Regfortis
EU AI Act AI system inventory: a practical guide and template for SMEs
An AI system inventory — a structured record of every AI tool your business uses — is the essential foundation for EU AI Act compliance. Without knowing what AI you use, you cannot meet your Article 4, Article 50, or Article 26 obligations. This guide explains what to include and how to build one.
Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744
What is an AI system inventory?
An AI system inventory is a structured register of every AI system or AI-powered tool your business uses professionally. For each system, the inventory records its purpose, the people it affects, how it is used, and its compliance status under the EU AI Act.
Unlike a general IT asset register, an AI inventory goes further: it captures the risk classification of each AI system, which EU AI Act obligations apply to it, and what compliance steps have been taken. It is a living document that evolves as your AI use-cases change.
Why do you need one for EU AI Act compliance?
The EU AI Act imposes different obligations depending on what AI systems you use and how you use them. Without a complete picture of your AI estate, you cannot:
Meet Article 4 (AI literacy)
You cannot ensure staff have "sufficient AI literacy" for systems you haven't mapped. The inventory tells you which staff interact with which AI — and therefore who needs what literacy support.
Comply with Article 50 (transparency)
You need to know which AI systems interact with customers or the public to implement the required disclosures. Missing a customer-facing AI chatbot from your inventory means a disclosure gap.
Prepare for Article 26 (high-risk AI)
Identifying which of your AI systems fall under Annex III is the first step. Without the inventory, you cannot prioritise which systems need fundamental rights impact assessments before December 2027.
Respond to supervisory enquiries
If a data protection authority, market surveillance authority, or the European AI Office asks what AI systems you use, the inventory gives you a structured starting point for regulator or adviser discussions.
What counts as an "AI system" for inventory purposes?
The EU AI Act defines an AI system in Article 3(1) as a machine-based system designed to operate with varying levels of autonomy that infers outputs such as predictions, recommendations, decisions, or content from inputs. Not every piece of software qualifies.
Likely in scope — include in inventory
- → Generative AI tools (ChatGPT, Gemini, Copilot, Claude)
- → AI-powered customer chatbots and virtual assistants
- → AI-assisted recruitment or HR tools
- → AI credit scoring or risk assessment tools
- → AI content generation and image creation tools
- → AI-based email filtering or triage systems
- → Machine learning-based analytics with recommendations
Likely out of scope — may exclude
- → Simple rule-based automation (if/then decision trees)
- → Traditional statistical tools without learning components
- → Basic spell checkers and grammar tools
- → Search functions without AI-driven ranking
- → Standard database queries and filters
When uncertain, include the system in the inventory and mark its scope status for review. An over-inclusive inventory is better than a gap.
AI system inventory template
Complete one record per AI system. You can maintain this as a spreadsheet, a shared document, or within your existing GDPR/DPIA register if you use one. The Regfortis Starter Pack documentation includes an editable template version.
System identification
System name
Name of the AI tool or system (e.g. "ChatGPT Enterprise", "HireVue Video Interview AI")
Provider
Name of the company that developed or supplies the AI system
Version / model
Version number or model designation where known
Date first used
When your organisation started using this system
Purpose and context
Business function
Which department or function uses this system (e.g. HR, Marketing, Finance, Customer Support)
Intended purpose
What the system is used for — be specific (e.g. "Summarising customer support tickets" vs "Ranking job applicants")
Affected persons
Who is affected by the AI's outputs — employees, customers, job applicants, or the general public
Decision type
Does the AI output inform decisions that significantly affect people? (Yes / No / Partially)
Risk classification
Prohibited practice check
Confirmed not within any Article 5 prohibited practice (Yes / Review needed)
Annex III category
Does this system match an Annex III high-risk use-case? (Yes / No / Uncertain — list category if Yes)
Risk level
Your assessment: Minimal / Limited / High risk
Compliance status
Article 4 (AI literacy)
Have relevant staff received AI literacy support for this system? (Yes / In progress / Not yet)
Article 50 (transparency)
If user-facing: is AI disclosure in place? (Yes / Not applicable / No — action required)
Article 26 (high-risk deployer)
If Annex III: FRIA status, database registration status (N/A if not high-risk)
Last compliance review date
Date the compliance status of this system was last reviewed
Oversight and contacts
Internal owner
Name and role of the person responsible for this AI system's compliance
Provider documentation
Location of provider's technical documentation, data processing agreement, or conformity declaration
Next review date
Scheduled date for next compliance review
How to keep your inventory current
An inventory that falls out of date creates compliance gaps. Build these practices into your AI governance routine:
Review on every new AI adoption
Before any team subscribes to a new AI tool or service, route it through a brief inventory intake. Add the system before it goes live.
Quarterly sweep
Every quarter, ask each team lead to confirm which AI tools their team uses. Shadow AI adoption (tools used without IT awareness) is common and creates undiscovered compliance gaps.
Annual compliance review
Once a year, review every entry for compliance status changes — including whether systems that were once not high-risk now fall into Annex III categories, or whether the regulatory landscape has changed.
Update on provider changes
When an AI tool provider releases a significant update, changes their data processing terms, or alters the AI model underlying their product, re-assess the affected entry.
Common mistakes SMEs make
- Only listing IT-procured tools — missing AI tools adopted directly by departments on SaaS subscriptions
- Treating AI embedded in standard productivity software (Microsoft 365 Copilot, Google Workspace AI) as out of scope without reviewing it
- Creating the inventory once and never updating it as new tools are adopted
- Not recording which specific staff interact with each AI system — making Article 4 literacy measures impossible to target
- Failing to include providers' data processing agreements in the inventory, leaving a gap for Annex III documentation requirements
Frequently asked questions
Is an AI system inventory a legal requirement under the EU AI Act?
The EU AI Act does not require businesses to produce a document specifically called an "AI system inventory." However, maintaining one is practically necessary to demonstrate compliance with Article 4 (AI literacy — you must know which AI systems your staff use), Article 50 (transparency — you must know which AI systems interact with users), and the Annex III deployer obligations under Article 26, which require you to identify, assess, and register high-risk AI systems. Without an inventory, systematic compliance is not achievable.
Does Microsoft 365 Copilot or ChatGPT Enterprise need to be in my AI inventory?
Yes. Both Microsoft 365 Copilot and ChatGPT Enterprise are AI systems within the scope of the EU AI Act's Article 3(1) definition. Any AI tool your business uses professionally — including AI features embedded in productivity software — should be assessed and included in your inventory. The entry should record the tool's purpose, which staff interact with it, and its compliance status under Articles 4 and 50.
How often should I update my AI system inventory?
At minimum: add a new entry before any new AI tool goes into professional use, and conduct a comprehensive compliance review at least once per year. In practice, many businesses need quarterly sweeps to catch AI tools adopted by individual teams outside central IT procurement. The inventory should also be reviewed whenever a provider makes significant changes to their AI model or data processing terms.
What is the difference between an AI system inventory and a GDPR Record of Processing Activities?
A GDPR Record of Processing Activities (ROPA) documents all personal data processing in your organisation. An AI system inventory is focused specifically on AI systems and their EU AI Act compliance status. The two overlap where AI systems process personal data — which is common — but serve different regulatory purposes. They can be maintained as linked documents, with AI Act compliance fields added alongside the relevant ROPA entries for AI-driven processing activities.
Get a ready-to-use inventory template
The Regfortis documentation packs include an editable AI system inventory template pre-mapped to Article 4, Article 50, and Annex III compliance fields. Start your free assessment to see which pack is right for your business.
Start free assessment
Annex III guide →
Related guides
- Article 4: AI literacy requirements
- Annex III: High-risk AI guide
- Full EU AI Act compliance checklist
- Key compliance deadlines
- Official regulatory sources
- EU AI Act for SMEs — full guide
This guide is for informational purposes only and does not constitute legal advice.