Home › Blog › EU AI Act
EU AI Act

Your AI inventory is the first compliance document that matters

By PROGEAT · 3 min read

Before governance frameworks and conformity assessments, there's a simpler question most organizations can't yet answer: which AI systems does your organization actually run?

Not the ones procurement signed off on. Not the ones in the architecture diagram. The ones actually in production — including the spreadsheet macro someone wired into an LLM API, the vendor tool with a "smart" feature nobody flagged as AI, and the pilot that quietly became load-bearing.

Why this is harder than it sounds

Most organizations assume they already know the answer, because they know what their IT or data teams built deliberately. What the inventory exercise almost always surfaces is everything else: a marketing team's subscription to a content tool that added an AI feature in a routine update, a finance analyst's personal use of a chatbot to draft reports, a customer service platform's "smart routing" that's been quietly making automated decisions about who gets escalated to a human. None of these were commissioned as "AI projects." All of them fall inside the EU AI Act's definition of an AI system, and all of them need to be accounted for before you can say anything meaningful about your organization's risk exposure.

What an inventory actually has to capture

A usable AI inventory isn't a spreadsheet of tool names. For each system, you need: what it does and what decisions or outputs it produces, who uses it and how central it is to their work, what data it touches (and whether any of that is personal or sensitive data), whether it's built in-house, bought from a vendor, or embedded inside another product you already use, and who inside the organization actually owns it. That last point matters more than it sounds — a shockingly large share of shadow AI usage has no clear internal owner at all, which is itself a governance gap independent of the AI Act.

How to actually find these systems

This is genuinely unglamorous work, and it doesn't happen by sending out a survey. It happens through structured conversations with team leads across the organization — not "do you use AI," which people will answer based on a narrow mental model of what counts, but "walk me through how your team gets X done," which surfaces the tools actually in the workflow. It happens through a review of software and API subscriptions and vendor contracts, since a meaningful share of shadow AI arrives bundled inside tools purchased for an unrelated reason. And it happens through IT's actual network and SaaS usage data, which is often the only source that reveals AI usage nobody higher up the chain ever approved or even knew about.

What this means in practice

You cannot classify risk, assign obligations, or scope a governance framework for systems you haven't found yet. Every subsequent step of EU AI Act compliance — risk classification, technical documentation, conformity assessment where required — depends on this inventory being genuinely complete, not just a list of the systems that were easy to remember. Organizations that treat the inventory as a formality, rather than the actual foundation, tend to discover the gaps later, at the worst possible time: during an audit, or after an incident.

Not sure where you stand?

Our free assessment tool maps your AI systems to the relevant EU AI Act obligations in minutes.

Start free assessment
← Back to all articles