AI governance · 11 min read
AI System Inventory and Risk Classification | EU AI Act
An AI register is the control plane for governance. If the organization cannot see its systems, owners, purposes, data and changes, it cannot manage obligations or operational risk.

Define the unit of inventory
Register a business use case, not merely a model name or vendor contract. The same model used for recruitment screening and internal text summarization represents different purposes, affected people, decisions and risks.
Assign a stable identifier so approvals, assessments, incidents, contracts and technical records can point to the same system.
Capture the minimum decision-grade data
The record must be useful to legal, security, procurement and the business without becoming an unmaintainable questionnaire. Use structured fields and link detailed evidence rather than copying documents into free text.
- Purpose, scope, users and affected groups
- Provider, deployer and other AI Act roles
- Models, data sources, outputs and integrations
- Autonomy, human review and consequence of error
- Lifecycle state, owner, controls and evidence links
Classify through a gated workflow
Begin with prohibited-practice screening, then assess high-risk categories and transparency obligations. Record the questions, answers, reviewer and date. Escalate uncertainty instead of forcing a convenient classification.
Classification is not permanent. Define change triggers such as a new purpose, model replacement, sensitive data, a new affected population or increased autonomy.
Connect controls to the record
Each required control needs an owner, status, evidence and next review date. This turns the inventory from a spreadsheet into a work queue and provides management with an accurate view of unresolved exposure.
Use role-based access: broad discovery, controlled editing and protected evidence for sensitive systems.
Retire systems deliberately
Retirement should revoke access, stop integrations, resolve retention duties, archive required evidence and confirm that downstream processes no longer depend on the system. Keep the historical record for auditability.
Frequently asked questions
Should employee use of public AI tools be inventoried?
Material recurring use cases should be registered even when the company does not own the model, especially where company or personal data is processed.
How often should classification be reviewed?
At a defined periodic interval and whenever purpose, model, data, users, autonomy or deployment context changes materially.
Is a spreadsheet sufficient?
It can support an initial discovery exercise, but mature governance needs workflow, ownership, access control, evidence links and change history.