AI system inventory and classification
Ensures the organisation knows every AI system it builds, buys or embeds, who owns it, what it is for and which legal risk tier it falls into, so that obligations can be assigned rather than discovered after the fact.
- Duties satisfied
- 1
- done properly, does the work
- Duties supported
- 10
- contributes; the duty needs more
- Jurisdictions
- 7
- Evidence items
- 3
How is it implemented?
A central register is populated through intake forms, procurement gates, code and vendor scans and periodic attestations from business units. Each entry records the owner, purpose, users and affected people, the jurisdictions it operates in, the models and vendors involved, the personal-data involvement and the current lifecycle status. A classification step assigns a risk tier using the organisation's own criteria and the categories defined by applicable law, and the tier drives which further controls apply. Shadow-AI discovery and a rule that nothing goes live without a register entry keep the inventory current.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
European Union 3 duties
-
satisfies Legal requirementProviders must document and register a conclusion that an Annex III system is not high-risk
EU AI Act · Article 6(4); Article 49(2) · applies from 2 Aug 2026
Classification with recorded rationale per system.
-
supports Legal requirement confidence highDo not deploy or provide AI for prohibited practices
EU AI Act · Article 5 · applies from 2 Feb 2025
A complete register is the population to be screened.
-
supports Legal requirementDeployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
EU AI Act · Article 25(1) and 25(2) · applies from 2 Aug 2026
Inventory records the organisation's role for each system.
Australia 1 duty
-
supports Voluntary confidence highProvide contestability, supply-chain transparency and records (guardrails 7 to 9)
Australian Voluntary AI Safety Standard · Guardrails 7, 8 and 9
Register with evidence links for third-party review.
Colorado (United States) 1 duty
-
supports Legal requirement confidence highDeployers must publish a statement about the high-risk AI systems they use
Colorado AI Act · C.R.S. 6-1-1703(5) · applies from 30 Jun 2026
Source of the list of deployed high-risk systems.
South Korea 2 duties
-
supports Legal requirementAI business operators must notify users in advance that a product or service runs on high-impact or generative AI
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 31(1) · applies from 22 Jan 2026
Classification identifies which products are high-impact or generative.
-
supports Legal requirement confidence highOperators of high-impact AI must establish and operate a risk management plan
Framework Act on the Development of Artificial Intelligence and Establishment of a Foundation for Trust · Article 34(1) · applies from 22 Jan 2026
Classification of systems against the high-impact list.
Texas (United States) 1 duty
-
supports Legal requirementHealth-care providers must disclose the use of AI in patient services
Texas Responsible AI Governance Act (TRAIGA) · Business and Commerce Code Section 551.051 · applies from 1 Jan 2026
Identifies clinical and administrative systems that use AI.
United Kingdom 1 duty
-
supports Voluntary confidence highEstablish accountability and governance for AI
UK AI regulation framework · Principle 4, Part 3
Named owner for each AI system.
United States 2 duties
-
supports Voluntary confidence highMap context, intended use and potential impacts (Map)
NIST AI RMF · MAP function
Intended purpose, users and settings recorded at intake.
-
supports Legal requirementPublish an annual AI use-case inventory
OMB M-25-21 · Section 3
Vendor-side register supplies the use-case descriptions agencies ask for.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| AI system register | Register entry | One row per system with owner, purpose, risk tier, jurisdictions, vendors and status. |
| Risk-tier classification sign-off | Approval or sign-off record | Reviewer confirmation of the assigned tier and the rationale. |
| AI intake and classification procedure | Procedure or standard operating process |
Owner: AI governance lead. Frequency: continuous.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 6.5 Governance failure Socioeconomic & Environmental3 incidents · 61 risk entries
- 7.4 Lack of transparency or interpretability AI system safety, failures, & limitations5 incidents · 42 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Clause 4.1, 4.3, 8.1; Annex A.6.2.2, A.9.4 | Editorial mapping to scope, operational planning and intended-use records. | medium |
| NIST AI RMF | MAP 1.1, 1.5; GOVERN 1.6 | high | |
| MITRE ATLAS | AML.M0023 AI Bill of Materials | low |
Cite this record
AIPolicyTracker (2026). “AI system inventory and classification”. https://aipolicytracker.org/controls/ai-system-inventory (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "AI system inventory and classification" satisfy?
- It is recorded as satisfying 1 and supporting 10 duties across European Union, Australia, Colorado (United States), South Korea, Texas (United States), United Kingdom and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- AI system register, Risk-tier classification sign-off and AI intake and classification procedure. Owner: AI governance lead. Frequency: continuous.