Reguly
Reguly

EU AI Act

Ask your AI providers before someone asks you.

The models come from outside — responsibility for using them stays with you. GPAI requests turn scattered emails into a record with status, response rate and archived evidence.

GPAI provider requests in Reguly: status counts and a table of requests to OpenAI, Mistral AI and Microsoft
Regulation
AI Act (EU) 2024/1689
Context
Art. 25 — sourcing diligence
Module
AI compliance → GPAI requests
Status per request
5

What matters most

A number instead of a feeling

Above the table sits the balance: requests in total, as drafts, sent, answered, refused or expired — plus the response rate as a percentage. That is the difference between “we asked about that once” and a statement someone can check. Two limits stated plainly: no software can force a provider to reply — “Refused” is just as much part of the record. And the legal assessment stays with you.

Ausgangslage

The diligence happens — it just is not provable

Hardly anyone trains their own foundation models; almost everyone uses someone else’s. The information about them sits with the provider — and the request for it disappears into an inbox nobody else sees.

  • Who asked which provider and when is known only to whoever wrote the email.
  • Replies sit somewhere as an email attachment — not where the rest of the evidence lives.
  • Without a follow-up, an unanswered request quietly fizzles out and nobody notices.

How you work with it

01

Settle which models are in use at all

The request stands or falls with the list that comes before it. The AI inventory holds every system with provider, area of use and responsible contact, and the role check places your own role. From that follows, with a reason, who you have to ask.

AI inventory in Reguly with role check, figures and a system list with risk badges
02

Draft the request from the provider catalogue

The provider catalogue pre-fills the contact address, typical products and — where available — the link to the data processing documentation. Subject and body come from a versioned standard template and stay editable. If a provider is missing, you enter it freely.

03

Send it and keep an eye on the deadline

Sending runs over the same infrastructure as supplier data: your own template, a fixed recipient, a logged outbound. You set a deadline in days — 14 are pre-filled. When it passes, Reguly marks the row as “Reminder due”; you trigger the follow-up yourself.

Supplier requests in Reguly: the same request infrastructure that GPAI requests are sent over
04

Take the reply, archive it, log it

The reply lands on the item: text, time of arrival, status “Answered”, archived as an evidence document if you want. Every change appears in the audit log with timestamp and action — the sequence can be reconstructed later even without the people involved.

Audit log in Reguly with a chronological history of all actions including timestamp, action and entity

Im Zusammenspiel

Ein Datenbestand, der weiterreicht

  1. 01

    AI inventory

    says which third-party models are in use

    System & provider · Area of use · Risk class

  2. 02

    GPAI requests

    collects the information from the provider and logs the history

    Request text · Status · Reply · Response rate

  3. 03

    Compliance vault

    keeps the reply as an evidence document

    archived evidence

Frequently asked questions

Does this apply to me at all if I only use ChatGPT and Copilot?

Particularly then. Anyone using third-party foundation models is well advised to document which transparency information they requested from the provider — that is what this module is for. Whether and to what extent a specific obligation applies to you is something to settle with your legal advisers.

Do I have to write the request text myself?

No. Subject and body come from a versioned standard template, and the provider preset pre-fills the contact address and typical products. You can change both before sending.

Does Reguly send the reminder automatically?

No — and we say so deliberately. Reguly counts the deadline from the send date and marks the row as “Reminder due” once it is exceeded. You trigger the follow-up with a click; it then goes out as a new email to the same address.

Does the record apply to the whole company?

It is kept per brand. Everyone with access to the brand sees the same requests, the same status and the same response rate — not just the person who wrote the email.

Show us your AI list

We will go through with you which providers you should write to and what the record looks like in the end.

Reguly

Compliance & customer experience on one platform — PPWR, ESPR and EU AI Act, one data pool.

GDPR compliantEU hosted

Reguly is software for documenting and organizing regulatory requirements and does not provide legal advice within the meaning of the German Legal Services Act (RDG). All content and automatically generated assessments are for information only and do not replace a case-by-case legal review. Responsibility for meeting regulatory obligations remains with the user.

© 2026 Reguly. Made in Düsseldorf · EU compliance for brands.