EU AI Act
Ask your AI providers before someone asks you.
The models come from outside — responsibility for using them stays with you. GPAI requests turn scattered emails into a record with status, response rate and archived evidence.

- Regulation
- AI Act (EU) 2024/1689
- Context
- Art. 25 — sourcing diligence
- Module
- AI compliance → GPAI requests
- Status per request
- 5
What matters most
A number instead of a feeling
Above the table sits the balance: requests in total, as drafts, sent, answered, refused or expired — plus the response rate as a percentage. That is the difference between “we asked about that once” and a statement someone can check. Two limits stated plainly: no software can force a provider to reply — “Refused” is just as much part of the record. And the legal assessment stays with you.
Ausgangslage
The diligence happens — it just is not provable
Hardly anyone trains their own foundation models; almost everyone uses someone else’s. The information about them sits with the provider — and the request for it disappears into an inbox nobody else sees.
- Who asked which provider and when is known only to whoever wrote the email.
- Replies sit somewhere as an email attachment — not where the rest of the evidence lives.
- Without a follow-up, an unanswered request quietly fizzles out and nobody notices.
How you work with it
Settle which models are in use at all
The request stands or falls with the list that comes before it. The AI inventory holds every system with provider, area of use and responsible contact, and the role check places your own role. From that follows, with a reason, who you have to ask.

Draft the request from the provider catalogue
The provider catalogue pre-fills the contact address, typical products and — where available — the link to the data processing documentation. Subject and body come from a versioned standard template and stay editable. If a provider is missing, you enter it freely.
Send it and keep an eye on the deadline
Sending runs over the same infrastructure as supplier data: your own template, a fixed recipient, a logged outbound. You set a deadline in days — 14 are pre-filled. When it passes, Reguly marks the row as “Reminder due”; you trigger the follow-up yourself.

Take the reply, archive it, log it
The reply lands on the item: text, time of arrival, status “Answered”, archived as an evidence document if you want. Every change appears in the audit log with timestamp and action — the sequence can be reconstructed later even without the people involved.

Im Zusammenspiel
Ein Datenbestand, der weiterreicht
01
AI inventory
says which third-party models are in use
System & provider · Area of use · Risk class
02
GPAI requests
collects the information from the provider and logs the history
Request text · Status · Reply · Response rate
03
Compliance vault
keeps the reply as an evidence document
archived evidence
Frequently asked questions
Does this apply to me at all if I only use ChatGPT and Copilot?
Particularly then. Anyone using third-party foundation models is well advised to document which transparency information they requested from the provider — that is what this module is for. Whether and to what extent a specific obligation applies to you is something to settle with your legal advisers.
Do I have to write the request text myself?
No. Subject and body come from a versioned standard template, and the provider preset pre-fills the contact address and typical products. You can change both before sending.
Does Reguly send the reminder automatically?
No — and we say so deliberately. Reguly counts the deadline from the send date and marks the row as “Reminder due” once it is exceeded. You trigger the follow-up with a click; it then goes out as a new email to the same address.
Does the record apply to the whole company?
It is kept per brand. Everyone with access to the brand sees the same requests, the same status and the same response rate — not just the person who wrote the email.
Passt dazu
Erst wissen, welche KI im Haus läuft.
Das KI-Inventar führt jedes eingesetzte KI-System mit Anbieter, Einsatzbereich und Verantwortlichem — und stuft es per Wizard in seine Risikoklasse ein.
Kompetenz, die sich belegen lässt.
Der AI-Literacy-Tracker protokolliert jede KI-Schulung mit Datum, Thema, Dauer und Teilnehmern — und warnt, wenn die letzte über 180 Tage zurückliegt.
Jeder Nachweis liegt bereit, keiner verfällt still.
Der Compliance-Vault legt alle Nachweise an einem Ort ab — Prüfberichte, Zertifikate und Erklärungen, versioniert und mit Ablaufüberwachung.
Show us your AI list
We will go through with you which providers you should write to and what the record looks like in the end.

