01
The inventory starts from the regulation's definitions
A useful inventory records, for each system used in the organization, whether it matches the definition of 'AI system' under Article 3 and what role the organization plays with respect to it — provider, deployer, importer, distributor or authorized representative.
This distinction determines what information is needed next: intended purpose, reasonably foreseeable misuse, and the controls linked to the system.
02
Why roles and purposes matter
The regulation distinguishes the provider, who develops or has a system developed and places it on the market, from the deployer, who uses it under its own authority. Importer, distributor and authorized representative cover other positions in the supply chain; the regulation defines 'operator' more broadly, including the provider, product manufacturer and deployer in addition to the authorized representative, importer and distributor.
03
Steps to build the inventory
Steps
- List every system and check whether it matches the definition of an AI system under Article 3.
- Assign the organization's role for each system: provider, deployer, importer, distributor or authorized representative.
- Record the intended purpose and the reasonably foreseeable misuse indicated by the provider.
- Link each system to the data governance, risk management and post-market monitoring procedures required for high-risk systems.
- Note the procedures for reporting serious incidents and the record-keeping arrangements linked to the system.
04
Hypothetical example
Hypothetical example: a company uses a chatbot supplied by a third party for customer service and an internal generative tool for drafting text. For the chatbot, the company is a deployer and checks the intended purpose stated by the provider; for the internally developed tool, the company takes on the role of provider and documents its own risk management system.
05
Minimum checks for each inventory entry
- Does the system fall within the Article 3 definition of an AI system?
- Has a clear role been assigned (provider, deployer, importer, distributor, authorized representative)?
- Are the intended purpose and reasonably foreseeable misuse documented?
- If the system generates synthetic content or deep fakes, is a machine-readable marker or user-facing disclosure in place?
- Are the data governance, risk management, post-market monitoring and serious incident reporting procedures linked?
06
What a company can set up with the support of a software partner
A company can ask a software partner to structure a central register of AI systems with fields for role, intended purpose, expected misuse and links to related technical documentation.
Review responsibilities can be assigned to specific roles — for example, those handling data, those assessing risks and those following up on incident reports — and a record of periodic reviews can be kept as a suggested operational choice, not as a guarantee provided by the software.
07
Frequent clarifications about the inventory
- The inventory distinguishes systems by the organization's role, not just by technology, because obligations and controls follow the role.
- The intended purpose stated by the provider is the reference point for also assessing reasonably foreseeable misuse of the system.
- For high-risk systems, the inventory should be able to link each entry to data governance, risk management and incident procedures.
08
Practical next step
Start the inventory with the systems already in use today: for each one, note the role, intended purpose and link to data and risk management procedures, so the organization has a verifiable baseline before expanding its use of AI.
FAQ
Frequently asked questions
Where does building the AI systems inventory concretely start?
It starts by verifying that each system matches the Article 3 definition of an AI system and assigning the corresponding organizational role, such as provider or deployer.
Why is it important to record the intended purpose of each system?
Because the intended purpose stated by the provider is the reference point for also assessing reasonably foreseeable misuse linked to the system.
What should be linked to each high-risk system in the inventory?
Data governance procedures, the risk management system, post-market monitoring and procedures for reporting serious incidents.
✓