Service Services / EU AI Act

EU AI Act · AI Inventory

Know what AI is running in your organization — and manage every obligation it creates.

Why this matters

You cannot fulfill an obligation for an AI system you don't know exists.

"For us it's DORA, not NIS2 – most vendors confuse them right away." That's how ICT risk managers in banks describe how little generic compliance tools capture their sector's specifics — and the same pattern appears in a different form with the EU AI Act: business units are already independently deploying chatbots, scoring models, and AI copilots, often without compliance knowing. This "shadow AI" escapes all systematic assessment.

Without a complete inventory, the AI Act's central question cannot be answered: does a system fall into the high-risk category under Annex III — triggering conformity assessment, technical documentation, and post-deployment monitoring obligations? If you don't know your systems, you cannot make that determination, regardless of how thorough your control framework otherwise is.

The AI Act's obligations phase in until 2027 — whoever waits to build their AI inventory until the next compliance milestone loses the lead time necessary for risk classification and documentation.

What you get

Four building blocks for a complete AI inventory.

21 obligations from the EU AI Act
4 risk classes, assigned automatically
Annex IV technical documentation, kept structured

AI inventory with risk classification

Every deployed AI system is captured and classified under Art. 6 in conjunction with Annex III — establishing up front which obligations apply, rather than resolving it per system afterward.

GPAI register with systemic risk flag

General-purpose AI models are recorded separately and marked with a systemic risk flag when they cross the Art. 51 thresholds — instead of getting lost in the same list as ordinary application systems.

AI incident register

Incidents involving AI systems are recorded in structured form and can be traced through to the competent authority under Art. 73 — instead of disappearing in a generic ticket system.

Conformity attestation

For high-risk systems, a traceable attestation of conformity status emerges — with owner and timestamp, instead of a loose promise in an email.

Learn more

More on the EU AI Act and the engine behind it.

EU AI Act — the regulation

Risk tiers, compliance roadmap to 2027, and primary sources in detail.

Regulation details →
Framework Packs — the engine

How control assessment works and how it covers the AI Act, NIS2, DORA, and ISO 27001 in parallel.

Function details →
Next step

Your first sealed AI inventory — today.

In 30 minutes we show you what ReportAct delivers for this service – no obligation.