Reguly
Reguly Docs

AI Act

AI inventory

Record every AI system in use, classify it and keep the classification on record.

What is the AI inventory?

The inventory is the list of every AI system your brand uses — with vendor, area of use, data types processed, contract status and the responsible person. It is the first thing market surveillance asks for and the basis of every further duty.

New entries start without a risk tier. The risk assistant walks through nine questions and then tags the system automatically — prohibited, high, limited or minimal. The answers are kept, so it stays traceable later why the classification came out as it did.

When do I add an entry?

  • Before the first productive use. The classification decides whether you may use the system at all — that is settled beforehand, not afterwards.
  • When the purpose changes. A chatbot that suddenly pre-sorts applications is a different system in the sense of the regulation. Re-assess it.
  • On a change of vendor. Vendor and model are part of the entry; they decide who the GPAI request goes to.

Step by step

  1. 1

    Create the system

    Via “New AI system”. Name, vendor and area of use are enough for a first entry.

  2. 2

    Add data types and contract

    Public, internal, personal or sensitive data — and whether a data-processing agreement is in place.

  3. 3

    Run the risk assistant

    Nine questions on purpose, affected people and context of use. At the end you get the tier, with the triggers that led to it.

  4. 4

    Work through the duties

    Depending on the tier: transparency notice, registration in the EU database, technical documentation or a fundamental-rights impact assessment.

  5. 5

    Re-assess on changes

    The assistant can be run again at any time; the previous assessment stays in the history.

Fields in an entry

FieldDescription
Name*What the system is called internally. Descriptive enough that colleagues recognise it.
Vendor*Who provides the model or the product. The addressee of the GPAI request.
Area of useSales/CRM, customer service, HR/recruiting, product/R&D or other. Drives the filter in the list.
Data typesPublic, internal, personal or sensitive. Does not decide the AI tier, but the GDPR duties alongside it.
Contract statusNo contract, standard terms, DPA signed or under review.
Responsible personWho owns this system in-house. The first point of contact in an audit.

* Required field

Archive rather than delete

A decommissioned system stays on record for the retention period. Archived entries drop out of the list but can be shown again via the “Archived” filter.

Common questions

Does every tool with AI belong in the inventory?
Everything used professionally that has an AI component. Including the spellchecker in your word processor — it will usually come out at minimal risk and is then done with.
What happens after the risk assistant?
The system is tagged with the tier automatically, and the triggers behind the classification appear in the result. For high risk, Reguly unlocks the further duties.

Related pages