Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What must an AI system inventory capture?
Updated
Regulation (EU) 2024/1689 has no article headed 'keep an inventory'. Articles 49 and 71 with Annex VIII set an EU-database registration duty for certain high-risk systems; ISO/IEC 42001:2023 asks for a register as practice. Not legal advice. Recording a row is not registration.
AI inventory requirements, last verified 10 September 2026 against Articles 6, 49, 71 and 113 and Annex VIII of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not register anything in the EU database.
This is Articles 49 and 71 and Annex VIII, not YOUR registration
Audience: a compliance owner, CISO, data-governance lead, or engineering manager building a defensible register of the models and AI systems an organisation builds, buys, or uses. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not file with the AI Office and does not register in the EU database.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 49 is the registration duty. Article 71 is the EU database the Commission sets up and maintains. Annex VIII lists the information submitted upon registration. None of those three texts is an inventory obligation in the ordinary sense: an inventory is how an organisation finds out which of its systems might fall inside them. Last verified 10 September 2026. Not legal advice.
- Statute versus standard versus guidance versus product: Articles 6, 49, 71 and 113 and Annex VIII of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 is a management-system standard, not a legal substitute for the Act. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. The field checklist below is a ShipReadyMetrics recommendation. This page labels which kind of text each claim rests on.
- The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page. The how-shipreadymetrics-builds-ai-inventory guide on this site is the product page for the register itself. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
- This page does not invent a 2 August 2026 date for Annex I product-embedded high-risk systems. Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. Article 113(a) is 2 February 2025 for Chapters I and II. Article 113(b) is 2 August 2025 for Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78, with the exception of Article 101. Those dates are not one number.
Three different texts: Article 49 registration, ISO 42001 practice, ShipReady recommendation
The most common inventory mistake is treating them as one thing. Article 49 is a legal duty to register named systems in a Commission-operated database, only if it applies. ISO/IEC 42001:2023 asks an organisation to know its AI systems as part of a management system — a standard, not a law. The field list further down is our own recommendation, offered because a register that only carries the Annex VIII fields is not enough to run an organisation. Last verified 10 September 2026. Not legal advice.
| Source | What the cited text is | Kind of text | Last verified |
|---|---|---|---|
| Article 49 of 2024/1689 — registration in the EU database | Registration in the EU database referred to in Article 71, before placing on the market or putting into service. Article 49(1) is the provider (or authorised representative) duty for Annex III high-risk systems, with the exception of point 2 of Annex III. Article 49(2) covers a provider that has concluded under Article 6(3) that its Annex III system is not high-risk. Article 49(3) covers deployers that are public authorities, Union institutions, bodies, offices or agencies, or persons acting on their behalf. Article 49(4) puts law-enforcement, migration, asylum and border-control cases in a secure non-public section. Article 49(5) keeps point 2 of Annex III at national level. | Article 49 of 2024/1689. Legal requirement, only if it applies. It binds particular providers and particular deployers, not every organisation with an AI inventory. This product does not register in the EU database. | 10 September 2026 |
| Article 71 of 2024/1689 — the EU database itself | The Commission shall, in collaboration with the Member States, set up and maintain an EU database containing information concerning high-risk AI systems registered under Articles 49 and 60, and AI systems not considered high-risk under Article 6(3) and registered under Article 6(4) and Article 49. Annex VIII Section A data is entered by the provider or, where applicable, the authorised representative; Annex VIII Section C data is entered by the public-authority deployer. Most of the registered information is publicly accessible; the Article 49(4) section is not. | Article 71 of 2024/1689. Legal requirement, addressed in part to the Commission. The database is operated by the Commission. This product is not that database and does not write to it. | 10 September 2026 |
| Annex VIII of 2024/1689 — the information submitted on registration | Annex VIII lists what is entered on registration: Section A for providers registering under Article 49(1), Section B for the Article 49(2) not-high-risk case, and Section C for public-authority deployers under Article 49(3). Section A runs to provider identity and contact details, any authorised representative, the trade name and unambiguous reference of the system, the intended purpose, a concise description of the data and operating logic, the market status, notified-body certificate details where applicable, the Member States concerned, the EU declaration of conformity, and electronic instructions for use. Counsel reads the authentic Annex; this row is a summary of its shape, not a substitute for it. | Annex VIII of 2024/1689. Legal requirement of the registration content, only if Article 49 applies. It is a checklist of fields for a registration that is owed — never a finding that YOU owe one. | 10 September 2026 |
| ISO/IEC 42001:2023 — knowing your AI systems as management-system practice | The standard's Annex A control areas cover, among others, resources for AI systems, the AI system life cycle, data for AI systems, use of AI systems, and third-party and customer relationships. Operationalising them requires an organisation to know which AI systems exist, who is accountable for each, and what has been assessed. That is inventory practice. | ISO/IEC 42001:2023. Best practice / standard, not a legal substitute for the Act. An ISO 42001 register is not an Article 49 registration and does not discharge it. | 10 September 2026 |
| The field checklist on this page | A superset: the identity and classification facts an organisation needs to answer 'which of our systems might be in scope, and who would have to do what', plus the artefact facts that make an obligation answerable later. | ShipReadyMetrics recommendation. Not the regulation, not a standard, and not legal advice. A named human still owns every classification in it. | 10 September 2026 |
What original Articles 49 and 71 actually say
Last verified 10 September 2026 against Articles 49 and 71 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. This page does not apply them to YOU. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 49(1) — provider registration before market or service | Authentic Article 49(1): Before placing on the market or putting into service a high-risk AI system listed in Annex III, with the exception of high-risk AI systems referred to in point 2 of Annex III, the provider or, where applicable, the authorised representative shall register themselves and their system in the EU database referred to in Article 71. | Article 49(1) of 2024/1689. Legal requirement, only if it applies. Both the operator and the system are registered. This page does not determine that YOU are a provider or that YOUR system is Annex III high-risk. | 10 September 2026 |
| Article 49(2) — the Article 6(3) not-high-risk conclusion is still registered | Authentic Article 49(2): Before placing on the market or putting into service an AI system for which the provider has concluded that it is not high-risk according to Article 6(3), that provider or, where applicable, the authorised representative shall register themselves and that system in the EU database referred to in Article 71. | Article 49(2) of 2024/1689. Legal requirement, only if it applies. Concluding not-high-risk under Article 6(3) is itself a documented conclusion, not a silence. This page does not run Article 6(3) for YOU. | 10 September 2026 |
| Article 49(3) — public-authority deployers register the use | Authentic Article 49(3): Before putting into service or using a high-risk AI system listed in Annex III, with the exception of high-risk AI systems listed in point 2 of Annex III, deployers that are public authorities, Union institutions, bodies, offices or agencies or persons acting on their behalf shall register themselves, select the system and register its use in the EU database referred to in Article 71. | Article 49(3) of 2024/1689. Legal requirement, only if it applies. It is a deployer duty limited to public authorities and Union bodies and those acting on their behalf, not deployers generally. This page does not determine that YOU are such a deployer. | 10 September 2026 |
| Article 49(4) and 49(5) — non-public section and national-level cases | Article 49(4) places registration for Annex III points 1, 6 and 7 in the areas of law enforcement, migration, asylum and border-control management in a secure non-public section of the EU database, with a restricted field set. Article 49(5) provides that high-risk AI systems referred to in point 2 of Annex III shall be registered at national level. | Article 49(4)–(5) of 2024/1689. Legal requirements, only if they apply. Not every registration is public and not every registration is central. This page does not classify YOUR system under Annex III. | 10 September 2026 |
| Article 71(1)–(2) — who operates the database and who enters what | Authentic Article 71(1), in substance: the Commission shall, in collaboration with the Member States, set up and maintain an EU database containing the information referred to in that Article concerning high-risk AI systems referred to in Article 6(2) registered in accordance with Articles 49 and 60, and AI systems not considered high-risk pursuant to Article 6(3) registered in accordance with Article 6(4) and Article 49. Article 71(2): the data listed in Section A of Annex VIII shall be entered into the EU database by the provider or, where applicable, by the authorised representative. | Article 71(1)–(2) of 2024/1689. Legal requirements. The Commission operates the database. Any private tool that holds the same fields is a working copy, never the register of record. | 10 September 2026 |
| Article 71(3)–(4) — deployer entries and public accessibility | Article 71(3): the data listed in Section C of Annex VIII shall be entered into the EU database by the deployer who is, or who acts on behalf of, a public authority, agency or body, in accordance with Article 49(3) and (4). Article 71(4): with the exception of the section referred to in Article 49(4), information registered in accordance with Article 49 shall be accessible and publicly available in a user-friendly manner, and should be easily navigable and machine-readable. | Article 71(3)–(4) of 2024/1689. Legal requirements. Public accessibility is a property of the EU database, not of YOUR internal register. | 10 September 2026 |
Inventory field checklist — a recommendation, not a finding
Every field below is a fact an organisation records about itself. Recording it is not an Article 49 registration, not a classification under Article 6, and not a determination that the Act applies. Where a field mirrors an Annex VIII entry, that is a convenience for a registration someone else has decided is owed — never a finding that YOU owe one. Last verified 10 September 2026. Not legal advice.
| Field | Why it earns its place | Kind of text | Last verified |
|---|---|---|---|
| System name and unambiguous reference | Annex VIII Section A asks for the trade name and any additional unambiguous reference allowing identification and traceability. Internally, it is the difference between one register row and three arguments about which system was meant. | Mirrors Annex VIII of 2024/1689 (legal requirement of a registration content, only if Article 49 applies) plus ShipReadyMetrics recommendation. | 10 September 2026 |
| Intended purpose and use case | Annex VIII Section A asks for a description of the intended purpose and of the components and functions supported. The intended purpose is also what Annex III categories are read against. A blank use case is honest; a guessed one is not. | Mirrors Annex VIII and Article 6 of 2024/1689 (legal requirements, only if they apply). Recording a use case is not a classification. | 10 September 2026 |
| Declared risk classification, and who declared it | An organisation's own view of the tier. It is a declaration, subject to challenge. A register that stores the declaration without storing who made it cannot be audited later. | ShipReadyMetrics recommendation. Article 6 classification is a legal question for counsel. A declared tier is not a finding. | 10 September 2026 |
| Provider or deployer posture for this system, and the external provider's name | The same organisation is a provider for one system and a deployer for another. Article 26 deployer duties and Article 16 provider duties do not travel together. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. | Mirrors Articles 3, 16, 25 and 26 of 2024/1689 (legal requirements, only if they apply). Recording a posture is not a determination of YOUR role. | 10 September 2026 |
| GPAI status, and whether systemic risk has been asserted | Chapter V duties are a separate track from the high-risk track, on a separate date under Article 113(b). The GPAI-requirements guide on this site is the Article 53 baseline page; the GPAI-systemic-risk guide on this site is the Article 51–55 page. | Mirrors Articles 51–55 of 2024/1689 (legal requirements, only if they apply). A flag is not a designation. | 10 September 2026 |
| Accountable owner — a named person, not a team mailbox | ISO/IEC 42001:2023 accountability practice, and the precondition for Article 14 and Article 26(2) human oversight actually being someone's job. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page. | ISO/IEC 42001:2023 practice plus ShipReadyMetrics recommendation. Naming an owner is not Article 14 compliance. | 10 September 2026 |
| Which governance artefacts exist: impact assessment, data governance, life cycle, transparency, responsible use, human oversight, record keeping, technical documentation | These are the questions an auditor asks first, and the ones an organisation most often cannot answer from memory. Recording that an artefact does not exist is a real answer; a blank is not. | Mirrors Articles 9 to 15 of 2024/1689 and ISO/IEC 42001:2023 (legal requirements only if they apply; the standard is not a legal substitute). Ticking a box is not conformity. | 10 September 2026 |
| Whether the organisation asserts an EU-database registration exists for this system | An organisation may need to record that a registration under Article 49 was made — by it, or by the provider it deploys from. That record is an attestation the organisation entered about itself. It is not the registration, it is not evidence of one, and no product writes it to the Commission's database. | Refers to Articles 49 and 71 of 2024/1689 (legal requirements, only if they apply). Recording an attestation is not registering. This product does not register in the EU database. | 10 September 2026 |
| Conformity-review date and last substantial modification | A dated review is the only way to distinguish 'assessed and current' from 'assessed once, in a version that no longer exists'. A modification recorded after the last review is an honest signal that the review predates the system. | Refers to Article 43 of 2024/1689 (legal requirement, only if it applies) plus ShipReadyMetrics recommendation. A date is not a conformity assessment. | 10 September 2026 |
| Logs and retention posture for this system | Article 12 is a design requirement for automatic recording of events; Article 19 and Article 26(6) are retention duties on providers and deployers respectively. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. | Refers to Articles 12, 18, 19 and 26(6) of 2024/1689 (legal requirements, only if they apply). Recording a retention intent is not retaining anything. | 10 September 2026 |
Legal requirement versus guidance versus ShipReady recommendation
The table below labels each text. Do not treat an internal register as a registration, do not treat a standard as the article, and do not treat a product surface as a determination. Last verified 10 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 6, 49, 71 and Annex VIII | Legal requirement — classification, registration in the EU database, the database itself, and the information submitted on registration, only if they apply. | Does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. Does not register anything. |
| Regulation (EU) 2024/1689 Article 113 | Legal requirement of the application dates. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; residual 2 August 2026; Article 113(c) Article 6(1) and corresponding obligations 2 August 2027. | Does not invent a 2 August 2026 date for Annex I product-embedded high-risk. Does not start a clock. |
| ISO/IEC 42001:2023 | Best practice / standard. An AI management system standard whose Annex A control areas imply a maintained register. Not a legal substitute for the Act. | Does not treat an ISO 42001 register, or an ISO 42001 certificate, as an Article 49 registration. |
| NIST AI RMF 1.0 (NIST AI 100-1, January 2023) | Guidance, not law. Voluntary US agency framework whose Map function covers context and inventory. | Does not treat a Map-function activity as an AI Act duty. |
| European Commission AI Act pages and AI Office materials | Commission materials. Guidance, not the regulation. | Does not treat a Commission page as rewriting Article 49, Article 71, or Annex VIII. |
| This product's AI inventory | ShipReady recommendation: an org-authored register of facts the organisation recorded about its own systems. Not a legal determination. | Does not register in the EU database, does not classify YOUR system, does not issue certifications, and does not affix a CE mark. A named human still owns the assessment. |
What to do now
As of last verification on 10 September 2026, Article 49 sits on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation. It is not a determination that the Act applies to YOU or that YOU owe a registration. Walk it with counsel.
- Write down every AI system the organisation builds, buys, embeds, or lets staff use — including the ones nobody owns yet. An incomplete register that says so is more useful than a tidy one that quietly omits things.
- For each row, record the intended purpose and leave the use case blank rather than guessing. A blank reads as needing review; a guess reads as an answer that was never given.
- Ask counsel whether Article 49 applies to any row, as a provider under Article 49(1) or 49(2), or as a public-authority deployer under Article 49(3). This page does not run that test. Marking eu_ai_act in an obligation map is not that determination.
- Name an accountable human per row before adding any further fields. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page.
- The how-shipreadymetrics-builds-ai-inventory guide on this site is the product page for the register, including its limits. The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a determination that YOU owe a registration, and not a filing. Walk it with counsel. The EU AI Act overview on this site is the pillar page.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- For each row, are YOU a provider, a deployer, an importer, or a distributor? This page does not determine that YOU are a provider or a deployer.
- Is the row an Annex III case, an Annex I product-embedded case, a GPAI model, or none of those? This page does not classify YOUR system as high-risk.
- If counsel finds Article 49(1), 49(2), or 49(3) in play, who registers — the provider, the authorised representative, or the public-authority deployer — and before which moment?
- Does recording euDatabaseRegistered in a product register YOUR system in the EU database? No. It records an attestation the organisation entered. The Commission operates the database under Article 71; this product does not write to it.
- Does an ISO/IEC 42001:2023 register discharge Article 49? No. It is a standard, not a legal substitute for the Act.
- Is a row's declared risk tier a classification? No. It is a declaration by the organisation, and counsel applies Article 6 to YOUR facts.
- Document the assessment, including a not-in-scope and no-registration-owed decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register. The inventory is org-authored: an administrator registers each system and records its declared tier, use case, ownership, provider or deployer posture, GPAI flags, and governance artefacts. Recording a row is not an Article 49 registration, is not a classification under Article 6, and is not a determination that the Act applies to YOU. Marking in-scope is not applicability. A named human still owns the assessment.
The euDatabaseRegistered field is an organisation attestation that a registration exists — never a platform assertion that one was made, and never a filing. This product does not register in the EU database, does not file with the AI Office, does not issue certifications, does not affix CE marks, and is not a notified body. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. The cyber risk register lives under Security and is a different register.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 10 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 6, 49, 71 and 113 and Annex VIII, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The technical-documentation guide on this site is the Articles 11 and 53 Annex IV/XI/XII page. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The how-shipreadymetrics-builds-ai-inventory guide on this site is the product page for the register. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated map of what an AI inventory can usefully hold, distilled from Regulation (EU) 2024/1689 Articles 49 and 71 and Annex VIII, with ISO/IEC 42001:2023 labelled as a standard and NIST AI RMF labelled as guidance, not the regulation. Whether the Act applies to YOU, whether YOU are a provider or a deployer, and whether any registration is owed are legal questions for counsel on your facts.
Does the EU AI Act require an AI inventory?
Not in those words. Regulation (EU) 2024/1689 has no article headed 'keep an inventory'. Articles 49 and 71 with Annex VIII require registration of particular systems in the Commission-operated EU database, and Articles 9 to 15 and Article 26 assume you know which systems you have. ISO/IEC 42001:2023 asks for that knowledge as management-system practice. An inventory is how an organisation finds out which of those texts might apply — it is not itself the duty. Last verified 10 September 2026.
Does recording a system in ShipReady register it in the EU database?
No. The Commission sets up and maintains the EU database under Article 71 of Regulation (EU) 2024/1689. Registration under Article 49 is made by the provider, the authorised representative, or a public-authority deployer, into that database. Recording a row in this product — including the euDatabaseRegistered attestation — records a fact the organisation entered about itself. This product does not register in the EU database and does not file with the AI Office.
Does an ISO 42001 inventory discharge Article 49?
No. ISO/IEC 42001:2023 is a voluntary management-system standard, and its Annex A control areas imply a maintained register as practice. The AI Act is Regulation (EU) 2024/1689. Holding an ISO 42001 certificate, or running an ISO 42001 register, is not a registration in the EU database and is not a determination that Article 49 has been satisfied. Last verified 10 September 2026.
Does declaring a risk tier in our register classify the system under Article 6?
No. A declared tier is an organisation's own statement. Article 6 and Annex III are applied by counsel to YOUR facts. A register can flag that a declared tier looks lower than the category a declared use case implies, and that flag is a prompt for review — never a classification, never a finding that YOUR system is high-risk, and never a conformity determination.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.