Inventory & Classification
AI Inventory and Use-Case Classification
What this control does
Maintain an inventory of AI systems/use cases and classify them by regulatory role, use, risk category and relevant conditions.
How to implement
Use an inventory to make AI use visible and route it to the right compliance review; an inventory entry is not itself a legal classification decision.
- Record each system or use case, its owner, supplier, intended purpose, users, affected people, deployment locations and lifecycle stage.
- Identify the organization's role for that system and screen for prohibited uses, potentially high-risk uses and relevant general-purpose AI model responsibilities. Do not treat model and system classifications as interchangeable.
- Route uncertain classifications to the responsible compliance or legal reviewer and link the decision to supporting evidence.
- Revisit the entry when branding, design, supplier or intended use changes. Include Article 25 role changes and the conditions under which a product manufacturer becomes a provider. Use the inventory to trigger specialist controls; do not interpret a missing tag as an exemption.
Suggested timing and triggers
At introduction and before release or deployment; when ownership, supplier, branding, design or intended use changes; periodic reconciliation set by the organization.
Evidence examples
System inventory with owner, supplier, purpose, role and review date Classification and applicability decisions with supporting sources Approvals or referrals for uncertain use cases Change records showing reassessment after a material change Links from inventory entries to relevant obligations and controls
How to check this control
Compare a sample of procurement, development and business-use records with the inventory. For one changed system, check that the current purpose and regulatory role were reassessed, and that resulting actions reached an accountable owner.
Related EU AI Act obligations
Article 5(1)(a)
Do Not Use Manipulative or Deceptive AI Practices That Cause Significant Harm
Article 5(1)(b)
Do Not Exploit Vulnerabilities Using AI in a Manner That Causes Significant Harm
Article 5(1)(ba), 5(1a)-(1b)
Do Not Generate or Manipulate Non-Consensual Intimate Content Using AI
Article 5(1)(bb), 5(1a)
Do Not Generate or Manipulate Prohibited Child Sexual Abuse Material Using AI
Article 5(1)(c)
Do Not Use Prohibited AI-Based Social Scoring
Article 5(1)(d)
Do Not Predict Individual Criminal Risk Solely From Profiling or Personality Characteristics
Article 5(1)(e)
Do Not Create or Expand Facial Recognition Databases Through Untargeted Image Scraping
Article 5(1)(f)
Do Not Use AI Emotion Recognition in Workplaces or Educational Institutions Except for Permitted Purposes
Article 5(1)(g)
Do Not Use Prohibited Biometric Categorisation to Infer Sensitive Characteristics
Article 6(4); Article 49(2)
Document the Assessment When an Annex III AI System Is Considered Not High-Risk
Article 25(1)
Assume Provider Responsibilities When Your Actions Make You the Provider of a High-Risk AI System
Article 25(3)
Assume Provider Responsibilities as the Product Manufacturer of Certain Annex I Section A High-Risk AI