Regfortis

EU AI Act AI system inventory: a practical guide and template for SMEs

An AI system inventory — a structured record of every AI tool your business uses — is the essential foundation for EU AI Act compliance. Without knowing what AI you use, you cannot meet your Article 4, Article 50, or Article 26 obligations. This guide explains what to include and how to build one.

Last regulatory review: 14 August 2026 · Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744

What is an AI system inventory?

An AI system inventory is a structured register of every AI system or AI-powered tool your business uses professionally. For each system, the inventory records its purpose, the people it affects, how it is used, and its compliance status under the EU AI Act.

Unlike a general IT asset register, an AI inventory goes further: it captures the risk classification of each AI system, which EU AI Act obligations apply to it, and what compliance steps have been taken. It is a living document that evolves as your AI use-cases change.

Why do you need one for EU AI Act compliance?

The EU AI Act imposes different obligations depending on what AI systems you use and how you use them. Without a complete picture of your AI estate, you cannot:

Meet Article 4 (AI literacy)

You cannot ensure staff have "sufficient AI literacy" for systems you haven't mapped. The inventory tells you which staff interact with which AI — and therefore who needs what literacy support.

Comply with Article 50 (transparency)

You need to know which AI systems interact with customers or the public to implement the required disclosures. Missing a customer-facing AI chatbot from your inventory means a disclosure gap.

Prepare for Article 26 (high-risk AI)

Identifying which of your AI systems fall under Annex III is the first step. Without the inventory, you cannot prioritise which systems need fundamental rights impact assessments before December 2027.

Respond to supervisory enquiries

If a data protection authority, market surveillance authority, or the European AI Office asks what AI systems you use, the inventory gives you a structured starting point for regulator or adviser discussions.

What counts as an "AI system" for inventory purposes?

The EU AI Act defines an AI system in Article 3(1) as a machine-based system designed to operate with varying levels of autonomy that infers outputs such as predictions, recommendations, decisions, or content from inputs. Not every piece of software qualifies.

Likely in scope — include in inventory

  • → Generative AI tools (ChatGPT, Gemini, Copilot, Claude)
  • → AI-powered customer chatbots and virtual assistants
  • → AI-assisted recruitment or HR tools
  • → AI credit scoring or risk assessment tools
  • → AI content generation and image creation tools
  • → AI-based email filtering or triage systems
  • → Machine learning-based analytics with recommendations

Likely out of scope — may exclude

  • → Simple rule-based automation (if/then decision trees)
  • → Traditional statistical tools without learning components
  • → Basic spell checkers and grammar tools
  • → Search functions without AI-driven ranking
  • → Standard database queries and filters

When uncertain, include the system in the inventory and mark its scope status for review. An over-inclusive inventory is better than a gap.

AI system inventory template

Complete one record per AI system. You can maintain this as a spreadsheet, a shared document, or within your existing GDPR/DPIA register if you use one. The Regfortis Starter Pack documentation includes an editable template version.

System identification

System name

Name of the AI tool or system (e.g. "ChatGPT Enterprise", "HireVue Video Interview AI")

Provider

Name of the company that developed or supplies the AI system

Version / model

Version number or model designation where known

Date first used

When your organisation started using this system

Purpose and context

Business function

Which department or function uses this system (e.g. HR, Marketing, Finance, Customer Support)

Intended purpose

What the system is used for — be specific (e.g. "Summarising customer support tickets" vs "Ranking job applicants")

Affected persons

Who is affected by the AI's outputs — employees, customers, job applicants, or the general public

Decision type

Does the AI output inform decisions that significantly affect people? (Yes / No / Partially)

Risk classification

Prohibited practice check

Confirmed not within any Article 5 prohibited practice (Yes / Review needed)

Annex III category

Does this system match an Annex III high-risk use-case? (Yes / No / Uncertain — list category if Yes)

Risk level

Your assessment: Minimal / Limited / High risk

Compliance status

Article 4 (AI literacy)

Have relevant staff received AI literacy support for this system? (Yes / In progress / Not yet)

Article 50 (transparency)

If user-facing: is AI disclosure in place? (Yes / Not applicable / No — action required)

Article 26 (high-risk deployer)

If Annex III: FRIA status, database registration status (N/A if not high-risk)

Last compliance review date

Date the compliance status of this system was last reviewed

Oversight and contacts

Internal owner

Name and role of the person responsible for this AI system's compliance

Provider documentation

Location of provider's technical documentation, data processing agreement, or conformity declaration

Next review date

Scheduled date for next compliance review

How to keep your inventory current

An inventory that falls out of date creates compliance gaps. Build these practices into your AI governance routine:

Review on every new AI adoption

Before any team subscribes to a new AI tool or service, route it through a brief inventory intake. Add the system before it goes live.

Quarterly sweep

Every quarter, ask each team lead to confirm which AI tools their team uses. Shadow AI adoption (tools used without IT awareness) is common and creates undiscovered compliance gaps.

Annual compliance review

Once a year, review every entry for compliance status changes — including whether systems that were once not high-risk now fall into Annex III categories, or whether the regulatory landscape has changed.

Update on provider changes

When an AI tool provider releases a significant update, changes their data processing terms, or alters the AI model underlying their product, re-assess the affected entry.

Common mistakes SMEs make

  • Only listing IT-procured tools — missing AI tools adopted directly by departments on SaaS subscriptions
  • Treating AI embedded in standard productivity software (Microsoft 365 Copilot, Google Workspace AI) as out of scope without reviewing it
  • Creating the inventory once and never updating it as new tools are adopted
  • Not recording which specific staff interact with each AI system — making Article 4 literacy measures impossible to target
  • Failing to include providers' data processing agreements in the inventory, leaving a gap for Annex III documentation requirements

Frequently asked questions

Is an AI system inventory a legal requirement under the EU AI Act?

The EU AI Act does not require businesses to produce a document specifically called an "AI system inventory." However, maintaining one is practically necessary to demonstrate compliance with Article 4 (AI literacy — you must know which AI systems your staff use), Article 50 (transparency — you must know which AI systems interact with users), and the Annex III deployer obligations under Article 26, which require you to identify, assess, and register high-risk AI systems. Without an inventory, systematic compliance is not achievable.

Does Microsoft 365 Copilot or ChatGPT Enterprise need to be in my AI inventory?

Yes. Both Microsoft 365 Copilot and ChatGPT Enterprise are AI systems within the scope of the EU AI Act's Article 3(1) definition. Any AI tool your business uses professionally — including AI features embedded in productivity software — should be assessed and included in your inventory. The entry should record the tool's purpose, which staff interact with it, and its compliance status under Articles 4 and 50.

How often should I update my AI system inventory?

At minimum: add a new entry before any new AI tool goes into professional use, and conduct a comprehensive compliance review at least once per year. In practice, many businesses need quarterly sweeps to catch AI tools adopted by individual teams outside central IT procurement. The inventory should also be reviewed whenever a provider makes significant changes to their AI model or data processing terms.

What is the difference between an AI system inventory and a GDPR Record of Processing Activities?

A GDPR Record of Processing Activities (ROPA) documents all personal data processing in your organisation. An AI system inventory is focused specifically on AI systems and their EU AI Act compliance status. The two overlap where AI systems process personal data — which is common — but serve different regulatory purposes. They can be maintained as linked documents, with AI Act compliance fields added alongside the relevant ROPA entries for AI-driven processing activities.

Get a ready-to-use inventory template

The Regfortis documentation packs include an editable AI system inventory template pre-mapped to Article 4, Article 50, and Annex III compliance fields. Start your free assessment to see which pack is right for your business.

Start free assessment

Annex III guide →

Related guides

  • Article 4: AI literacy requirements
  • Annex III: High-risk AI guide
  • Full EU AI Act compliance checklist
  • Key compliance deadlines
  • Official regulatory sources
  • EU AI Act for SMEs — full guide

This guide is for informational purposes only and does not constitute legal advice.

Primary legal sources