Every obligation under the European Artificial Intelligence Regulation (AI Act) depends on a preliminary question: what AI systems does the company have and what role does it play in relation to them? It is not possible to determine whether the transparency requirements under Article 50, the AI literacy requirements under Article 4 or the high-risk regime apply without having a complete map of the company’s systems.
That map is the AI systems inventory: the first deliverable of any compliance plan and one of the documents that a regulator, corporate client or investor in a due diligence process may request to understand how the company manages its use of artificial intelligence.
This guide explains how to build it.
What counts as an “AI system”
The AI Act defines an AI system as a machine-based system designed to operate with varying levels of autonomy, which may exhibit adaptiveness after deployment and which, for explicit or implicit objectives, infers from the input it receives how to generate outputs —such as predictions, content, recommendations or decisions— that can influence physical or virtual environments.
In practice, for a technology company, this should be interpreted broadly: it includes proprietary models, AI functionalities integrated through third-party APIs —such as OpenAI, Anthropic or Google—, SaaS tools with AI components and certain traditional scoring or recommendation systems.
By contrast, fixed programmed rules without the ability to infer are not AI systems, although the boundary requires a case-by-case analysis.
The three lists in the inventory
A common mistake is to inventory only the company’s own product. A complete inventory should cover three layers:
- AI developed by the company: proprietary models and systems, whether marketed externally or intended for internal use.
- AI integrated by the company: functionalities built on third-party models or APIs within the company’s products or processes. Integrating third-party AI does not exempt the company from obligations: depending on how the system is marketed, modified or used, the company may assume different roles under the AI Act.
- AI used internally by the company: third-party tools used by employees and teams, such as coding assistants, content generators, recruitment systems or customer support chatbots. This is where “shadow AI” often emerges: AI tools used by employees without internal authorisation, supervision or documentation.
Where to look: discovery sources
Identifying every system requires more than simply asking the IT department. Different sources should be cross-checked:
- Billing and SaaS subscriptions: recurring expenses may reveal tools that were never formally declared as AI systems.
- IT systems inventory and GDPR records of processing activities: a significant part of the work may already have been done if these two records are cross-referenced.
- Code repositories and dependencies: these can reveal SDKs, libraries and API calls to third-party models.
- Short departmental survey: HR, marketing, support, sales and development teams often account for a significant proportion of the AI tools used within an organisation.
- Supplier contracts: AI clauses, data processing addenda and API terms of use may reveal systems that need to be included in the inventory.
The record for each system
For each system identified, the inventory should include, at a minimum:
- name and functional description;
- provider of the model or underlying technology;
- the company’s role under the AI Act —provider, deployer, importer or distributor—;
- users and affected persons;
- data processed and whether personal data is involved;
- the decision, recommendation, content or other output produced;
- responsible department;
- purpose of the system;
- and contractual basis with the provider.
This record makes it possible to take the next step: classifying each system under the AI Act.
Classifying each system and assigning its compliance date
Once the map is complete, each system should be classified under the AI Act and assigned its corresponding compliance timetable. This exercise is particularly important following the changes introduced to the European regulatory calendar.
The main categories to review are:
- Prohibited practices (Article 5): the prohibitions started to apply on 2 February 2025. No system used by the company should fall within any of these prohibited practices.
- High-risk AI systems: certain systems falling within the areas covered by the AI Act —for example, certain uses related to employment, education, access to specific services or the assessment of individuals— are subject to an enhanced compliance regime and a specific timetable that must be analysed for each system.
- Transparency obligations (Article 50): these apply, among other cases, to certain systems that interact directly with individuals and to certain AI-generated or manipulated content, including deepfakes. These obligations form part of the regime applicable from August 2026.
- General-purpose AI models (GPAI): those developing and placing these types of models on the market are subject to specific obligations under the AI Act.
- Other systems: even where a system is not subject to specific high-risk or transparency obligations, it is advisable to document the legal assessment that led to that conclusion.
The inventory should also be connected to a cross-cutting obligation: Article 4 of the AI Act requires providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among their staff and other persons dealing with the operation and use of AI systems on their behalf. This obligation has applied since February 2025.
Keeping the inventory up to date
An AI systems inventory can quickly become outdated: every new functionality, provider, API or tool adopted by employees may change it.
Good practice is to appoint a person responsible for the inventory, establish periodic reviews —for example, quarterly in product companies— and integrate registration in the inventory into procurement processes, supplier onboarding and the development of new functionalities.
A dated, updated and version-controlled inventory also provides relevant evidence of diligence and AI governance in the event of regulatory supervision.
Conclusion
An AI systems inventory is not merely an administrative formality: it is the tool that makes it possible to determine which obligations apply to the company, to which systems and from what date.
Doing it properly helps avoid both non-compliance and over-compliance: spending time and resources on obligations that do not actually apply.
At our practice, we carry out AI system inventories and classifications as the first stage of our AI Act compliance audits for technology companies.
If your company develops, integrates or uses artificial intelligence, we can help you build your AI systems map and AI Act compliance plan.
