Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point AI & Automation

Log: AI System Inventory and EU AI Act Classification Register

A plug-and-play register of every AI system a life-sciences company develops or uses, with the fields the EU AI Act forces you to decide: provider or deployer role, risk tier and the route to it, GPAI dependency, prohibited-use screen, owner, and review date, with field definitions, a filled sample row, and the regulations it satisfies.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use register. Replace every <<FILL: ...>> placeholder with your own specifics, set your document numbers and dates, and route it through your normal document control. A worked filled sample row follows the field definitions. This is general guidance to adapt, not legal or regulatory advice; confirm the EU AI Act text and dates against the current Official Journal version before relying on a classification.

Document control header

FieldEntry
Register titleAI System Inventory and EU AI Act Classification Register
Document number<<FILL: register ID>>
Owner<<FILL: e.g. AI Governance Lead / Head of Quality>>
Review cadence<<FILL: e.g. quarterly>>
Last reviewed<<FILL: date>>

Purpose

The EU AI Act (Regulation (EU) 2024/1689) applies based on where an AI system or its output is used, so a US-headquartered company can be in scope. You cannot classify what you have not found. This register is the foundation step: a single list of every AI system the company develops or uses, reaching beyond the lab and plant into HR, security, IT, and commercial, with the classification decisions recorded as controlled data.

Field definitions

FieldFormatRequiredWho entersWhen
System IDtext / codeYesRegister ownerAt entry
System name and short descriptiontextYesSystem ownerAt entry
Business function and location of usetext (incl. EU use?)YesSystem ownerAt entry
Develop or buyBuilt in-house / Commercial / Embedded in vendor productYesSystem ownerAt entry
AI Act roleProvider / Deployer / BothYesAI GovernanceAt classification
Uses a GPAI model?Yes (name model and provider) / NoYesData ScienceAt classification
Prohibited-use screen (Article 5)Pass / Flag (describe)YesLegal / PrivacyAt classification
Risk tierProhibited / High-risk / Limited / MinimalYesAI GovernanceAt classification
High-risk route (if high)Annex I (product) / Annex III (use)ConditionalRegulatory / AI GovernanceAt classification
Classification basis (record reference)doc IDYesAI GovernanceAt classification
Personal data / GDPR touchpointYes (DPIA ref) / NoYesLegal / PrivacyAt classification
Accountable ownername / roleYesRegister ownerAt entry
Status and next reviewtext + dateYesRegister ownerOngoing

How to use it

  1. Find everything. Sweep the lab, plant, HR, security, IT, and commercial. Include AI hidden inside vendor features.
  2. Assign the role per system. Building your own model makes you a provider, even if it never leaves the company. Buying and running a tool makes you a deployer. You can be both.
  3. Screen for prohibited use first. Article 5 is the highest-penalty band and its deadline (2 February 2025) has passed. Check HR, security, and workforce tools especially.
  4. Classify by tier and record the basis. Where you conclude “not high-risk” under an Annex III exception, capture the Article 6(4)-style assessment as a controlled record (see assessment-eu-ai-act-classification).
  5. Flag the GDPR touchpoint so the data-protection screen runs alongside the AI-Act one.
  6. Review on cadence and whenever a system is added, retrained, or repurposed (which can flip a deployer into a provider).

The register

System IDName / descriptionFunction / EU useDevelop or buyAI Act roleGPAI?Art. 5 screenRisk tierHigh-risk routeClassification refGDPR / DPIAOwnerStatus / next review
<<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Retention

Retain the register and each classification record per your records retention schedule, for not less than <<FILL: retention period>>, and keep superseded classifications so a decision can be reconstructed.

References

Regulation (EU) 2024/1689 (EU AI Act): Article 5 (prohibited practices), Article 6 (high-risk classification, Annex I and Annex III), Article 6(3) and 6(4) (non-high-risk exception and its documentation). General Data Protection Regulation (EU) 2016/679 for the personal-data touchpoint. Note the Digital Omnibus simplification package may change high-risk dates and details; confirm the adopted text.


Filled sample rows

Illustrative entries showing the range of systems and tiers (company and systems are fictitious).

System IDName / descriptionFunction / EU useDevelop or buyAI Act roleGPAI?Art. 5 screenRisk tierHigh-risk routeClassification refGDPR / DPIAOwnerStatus / next review
AI-001Deviation-triage model suggesting investigation priorityQuality, used by EU siteBuilt in-houseProvider and DeployerNoPassMinimal (only ranks completed human input, no decision)N/ACLASS-AI-001NoHead of QualityActive, review Q4 2026
AI-002Dosing-guidance feature in a connected delivery device (combination product)Patient-facing, EU marketBuilt in-houseProviderNoPassHigh-riskAnnex I (MDR Class IIa constituent)CLASS-AI-002Yes, DPIA-014Reg AffairsActive, conformity assessment planned
AI-003HR vendor tool inferring candidate sentiment from interview videoRecruitment, EU candidatesCommercialDeployerNoFlag: possible emotion inference in workplaceProhibited (under review with Legal)N/ACLASS-AI-003Yes, DPIA-018HR / LegalOn hold pending Legal review
AI-004Patient-support chatbot on the company websiteCommercial, EU usersCommercial (on vendor LLM)DeployerYes (vendor LLM)PassLimited (transparency: disclose AI)N/ACLASS-AI-004Yes, DPIA-021CommercialActive, AI disclosure added

The HR tool (AI-003) is the kind of edge case the inventory exists to surface: not core science, but potentially a prohibited practice in the highest penalty band, found only because the sweep reached HR.

Common findings this register prevents

  • “We are a US company” used as an exemption while EU sites use the AI or its output.
  • Hidden AI inside a vendor feature, never inventoried or classified.
  • A “minimal-risk” assertion with nothing written down to support it.
  • A prohibited HR or security tool missed because the sweep stopped at the lab.
  • A model retrained or repurposed without re-checking whether the role flipped to provider.

How to adapt this register

  1. Set the document number, owner, and review cadence.
  2. Add columns your governance needs (cost centre, vendor, data sources).
  3. Link each row to its classification record and any DPIA.
  4. Run the sweep across all functions, not just the obvious technical ones.
  5. Confirm the AI Act articles and dates against the current Official Journal text.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.