01

The short answer

A company builds the inventory by listing, for each AI system in use, the role it holds (provider, deployer, importer, distributor or authorised representative), the intended purpose set by the provider, and the risk elements, as defined in Article 3 of Regulation (EU) 2024/1689.

02

Why role and purpose are the starting point

The Regulation precisely distinguishes who develops an AI system (the provider), who uses it under its own authority (the deployer), and who imports or distributes it. The intended purpose, communicated by the provider through instructions, promotional material and technical documentation, defines the legitimate context of use for every system listed in the inventory.

03

Practical sequence for populating the inventory

Steps

  1. List every active AI system, noting its name, function and original provider.
  2. Assign the correct company role for each system: provider, deployer, importer or distributor.
  3. Record the intended purpose stated by the provider in technical documentation or sales material.
  4. Register known risk elements, understood as the probability and severity of possible harm.
  5. Link each system to the data management and record-keeping procedures already in place.

04

A hypothetical case

Hypothetical case: a company uses a third-party tool to screen candidates during recruitment. In the inventory it records its own role as deployer, since it uses the system under its own authority, the intended purpose stated by the provider in the instructions for use, and links the system to internal data management and record-keeping procedures.

05

Minimum checks for each inventory entry

  • The assigned role (provider, deployer, importer, distributor, authorised representative) is correct.
  • The intended purpose is taken from the provider's documentation, not from an internal interpretation.
  • The risk level is noted as a combination of probability and severity of harm.
  • The data management procedures linked to the system are identified and traceable.
  • It is stated who within the company is responsible for updating the entry.

06

What a management software can oversee

A company can choose to set up, together with its software partner, a structured register that collects for each AI system the company role, the intended purpose, internal responsible persons, and links to the data management, monitoring and record-keeping procedures required for high-risk systems. This is a suggested operational criterion, not an obligation arising from the software itself.

07

Frequently recurring questions

The most common questions concern the distinction between provider and deployer, the minimum content of data management, and why the intended purpose should always be recorded exactly as stated by the provider.

08

Next step

The next step is to verify, system by system, whether the recorded company role truly matches actual use, and to link each inventory entry to the internal data management and record-keeping procedures already in place.

FAQ

Frequently asked questions

What is the difference between a provider and a deployer of an AI system?

The provider develops the AI system or has it developed and places it on the market under its own name; the deployer uses it under its own authority, except for personal, non-professional use.

What must the data management linked to a high-risk AI system include?

It includes acquisition, collection, analysis, labelling, storage, filtering, extraction, aggregation and retention of data, plus any other operation carried out before placing the system on the market or putting it into service.

Why should the inventory record the intended purpose stated by the provider?

Because the intended purpose defines the specific context and conditions of use indicated by the provider in instructions, promotional material and technical documentation, and delimits the legitimate use of the system.

Sources and verification