AI Systems Inventory: A Practical Guide to Compliance | V-PROOF
Most organizations that launch an AI governance program run into the same problem within the first week: they don't know exactly which AI systems they're using.
Not because everyone in the organization knows it. But because no one has a centralized, consistent, and up-to-date view of it.
Without inventory, there is no governance. And without governance, there is no compliance.
Why Inventory Is the First Real Obligation of the EU AI Act
The General Data Protection Regulation ( EU AI Act ) establishes as a fundamental requirement that operators of AI systems understand and document the systems they deploy. The entire compliance framework of the Regulation—and of ISO/IEC 42001—is based on the assumption that the organization maintains a complete and up-to-date inventory.
You can't manage the risk of something you don't know exists
You cannot demonstrate human oversight of an unregistered system
You can't comply with the technical documentation requirements if you don't know what to document
What Should an AI Systems Inventory Include?
Name, version, vendor, deployment date, designated internal contact.
What decisions do you make or help make, regarding whom, and in which business processes ? In functional, non-technical language.
Does it fall under Annex III? Does it have an impact on fundamental rights? Is the risk high, limited, or minimal?
Source, sensitivity, and legal basis for processing. Includes training data and operational data.
Existing human oversight mechanisms, frequency, and responsible party. Not the ones that should exist, but the ones that actually exist.
What regulatory obligations apply, and what is the actual status of compliance with each one?
Deployed versions, use case changes, model updates. Each change includes the date and the person responsible.
The Four Errors That Invalidate the Inventory
Take inventory of tools rather than systems
"We use ChatGPT" is not an AI governance record. The relevant record describes the use case, the process, and the controls—notjust the name of the tool.
Do not update when the usage changes
A system deployed for a low-risk scenario can evolve into a high-risk one without anyone updating the records. Static inventories become invalid within weeks.
Exclude third-party systems
EU AI Act does not exempt your organization from compliance just because the system is provided by a third party. If you deploy or use it, the responsibility for compliance falls on you.
Do not assign internal personnel
An inventory with no owner isn't an inventory— it's a document that no one updates and that, within six months, no longer reflects reality.
The inventory states what should have happened. Verifiable evidence shows that it did happen.
V-PROOF Protocol · AI Governance Infrastructure 2026From Inventory to Verifiable Evidence
A well-structured inventory is the map. V-PROOF operates at the layer that transforms that map into actual compliance: it captures asset by asset the AI-to-human ratio, explicit human approval, and the regulatory context, and generates the V-Seal, SHA-256 + timestamp from the Base L2 blockchain.
System X should include human review of all outputs from process Y
This output from process Y, today at 10:23 a.m., was reviewed and approvedV-Seal (verifiable via QR code)
Build the inventory and demonstrate that it works
Systems Inventory · Classification EU AI Act · Verifiable Evidence asset by asset.
The starting point for any genuine AI governance program.
