Guide · 2026-09-21T00:00:00.000Z · reviewed 2026-09-21T00:00:00.000Z
Build an AI system inventory in one day
An eight-hour plan to find every AI system your company uses, record the 21 facts that matter, and get it signed off. The inventory is the first thing every AI regulation asks for.
Why the inventory comes first
Every obligation on the deadline tracker starts with the same question: which AI systems do you use, for what, with whose data, in which countries? Poland’s supervisor expects a register. Korea’s high-impact duties and Colorado’s automated-decision rules apply per system. Article 50 applies per system. You cannot classify, disclose, train or contract for what you have not listed.
The day
09:00 to 10:00, scope and owner. Name one owner. Decide the unit: every product, tool or feature that makes predictions, generates content or automates decisions, including features inside tools you already pay for (CRM assistants, ATS ranking, email autocompletion, meeting summarisers).
10:00 to 12:00, discovery. Four sources, in this order:
- Single sign-on and identity provider: every app with “AI”, “assistant”, “copilot” or a known AI vendor.
- Finance: expense claims and card statements for AI subscriptions bought by individuals.
- IT: browser extensions and API keys issued in the last 24 months.
- A ten-minute survey to team leads: “Which AI tools does your team use, for what, and does any output go to customers?”
Expect two to three times more systems than you assumed.
13:00 to 15:00, record. For each system fill the columns in the free template: identity and owner, role under the Act (provider or deployer), data types and personal data, customer-facing, generates content, decision-support area, jurisdictions, and the four evidence columns (disclosure in place, training completed, vendor documents reviewed, contract reviewed).
15:00 to 17:00, classify. Run each system through the questions in the readiness scan: prohibited practice, Annex III candidate, Article 50 case, or minimal. Record the result and the date. The kit’s risk-classification procedure gives you the full decision tree with the Korea and US overlays.
17:00 to 17:30, sign-off. The owner signs the version, sets a review date six months out, and files it where an inspector could be shown it within a day.
Pitfalls
- Counting vendors, not systems. One vendor can be three systems with three risk classes.
- Ignoring embedded features. The ATS that “ranks candidates” is an Annex III candidate whether or not anyone calls it AI.
- No review date. An inventory without a review date is a snapshot, not a control.
- Storing it in someone’s head. The evidence is the file, with its version and sign-off.
What the inventory unlocks
With the inventory done, the acceptable-use policy writes itself from the approved-tools column, the disclosure work is a filter on customer_facing = Yes, and vendor due diligence is a filter on vendor_docs_reviewed = No. The Compliance Kit version adds dropdown validation, a definitions sheet and the risk-class logic.
Sources
- KTZR, Polish AI Systems Act summary (register and inspection expectations)
- EU AI Act explorer, Article 50
- Cooley, Korea AI Basic Act overview