Inventory your AI systems
Start by mapping every AI tool your organization uses. This inventory is the foundation of your compliance strategy. You must distinguish between internal prototypes and customer-facing products, as regulators treat them differently. The EU AI Act entered into force on 1 August 2024 and becomes fully applicable on 2 August 2026 European Union, AI Act. The recent EU AI Omnibus further extends high-risk compliance deadlines effective August 2026 Kasowitz Benson Torres, July 2026 Update. Knowing which systems fall under these regulations is the first step toward compliance.
Create a central registry for all AI models. Include the model name, purpose, data sources, and current deployment status. Flag any system that makes automated decisions affecting hiring, credit, or legal rights. These are likely high-risk and require immediate attention. Internal prototypes used only for research may have different obligations, but document their development stage clearly.
Use the checklist below to track your progress. This ensures no system is overlooked during the audit.
-
Identify all AI models in use
-
Categorize by risk level (high, limited, minimal)
-
Document data sources and training methods
-
Flag systems affecting employees or customers
Once the inventory is complete, you can move to risk assessment. This baseline allows you to prioritize resources and meet regulatory deadlines efficiently.
Classify risk under the AI Act
To determine the compliance burden for your systems, you must map each identified AI solution to one of the four risk categories defined by the EU AI Act. This classification dictates whether a system is banned, requires strict oversight, or faces minimal regulation. The Act enters into full application on 2 August 2026, making this classification step critical for your 2026 audit timeline.
The risk framework is hierarchical. Unacceptable risk systems are prohibited outright. High-risk systems face the most stringent obligations, including conformity assessments and human oversight. Limited risk systems require transparency, such as informing users they are interacting with AI. Minimal risk systems are largely unregulated, though voluntary codes of conduct are encouraged.
Use the comparison below to identify the specific obligations attached to each tier. This table serves as your primary reference for determining the audit scope required for each system in your inventory.
| Risk Tier | Key Compliance Obligations | Application Date | Common Examples |
|---|


No comments yet. Be the first to share your thoughts!