Every AI governance conversation, whatever it is nominally about, ends up at the same place: somebody asks what AI the organisation is actually running, and the room goes quiet.
The inventory is the foundational artefact. Not because a regulation names it - the Act requires it explicitly only for high-risk systems - but because every other obligation depends on knowing what you have. You cannot assess the risk of a system you have not listed.
The answer is never zero
In every assessment we have run, the first inventory finds systems nobody had approved. Not through misconduct - through ordinary people solving ordinary problems with tools that were free and available.
This matters for how you run the exercise. If it feels like an audit with consequences, you will get a short and useless list. If it is framed as an inventory rather than an investigation, you get the truth. Say so explicitly when you start.
Where to look
Procurement and expense records. Subscriptions to AI tools, and the AI features inside tools you bought for other reasons. Your CRM, your helpdesk and your HR system have almost certainly grown AI features since you bought them.
The browser. Ask, do not scan. A short anonymous survey - what AI tools do you use for work, and what for - produces more than any technical inspection.
Your own product. Anything customer-facing that is described in marketing as intelligent, smart, automated or predictive.
Vendors. Ask suppliers directly whether their product incorporates AI, and whether any of it is a general-purpose model. Many will not have thought about the question either.
Shadow spend. Personal cards, free tiers, browser extensions. The hardest to find and often the most exposed, because no contract governs them.
What to record for each system
Keep this short enough that it gets completed. Ten fields, not forty.
Name and vendor. What it does, in one sentence a non-technical director would understand. Who owns it - a person, not a department. Who uses it. What data goes in, and particularly whether that includes personal or client-confidential data. What comes out, and what happens next - specifically whether any decision is made or materially influenced. Is a person in the loop, and can they actually overrule it. Is it customer-facing. Contract and review date. Your risk classification under the Act, once you can make it.
The decision field is the one that does the work. A system that drafts text is a different proposition from one that ranks candidates, and the inventory is where that distinction first becomes visible.
Classifying, once the list exists
Only now is classification possible. Against the Act, sort into: prohibited - stop immediately; high-risk under Annex III - a real programme, with a December 2027 date; limited-risk with transparency duties - chatbots and generated content, in force now; and minimal risk, which is most of it.
Expect the distribution to be lopsided. Most systems land in minimal, a handful in transparency, occasionally one in Annex III that nobody had noticed - usually in recruitment.
One register, four regimes
The columns that satisfy the EU Act also answer what the UK, the United States and Australia ask. This is the strongest argument for building the inventory properly once.
United Kingdom. UK GDPR Articles 22A to 22D, live since 5 February 2026, turn on two facts about each decision: is it solely automated, and is it significant. Those are two of your columns. If special category data is involved the restriction is tighter still, which is a third. Public bodies additionally publish records under the Algorithmic Transparency Recording Standard, which asks for the tool, the owner, the decision it influences and the stage of deployment - the same fields, in public.
United States. New York City’s bias audit cannot start until somebody produces a list of automated employment decision tools, their vendors, and the dates they were used. Illinois and California employment rules require notice to the people affected, which requires knowing who they are. California’s automated decision-making technology rules, which bite from 1 January 2027, require a record of which systems make significant decisions about consumers. Every one of those is a query against a register you either have or do not.
Australia. Commonwealth agencies already keep an internal AI use-case register with named owners under the AI in government policy, and suppliers inherit the obligation through procurement. From 10 December 2026 privacy policies must describe the kinds of decisions made solely by a computer program, which is a published extract of the same register.
So the inventory is not EU compliance work with international spillover. It is the one artefact that every regime in this list assumes you already hold, and the only one that cannot be produced retrospectively in a week. Build it once, keep it current, and the jurisdiction question becomes a filter rather than a project. We build these for clients in Ireland, the United Kingdom, the United States and Australia.
Keeping it alive
An inventory taken once is a photograph of a room people keep moving furniture in. Attach it to something that already happens: new supplier onboarding, the quarterly risk review, the annual budget cycle. Give it a named owner and a review date.
Ninety minutes per system is a fair estimate for the first pass, less for the ones that turn out to be trivial. No procurement required. It is the single highest-value afternoon in this entire subject, and it is the artefact every subsequent conversation will start from.