EU AI Act · AI Inventory
Know what AI is running in your organization — and manage every obligation it creates.
You cannot fulfill an obligation for an AI system you don't know exists.
"For us it's DORA, not NIS2 – most vendors confuse them right away." That's how ICT risk managers in banks describe how little generic compliance tools capture their sector's specifics — and the same pattern appears in a different form with the EU AI Act: business units are already independently deploying chatbots, scoring models, and AI copilots, often without compliance knowing. This "shadow AI" escapes all systematic assessment.
Without a complete inventory, the AI Act's central question cannot be answered: does a system fall into the high-risk category under Annex III — triggering conformity assessment, technical documentation, and post-deployment monitoring obligations? If you don't know your systems, you cannot make that determination, regardless of how thorough your control framework otherwise is.
The AI Act's obligations phase in until 2027 — whoever waits to build their AI inventory until the next compliance milestone loses the lead time necessary for risk classification and documentation.
Four building blocks for a complete AI inventory.
AI inventory with risk classification
Every deployed AI system is captured and classified under Art. 6 in conjunction with Annex III — establishing up front which obligations apply, rather than resolving it per system afterward.
GPAI register with systemic risk flag
General-purpose AI models are recorded separately and marked with a systemic risk flag when they cross the Art. 51 thresholds — instead of getting lost in the same list as ordinary application systems.
AI incident register
Incidents involving AI systems are recorded in structured form and can be traced through to the competent authority under Art. 73 — instead of disappearing in a generic ticket system.
Conformity attestation
For high-risk systems, a traceable attestation of conformity status emerges — with owner and timestamp, instead of a loose promise in an email.
More on the EU AI Act and the engine behind it.
Risk tiers, compliance roadmap to 2027, and primary sources in detail.
Regulation details →How control assessment works and how it covers the AI Act, NIS2, DORA, and ISO 27001 in parallel.
Function details →Your first sealed AI inventory — today.
In 30 minutes we show you what ReportAct delivers for this service – no obligation.