Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How does ShipReady Metrics build an AI inventory?
Updated
An administrator registers each AI system by hand, with its declared tier, use case, role, GPAI flags, owner, and artefacts. Shadow-AI signals can propose a system, never classify it. There is no auto-discovery of every model. Not legal advice.
ShipReady Metrics AI inventory, last verified 10 September 2026 against Articles 6, 26, 43, 49 and 71 and Annex VIII of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024) for the fields being mapped. ISO/IEC 42001:2023 is a management-system standard, not the regulation. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. Recording a row is not an Article 49 registration, and this product does not register in the EU database.
The register is org-authored, and that is the design
Audience: someone about to build or migrate an AI inventory, who needs to know before they start what this product will fill in and what a human has to type. This page is not legal advice. It does not start a clock. Nothing here is a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk.
The path is: signed-in app → Compliance → AI governance. An administrator registers a system there. The register is deliberately org-authored rather than connector-derived, because the fields that matter most — intended purpose, risk tier, role, ownership — are judgements about the organisation, not properties a scanner can read off a network. A tool that guessed them would produce a tidy inventory that is confidently wrong, which is worse than an obviously incomplete one. Last verified 10 September 2026. Not legal advice.
- Four kinds of text appear here, and they are labelled: legal requirements of Regulation (EU) 2024/1689 (only if they apply); Commission and AI Office materials, which are guidance, not the regulation; ISO/IEC 42001:2023, a standard and not a legal substitute for the Act; and ShipReadyMetrics capability, which describes shipped behaviour and never a legal determination.
- Registering a system is admin-gated and step-up authenticated. That is a product control, not an Act requirement.
- The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page — the vendor-neutral version of what a register should hold. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page. The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
What a human types, per system
The field list below is what the register actually holds, in the order it is usually filled in. Each row says what the field is for and what recording it does not amount to. Last verified 10 September 2026. Not legal advice.
| Field | What it holds | What recording it does not do | Kind of text |
|---|---|---|---|
| System name | A human-readable name for one AI system, capped in length. It is the identity the rest of the row hangs off. | Does not identify the system to any authority and is not an Annex VIII trade-name entry. | ShipReadyMetrics capability. |
| Declared risk classification — high, limited, or minimal | The organisation's own declared tier for the system. High-risk systems are the subjects the governance obligation checks are graded over. | Does not classify the system under Article 6 and is not a determination that YOUR system is high-risk. | ShipReadyMetrics capability, informed by Article 6 of 2024/1689 (a legal requirement, only if it applies). |
| Declared EU AI Act use case | A picked use-case key, or blank. The register reconciles the declared tier against the tier that use case implies, so a system declared minimal with an employment-screening use case is flagged as under-declared. A blank or unmapped use case reads as review required — never a guessed tier. | Does not decide the use case for you, does not classify the system, and a flag is a prompt for review, not a finding. | ShipReadyMetrics capability, informed by Article 6 and Annex III of 2024/1689 (legal requirements, only if they apply). |
| Third-party flag and external provider name | Whether the organisation uses a system a vendor supplies, and who that vendor is. A high-risk third-party system is the deployer shape. | Does not determine that YOU are a deployer under Article 26 and cannot verify the provider's conformity for you. | ShipReadyMetrics capability, informed by Articles 25 and 26 of 2024/1689 (legal requirements, only if they apply). |
| Accountable owner | The org member answerable for the system. A system with no owner reads as a disclosed accountability gap, not as a pass. | Assigning an owner is not an Article 26(2) assignment of human oversight and is not Article 14 compliance. | ShipReadyMetrics capability, informed by ISO/IEC 42001:2023 accountability practice (a standard, not a legal substitute). |
| The eight governance artefacts | Impact assessment, data governance, life cycle, transparency information, responsible use, human oversight, record keeping and event logging under Article 12, and technical documentation under Article 11 and Annex IV. Each is a boolean the organisation sets. | Ticking a box records that an artefact exists. It does not read the artefact, does not judge its quality, and is not a conformity determination. | ShipReadyMetrics capability, informed by Articles 9 to 15 of 2024/1689 (legal requirements, only if they apply). |
| GPAI flags: is a general-purpose model, has systemic risk, Article 53 documentation, Article 55 safeguards | Whether the organisation itself provides a general-purpose AI model, and whether it asserts systemic risk, with the matching documentation flags. | Does not designate a model as having systemic risk, does not file with the AI Office, and is not an Article 51 designation. | ShipReadyMetrics capability, informed by Articles 51 to 55 of 2024/1689 (legal requirements, only if they apply). |
| Supply-chain and provider-duty fields: provider conformity held, value-chain agreement, post-market monitoring, EU declaration of conformity, EU-database registration | Separate attestations the organisation enters about a system, graded by standalone lenses rather than folded into the eight obligations. | Recording euDatabaseRegistered is an attestation that a registration exists. It is not an Article 49 filing, and this product does not register in the EU database. Recording a declaration of conformity is the organisation's statement that a signed declaration exists, never a platform assertion of conformity. | ShipReadyMetrics capability, informed by Articles 25, 26, 47, 49, 71 and 72 of 2024/1689 (legal requirements, only if they apply). |
| Article 50 transparency triggers and measures | Per-characteristic pairs: does the system interact with natural persons, generate synthetic content, do emotion recognition or biometric categorisation, or produce deep fakes or public-interest text — and is the matching disclosure or marking in place. | Does not decide which Article 50 limbs apply to your system. | ShipReadyMetrics capability, informed by Article 50 of 2024/1689 (a legal requirement, only if it applies). |
| Conformity-review date and last substantial modification | When an admin last confirmed a review, and when the system last changed substantially. A modification recorded after the review reads as a re-assessment being due. | Is not an Article 43 conformity assessment, and a missing date reads as not tracked rather than as overdue. | ShipReadyMetrics capability, informed by Article 43 of 2024/1689 (a legal requirement, only if it applies). |
Shadow-AI proposals: detection can suggest, a human still classifies
Signals about AI tools in use can surface a system the register does not know about, and an administrator can register it in one click. What that click does not do is the point of this section. Last verified 10 September 2026. Not legal advice.
| Element | Behaviour as shipped | Why | Kind of text |
|---|---|---|---|
| System name and inferred provider | Carried over from the proposal, along with the third-party flag. | These are observations, not judgements. Getting them wrong is cheap to correct and visible on the row. | ShipReadyMetrics capability. |
| Risk classification | Floors at minimal. The proposal never sets a higher tier, whatever the detection saw. | A tier is a governance judgement. A detected tool arriving pre-labelled high-risk would manufacture an obligation; arriving pre-labelled minimal without review would hide one. The floor plus the review flag makes the human step unavoidable. | ShipReadyMetrics capability. Not a classification under Article 6 of 2024/1689. |
| Use case | Left blank. A blank use case reads as review required on the register. | The classifier returns review required over a blank use case rather than guessing a tier, so an unreviewed row is honestly flagged instead of silently passing. | ShipReadyMetrics capability. Not a determination that YOUR system is high-risk. |
| Governance artefacts | Empty. Nothing is assumed to exist. | An artefact nobody recorded is a gap, and the register says so rather than inferring one from the vendor's marketing. | ShipReadyMetrics capability. |
Honest limits
The limits below are properties of the product as shipped, not caveats about a future release. An AI inventory tool that hides them is selling a false completeness. Last verified 10 September 2026. Not legal advice.
- There is no auto-discovery of every model your organisation uses. A model called from application code over an ordinary HTTPS request looks like any other network call. Signals can narrow the search; they cannot enumerate the estate.
- Detection can propose, never classify. A proposal's tier floors at minimal and its use case is blank precisely so that a human has to do the classification.
- Every judgement field is a declaration. Tier, use case, role, and artefact booleans are what the organisation says about itself, and the register grades coverage over those declarations.
- Ticking an artefact box does not read the artefact. The register knows that a technical-documentation artefact was recorded; it does not know whether that document satisfies Annex IV.
- Coverage is graded over declared high-risk systems. Systems declared at a lower tier are not counted as subjects — which is why the under-declaration flag exists and why a full-coverage pass is refused while the high-risk population is unsettled.
- Demo fixtures are excluded from graded paths. A fabricated gap is as dishonest as a fabricated pass.
- The register is not the EU database. The Commission sets up and maintains that database under Article 71, and registration under Article 49 happens there. This product does not write to it.
- An empty inventory yields not verified, never a pass. Nothing to assess is reported as nothing to assess.
Legal requirement versus guidance versus ShipReady capability
The table below labels each text so that a field name is never read as a legal conclusion. Last verified 10 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 6, 49 and 71 and Annex VIII | Legal requirements — classification, registration in the EU database, the database itself, and the information submitted on registration, only if they apply. | Does not classify YOUR system, does not register anything, and does not determine that the Act applies to YOU. |
| Regulation (EU) 2024/1689 Articles 25, 26, 43, 47, 50 and 72 | Legal requirements — value-chain allocation, deployer duties, conformity assessment and re-assessment, the EU declaration of conformity, transparency duties, and post-market monitoring, only if they apply. | Does not perform a conformity assessment, does not sign a declaration, and does not decide which transparency limbs apply. |
| ISO/IEC 42001:2023 | Best practice / standard. Register and accountability practice inside an AI management system. Not a legal substitute for the Act. | Does not treat a maintained register, or a certificate, as an Article 49 registration. |
| European Commission AI Act pages and AI Office materials | Commission materials. Guidance, not the regulation. | Does not treat Commission material as rewriting Article 49, Article 71, or Annex VIII. |
| The AI inventory described on this page | ShipReadyMetrics capability. An org-authored register of declarations, with coverage graded over declared high-risk systems and honest not-verified results where nothing was assessed. | Not a classification, not a registration, not a conformity determination, and not legal advice. A named human still owns the assessment. |
What to do now
As of last verification on 10 September 2026, Articles 49 and 71 sit on the Article 113 residual application of 2 August 2026, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation, not a determination that any of it binds YOU.
- Seed the register from what people already know: procurement records, the list of vendors with data-processing agreements, and the tools engineering already pays for. Perfection is not the bar; a first pass that is visibly incomplete is.
- Leave the use case blank when nobody knows it. A blank reads as review required, which is a task; a guess reads as an answer, which is a hidden risk.
- Give every row an owner in the same sitting. An unowned row will not be maintained, and an unmaintained register is the failure mode of this whole exercise.
- Treat the under-declaration flag as a prompt for counsel, not as a finding. It compares a declared tier against the tier a declared use case implies; it does not apply Article 6 to your facts.
- The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The how-shipreadymetrics-supports-ai-governance guide on this site is the wider product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list for building the register, not a determination that the Act applies to YOU. Walk the legal questions with counsel. The ai-inventory-requirements guide on this site is the vendor-neutral version.
- Is every AI system the organisation builds, buys, embeds, or lets staff use written down — including the ones nobody owns?
- Does each row carry a declared tier, and does the person who declared it know it is a declaration rather than a classification?
- Is the use case picked, or blank? A blank is an honest review flag; a guess is not.
- Does each row name an accountable human?
- For third-party systems, is the external provider recorded, and does anyone hold the provider's instructions for use?
- Does a shadow-AI proposal set a risk tier for you? No. It floors at minimal with a blank use case, and a human classifies it.
- Does this product discover every model in use? No. The register is org-authored, and there is no auto-discovery of the whole estate.
- Does recording euDatabaseRegistered register the system in the EU database? No. It is an attestation the organisation entered; the Commission operates that database under Article 71.
- Document the assessment, including the systems you decided not to register and why. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register. Registration is admin-gated. The inventory can be exported, including as a machine-readable AI bill of materials in CycloneDX form; that export is portability, not an Annex VIII submission and not an Annex IV dossier. Marking in-scope is not applicability. A named human still owns the assessment.
This product does not register in the EU database, does not file with the AI Office, does not issue certifications, does not affix CE marks, and is not a notified body. The obligation map lists frameworks the organisation has marked in-scope. The cyber risk register lives under Security and is a different register from the AI risk register.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 10 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. Product claims describe shipped behaviour. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 6, 9 to 15, 25, 26, 43, 47, 49, 50, 51 to 55, 71, 72 and 113 and Annexes III, IV and VIII, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The AI-ownership-accountability guide on this site is the Articles 4, 14 and 26 RACI page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The how-shipreadymetrics-supports-ai-governance guide on this site is the product map. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated description of how the AI inventory works, set beside the fields in Regulation (EU) 2024/1689 and ISO/IEC 42001:2023 that those fields relate to. Whether the Act applies to YOU, and how any system should be classified, are legal questions for counsel on your facts. A register row is never a legal determination, and this page does not start a clock.
Does ShipReady automatically discover every AI system we use?
No. The inventory is org-authored: an administrator registers each system. Signals about AI tools in use can propose a system for registration, but a model called from application code over an ordinary HTTPS request is indistinguishable from any other network call. Treat the register as a maintained list with a detection assist, not as a complete discovered estate.
Does a shadow-AI proposal classify the system for us?
No. A proposal carries the name, the inferred provider, and the third-party flag. The risk tier floors at minimal and the use case is left blank, so the register reads the row as review required and a human has to classify it. That is deliberate: a detected tool arriving pre-labelled would either manufacture an obligation or hide one, and both are dishonest.
Does recording a system register it in the EU database?
No. The Commission sets up and maintains the EU database under Article 71 of Regulation (EU) 2024/1689, and registration under Article 49 happens there. The euDatabaseRegistered field records an attestation the organisation entered about itself. This product does not register in the EU database, does not file with the AI Office, and does not start a clock.
Does ticking the artefact boxes mean we meet the obligations?
No. A tick records that the organisation says an artefact exists. Nothing reads that artefact or judges whether it satisfies Annex IV, Article 9, or any other requirement. Coverage is graded over declared high-risk systems, an empty inventory yields not verified rather than a pass, and a full-coverage pass is refused while systems look under-declared. A named human still owns the assessment.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.