AIPolicyTracker
RegisterFree · no accountEU AI ActISO/IEC 42001NIST AI RMF

AI System Inventory

One row per AI system: purpose, role under the law, jurisdictions, risk tier, data, owner and review dates, with the recorded duties for each role on a reference sheet.

Formats: XLSX and DOCX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Inventory sheet with dropdowns for lifecycle stage, legal role, jurisdiction and EU AI Act tier
  • Automatic next-review date and overdue flag
  • Reference sheet: every recorded duty by legal role, with its source reference and record link
  • Reference sheet: jurisdictions with binding AI law

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Inventory · 18 columns · blank, 200 rows ready to fill
First rows of the Inventory sheet
System IDSystem nameBusiness ownerIntended purposeLifecycle stage ▾Your role under the law ▾Primary jurisdiction ▾EU AI Act tier ▾Personal data ▾Automated decisions about people ▾VendorModel / providerData sourcesLast reviewNext review ƒReview status ƒEvidence linkNotes
Rows are yours to fill; the dropdowns, formulas and colour rules are already in place.

One row per AI system, including third-party tools with AI features. Decide the role before the tier: obligations follow the role.

Sheet: Duties by role · 14 columns · 112 rows from the records
First rows of the Duties by role sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Establish accountability processes and a risk-management process (guardrails 1 and 2)Governance and accountabilityAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 1 and 2Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail AI accountability and risk-management documentationClauses 5 and 6GOVERN and MAPSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6)Human oversightAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 4, 5 and 6Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enabTest reports and user disclosure recordsMEASURE and MANAGE functionsSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency
Provide contestability, supply-chain transparency and records (guardrails 7 to 9)Vendor and supply-chain governanceAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 7, 8 and 9Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, modelAI system register and supplier disclosuresGOVERN 6.xSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records
Large frontier developers must publish a frontier AI frameworkSafety testing and evaluationCalifornia SB 53California (United States)General-purpose AI model providerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, Published frontier AI frameworkGOVERN 1.x; NIST AI 600-1Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework
Report critical safety incidents to the Office of Emergency ServicesIncident reporting and handlingCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code, Chapter 25.1 (as added by SB 53)2026-01-01Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and thIncident classification and reporting procedureMANAGE 4.3Source-linkedhttps://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting
Frontier developers must publish a transparency report before deploying a new frontier modelTransparency and disclosureCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementBusiness and Professions Code Section 22757.12 (as added by SB 53)2026-01-01Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websiPublished model transparency report; Redaction justification logAnnex A.8.2, A.8.3GOVERN 4.2, MAP 5.1, MEASURE 2.6Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report

Every recorded duty, with the roles it binds. Filter the "Who it binds" column by the role you chose in the inventory.

Sheet: Jurisdictions · 5 columns · 42 rows from the records
First rows of the Jurisdictions sheet
JurisdictionBinding instrumentStatusApplies fromRecord
ArgentinaDecisión Administrativa 899/2024In forcehttps://aipolicytracker.org/policies/argentina-decision-administrativa-899-2024
ArgentinaDisposición 2/2023In forcehttps://aipolicytracker.org/policies/argentina-disposicion-2-2023
California (United States)California SB 53In force2026-01-01https://aipolicytracker.org/policies/us-california-sb-53
ChinaInterim Measures for the Management of Generative Artificial Intelligence ServicesIn forcehttps://aipolicytracker.org/policies/china-interim-measures-for-the-management-of-generative-artificial-intelligence-services
ChinaMeasures for Labeling Artificial Intelligence-Generated and Synthetic ContentIn forcehttps://aipolicytracker.org/policies/china-measures-for-labeling-artificial-intelligence-generated-and-synthetic-content
Colorado (United States)Colorado AI ActAdopted2026-06-30https://aipolicytracker.org/policies/us-colorado-ai-act

Document outline (DOCX)

  1. Why an inventory
  2. Fields and what to record
  3. Duties that require a record of your systems
  4. Establish accountability processes and a risk-management process (guardrails 1 and 2)
  5. Frontier developers must protect employees who report catastrophic-risk concerns
  6. Developers must document high-risk systems and disclose known risks
  7. Draw up technical documentation before placing a high-risk system on the market
  8. Design high-risk systems to log events automatically
  9. Use high-risk AI as instructed, monitor it and inform affected people
  10. Providers must meet the full set of provider duties for high-risk AI
  11. Providers must keep high-risk AI documentation for ten years
  12. Providers must retain automatically generated logs under their control
  13. Providers must supply conformity evidence and log access to authorities on request
  14. Non-EU providers must appoint an EU authorised representative for high-risk AI
  15. Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI

Duties this template covers (27)

Each is cited in the file with its source reference and a link back to the record.

See all 27 duties →

Legal basis

Version history

Versions of AI System Inventory
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI System Inventory free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 166 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI System Inventory free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 166 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.