An AI system inventory for the EU AI Act should identify each system, its intended purpose, operator roles, users, affected people, data, models, outputs, actions, category, evidence, and current version. A list of vendor names cannot support those decisions.
We reached the same conclusion while documenting Skybridge. “Uses Claude” told us almost nothing about a production release. The useful record named the workspace, task, source connections, model route, tool authority, approver, deployment, and known limits.
This template supports legal review but does not replace it.
A vendor list answers the wrong question
One SaaS product may contain a meeting summarizer, recruitment feature, writing assistant, and automated action. Those uses can have different purposes and classifications. One custom system can also depend on several suppliers.
Inventory records should therefore be organized around the AI system and use case. Link every system to its software and provider records. A provider name alone cannot describe the system.
Use one record with 12 fields
| Field | What to record |
|---|---|
| System identity | Name, internal owner, supplier, version, and environment |
| Intended purpose | Business result, designed use, and prohibited uses |
| People | Users, affected groups, approvers, and support contacts |
| Operator roles | Provider, deployer, upstream model provider, and other relevant actors |
| Data | Categories, sources, destinations, logs, retention, and regions |
| Models | Provider, model, version, routing rule, and change policy |
| Retrieval | Authorized sources, runtime access rule, index, and cache behavior |
| Outputs | Content, recommendation, score, prediction, or decision support |
| Actions | Read, draft, change, send, spend, delete, and prohibited operations |
| Classification | Scope reasoning, risk category, Article 50 analysis, and legal reviewer |
| Evidence | Instructions, tests, documentation, approvals, incidents, and monitoring |
| Lifecycle | Release date, review triggers, retirement, export, and deletion |
Add links to source artifacts. Copying every document into the inventory creates another stale store.
Discover systems through business work
Start with procurement and identity-management records, then interview the owners of recurring work. Ask which tools summarize, rank, predict, recommend, generate, or act. Include embedded features that arrived through a product update and departmental tools bought outside central procurement.
Inspect automations and API keys. An AI feature invoked by a scheduled workflow may never appear in a user survey. Review browser extensions and shared accounts with appropriate employee and privacy safeguards.
The goal is accountable discovery. It is not a hunt for someone to blame for experimenting.
Connect classification to evidence
A category field should contain reasoning and a date. Record the intended-purpose sentence, applicable provision, assumptions, reviewer, and next trigger. Link a high-risk conclusion to the obligation matrix. Link an Article 50 case to interface or marking evidence.
Where classification is unresolved, use “legal review required” and narrow the release. “Low risk” should never be the default value created by an empty cell.
What Skybridge added to our inventory method
Skybridge has separate development and production environments, configurable model routes, scoped connections, agent access, scheduled automations, and action tools. That implementation made five details especially important.
First, inventory the route used in the released system rather than every available provider. Second, record service identities alongside human users. Third, separate retrieval access from connector availability. Fourth, name action authority by operation. Fifth, bind evidence to an exact release.
The Skybridge cockpit records retrieval scope and approval history alongside the target production gate, keeping each release decision tied to current evidence.
Review changes before the inventory goes stale
Trigger review when the system receives a new purpose, user group, affected population, data category, model, supplier, retrieval route, action, or interface. Article 25 makes purpose and substantial changes particularly important for some high-risk systems.
Automate collection where it helps. A deployment pipeline can write the revision and model configuration. An identity system can report owners. A human still needs to decide what the change means.
Review the inventory with legal, technical, and operating owners on a proportionate cadence. Archive retired systems with evidence of data return or deletion. The EU AI Act compliance checklist shows how to use each record in a release decision.
Use status words that describe the decision. “Discovered” means the record still needs an owner. “Under assessment” means scope or classification remains open. “Evaluation only” means the system has a controlled test perimeter. “Released” means named owners accepted a defined version. “Restricted” means an explicit condition limits use. “Retired” means operation stopped and lifecycle work was completed. Avoid a single red, amber, or green field that mixes legal conclusion, engineering readiness, and business approval.
Give every unresolved field a due date and a person. An inventory becomes valuable when it creates work and prevents unsupported release, not when it merely increases the number of rows in a governance spreadsheet.
AI inventory questions
Is an AI use-case register the same as an AI system inventory?
They can be combined. The useful record connects the business use to the technical system, suppliers, data, authority, classification, and evidence.
Should employee use of public AI tools be included?
Include organizational uses that fall within the inventory policy and legal scope. Record the use and data path even when the company did not buy a custom system.
Who should own the inventory?
One function can maintain the process, while each system needs a business owner and technical owner. Legal, privacy, security, HR, and procurement contribute according to the use.
Primary references
Continue reading: EU AI Act 2026: What Businesses Must Do Now.