AI systems inventory

AI systems inventory

How to map your organization's AI systems and classify them by risk level under the AI Act.

Why an AI inventory

The AI Act requires organizations to identify and classify all AI systems in use, distinguishing between systems developed in-house and third-party systems. The inventory is the starting point for any compliance journey.

The inventory includes:

  • AI systems developed in-house (proprietary models, ML pipelines)
  • AI systems purchased from third-party vendors (SaaS with AI features, analytics tools)
  • Open-source AI systems integrated into business processes

Adding a system to the inventory

  1. From the AI Act Readiness section, click Add system
  2. Fill in the system record: name, description, vendor, adoption date
  3. Specify the usage context: business area, type of users, data processed
  4. Privacta suggests a preliminary risk classification based on the information entered

Classification by risk level

The AI Act divides systems into four categories:

Category Description Examples
Unacceptable risk Banned by the AI Act Subliminal manipulation, social scoring
High risk Strict documentation and oversight obligations HR analytics, fraud detection, access to essential services
Limited risk Transparency obligations towards users Chatbots, content generators
Minimal risk No specific obligations Spam filters, product recommendations

Privacta guides the classification with targeted questions based on the EU AI Office guidelines. The final classification is always reviewable by the compliance owner.

Linking AI systems to GDPR processing

For AI systems that process personal data, Privacta lets you link the AI record to the corresponding processing activity in the Records of Processing and to any DPIA. This link ensures traceability between GDPR and AI Act obligations on the same system.

📄 Add a screenshot of the inventory with systems classified by risk category