundamental rights
  2. Non-discrimination and equality
  3. Transparency and notice
  4. Reliability and safety across the AI lifecycle
  5. Responsibility and accountability of developers and operators
  6. Promoting innovation for social welfare

For internal governance documentation, map each of your AI system's controls to the 6 ethical principles. This is the closest thing Israel has to a national AI framework, and enterprise customers in Israel are increasingly asking for alignment statements.

The Ministry of Innovation is formalising an AI Policy Coordination Center that is expected to release a Risk Management Toolbox for sector regulators (standardised impact-assessment templates and transparency-report patterns). Track its publications alongside PPA, Bank of Israel, and MoH circulars.

Two newer reference points to fold into governance docs:

  • The Innovation Authority published the National Program for Artificial Intelligence overview in May 2025, integrating activities across the Ministry of Innovation, Finance, Defense (DDR&D), Council for Higher Education, the National Digital Agency, and the Ministries of Foreign Affairs and Justice.
  • In January 2026 the US State Department and Israel announced a Strategic Partnership on AI, Research, and Critical Technologies, which gives Israeli AI exporters a more concrete signal to align with NIST AI RMF in dual-track US/EU compliance stories.

A new multi-year national AI strategy is anticipated after 2026, likely emphasising generative AI, LLM security, and environmental impact.

Step 3: Privacy Protection Law (PPL) Applied to ML

The PPL predates LLMs but applies to any ML pipeline processing personal information. Amendment 13 came into force on August 14, 2025 and modernises it significantly. The PPA granted a temporary grace period on the new DPO obligation until October 31, 2025 to let organisations prepare; that grace period has expired, so DPO appointment where triggers apply is now fully enforceable. Map each pipeline stage to its obligations:

| Pipeline stage | Core PPL obligations | Amendment 13 additions | |----------------|---------------------|------------------------| | Data collection | Lawful basis, consent or exemption, notice to data subjects | Expanded "personal information" definition, stricter consent standards | | Storage | Database registration thresholds, Data Security Regulations 2017 technical and organizational measures | Data Security Officer role for large databases | | Training | Purpose limitation, minimization | DPO role for orgs processing sensitive data at scale or doing systematic monitoring | | Inference | Data subject rights (access, correction, deletion) even for inferred attributes | Broader data subject rights, incident reporting | | Monitoring | Access logs, audit trails | Expanded breach notification obligations | | Retention | Retention limits proportional to purpose | Clearer deletion obligations |

The PPA draft AI guidance, published April 30, 2025 with public consultation closing June 5, 2025, is the first sector-specific signal. As of May 2026 it remains formally in draft and has not been finalised into a binding directive, but PPA officials have stated they will enforce it as if it were statutory. Treat it as the PPA's operative compliance standard and align with it as if binding. Key positions:

  • Legal basis is required at every lifecycle stage, including training
  • Unauthorized scraping of personal data for AI training is expressly prohibited
  • Data subject rights (access, correction, erasure) must be honored even when data is baked into model weights
  • Orgs heavily reliant on AI should appoint a DPO under Amendment 13, whom the PPA treats as the most suitable figure to handle AI-related privacy questions
  • Generative-AI usage policy: organisations should adopt an internal policy covering which tools are permitted, who may use them, what data may be uploaded, and retention limits on prompts

In February 2026 the PPA went further and published a final opinion on consent under Israeli privacy law, which the PPA treats as binding. The opinion explicitly addresses AI: scraping personal data from the internet to train AI models without informed consent is described as unlawful privacy infringement, and the PPA states that publishing data on social media does not constitute informed consent for AI training. Even with the AI guidance still formally in draft, the consent opinion now closes the "but the AI rules are just draft" defence on the scraping question.

Do NOT use web-scraped Hebrew social content or forum data for training without a documented legal basis. This is the fastest way to draw PPA enforcement attention under Amendment 13, the draft AI guidance, and the February 2026 consent opinion.

Step 4: Sector-Specific Rules

| Sector | Regulator | Relevant framework | What it actually requires | |--------|-----------|-------------------|---------------------------| | Banking, Fintech | Bank of Israel Supervisor of Banks | Proper Conduct of Banking Business Directive 364 (published 18/11/2024), consolidates former Directives 357, 361, 363 into "Management of IT, Information Security, and Cyber Protection Risks" | Technology-neutral governance, risk management, incident response for IT and cyber. Not AI-specific but applies to AI in banks. Model risk management lives in supervisory guidance | | Health, Medtech | Ministry of Health Medical Devices Division (AMAR) | AMAR framework applies to AI as software-as-medical-device | Registration, clinical validation, post-market surveillance. Compare to FDA SaMD framework for engineering analogies but not legal substitution | | Insurance | Capital Markets, Insurance and Savings Authority | Algorithmic decisions in underwriting and claims | Transparency, non-discrimination, appeals process | | Transport (autonomous) | Ministry of Transport | Test permit framework for autonomous vehicles | Insurance, safety driver, incident reporting | | Defense and dual-use | Ministry of Defense (DECA / DSDE) | Wassenaar Arrangement export controls (Israel is a participating state) | Export licensing for dual-use AI; applies to model weights and training data in some cases |

If your AI system operates in two or more of these sectors, the strictest regime generally prevails unless regulators have issued specific guidance on overlap.

Step 5: EU AI Act Exposure for Israeli Companies

Regulation (EU) 2024/1689 entered into force on August 1, 2024 with staggered applicability through 2027. An Israeli company is caught by the Act when:

  1. It places an AI system on the EU market (sells, licenses, or makes available to EU users)
  2. It puts an AI system into service in the EU under its own name
  3. The output of its AI system is used in the EU, even if the system is operated outside the EU

Key obligations by risk tier:

| Tier | Examples | Israeli exporter obligations | |------|----------|------------------------------| | Prohibited | Social scoring, real-time remote biometric ID in public for law enforcement, emotion recognition at work or school | Cannot place on EU market | | High-risk (Annex III) | Biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, administration of justice | Conformity assessment, risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity, quality management system, registration in EU database, authorized representative in EU | | Limited-risk | Chatbots, deepfakes, emotion recognition | Transparency obligations (disclose AI use, label synthetic content) | | Minimal-risk | Most other AI | Voluntary codes of conduct | | GPAI | Foundation models | Technical documentation, information to downstream deployers, copyright policy, training data summary; systemic-risk models face additional obligations |

Staggered timeline:

  • February 2, 2025 (now in force): Prohibitions (Article 5) and AI literacy obligations (Article 4) apply
  • August 2, 2025 (now in force): GPAI obligations, governance structures, and penalties apply. New GPAI models placed on the EU market after this date must comply immediately; providers of GPAI models already on the market before August 2, 2025 have until August 2, 2027 to bring their models and documentation into compliance
  • December 2, 2026 (upcoming): Article 50(2) synthetic-content transparency obligations apply. Providers of AI systems generating synthetic audio, image, video, or text must mark outputs as artificially generated in a machine-readable format
  • December 2, 2027 (revised, previously August 2, 2026): Annex III high-risk requirements under Articles 6-15 apply to stand-alone high-risk AI systems
  • August 2, 2028 (revised): High-risk requirements apply to AI systems embedded in products already regulated under sector-specific EU law (Annex I)

Note: the "Digital Omnibus on AI" agreement of May 7, 2026 (Council + Parliament provisional political agreement, pending formal adoption) postponed the Annex III high-risk deadline from August 2, 2026 to December 2, 2027, and the Annex I product-embedded deadline to August 2, 2028. It also compressed the Article 50(2) transparency grace period so it now takes effect December 2, 2026. GPAI obligations (in force since August 2, 2025) were NOT postponed. Formal adoption by Parliament and Council is expected in June or July 2026, ahead of the original August 2, 2026 deadline; if formal adoption slips past August 2, 2026 the unamended timeline reactivates. Treat these dates as provisional and confirm against the EU Official Journal before relying on them in customer commitments.

The European AI Office published the final General-Purpose AI Code of Practice on July 10, 2025, endorsed by the Commission and the AI Board on August 1, 2025. The Code is voluntary but is the Commission's preferred route for demonstrating compliance with GPAI obligations. It has three chapters: Transparency, Copyright, and Safety and Security. Israeli GPAI providers selling into the EU should consider signing onto the Code rather than building a bespoke compliance story.

Non-EU providers of high-risk AI systems must appoint an EU authorized representative under Article 22. Budget for this as a legal-ops cost, not an engineering one.

Step 5.5: Voluntary International Frameworks Worth Aligning With

Because Israel's MoI 2023 policy favours soft-law and OECD alignment, voluntary international frameworks accepted by Israeli regulators double as useful scaffolding for enterprise AI risk reviews:

| Framework | What it is | Why Israeli teams should care | |-----------|-----------|-------------------------------| | ISO/IEC 42001:2023 | First certifiable AI management system standard (AIMS). Published December 2023. Plan-do-check-act structure with 38 controls covering risk management, impact assessment, lifecycle management, third-party oversight. | Certification is increasingly asked for in enterprise procurement. Controls map cleanly to EU AI Act high-risk obligations and PPA guidance. Treat as the AI-specific counterpart to ISO/IEC 27001. | | NIST AI RMF 1.0 | US National Institute of Standards and Technology framework (January 2023) organised around Govern, Map, Measure, Manage. Augmented by the Generative AI Profile (NIST-AI-600-1, July 2024) and the Cyber AI Profile (preliminary draft NIST IR 8596 published December 16, 2025; comment period closed January 30, 2026; final expected later in 2026). RMF 1.1 addenda and an AI in Critical Infrastructure profile (concept note April 7, 2026) are also in flight. | OECD-aligned and widely accepted by US enterprise customers, and now reinforced by the January 2026 US-Israel Strategic Partnership on AI. The risk taxonomy fits alongside MoI 2023 ethical principles in compliance docs. | | OECD AI Principles | OECD Recommendation of the Council on AI, adopted 2019, updated 2024. | Explicitly referenced by Israel's MoI 2023 policy as a baseline. Alignment is essentially free in your governance docs. | | EU GPAI Code of Practice | Voluntary compliance route for EU AI Act GPAI obligations (July 2025, Commission-endorsed August 2025). | If you ship a foundation model into the EU, this is the lowest-friction compliance pathway. |

Pick one or two as the backbone of your documentation and cross-reference the rest. You rarely need all four at once.

Step 6: Generate Documentation Artifacts

Four artifacts cover most enterprise and regulatory asks:

  1. Model card: based on Mitchell et al. 2019 ("Model Cards for Model Reporting"). Add Israeli-context fields: PPL database registration status, Amendment 13 DPO designation, MoI 2023 principles alignment, sector regulator applicability. Use scripts/generate_model_card.py to render from a JSON input.
  1. Data statement: based on Bender & Friedman 2018 ("Data Statements for NLP"). For Hebrew datasets, explicitly document speaker or author demographics, dialect and register coverage (modern standard, religious, academic, spoken), nikud presence, code-switching with English or Arabic, source platforms, scraping lawfulness, and PII scrubbing method.
  1. DPIA (Data Protection Impact Assessment): aligned to PPL and Amendment 13. Full template in references/dpia-template.md. Required fields include purpose

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.