AI Act
AI inventory
Record every AI system in use, classify it and keep the classification on record.
What is the AI inventory?
The inventory is the list of every AI system your brand uses — with vendor, area of use, data types processed, contract status and the responsible person. It is the first thing market surveillance asks for and the basis of every further duty.
New entries start without a risk tier. The risk assistant walks through nine questions and then tags the system automatically — prohibited, high, limited or minimal. The answers are kept, so it stays traceable later why the classification came out as it did.
When do I add an entry?
- Before the first productive use. The classification decides whether you may use the system at all — that is settled beforehand, not afterwards.
- When the purpose changes. A chatbot that suddenly pre-sorts applications is a different system in the sense of the regulation. Re-assess it.
- On a change of vendor. Vendor and model are part of the entry; they decide who the GPAI request goes to.
Step by step
- 1
Create the system
Via “New AI system”. Name, vendor and area of use are enough for a first entry.
- 2
Add data types and contract
Public, internal, personal or sensitive data — and whether a data-processing agreement is in place.
- 3
Run the risk assistant
Nine questions on purpose, affected people and context of use. At the end you get the tier, with the triggers that led to it.
- 4
Work through the duties
Depending on the tier: transparency notice, registration in the EU database, technical documentation or a fundamental-rights impact assessment.
- 5
Re-assess on changes
The assistant can be run again at any time; the previous assessment stays in the history.
Fields in an entry
| Field | Description |
|---|---|
| Name* | What the system is called internally. Descriptive enough that colleagues recognise it. |
| Vendor* | Who provides the model or the product. The addressee of the GPAI request. |
| Area of use | Sales/CRM, customer service, HR/recruiting, product/R&D or other. Drives the filter in the list. |
| Data types | Public, internal, personal or sensitive. Does not decide the AI tier, but the GDPR duties alongside it. |
| Contract status | No contract, standard terms, DPA signed or under review. |
| Responsible person | Who owns this system in-house. The first point of contact in an audit. |
* Required field
Archive rather than delete
Common questions
Does every tool with AI belong in the inventory?
What happens after the risk assistant?
Related pages

