Reguly

EU AI Act

First find out what AI is running.

A register of every AI system in your company: vendor, area of use, owner — and per system the risk class every other obligation follows from. Most companies find more than they expected.

AI Act (EU) 2024/1689 · Art. 4 in force since 02/02/2025, high-risk obligations from 02/08/2026

Your role

Which obligations apply depends on what you do with the AI.

The regulation knows four roles, and they do not exclude one another: pass a bought-in system on under your own name and you turn from deployer into provider, with markedly more duties. Eight questions settle where you stand.

  1. Provider

    develops or places on the market

  2. Deployer

    uses under own authority

  3. Importer

    brings in from third countries

  4. Distributor

    makes available unchanged

The same company can be deployer for one system and provider for another — which is why the check runs per system, not per company.

A register instead of a hunch

Every system with vendor, area of use, owner and contract status. The risk class sits on each row, and whatever is not yet classified shows up as such instead of slipping through.

More on the AI inventory
Reguly AI inventory: systems with vendor, area of use, owner and risk class per row

Ask your vendors before someone asks you

The models come from outside; responsibility for using them stays with you. Scattered emails become a log with status, response rate and archived evidence — including when a vendor refuses to answer.

More on GPAI requests
Reguly GPAI requests: enquiries to AI vendors with status, send date and response rate

Competence you can evidence

Article 4 requires sufficient AI literacy among the people operating your systems — in force since 2 February 2025, for everyone, regardless of risk class. The tracker turns that into a log instead of a claim.

More on AI literacy
Reguly AI literacy tracker: sessions with date, topic, duration and attendee count

The class decides the duties

Once the risk class is set, so is the list: transparency notices, human oversight, technical documentation, EU registration, fundamental rights impact assessment and serious-incident reporting — each with its reference.

More on the obligations
Obligations checklist for an AI system in Reguly, each item with its article reference and status

Try it

Classify a system — right here, no account.

The risk class is the hinge of the whole regulation: every other obligation follows from it. And it cannot be guessed, only worked through — prohibited practices under Article 5, high risk under Annex III, transparency duties under Article 50.

This is the very wizard customers use inside the product. It is fully available here: answer the questions, read the classification. Only the result is not saved, because saving it needs an account and a system to attach it to.

The Reguly risk wizard: questions under Article 5, Annex III and Article 50 with the running classification
  • Every question names its reference in the regulation.
  • The classification appears as you answer.
  • Nothing is sent and nothing is stored.
  • The classification is reasoned preparation, not legal advice.
Read the AI inventory documentation

Demo

We record your systems, not examples.

Bring a list, or just the three tools that come to mind. We enter them during the call, classify them and show which obligations follow — and which deadlines are already running.

About 30 minutes. Reguly is not a substitute for legal advice; the classification is reasoned preparation.

  • Your actor role gets settled, system by system.
  • The wizard runs on one of your real systems.
  • You see which vendors you have to write to.
  • Your Art. 4 training status gets an honest number.

The same platform carries the packaging and passport obligations. All three regulations at a glance.

Questions

What we get asked most.

Is the wizard’s classification legally binding?

No. It is structured, reasoned preparation — every question with its reference. What follows from it belongs in front of a lawyer; Reguly is not a substitute for legal advice.

Does this even apply to us if we only use ChatGPT and Copilot?

Yes. Anyone using an AI system under their own authority is a deployer and has duties — at minimum AI literacy under Art. 4, and for customer-facing systems the disclosure under Art. 50.

What exactly does Article 4 require?

Sufficient AI literacy among the people operating your AI systems. No scope is prescribed — you still have to evidence it. The duty has applied since 2 February 2025.

When is a FRIA due?

The fundamental rights impact assessment under Art. 27 applies to certain deployers of high-risk systems, not to everyone. Reguly flags when a system falls under it and walks you through the assessment.

Does Reguly report a serious incident to the authority?

No. The report stays your action. Reguly prepares it in full — facts, timestamps, affected system and evidence — and logs what was reported when.

Can we be deployer for one system and provider for another?

Yes, and that is the normal case. Pass a bought-in system on under your own name and you become its provider. That is why the role is checked per system, not per company.

What happens to a system we stop using?

It is archived, not deleted. The classification, the obligations list and the evidence remain — in an audit, what you used to run counts too.

Bereit anzufangen?

Start with the overview.

The inventory is the one thing that comes before everything else. Set it up — free and without a credit card.

Reguly is not a substitute for legal advice.