Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Template · the gateway artefact

AI system inventory

Every obligation, every questionnaire and every classification decision starts here. It is a spreadsheet at ten systems and a project at a hundred, and almost every organisation discovers it has more than it thought.

Gates Arts. 6(4), 49, 72ISO/IEC 42001 Annex A

The fields

FieldWhy it is there
System name and ownerA named person, not a team. Ownership is the field that decays fastest.
Intended purposeDrives classification, gets registered publicly, bounds marketing claims. Art. 3(12) →
Is it an AI system?The Art. 3(1) determination, with reasoning. Record the ones you concluded are not.
Your roleProvider, deployer, importer, distributor — per system, not per company. Flag Art. 25 exposure. Roles →
Risk tier and basisProhibited / high-risk / transparency / minimal, with the Annex III sub-point or Annex I instrument.
Art. 6(3) positionClaimed or not, with the profiling analysis and the date. Derogation →
Art. 50 exposureInteracts with people? Generates synthetic output? Live obligation.
Third-party componentsFoundation models, pre-trained components, labelling vendors. Annex IV heading 2 needs them.
Personal dataYes/no, categories, special categories. Links to the DPIA and FRIA questions.
Deployment geographyEU market placement, EU deployers, output used in the EU.
Log control and retentionWhich party holds which logs, for how long. The SaaS gap. Arts. 12, 19 →
Last reviewedAn inventory without a review date is a snapshot, not a control.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Shadow AI is the hard part

The systems you know about are the easy half. The other half is a marketing team’s copy generator on a corporate card, an analyst’s spreadsheet plugin, a support team’s summarisation tool inside a SaaS product they already had.

Practical recommendation. Three sources find most of it: expense and card data filtered for known AI vendors; your SSO and OAuth grant logs, which show what people actually connected; and a short amnesty survey that asks what people use without asking them to justify it. The last works considerably better than a policy reminder.

Then decide what you do about it. An inventory that triggers punishment stops being accurate within a quarter.

Who maintains it

The failure mode is not building it. It is that nothing adds to it. Three mechanisms that hold:

  • A gate in the delivery process. New system, new inventory row, before launch.
  • A procurement gate. New vendor involving AI, new row, at contract.
  • A scheduled review with a named owner and a date, matching your ISO/IEC 42001 review cycle if you have one.

Status labels on this page

Verified fact: Article references and dates cited above, checked against the consolidated Regulation.

Expert analysis: The tables, tiering and assessments on this page are our practice, not a standard.

Unsettled: Procurement practice is not codified and varies by buyer. Verify specific programme requirements against the buyer's own published materials.

Next step

The inventory is a management system output

Maintained by hand it decays. Produced and reviewed as part of a management system it stays current, and it is the same artefact that answers procurement questionnaires and seeds a conformity assessment.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What is an AI system inventory?

A register of the AI systems an organisation develops or uses, recording for each one the intended purpose, the organisation's role in relation to it, its risk classification and the basis for that classification, third-party components, personal data involvement, deployment geography, log control and retention, and a review date. It is the artefact that gates classification, registration, conformity assessment and customer due diligence.

Is an AI inventory required by the EU AI Act?

The Regulation does not name an inventory as a standalone deliverable. It is required in practice because several obligations cannot be met without one: the Article 6(4) documented classification assessment, Article 49 registration, Article 72 post-market monitoring and the Article 17 quality management system all assume you know which systems you have. ISO/IEC 42001 requires equivalent records through its Annex A controls.

How do you find shadow AI?

Expense and card data filtered for known AI vendors, single sign-on and OAuth grant logs showing which third-party tools people have connected, and an amnesty-framed survey that asks what people use without requiring them to justify it. Enforcement-framed discovery tends to produce an inventory that is inaccurate within a quarter.