Compliance / AI Act
The AI Act sets duties by risk and by role. RegNext keeps an inventory of the AI systems your firm uses, tests each one against the regulation’s own criteria — a person confirms the result — and lists the duties that follow, each with its article.
What it asks
The AI Act sorts AI by risk and gives each role its own duties. If you use AI built by others, you are a deployer — until something you do makes you its provider.
Some uses of AI are banned outright — social scoring, for example, or manipulative techniques that cause harm.
Article 5Each system is tested against the eight prohibited practices, one question each, with the article’s text beside it.
Systems used in the areas the regulation lists — creditworthiness assessment or recruitment, for instance — are high-risk and carry the heaviest duties.
Article 6, Annex IIIThe product-safety route, the eight listed areas — credit scoring and insurance pricing flagged — and the exemption, which never applies when a system profiles people.
If you use a high-risk system: use it as instructed, assign human oversight, monitor it, keep its logs and inform the people concerned.
Article 26A few questions about how you use each system decide which duties apply — oversight, monitoring, logs, informing people, a fundamental-rights impact assessment where required — each in the law’s words.
Putting your name on a high-risk system, modifying it substantially or changing its purpose can make you its provider — with the provider’s duties.
Article 25The three ways a deployer becomes a provider, tested for each system, with a warning when one is met.
Inventory
Record each AI system with its purpose, its supplier and its business owner, and whether you use it for your firm or for a client. Its status follows it from draft to retirement.
Classification
Answer yes, no or don’t know to each test — the prohibited practices, the product-safety route, the high-risk areas and the exemption. RegNext proposes the class and a person confirms it. A missing answer leaves the system undetermined rather than guessed.
Duties
A few questions about how you use a system decide which deployer duties apply — human oversight, monitoring, keeping logs, informing staff and the people affected, an impact assessment where required. Each duty is shown in the law’s words. And if something you do would make you the provider, RegNext tells you.
Questions
No. Fixed tests taken from the regulation propose the class, a person confirms it, and a missing answer leaves the system undetermined.
Yes, as a deployer. Some duties concern every firm that uses AI, such as AI literacy; more apply when a system is high-risk. RegNext lists the ones that apply to each system.
It tells you when what you do would make you a provider. The provider’s own duties — and those for general-purpose AI models — are not covered yet.
RegNext tells you when one is required and that the authority must be notified. The assessment itself is written outside RegNext for now.
Recorded once
The company behind an AI system is also a supplier — an ICT provider under DORA, a processor under GDPR. RegNext records it once and shows it under every framework that applies.
Major incidents, critical functions and the register of information.
DORA NIS2Significant incidents, the measures of Article 21 and your supply chain.
NIS2 GDPRRecords of processing, DPIA screening, requests and breaches.
GDPR OverviewRisks, controls, policies, incidents and suppliers, shared across every framework.
Compliance
Explore how RegNext supports regulatory intelligence and compliance execution in your industry.