Most companies that start with the AI Act make the same mistake: they write a policy before they know what they use.
That's like writing a fire safety policy without knowing where the smoke detectors are.
AI is already in use — scattered and undocumented
In a typical SMB with 10–50 employees, AI already exists in more places than management thinks:
- ChatGPT/Copilot — employees use them daily for emails, summaries, code suggestions.
- CRM AI features — lead scoring, suggested next steps, automatic summaries.
- Support tools — chatbots, AI-suggested replies, case classification.
- HR tools — CV screening, interview scheduling, performance analytics.
- Marketing — AI-generated text, image generation, SEO tools.
- Finance — automatic invoice matching, anomaly detection.
Nobody has listed them. Nobody has classified them. Nobody knows who's responsible.
An AI register in 30 minutes
Start with a spreadsheet. Seven columns are enough:
| System | Usage | Affected persons | Risk class | Owner | Approval required? | Next review |
|---|---|---|---|---|---|---|
| ChatGPT | Email drafts, text editing | Internal + customers (if emails sent) | Minimal/Transparency | Anna | No (internal), Yes (external) | 2026-Q3 |
| HubSpot AI | Lead scoring | Prospects, customers | Minimal | Erik | No | 2026-Q3 |
| Recruitment AI | CV screening | Job applicants | High risk | HR lead | Yes | 2026-Q2 |
You don't need to finish in one day. Start with the systems that affect external people — customers, job applicants, partners.
Three questions per system
For each AI system in the register, ask three questions:
1. Who is affected if AI is wrong?
If the answer is "only me" (e.g., ChatGPT for internal notes) — low risk. If the answer is "job applicants" or "customers receiving automated decisions" — high risk.
2. Does the affected person know AI is involved?
If not — you have a transparency problem that needs fixing regardless of risk class.
3. Who in the company owns this system?
If the answer is "nobody" — that's your first problem to solve.
Why policy without inventory fails
An AI policy that says "we use AI responsibly" without knowing which AI is in use is meaningless.
It's like GDPR without a data register. The words exist, but the control doesn't.
With a register, you can:
- Prioritize — focus on high-risk systems first.
- Act — add transparency and approval where needed.
- Demonstrate — to customers, auditors, and authorities that you're in control.
- Update — when new systems are added or old ones removed.
The AI Act context
The AI Act doesn't explicitly require a register for all companies. But for deployers of high-risk systems, the documentation requirements practically demand an inventory.
And regardless of legal requirements: a company that knows which AI systems it uses makes better decisions than one that doesn't.
Next step
Open a new spreadsheet. Create seven columns. List all AI systems you use — start with those affecting customers and employees.
That's your inventory. That's your first AI Act step.