01
The short answer
A company can build its inventory of artificial intelligence systems starting from the definition of an 'AI system' in Article 3 of Regulation (EU) 2024/1689, which describes an automated system capable of inferring from input how to generate outputs such as predictions, content, recommendations, or decisions. For each system identified, the company records the specific role it holds — provider, deployer, importer, or distributor — because each role carries distinct obligations; the regulation groups these roles, together with product manufacturer and authorised representative, under the umbrella term 'operator'. The inventory thus becomes the basis for documenting intended purpose, data processed, and management responsibilities.
02
Why roles matter
The regulation distinguishes precise roles along the supply chain. The provider develops the system or has it developed and places it on the market or puts it into service under its own name; the deployer uses it under its own authority, except for non-professional personal use; the importer places on the market a system bearing the mark of an entity from a third country; the distributor makes it available without being the provider or importer. The regulation defines 'operator' as the umbrella term covering provider, product manufacturer, deployer, authorised representative, importer, and distributor. Recording the specific role for each system in the inventory allows the obligations set out in the regulation to be correctly linked to each entry.
03
Steps to build the inventory
Steps
- List each AI system in use, checking whether it matches the definition in Article 3.
- For each system, indicate the company's specific role among provider, deployer, importer, or distributor, keeping in mind that 'operator' is the term that covers all of them.
- Record the intended purpose declared by the provider, including instructions for use and technical documentation.
- Note whether the system generates synthetic content, deep fakes, or uses emotion recognition or biometric categorisation.
- Link each high-risk system for which the company is a provider to the applicable risk management and post-market monitoring procedures.
04
Hypothetical example
Hypothetical example: a manufacturing company uses a predictive maintenance system developed by a third-party provider. In the inventory, it records the system as used in the capacity of deployer, notes its intended purpose as indicated in the provider's technical documentation, and verifies that it does not generate synthetic content nor use emotion recognition, so it does not trigger the transparency obligations described for those specific cases.
05
What to record for each system
- System name and correspondence with the AI system definition in Article 3.
- The company's specific role: provider, deployer, importer, or distributor, noting that 'operator' is the umbrella term covering all of them.
- Intended purpose and instructions for use provided by the provider.
- Presence of synthetic content, deep fakes, emotion recognition, or biometric categorisation.
- Link to the risk management system and post-market monitoring procedures, if the company is a provider of a high-risk system.
06
How software can support the inventory
A company can ask its software partner to configure a structured register that gathers, for each AI system, the role held, the intended purpose, and the data processed, as defined by the regulation. This is a suggested operational choice, not a software requirement: what matters is that the register be traceable, assign clear responsibilities among the roles involved, and keep documentation up to date over time, so it can be linked to risk management procedures when the company acts as a provider of a high-risk system.
07
Quick clarifications
- The inventory must clarify whether the company acts as a provider or as a deployer, because the obligations change accordingly.
- The intended purpose declared by the provider should be kept together with the technical documentation received.
- Systems that generate synthetic content or deep fakes require a specific notation in the inventory, subject to the exceptions provided.
08
The next step
The next useful step is to start the inventory from the systems already in use, assigning each one the role set out by the regulation and the purpose declared by the provider, to build a solid basis on which to add further controls.
FAQ
Frequently asked questions
What is an 'AI system' under the regulation?
It is an automated system that operates with varying levels of autonomy, may adapt after deployment, and infers from input how to generate outputs such as predictions, content, recommendations, or decisions.
What is the difference between a provider and a deployer?
The provider develops the system and places it on the market or puts it into service under its own name; the deployer uses it under its own authority, except for non-professional personal use.
When does a system require additional transparency obligations?
When it generates synthetic content, images, or manipulated audio/video ('deep fakes'), or uses emotion recognition or biometric categorisation, subject to the exceptions provided by the regulation.
✓