AIG-003 AI System Inventory
Description
A maintained inventory of all AI systems in use or in development exists. Each entry records the system name, version, owner, intended purpose, deployment status, risk classification and the frameworks or third-party models the system depends on. The inventory is reviewed quarterly and updated whenever a system is deployed, substantially modified or decommissioned. The regulatory classification of each system is determined and recorded before the system is placed on the market or put into service, with the reasoning, the person who made it and the date, and the record states whether the system is a safety component of a product that has to undergo third-party conformity assessment, which listed high-risk area it falls in if any, and where an exemption is relied on the condition relied on and why it holds; a system that profiles natural persons is recorded as high-risk whatever the exemption conditions would otherwise give. The determination is made again on substantial modification and is produced to a competent authority on request. Where regulation requires it, the system and its provider are registered in the applicable public database before the system is placed on the market, including where the provider has concluded the system is exempt, and the registration reference is recorded against the inventory entry. Where a system or model the organisation provides is subject to a threshold that triggers a notification duty, the inventory entry records the measure the threshold is set against and its current value, the notification is made within the period the regulation allows with the evidence that the threshold was crossed, and its reference is recorded against the entry.
Rationale
You cannot govern what you cannot enumerate, and an AI inventory is the prerequisite for applying risk treatment proportionately. The classification field on its own is a claim; the determination behind it is what an authority asks for, and the answer decides which obligations and which application dates bind. Registration and threshold notification are recorded against the inventory entry because that is the only place the system, its classification and its filings sit together. Article numbers and jurisdiction names stay out of the control text and live in the mapping notes. The registration this control records is the one made by the entity that places the system on the market. Where the organisation operating a system owes a filing of its own, that filing is AIG-045 and its reference sits beside this one against the same inventory entry.
Applicability (9 profiles)
The inventory, the risk class recorded for each system and the Art.25 check on the deployer's own modifications are the deployer's. The provider's classification and registration references are taken from the documentation it releases (AIG-034). Registration of use by a public authority (EU-AI-Art.49.2 in the extract, Art.49(3) in the Regulation) belongs to public-body-deployer-eu.
The inventory holds each model with its designation status. The Art.52(1) notification to the Commission within two weeks of meeting the systemic-risk threshold is the threshold notification clause of this control.
Art.6(4) makes the exemption assessment a document rather than a field: a provider who considers an Annex III system is not high-risk documents that assessment before the system is placed on the market and produces it to a national competent authority on request. Art.49(1) adds a counterparty and a clock the inventory has to carry, registration of the provider and the system in the EU database under Art.71 before an Annex III system is placed on the market or put into service, Annex III point 2 excepted. Art.49(2) requires the same registration for the system the provider concluded is exempt, so the exemption route ends in a public entry rather than in silence. Annex VIII fixes the content of both, with the Regulation (EU) 2026/1744 deletion of section B points 7 and 9 shortening the exempt-system entry (ADR-025).
The inventory entry for a high-risk Annex III system carries two register references and this control holds both sides of the pair. Art.49(1) registration of the system is the provider's and is stated here; Art.49(3) registration of the deployment belongs to the Art.49(3) seat and sits on AIG-045, so the entry reads the provider's filing and the body's own filing together. The entry also records which clock the system sits on: Art.111(2) gives a high-risk system intended for use by a public authority and placed on the market before 2 December 2027 until 2 August 2030, while a system procured after that date complies from first use. The Art.6(2) and (3) classification record is unchanged from the base.
Framework Mappings (14)
| EU-AI-Art.49.1 | EU Database Registration — Provider Registration | full |
| EU-AI-Art.49.3 | EU Database Registration — Registration of Self-Assessed Exempt Systems | full |
| EU-AI-Art.52.1 | GPAI Model Obligations — Systemic Risk Notification to the Commission | full |
| EU-AI-Art.6.1 | Classification — High-Risk as a Safety Component under Annex I | full |
| EU-AI-Art.6.2 | Classification — Annex III High-Risk Categories and the Derogation | full |
| EU-AI-Art.6.3 | Classification — Documented Exemption Assessment and Registration | full |
| A.4.2 | Resource documentation | full |
| GV-1.3-001 | Risk Management Activity Level Determination | GV-1.3-001 | informative |
| GV-1.6-001 | AI System Inventory | GV-1.6-001 | full |
| GV-1.6-002 | AI System Inventory | GV-1.6-002 | partial |
| GV-1.6-003 | AI System Inventory | GV-1.6-003 | partial |
| MP-2.2-001 | AI System Knowledge Limits Documentation | MP-2.2-001 | partial |
| GOVERN 1.6 | AI System Inventory | full |
| MAP 1.4 | AI System Business Value Definition | full |
Evidence (4)
AI system inventory register listing all AI systems in use or under development, with required fields: system name, version, owner, purpose, deployment status, risk classification, and third-party dependencies.
Example: AI System Inventory v4 (Airtable or Confluence table), reviewed by AI governance lead on 2026-01-15, with 12 entries covering all production and staging systems
Test: Request the AI system inventory. Verify: (1) each entry contains all required fields (name, version, owner, purpose, status, risk classification, dependencies), (2) at least one quarterly review event is recorded in the last 12 months, (3) cross-check inventory against deployment pipeline or cloud account to identify unregistered AI endpoints, (4) decommissioned systems are marked deprecated rather than deleted.
Automated cloud resource scan or MLOps platform export confirming that all live AI model endpoints and inference services correspond to entries in the AI system inventory.
Example: AWS SageMaker endpoint list export (JSON) dated 2026-04-01, cross-referenced against AI inventory; SaaS ML platform (Weights & Biases) active deployment export
Test: Obtain the infrastructure scan or MLOps platform export. Compare all active model endpoints against the inventory. Verify: (1) every active endpoint has a matching inventory entry, (2) no orphaned or unregistered endpoints exist, (3) scan timestamp is within the last 30 days.
Regulatory classification record for each AI system, stating the determination, the reasoning, the person who made it, the date and the trigger that would cause it to be made again.
Example: Classification determination, underwriting-assist v2, signed 2026-03-09
Test: Request the classification records behind the inventory's risk classification field. Verify: (1) every system in the inventory has a record dated before its first production release, (2) the record states which listed high-risk area was considered and the conclusion reached for each, (3) the safety-component question is answered with reasoning rather than left blank, (4) where an exemption is relied on, the condition and the reasoning are stated and profiling is expressly ruled out, (5) a system substantially modified during the period carries a re-determination dated after the modification, (6) a sampled record can be produced in the form an authority would receive it.
Registration and notification references recorded against the inventory entries that require them, with the filing date and a copy of the filing.
Example: Inventory extract with registration references, Q3 2026, plus filed registrations
Test: Request the registration and notification references. Verify: (1) every system whose classification record says registration is required carries a reference, (2) each reference resolves to a filing dated before that system's market placement date, (3) systems recorded as exempt carry a registration reference as well, (4) where a threshold-based notification fell due in the period, the filing date falls within the period the regulation allows counted from the date the inventory entry shows the threshold was crossed, (5) the measure the threshold is set against carries a current value and a date on each entry it applies to.
Questions (3)
Does your organisation maintain a current inventory of all AI systems in use or under development?
An AI inventory is the prerequisite for proportionate risk treatment. It should cover production, staging, and development systems and be reviewed at least quarterly.
Which of the following fields does your AI system inventory record for each entry?
All six fields should be present. Risk classification and dependency tracking are the most commonly missing fields; without them the inventory cannot drive proportionate risk controls or supply chain oversight.
For AI systems that a regulator classifies, which of the following does your inventory hold?
Options run from the most commonly held to the least. A classification field with no determination behind it is a claim, not a record, and the determination is what an authority asks to see. Systems assessed as exempt are the ones most often missing a registration reference, because the exemption is read as removing the filing rather than pairing with it.