Start by building a complete inventory of every AI system in use or development, then classify each one by risk level and business purpose. Capture data sources, governance controls, and where the system is deployed. That inventory becomes the control point for scoping obligations, prioritising remediation, and proving to regulators that compliance decisions were made systematically rather than ad hoc.
Why AI inventory is the compliance starting point
For eu ai act readiness, the inventory is not an administrative list. It is the evidence base that shows which systems exist, who owns them, what they do, and which obligations apply. Without that baseline, organisations cannot reliably distinguish a prohibited use case from a limited-risk tool, identify high-risk systems, or prove that governance decisions were made consistently. The EU AI Act makes that classification exercise central rather than optional.
A useful inventory also prevents compliance drift. AI tools are often introduced through procurement, citizen development, vendor pilots, or embedded product features, and each route creates a different visibility problem. Teams commonly track model names or vendor platforms but miss the actual deployed use cases, data inputs, and business owners that determine legal exposure. In practice, many organisations discover the gaps only after a new system has already been deployed or a regulator asks how the classification was reached rather than after a deliberate governance review.
What a usable AI inventory needs to capture
A compliance-grade inventory should describe each AI system at the level needed to assess both legal scope and operational control. That means more than a title or vendor name. The minimum practical record usually includes the system purpose, the business owner, the deployment environment, the data sources it consumes, the type of outputs it produces, the affected users or customers, and the current governance status. It should also record whether the system is under development, in limited test, or live in production, because the compliance posture can change as the same system moves through its lifecycle.
Organisations should also capture the features that affect regulatory classification. A system embedded in a workflow may be low visibility even if it looks routine to users. A model that influences access decisions, screening, ranking, or safety-related outcomes may have a very different risk posture from a conversational assistant used for drafting. That is why the inventory should link each system to the underlying use case, not just the technical model. When the inventory is structured well, it becomes the working document for classifying risk, mapping controls, and assigning remediation ownership.
- Record the AI use case, not just the tool or model name.
- Note the source of training, tuning, and operational data where known.
- Identify the owner who can approve, pause, or retire the system.
- Document deployment context, including internal, vendor-hosted, and embedded use.
- Capture the current classification decision and the rationale behind it.
The point is to make the inventory decision-useful. If a record cannot help a reviewer understand scope, risk, and accountability, it is not yet ready for compliance use.
Where inventories usually fail and what to do instead
Tighter inventory control increases reporting overhead, so organisations have to balance completeness against the speed at which AI appears in the business. That trade-off matters because the biggest failure mode is not usually malicious concealment; it is fragmentation. Different teams maintain different registers for data protection, procurement, security, and model governance, and none of them alone is complete. A compliance inventory should therefore act as the integrating record, not a duplicate spreadsheet that competes with every other list.
There is also a genuine grey area around borderline systems. Some organisations debate whether a rules-based workflow, a third-party embedded feature, or a generative assistant counts as AI for inventory purposes. Guidance and regulatory interpretation continue to mature, so the safest approach is to record uncertain cases with a provisional classification and a review date rather than to exclude them. The practical question is not whether every item is immediately high risk, but whether the organisation can defend why it included or excluded each system.
Teams should be especially careful where inventory scope depends on third-party software. Vendor assurances are not enough on their own, because the compliance burden can shift depending on how the system is used, configured, or marketed. If the organisation cannot trace the business purpose, data lineage, and accountable owner, the inventory is still incomplete even if the technology stack is well understood.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST AI RMF set the technical controls, while EU AI Act and ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| EU AI Act | Article 4 — AI literacy | Inventory governance depends on people making defensible AI classification decisions. |
| Article 5 — Prohibited AI practices | An inventory must surface systems that may fall into banned-use screening. | |
| Article 6 — High-risk AI systems | The inventory must identify systems whose use case triggers high-risk obligations. | |
| Recommendation — Train responsible owners to classify AI systems consistently and explain the rationale. Screen inventory entries for prohibited uses before assigning routine compliance status. Classify each system against high-risk criteria so obligations can be scoped correctly. | ||
| ISO/IEC 42001:2023 | 4.2 — Understanding the needs and expectations of interested parties | An AI inventory supports stakeholder-aware governance and accountability. |
| 8.1 — Operational planning and control | Inventory records are needed to control AI operation through its lifecycle. | |
| Recommendation — Align inventory scope to the stakeholders and obligations each AI system affects. Maintain AI records as an operational control that stays current through change. | ||
| NIST AI RMF | GOVERN — AI governance | Inventory is the governance basis for deciding ownership, scope, and accountability. |
| MAP — Map AI context and use | The inventory must map purpose, context, and deployment before risk treatment. | |
| MANAGE — Manage AI risks | Inventory classification feeds prioritisation and remediation of AI risks. | |
| Recommendation — Use governance records to assign owners and approve AI system classification decisions. Map each AI system’s purpose, context, and data flows before assessing obligations. Use the inventory to prioritise AI risk treatment and remediation work. | ||
Practitioner Guidance
What to prioritise: Build the inventory around business-owned AI use cases first, then map the supporting technology underneath them. That sequence is more reliable than starting with model catalogues because it ties each entry to the decision-maker who can actually fix gaps or stop use.
What to verify: For each record, verify three things before trusting it: the system is real and active, the stated purpose matches how it is actually used, and the classification rationale can be explained without relying on tribal knowledge. If any one of those is missing, treat the entry as provisional.
Common mistake: Treating the inventory as a one-time compliance project rather than a living control. AI changes through retraining, feature updates, vendor releases, and new deployments, so the inventory must be updated through a defined change process or it will rapidly lose evidential value.
Practitioner takeaway: The best ai inventory is the one that can survive scrutiny, because it shows not only what AI exists but also who owns it, why it was classified that way, and how the organisation will keep that answer current.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org