Running EU AI Act readiness in spreadsheets
The honest competitor to every governance tool is a spreadsheet, and pretending otherwise insults your intelligence. So here is the fair version: what the spreadsheet does well, where it structurally breaks, and the signals that you have crossed the line.
Updated July 17, 2026 · Informational guidance, not legal advice
Where the spreadsheet genuinely works
- The first inventory: columns for system, purpose, role, vendor, data, owner — a spreadsheet captures a discovery pass perfectly well. Our free register template is exactly this, and we mean it when we say it stands alone.
- A handful of systems, one owner: with five systems and one person maintaining the record, the coordination problems tools solve barely exist yet.
- Deciding whether you have a problem at all: an afternoon with a spreadsheet and a classification walkthrough tells you whether anything you run is high-risk or transparency-bound. That answer is worth having before you evaluate any tool, including ours.
The four structural breaks
- Staleness is invisible. A cell does not know it is nine months old. The AI Act's duties are continuous — oversight assignments, log retention, monitoring — and the register's job is to show the record was operated, not merely written. Spreadsheets hold state; they do not run a rhythm.
- Obligation logic lives in someone's head. Which articles apply to a system is a function of role, risk class, and use — logic a spreadsheet cannot encode. The person who knew why row 14 was classified that way leaves, and the reasoning leaves with them unless it was written down per entry, which in practice it rarely is.
- No audit trail. When a classification changes in a spreadsheet, the old value is simply gone. An operating record needs the opposite: append-only history showing what was decided, when, by whom, and what changed — the property reviewers actually probe.
- Multiplayer falls apart. Owners, review sign-offs, and chase-ups across product, legal, and engineering turn one honest spreadsheet into six conflicting copies. The moment the record has more than one accountable human, the file stops being the truth.
The tell
Every team that outgrew the spreadsheet describes the same moment: someone senior asked "is this current?" and nobody could answer without a meeting. That question is the product boundary. Before it, the spreadsheet is fine; after it, the spreadsheet is a liability wearing the costume of a record.
A fair migration path
Start with the spreadsheet — genuinely. Run the inventory, classify each system, name owners. If everything comes back minimal-risk with a couple of Article 50 disclosures, operate the spreadsheet with a quarterly calendar reminder and spend your tool budget elsewhere. If systems come back high-risk, or the register needs more than one maintainer, or a customer or authority is going to read the record: move it into something that runs the rhythm for you — staleness flags, obligation mapping, sign-offs, and an audit trail. The import should take an afternoon precisely because the spreadsheet already holds the right fields.
Take the spreadsheet route — with the right columns
The free AI system register template gives you the 14 fields and a realistic filled-in example. If you outgrow it, it imports straight in.
Get the free templateFrequently asked questions
Is a spreadsheet register acceptable to a regulator or enterprise customer?
There is no format requirement — what reviewers probe is whether the record is complete, current, and operated. A maintained spreadsheet beats an abandoned platform. The honest problem is that spreadsheets make "current and operated" expensive to prove, which is exactly what the review tests. This is informational guidance, not legal advice.
What should the spreadsheet contain, minimum?
One row per system: name, one-sentence purpose, role (provider/deployer), vendor and model, data inputs and subjects, risk classification with a sentence of reasoning, Article 50 duties if any, a named owner, evidence location, and a next-review date. Our free template has all fourteen fields with a filled example.
When is the right time to move off it?
The three reliable triggers: a system classifies as high-risk (Article 26 duties need owners, cadence, and proof), the record gains a second maintainer, or an external reviewer is scheduled to read it. Any one of them is enough; two is overdue.
Can we import an existing spreadsheet into Attevera?
Yes — CSV import is supported on all plans, and the free template's fields map directly. The point of starting in a spreadsheet is that nothing is wasted when you graduate.