AI Act-Compliant AI Systems Registry: What It Must Contain and How to Keep It Up to Date

Edited by Solucom · June 25, 2026

Establishing a registry of AI systems is the first step toward AI Act. But a registry is only useful if it is complete e vivo: it stays up-to-date over time. Otherwise, it's just a file that gets old. Let's see what it should contain and, above all, how to keep it alive without it becoming a burden.

What should it contain, item by item

For each AI tool you use in the company, the log should state at least:

  • Tool and supplier. Which AI, from whom (the vendor), and in what version or plan.
  • Use and purpose. What do you actually use it for: writing texts, sorting emails, analyzing data, supporting customers.
  • Responsible. Who in the company is responsible for that tool. Without a name, no one will update it.
  • Data processed. What information passes from the device, especially if personal or sensitive?.
  • Risk level. A classification of use based on the AI Act framework: most uses pose a limited risk, but those involving decisions about people should be examined more closely.
  • Status and dates. Active or decommissioned, since when, and most importantly When was the last revision made? and when is the next one scheduled?.
  • People and training. Who is authorized to use it and if they have received the minimum training (’AI literacy required from AI Act).

The hard part isn't creating it, it's maintaining it.

Filling out the register the first time is easy: it takes half a day and you leave satisfied. The problem comes two months later, when someone activates a new tool, someone else decommissions one, an evaluation expires — and no one updates anything. This is exactly why, as we've already seen, An Excel spreadsheet isn't enoughIt doesn't warn you, it doesn't distinguish roles, it leaves no trace.

How to keep him alive

  • Deadline reminder. Periodic reviews should be pushed to you automatically, not rely on someone's memory.
  • One manager per voice. Every tool has a clear owner: that's the single most important thing keeping a registry alive.
  • A review cadence. Decide how often you review it (e.g., every 6 or 12 months) and make it automatic.
  • A change log. Who changed what and when: in the event of a check, this is what proves the log is real, not rebuilt at the last minute.
  • An exportable file. When you need to show something, you must be able to generate a neat document in one click, not chase scattered information.

Frequently Asked Questions

How detailed should it be?

Enough to demonstrate that you have control over your AI usage. Better a few updated entries than a hundred fields filled out once and never again.

How often do you see each other?

A fixed cadence (6-12 months) for ordinary uses, plus a review each time you introduce or decommission a tool.

Where do I start?

From the inventory of what you already use: it's often more than you think.

Do you want an easy and fast AI log to keep updated? AInventory It has AI tools, people, and reviews together, with automatic reminders and exportable dossiers ready for an audit. There's a free plan to get started right away.