AI Systems Inventory: A Practical Guide to Compliance | V-PROOF

AI Governance· EU AI Act· Practical Guide· September 15, 2026· Reading time: 3 min.
IA InventoryEU AI ActAI RegistryPractical Guide

Most organizations that launch an AI governance program run into the same problem within the first week: they don't know exactly which AI systems they're using.

Not because everyone in the organization knows it. But because no one has a centralized, consistent, and up-to-date view of it.

The typical scenario in any medium-sized organization
Marketing uses a content generator. No registration required.
HR has a resume screening system. High risk: EU AI Act.
Legal uses a contract drafting assistant. Unclassified.
Operations deployed a predictive model 9 months ago. IT purchased it, but no one documented the use case.

Without inventory, there is no governance. And without governance, there is no compliance.

Why Inventory Is the First Real Obligation of the EU AI Act

EU AI Act · Effective August 2, 2026

The General Data Protection Regulation ( EU AI Act ) establishes as a fundamental requirement that operators of AI systems understand and document the systems they deploy. The entire compliance framework of the Regulation—and of ISO/IEC 42001—is based on the assumption that the organization maintains a complete and up-to-date inventory.

Out of stock

You can't manage the risk of something you don't know exists

Out of stock

You cannot demonstrate human oversight of an unregistered system

Out of stock

You can't comply with the technical documentation requirements if you don't know what to document

What Should an AI Systems Inventory Include?

Identification

Name, version, vendor, deployment date, designated internal contact.

Use case

What decisions do you make or help make, regarding whom, and in which business processes ? In functional, non-technical language.

EU AI Act classification

Does it fall under Annex III? Does it have an impact on fundamental rights? Is the risk high, limited, or minimal?

Data Used

Source, sensitivity, and legal basis for processing. Includes training data and operational data.

Active Controls

Existing human oversight mechanisms, frequency, and responsible party. Not the ones that should exist, but the ones that actually exist.

Compliance Status

What regulatory obligations apply, and what is the actual status of compliance with each one?

Change Log

Deployed versions, use case changes, model updates. Each change includes the date and the person responsible.

The Four Errors That Invalidate the Inventory

Take inventory of tools rather than systems

"We use ChatGPT" is not an AI governance record. The relevant record describes the use case, the process, and the controls—notjust the name of the tool.

Do not update when the usage changes

A system deployed for a low-risk scenario can evolve into a high-risk one without anyone updating the records. Static inventories become invalid within weeks.

Exclude third-party systems

EU AI Act does not exempt your organization from compliance just because the system is provided by a third party. If you deploy or use it, the responsibility for compliance falls on you.

Do not assign internal personnel

An inventory with no owner isn't an inventory— it's a document that no one updates and that, within six months, no longer reflects reality.

The inventory states what should have happened. Verifiable evidence shows that it did happen.

V-PROOF Protocol · AI Governance Infrastructure 2026
V-PROOF Protocol · Evidence Layer

From Inventory to Verifiable Evidence

A well-structured inventory is the map. V-PROOF operates at the layer that transforms that map into actual compliance: it captures asset by asset the AI-to-human ratio, explicit human approval, and the regulatory context, and generates the V-Seal, SHA-256 + timestamp from the Base L2 blockchain.

Inventory

System X should include human review of all outputs from process Y

V-PROOF

This output from process Y, today at 10:23 a.m., was reviewed and approvedV-Seal (verifiable via QR code)

V-PROOF

Build the inventory and demonstrate that it works

Systems Inventory · Classification EU AI Act · Verifiable Evidence asset by asset.
The starting point for any genuine AI governance program.

Request a Strategic Assessment →
Previous
Previous

Your code already has a history. Strategic Provenance turns that history into evidence.

Next
Next

Why Your GRC Tool Isn't Enough to Govern AI—and What Is