AI Act
GPAI requests
Request the information under Art. 53 from the vendors of the underlying models and document the process.
Why these requests?
Anyone deploying a general-purpose AI model — GPT, Claude, Gemini or an open model — relies on information only the vendor holds: technical documentation, a training-data summary, a copyright policy. Art. 53 obliges the vendor to make these available.
What counts for you is the documented process. Reguly keeps one request per vendor and product, with status, date sent and reply. If the information is withheld as a trade secret, that too is a result — it documents that you asked, and becomes the basis for your own risk assessment.
When do I send a request?
- After the inventory entry. Vendor and product are already there; the request picks them up.
- On a model change. A new model version may have different training data. The old answer does not cover it.
- When an audit is coming. The requests with status and date are the evidence that you exercised your duty of care.
Step by step
- 1
Create the request
Vendor, product and recipient address. Without an address it stays a draft.
- 2
Check the text
Reguly drafts the request under Art. 53. The text can be adjusted before it goes out.
- 3
Send and follow up
The status switches to “sent”. If no answer comes, a reminder can be scheduled.
- 4
Record the answer
Answered, declined or expired. For a refusal the reason belongs in the note — it carries your own assessment.
A refusal is not a failure
Common questions
Do I need one request per system or per vendor?
Does Reguly send the email itself?
Related pages

