AI systems inventory
How to map your organization's AI systems and classify them by risk level under the AI Act.
Why an AI inventory
The AI Act requires organizations to identify and classify all AI systems in use, distinguishing between systems developed in-house and third-party systems. The inventory is the starting point for any compliance journey.
The inventory includes:
- AI systems developed in-house (proprietary models, ML pipelines)
- AI systems purchased from third-party vendors (SaaS with AI features, analytics tools)
- Open-source AI systems integrated into business processes
Adding a system to the inventory
- From the AI Act Readiness section, click Add system
- Fill in the system record: name, description, vendor, adoption date
- Specify the usage context: business area, type of users, data processed
- Privacta suggests a preliminary risk classification based on the information entered
Classification by risk level
The AI Act divides systems into four categories:
| Category | Description | Examples |
|---|---|---|
| Unacceptable risk | Banned by the AI Act | Subliminal manipulation, social scoring |
| High risk | Strict documentation and oversight obligations | HR analytics, fraud detection, access to essential services |
| Limited risk | Transparency obligations towards users | Chatbots, content generators |
| Minimal risk | No specific obligations | Spam filters, product recommendations |
Privacta guides the classification with targeted questions based on the EU AI Office guidelines. The final classification is always reviewable by the compliance owner.
Linking AI systems to GDPR processing
For AI systems that process personal data, Privacta lets you link the AI record to the corresponding processing activity in the Records of Processing and to any DPIA. This link ensures traceability between GDPR and AI Act obligations on the same system.
📄 Add a screenshot of the inventory with systems classified by risk category