Template
AI inventory template: the fields that actually matter
An AI inventory that lists tool names cannot answer a single compliance question. The unit of record is the use case: one tool used for two purposes is two rows. This page gives the fields to capture, why each one is there, and the three columns that do most of the work — purpose, data, and the decision the output affects.
Why the use case is the unit, not the tool
Risk under the AI Act follows the use, not the product. The same assistant is minimal risk when it tidies a draft and high risk when it ranks job applicants. An inventory keyed on tool names collapses that distinction and cannot support any classification.
This is also what buyers ask for. A procurement questionnaire asks what the AI is used for and who is accountable, not which vendors you hold licences with.
- One tool with two purposes is two rows.
- A row is a use case: tool plus purpose plus data plus owner.
- Rows are what get classified, approved or retired.
- A tool list is a licensing record, not an inventory.
The fields to record
Start with these columns. The first four are enough to be useful on day one; the rest can be filled in as the inventory matures.
- Use case — one sentence describing what it is used for.
- Tool and vendor — the product and who provides it.
- Owner — a named person, not a team.
- Data involved — personal data, special categories, confidential business data, or none.
- Decision affected — what the output influences, and whether a human decides.
- Users — which team, and roughly how many people.
- Risk class — unacceptable, high, limited or minimal, with the reason.
- Role — whether you are provider or deployer for this use case.
- Legal basis — where personal data is processed.
- Data processor agreement — in place, not needed, or missing.
- Approved — yes, no, or pending, and by whom.
- Last confirmed — the date a named person verified this row.
The three columns that do the work
If you record nothing else, record purpose, data and decision. Those three determine the risk class, the data protection obligations and whether human oversight is required. Everything else is administration around them.
The last confirmed date matters more than it looks. An inventory nobody has re-checked in a year is evidence of a process that stopped, which is worse than no inventory when a customer or an authority asks.
- Purpose decides whether an Annex III area is engaged.
- Data decides whether the GDPR obligations bite, and how hard.
- Decision decides whether meaningful human oversight is required.
- Last confirmed decides whether anyone should believe the row.
Keeping it honest
Inventories decay because they are collected once, by a central team, from people who have no reason to answer. The rows that matter most — the unapproved tool someone tried last week — are exactly the ones least likely to be volunteered.
Make confirmation cheap and attributable: a named person confirms a short row about their own work, and the date is recorded. That is the difference between a document and a control.
- Ask the person doing the work, not a central proxy.
- Keep each row short enough to confirm in under a minute.
- Record who confirmed it and when.
- Re-confirm on a schedule, and after any change of purpose.
Frequently asked questions
What should an AI inventory contain?
One row per use case, with the purpose, the tool, a named owner, the data involved, the decision the output affects, the risk class and the date someone last confirmed it. Purpose, data and decision are the three fields that determine the obligations.
Is a list of AI tools enough?
No. Risk under the AI Act follows the use, not the tool, so a list of product names cannot support a risk classification or answer a customer questionnaire. The same tool can appear in several rows with different risk classes.
Is an AI inventory legally required in Norway?
Not as a standalone Norwegian requirement, because the Norwegian act has not been adopted. In practice the GDPR record of processing already covers AI use involving personal data, and every AI Act obligation that arrives later depends on knowing what is used and for what.
How often should the inventory be updated?
Re-confirm on a fixed cycle — twice a year is a reasonable floor while the rules are moving — and immediately when a tool gains new AI features or a use case changes purpose.
Can a spreadsheet work as an AI inventory?
Yes, to begin with. A spreadsheet with the fields above beats no inventory. It tends to break down when rows need confirming by many people on a schedule, because chasing confirmations by hand is what causes the record to go stale.
Free orientation tool
Understand how the EU AI Act may apply
Answer plain-language questions, get explanations as you go, and see the official legal basis behind your result.
Start the AI Act assessment