"What AI do we actually use?"
It's the question boards are asking MDs this year — usually after reading another AI Act headline, sometimes after a customer's procurement questionnaire arrives with a deadline attached. Most leaders answer with the short list: Copilot, ChatGPT, that CRM add-on someone signed off in the spring. The honest answer is longer, and nobody in the room has it.
That gap has a fix, and it's less dramatic than the consulting decks suggest: an AI inventory. This page covers what one is, what goes in it, and how to build a credible version in a working afternoon without buying anything. It's part of our cluster on AI Act compliance in practice — for the regulatory backdrop, start with our full guide to the EU AI Act for UK and Irish businesses.
What is an AI inventory, exactly?
An AI inventory — you'll also hear it called an AI register for businesses — is exactly what it sounds like: a list of every AI system your organisation uses, with enough detail per row that someone else could pick it up and understand the picture. Not software. Not a platform. A register: one row per system, a handful of fields, a named owner, a review date.
The EU AI Act never says "thou shalt maintain an AI inventory" as a standalone rule with its own fine attached. It doesn't need to. Every obligation that does exist — classifying your systems by risk, ensuring staff are AI-literate, keeping logs, handling incidents, assigning who's accountable — starts from the same premise: you know which AI systems you operate. You can't classify a system you've never heard of. You can't train people on a tool nobody will admit to using.
That's why the inventory is artefact zero. It's the document that makes every other obligation possible — and, in practice, it's the first thing a regulator, a customer's procurement team, or your insurer asks to see. "What is an AI inventory?" turns out to be the easy question. The useful one is: does yours exist, and is it true?
Why the AI Act makes it non-optional
Strip the regulation down and the obligations cascade from a single fact. To classify your systems by risk tier, you need the list of systems. To meet the Article 4 AI literacy duty, you need to know which tools staff actually use, so training can match reality. To keep the logs the Act expects and handle incidents when they happen, you need to know where AI touches your operations in the first place. To say who's accountable for any of it, someone has to own each system — which, again, means knowing what they are. (We're publishing plain-English guides on risk classes, literacy and logging over the coming weeks — this page is the foundation they all build on.)
None of that works blind. An inventory isn't the most exciting compliance artefact — it's the one the rest of them are written on.
UK-registered firms tend to assume this is an EU-only problem. It follows output, not registration: if your AI systems' output is used in the EU, you sell to EU customers, or EU-based people use your tools, you're in scope. The three tests are unpacked in does the EU AI Act apply to UK businesses? — and the geography argument doesn't save you, as the Brexit misconception explainer shows. Practical guidance, not legal advice; we work alongside your legal counsel.
What actually goes in an AI inventory
Eight fields per system. Deliberately un-sexy — the point is a document your ops manager maintains in twenty minutes a quarter, not a second job. For each AI system, record:
Name and vendor — what it's called and who supplies it.
Purpose — what it actually does for you, in one sentence.
Who uses it — which teams, roughly how many people.
Data it touches — customer data, staff data, commercial data, nothing sensitive.
Procured or adopted — bought through procurement, or quietly adopted by a team.
Risk tier — your current read on where it sits under the Act.
Named owner — one person, by name, accountable for the entry.
Last reviewed — the date someone confirmed the row is still true.
One worked example, so it's concrete. A row from a typical 100-person B2B firm:
Example entry — one AI system, one row
- Name & vendor
- Support Co-Pilot (fictional) — chat assistant embedded in the service desk
- Purpose
- Drafts replies to tier-1 support tickets; agent approves and sends
- Who uses it
- Support team, 6 agents
- Data it touches
- Ticket text — includes customer names and account details
- Procured or adopted
- Adopted — enabled by the team during a renewal, never through procurement
- Risk tier
- Low under current read — human-in-the-loop, no automated decisions
- Owner
- Head of Support
- Last reviewed
- 2026-09-25
That's the whole artefact. A hundred-row version of this in a spreadsheet is a genuinely defensible AI inventory. Anyone selling you the idea that you need a platform first is solving their problem, not yours.
The shadow AI problem: why the spreadsheet is always wrong
Here's the uncomfortable part. The list procurement maintains and the list of what's actually running are never the same list. Teams adopt tools on their own — a browser extension that writes emails, an AI feature silently switched on inside existing SaaS, a free chatbot someone pasted customer data into to "test something". None of it shows up in any budget line. None of it has an owner.
This is shadow AI, and it's the reason a first-draft inventory built from procurement records alone will be wrong — usually by a factor, not a rounding error. The gap matters precisely because unowned tools are where AI Act exposure concentrates: no literacy coverage, no data assessment, no oversight. We're publishing a full guide to shadow AI shortly; for now, treat every discrepancy between the official list and reality as a finding, not an annoyance.
Halfway through building your list, most MDs have the same realisation: "I genuinely don't know what my team is using." That's not a failure — that's the inventory working. Take the AI Act quiz (2 minutes) if you want a quick read on how exposed your current setup is while the draft is still warm.
How to build one in a working afternoon
Scaled for an SME, no platform pitch. Four steps:
- Start with spend, not surveys. Pull the last 12 months of SaaS and software invoices plus the corporate card list. Every AI-bearing product you pay for goes on the sheet first — these rows are easy and they seed the rest.
- Ask the teams — anonymously. Five questions, two minutes, no names: which AI tools do you use weekly, which did you try and drop, what did you paste into them. Anonymity is what makes the answers honest. The delta between this and step 1 is your shadow AI finding.
- Verify what you can. If you have SSO, check the app list against what staff actually authenticate to. If you have browser or endpoint tooling, cross-check extensions. This step is optional at 30 staff, close to mandatory at 200.
- Assign owners and set the rhythm. Every row gets a named owner. The register gets a quarterly review — twenty minutes, tick or amend each row. An inventory that's stale is just a more confident way of being wrong.
That's the afternoon. The output isn't a legal opinion — it's the list, the gaps, and a starting order for closing them. From there the ladder runs: the quiz to read your exposure, an Exposure Assessment to confirm which of the Act's triggers you meet, and — where the stakes justify it — our AI Act Readiness service, which turns the inventory into a prioritised compliance plan alongside your legal counsel.
What to do next
You can't comply with what you can't see — and the seeing is the cheap part. Take the AI Act quiz (six questions, two minutes), then block the afternoon and build the list. The obligations feel lighter once artefact zero exists.