The first question of EU AI Act (Regulation EU 2024/1689) compliance is not "how do I get compliant", but something far more concrete: which artificial intelligence systems do I actually use, and at what risk level do they sit? Without that answer every other activity — documentation, human oversight, training — is blind. Inventory and risk classification are the starting point, and they are also the step almost every organisation skips.
Why start with the register, and why now
In 2026 a dangerous idea has spread: that postponing high-risk obligations removes the urgency. The simplification package (the so-called Digital Omnibus) received the co-legislators' final green light — with the Council's approval on 29 June 2026 — and publication in the EU Official Journal is expected shortly. But the postponement concerns only high-risk systems: the other deadlines stay in place.
- 2 February 2025 — bans on unacceptable-risk systems (Art. 5) and the AI literacy obligation (Art. 4) are in force.
- 2 August 2025 — rules for general-purpose AI models (GPAI) apply.
- 2 August 2026 — the transparency obligations (Art. 50) apply; only the watermarking of content generated by systems already on the market gets a technical reprieve to 2 December 2026.
- 2 December 2026 — a new prohibition (Art. 5) on AI-generated non-consensual intimate imagery and synthetic child sexual abuse material.
- 2 December 2027 — obligations for standalone high-risk systems (Annex III), postponed from 2 August 2026.
- 2 August 2028 — obligations for high-risk systems embedded in regulated products (Annex I).
The takeaway: the bans already bite and transparency is imminent. You cannot switch off a prohibited system you don't know you use, nor label a chatbot you never catalogued. The delay is time to prepare, not permission to defer.
The four risk tiers of the AI Act
The AI Act takes a risk-based approach and distinguishes four levels.
- Unacceptable risk (prohibited) — Art. 5. Practices such as social scoring, subliminal manipulation, untargeted scraping of faces to build facial-recognition databases, or emotion recognition at work and in schools. If a system falls here, it must be retired.
- High risk — Art. 6, combined with Annex I (safety components of already regulated products) and Annex III (eight "standalone" areas: biometrics; critical infrastructure; education and training; employment and worker management; access to essential public and private services, including creditworthiness; law enforcement; migration, asylum and border control; administration of justice and democratic processes).
- Limited risk (transparency) — Art. 50. Chatbots and assistants must tell users they are interacting with an AI; generated or manipulated content (text, images, audio, video, deepfakes) must be marked in a machine-readable way and disclosed.
- Minimal risk — everything else (spam filters, most productivity tools). No specific obligations, only voluntary codes of conduct.
Mind the Art. 6(3) derogation: an Annex III system may not be high-risk if it poses no significant risk to health, safety or fundamental rights — but it is always high-risk if it performs profiling of natural persons. And whoever classifies it as not high-risk must document that assessment before putting it into service (Art. 6(4)) and is subject to the registration obligation of Art. 49(2). Classifying "by gut feeling" is not an option.
How to build the AI systems register
- Define what you count. Use the broad notion of "AI system" in Art. 3: it covers third-party tools, AI features inside SaaS software you already use (CRM, HR, help desk) and generative models used by employees.
- Sweep every source. Poll departments, SaaS contracts, integrated APIs and — above all — shadow AI: tools adopted without formal approval are the most forgotten line of any inventory.
- Record the essential data for each system (see the table below).
- Classify the risk using the four tiers, justifying the choice.
- Assign an owner and an action to each row: who is responsible and what must be done (retire, document, add transparency, train, monitor).
- Keep the register alive. Every new tool goes in before it is adopted, not after.
The register in practice: the columns that matter
| System | Provider | Purpose | Personal data | Role | Risk tier | Owner | Action |
|---|---|---|---|---|---|---|---|
| e.g. CV screening | Vendor X | Candidate selection | Yes | Deployer | High (Annex III) | HR | Document, human oversight |
| e.g. site chatbot | Vendor Y | Customer support | Yes | Deployer | Limited (Art. 50) | Marketing | Disclose "you're talking to an AI" |
| e.g. spam filter | Vendor Z | Email security | No | Deployer | Minimal | IT | No action |
Three columns make the difference: the role (are you the provider or the deployer of that system?), personal data (which weaves GDPR obligations together with AI Act ones) and the risk tier with its matching action. The rest makes the register defensible before an authority.
The most common mistakes
- Cataloguing only "obvious" AI and forgetting the AI features embedded in everyday tools.
- Ignoring shadow AI: generative models used by teams that no one has mapped or approved.
- Confusing roles: assuming that using a third-party system removes the deployer's obligations.
- Classifying without documenting: for an Annex III system deemed not high-risk, the assessment must be written down (Art. 6(4)).
- Treating the inventory as a one-off event rather than a living register.
Where to start
A well-made inventory is the foundation everything else in compliance rests on: without it you don't know which obligations apply to you or where to focus resources. An independent gap assessment starts right here — it maps the systems, classifies their risk and returns a plan with priorities, owners and dates. It is the cheapest way to turn regulatory uncertainty into concrete decisions.