AI System Inventory
One row per AI system: purpose, role under the law, jurisdictions, risk tier, data, owner and review dates, with the recorded duties for each role on a reference sheet.
What's inside
- Inventory sheet with dropdowns for lifecycle stage, legal role, jurisdiction and EU AI Act tier
- Automatic next-review date and overdue flag
- Reference sheet: every recorded duty by legal role, with its source reference and record link
- Reference sheet: jurisdictions with binding AI law
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Inventory
| System ID | System name | Business owner | Intended purpose | Lifecycle stage ▾ | Your role under the law ▾ | Primary jurisdiction ▾ | EU AI Act tier ▾ | Personal data ▾ | Automated decisions about people ▾ | Vendor | Model / provider | Data sources | Last review | Next review ƒ | Review status ƒ | Evidence link | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Rows are yours to fill; the dropdowns, formulas and colour rules are already in place. | |||||||||||||||||
One row per AI system, including third-party tools with AI features. Decide the role before the tier: obligations follow the role.
Sheet: Duties by role
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Establish accountability processes and a risk-management process (guardrails 1 and 2) | Governance and accountability | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 1 and 2 | Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail | AI accountability and risk-management documentation | Clauses 5 and 6 | GOVERN and MAP | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management | |
| Test and monitor systems, enable human control, and be transparent with users (guardrails 4 to 6) | Human oversight | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 4, 5 and 6 | Test AI models and systems before deployment and monitor them in operation; enable meaningful human control and intervention; and inform end users about AI-enab | Test reports and user disclosure records | MEASURE and MANAGE functions | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-testing-human-control-transparency | ||
| Provide contestability, supply-chain transparency and records (guardrails 7 to 9) | Vendor and supply-chain governance | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 7, 8 and 9 | Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, model | AI system register and supplier disclosures | GOVERN 6.x | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records | ||
| Large frontier developers must publish a frontier AI framework | Safety testing and evaluation | California SB 53 | California (United States) | General-purpose AI model provider | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Large frontier developers must publish and maintain a framework describing how they incorporate national and international standards, assess catastrophic risk, | Published frontier AI framework | GOVERN 1.x; NIST AI 600-1 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-frontier-ai-framework | |
| Report critical safety incidents to the Office of Emergency Services | Incident reporting and handling | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code, Chapter 25.1 (as added by SB 53) | 2026-01-01 | Frontier developers must report critical safety incidents to the California Office of Emergency Services within the statutory time limit after discovery, and th | Incident classification and reporting procedure | MANAGE 4.3 | Source-linked | https://aipolicytracker.org/obligations/us-california-sb-53-critical-safety-incident-reporting | |
| Frontier developers must publish a transparency report before deploying a new frontier model | Transparency and disclosure | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Business and Professions Code Section 22757.12 (as added by SB 53) | 2026-01-01 | Before or at the time a frontier developer deploys a new frontier model, or a substantially modified version, it must publish a transparency report on its websi | Published model transparency report; Redaction justification log | Annex A.8.2, A.8.3 | GOVERN 4.2, MAP 5.1, MEASURE 2.6 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-transparency-report |
Every recorded duty, with the roles it binds. Filter the "Who it binds" column by the role you chose in the inventory.
Sheet: Jurisdictions
| Jurisdiction | Binding instrument | Status | Applies from | Record |
|---|---|---|---|---|
| Argentina | Decisión Administrativa 899/2024 | In force | https://aipolicytracker.org/policies/argentina-decision-administrativa-899-2024 | |
| Argentina | Disposición 2/2023 | In force | https://aipolicytracker.org/policies/argentina-disposicion-2-2023 | |
| California (United States) | California SB 53 | In force | 2026-01-01 | https://aipolicytracker.org/policies/us-california-sb-53 |
| China | Interim Measures for the Management of Generative Artificial Intelligence Services | In force | https://aipolicytracker.org/policies/china-interim-measures-for-the-management-of-generative-artificial-intelligence-services | |
| China | Measures for Labeling Artificial Intelligence-Generated and Synthetic Content | In force | https://aipolicytracker.org/policies/china-measures-for-labeling-artificial-intelligence-generated-and-synthetic-content | |
| Colorado (United States) | Colorado AI Act | Adopted | 2026-06-30 | https://aipolicytracker.org/policies/us-colorado-ai-act |
Document outline (DOCX)
- Why an inventory
- Fields and what to record
- Duties that require a record of your systems
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Developers must document high-risk systems and disclose known risks
- Draw up technical documentation before placing a high-risk system on the market
- Design high-risk systems to log events automatically
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must keep high-risk AI documentation for ten years
- Providers must retain automatically generated logs under their control
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
Duties this template covers (27)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Keep records of consequential decisions influenced by the technology for three years
- Developers must supply deployers with documentation of the technology
- Draw up technical documentation before placing a high-risk system on the market
- Design high-risk systems to log events automatically
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must keep high-risk AI documentation for ten years
- Providers must retain automatically generated logs under their control
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI System Inventory free?
- Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 166 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI System Inventory free?
- Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 166 recorded duties are cited in it, drawn from 11 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.