How to build an AI system inventory, step by step
You cannot classify, oversee, or evidence systems you have not found. Here is the discovery method that surfaces the AI your organization actually uses — including the tools nobody told IT about — and turns the first pass into a record that stays current.
Updated July 24, 2026 · Informational guidance, not legal advice
Scope first: what counts as an AI system
Before hunting, decide what you are hunting for. The EU AI Act's Article 3(1) definition covers machine-based systems that infer from inputs how to generate predictions, content, recommendations, or decisions. That is deliberately broad, and for inventory purposes breadth is a feature: the cost of listing a borderline system is one row; the cost of missing one is an unclassified obligation.
- In scope: AI features inside your own product; vendor SaaS with AI capabilities your teams use (support suites, HR screening, sales intelligence, coding assistants); general-purpose assistants used with work data; internal models and automations, however small.
- Record-but-flag: pure rule-based automation with no inference, and AI features that exist in a tool but are switched off — one line each, marked out of scope, so the conclusion is documented rather than assumed.
- The unit is the system in its use context, not the vendor: one platform used for two materially different purposes is two entries, because role and risk classification can differ per use.
The five discovery passes
No single source catches everything. Five passes, each cheap, catch nearly all of it:
- 1. Procurement and expense records: search vendor invoices and card spend for AI-adjacent line items. This catches paid tools, including ones bought by a single team.
- 2. SSO and app logs: your identity provider's application list is the closest thing to ground truth for what SaaS is actually in use. Flag anything with AI features, not just AI-first products.
- 3. Product and engineering review: what models, APIs, and AI features ship in your own product, including experiments behind flags. This is where provider-role systems surface.
- 4. Team survey: a short form to every team lead — what tools with AI features does your team use, for what, with what data. Phrase it as inventory, not enforcement, or shadow usage stays hidden.
- 5. The browser check: many AI tools are free-tier web apps that never touch procurement or SSO. Ask specifically about free tools used with work content — this is where shadow AI lives.
Shadow AI is a disclosure problem, not a discipline problem
If the survey reads like a compliance dragnet, people omit the unofficial tools — and the inventory misses exactly the usage that carries the most unmanaged risk. Make the first pass amnesty-flavoured: the goal is a true picture, and policy decisions come later, per system, with owners in the room.
Populate the entries while the trail is warm
For each discovered system, capture the register fields in the same pass — chasing details a second time costs more than collecting them the first time. The minimum viable entry: name, one-sentence purpose, the team using it, vendor and underlying model where known, data inputs and data subjects, whether people in the EU are affected, and a first-guess role (provider, deployer, or both).
Then run classification as its own step: each entry through Article 5 (any prohibited practice), Article 6 and Annex III (high-risk or not, with reasoning), and Article 50 (does it interact with people or generate content). Classification is where the inventory turns from a list into an obligation map — and it is the step that determines everything downstream.
Keeping it alive
The first inventory is a project; the register is a rhythm. Three mechanisms keep it from rotting into last quarter's spreadsheet:
- An intake trigger: new AI tools and features enter the register at adoption — a line in the procurement checklist and the product launch checklist is enough.
- Named owners per entry: the person who can answer for the system's use, oversight, and evidence — and who is chased when the entry goes stale.
- A review cadence with dates on every entry: monthly review of what changed, quarterly re-check of classifications, and a visible flag when a review date passes.
Teams that operate this rhythm meet the August 2, 2026 Article 50 transparency date with a register, classifications, owners, and a gap list — and reach the December 2, 2027 Annex III date with evidence history rather than a document sprint. Teams that ran a one-off inventory in 2025 arrive with a historical document.
Classify what you find, system by system
The free Attevera classifier walks each discovered system through Articles 5 and 6 and Annex III in minutes, and gives you the reasoning to paste into your register. No signup.
Run the free classifierFrequently asked questions
How long does a first inventory take?
For a mid-market product organization, the five discovery passes typically fit in one to two weeks of part-time effort, with the team survey as the long pole. Classification adds a focused session per batch of systems. The trap is not effort but perfectionism — ship the 90% inventory and let the rhythm catch the tail.
Do free AI tools employees use really belong in the register?
If they are used with work data or their output enters work product, yes — the AI Act's duties attach to use under your authority, not to whether a tool was invoiced. Many organizations pair the inventory with a short approved-tools policy so the answer to "can I use this?" has somewhere to live.
Who should own the inventory effort?
One accountable owner for the register as a whole — commonly product operations, risk, or compliance — with per-system owners named in each entry. Discovery is a coalition effort (IT for SSO data, finance for spend, engineering for the product), but a register with no single owner stops being maintained within a quarter.
Is an AI inventory the same as an AI register?
The inventory is the discovery exercise; the register is the maintained record it produces. In practice the terms are used interchangeably — what matters is that the artifact carries classifications, owners, and review dates, not just a list of tool names. This is informational guidance, not legal advice.