EU AI Act
First know which AI is running in the building.
A register of every AI system in your brand: provider, area of use, owner — and per system the risk class from which every further obligation follows.

- Regulation
- (EU) 2024/1689
- Role check
- 8 questions
- Risk classes
- 4 + unclassified
- Areas of use
- 9
Ausgangslage
Nobody in the building knows how many AI systems are running
The AI Act ties every obligation to a specific system and its risk class. As long as the list of those systems does not exist, not a single obligation can be assigned cleanly — and none can be met.
- AI rarely enters through IT: a subscription in marketing, an assistant in service, a pre-screening in recruiting — bought, not introduced.
- Without a settled role it stays open which obligations bite: providers, deployers, importers, distributors and GPAI providers carry different loads.
- The classification is made on gut feeling — without a recorded rationale anyone could follow later.
Zeitachse
What the obligations hang on
The regulation staggers its requirements partly by calendar, partly by the moment a system is placed on the market. The module carries these three stages, each with the article it comes from.
Since February 2025
AI literacy is mandatory
Anyone operating AI needs sufficient AI literacy; documented training has been mandatory since then (Art. 4). If the last one is more than 180 days ago, the tracker speaks up.
From August 2026
Registration and incident reporting
For high-risk systems under Annex III: registration in the EU database (Art. 71) and reporting of serious incidents (Art. 73). Reguly prepares both — you make the contact with the authority.
Before placing on the market
The system-bound trigger
Not a date but a moment: the FRIA (Art. 27), the technical documentation (Annex IV) and the conformity assessment (Art. 43) must exist beforehand. Which is why the risk class is decided early.
How you work with it
Settle the role
Eight yes/no questions place you as provider, deployer, importer, distributor or GPAI provider and detect a high-risk case under Annex III. The result appears as role cards with the number of obligations that bite — each with its article and a note on what Reguly does and does not do about it.
Record the systems
Per system: name, provider, use case, area of use, categories of data processed and a responsible contact. Three figures hold the picture — active, high-risk or prohibited, not yet classified. Systems that have been retired are archived rather than deleted.

Classify the risk and derive the obligations
The wizard walks through prohibited practices, high risk, transparency and context, and shows live where the answers are heading. What is saved is not only the class but also the trigger with its article reference — the difference between an opinion and a verifiable classification. From that comes the checklist: for high risk including the FRIA, the technical documentation under Annex IV and the EU registration.
Collect provider information
Anyone using third-party foundation models documents the sourcing diligence under Art. 25: pick a provider preset, assemble the request, track the reply. If it does not come, Reguly reminds; when it does, it moves into the vault as an audit PDF.

Prove competence
The literacy tracker keeps the record required by Art. 4: date, topic, duration, participants and the person delivering it, internal or external. If the last training is more than 180 days ago, that becomes a warning — visible in the obligations checklist on the system as well.

Im Zusammenspiel
Ein Datenbestand, der weiterreicht
01
AI inventory
holds the systems and their risk class
Risk class · Trigger · Owner
02
GPAI requests
collects the AI providers’ information under Art. 25
Provider reply · Response rate
03
Compliance vault
archives the evidence as a PDF
FRIA · Submission package · Audit PDF
Frequently asked questions
Is the wizard’s classification legally binding?
No. It structures the classification along the criteria of the regulation and records which answer triggered it. The legal assessment stays with you or your law firm — Reguly does not provide legal advice.
When is a FRIA due?
As a deployer, in a high-risk case under Annex III and with the class “high”. Reguly then marks the fundamental rights impact assessment as the next step; completing it with a sign-off files it as a PDF in the vault.
Does Reguly report a serious incident to the authority?
No. Reguly records the incident with severity and time of discovery and counts the deadline — 72 hours for a death or a breach of fundamental rights, 15 days otherwise. You make the report. Incidents currently live client-side per system; a PDF export to the vault is planned.
What happens to a system we no longer use?
You archive it. It disappears from the figures and the default view, keeps its classification and history, and can be brought back through the filter.
Passt dazu
Jeder Nachweis liegt bereit, keiner verfällt still.
Der Compliance-Vault legt alle Nachweise an einem Ort ab — Prüfberichte, Zertifikate und Erklärungen, versioniert und mit Ablaufüberwachung.
Die Verordnung, zerlegt in 16 Maßnahmen.
Die Compliance-Roadmap zerlegt die PPWR in 16 Maßnahmen mit Frist, Status und Verantwortlichem — von der Geltung ab August 2026 bis zu den Stufen ab 2030.
Get the first overview
Show us in a conversation which AI tools are in use at your company — we will show you what the inventory looks like, roles and risk classes included.

