Reguly
Reguly

EU AI Act

First know which AI is running in the building.

A register of every AI system in your brand: provider, area of use, owner — and per system the risk class from which every further obligation follows.

AI inventory in Reguly: result of the role check, three recorded systems with risk class and responsible contact
Regulation
(EU) 2024/1689
Role check
8 questions
Risk classes
4 + unclassified
Areas of use
9

Ausgangslage

Nobody in the building knows how many AI systems are running

The AI Act ties every obligation to a specific system and its risk class. As long as the list of those systems does not exist, not a single obligation can be assigned cleanly — and none can be met.

  • AI rarely enters through IT: a subscription in marketing, an assistant in service, a pre-screening in recruiting — bought, not introduced.
  • Without a settled role it stays open which obligations bite: providers, deployers, importers, distributors and GPAI providers carry different loads.
  • The classification is made on gut feeling — without a recorded rationale anyone could follow later.

Zeitachse

What the obligations hang on

The regulation staggers its requirements partly by calendar, partly by the moment a system is placed on the market. The module carries these three stages, each with the article it comes from.

  1. Since February 2025

    AI literacy is mandatory

    Anyone operating AI needs sufficient AI literacy; documented training has been mandatory since then (Art. 4). If the last one is more than 180 days ago, the tracker speaks up.

  2. From August 2026

    Registration and incident reporting

    For high-risk systems under Annex III: registration in the EU database (Art. 71) and reporting of serious incidents (Art. 73). Reguly prepares both — you make the contact with the authority.

  3. Before placing on the market

    The system-bound trigger

    Not a date but a moment: the FRIA (Art. 27), the technical documentation (Annex IV) and the conformity assessment (Art. 43) must exist beforehand. Which is why the risk class is decided early.

How you work with it

01

Settle the role

Eight yes/no questions place you as provider, deployer, importer, distributor or GPAI provider and detect a high-risk case under Annex III. The result appears as role cards with the number of obligations that bite — each with its article and a note on what Reguly does and does not do about it.

02

Record the systems

Per system: name, provider, use case, area of use, categories of data processed and a responsible contact. Three figures hold the picture — active, high-risk or prohibited, not yet classified. Systems that have been retired are archived rather than deleted.

Dialog for recording an AI system in Reguly with fields for name, provider, product, purpose, area of use and the data categories from public to sensitive personal data
03

Classify the risk and derive the obligations

The wizard walks through prohibited practices, high risk, transparency and context, and shows live where the answers are heading. What is saved is not only the class but also the trigger with its article reference — the difference between an opinion and a verifiable classification. From that comes the checklist: for high risk including the FRIA, the technical documentation under Annex IV and the EU registration.

04

Collect provider information

Anyone using third-party foundation models documents the sourcing diligence under Art. 25: pick a provider preset, assemble the request, track the reply. If it does not come, Reguly reminds; when it does, it moves into the vault as an audit PDF.

GPAI requests in Reguly under Art. 25: requests per provider with status, response rate and send date
05

Prove competence

The literacy tracker keeps the record required by Art. 4: date, topic, duration, participants and the person delivering it, internal or external. If the last training is more than 180 days ago, that becomes a warning — visible in the obligations checklist on the system as well.

AI literacy tracker in Reguly under Art. 4 with trainings, participants, duration and the date of the last session

Im Zusammenspiel

Ein Datenbestand, der weiterreicht

  1. 01

    AI inventory

    holds the systems and their risk class

    Risk class · Trigger · Owner

  2. 02

    GPAI requests

    collects the AI providers’ information under Art. 25

    Provider reply · Response rate

  3. 03

    Compliance vault

    archives the evidence as a PDF

    FRIA · Submission package · Audit PDF

Frequently asked questions

Is the wizard’s classification legally binding?

No. It structures the classification along the criteria of the regulation and records which answer triggered it. The legal assessment stays with you or your law firm — Reguly does not provide legal advice.

When is a FRIA due?

As a deployer, in a high-risk case under Annex III and with the class “high”. Reguly then marks the fundamental rights impact assessment as the next step; completing it with a sign-off files it as a PDF in the vault.

Does Reguly report a serious incident to the authority?

No. Reguly records the incident with severity and time of discovery and counts the deadline — 72 hours for a death or a breach of fundamental rights, 15 days otherwise. You make the report. Incidents currently live client-side per system; a PDF export to the vault is planned.

What happens to a system we no longer use?

You archive it. It disappears from the figures and the default view, keeps its classification and history, and can be brought back through the filter.

Get the first overview

Show us in a conversation which AI tools are in use at your company — we will show you what the inventory looks like, roles and risk classes included.

Reguly

Compliance & customer experience on one platform — PPWR, ESPR and EU AI Act, one data pool.

GDPR compliantEU hosted

Reguly is software for documenting and organizing regulatory requirements and does not provide legal advice within the meaning of the German Legal Services Act (RDG). All content and automatically generated assessments are for information only and do not replace a case-by-case legal review. Responsibility for meeting regulatory obligations remains with the user.

© 2026 Reguly. Made in Düsseldorf · EU compliance for brands.