/ THE SHORT ANSWER
- 01Give different uses of one platform separate records when their consequences differ.
- 02Record actual access and action permissions.
- 03Assign review triggers as well as owners.
/ dotSuper point of view
dotSuper analysis: an inventory is useful when it makes approval, restriction and retirement decisions easier.
Inventory the use, not the logo
A single product entry hides the differences between those uses.
Begin with a sentence describing what the system does, for whom and with what influence over a decision.
Bundesnetzagentur explains that AI requirements depend on the system's level of risk.
[1] The practical implication is to preserve the information needed for assessment.
A vendor's broad statement about its product cannot substitute for understanding how your organisation has configured and deployed it.
Give each use a stable identifier and an owner with authority over the workflow.
If nobody can approve a restriction or answer a question about the data source, record the ownership gap explicitly.
Assigning the software administrator by default may hide a business decision that belongs elsewhere.
Capture the evidence that changes an approval
Public product descriptions, confidential drawings and employee case notes are different data sets even if all arrive as documents.
Identify where access is inherited and where a separate connector may broaden it.
Describe outputs in operational terms.
Search results, suggested drafts, ranked recommendations and executed transactions have different consequences.
Record whether somebody reviews the output, what evidence they receive and whether the system can bypass that review through an integration.
Keep links to relevant contracts, configuration screenshots and source registers.
The inventory should point to evidence rather than duplicate entire documents.
For uncertain fields, use unknown with a named follow-up.
A blank cell is too easily interpreted as either no risk or no information, depending on the reader.
Use a compact record with a decision attached
Add fields when they enable a real decision.
Avoid collecting technical detail that nobody uses while leaving access and business ownership unclear.
Use statuses that distinguish approved, restricted, under assessment and retired.
Add the permitted scope to an approval.
An assistant approved for public documents should not inherit approval for confidential customer drawings merely because the software name remains unchanged.
| Field | Useful content | Decision supported |
|---|---|---|
| Purpose | Task and affected people | Whether the use is appropriate |
| Inputs | Repositories and sensitivity | Whether access is justified |
| Influence | Advice, ranking or execution | Required review and safeguards |
| Owner | Named accountable role | Who can restrict or retire it |
| Evidence | Configuration and contract links | What has actually been checked |
| Trigger | New data, actions or purpose | When reassessment is needed |
A hypothetical three-use ERP extension
One feature suggests descriptions for spare parts.
Another recommends supplier choices.
A third predicts which employee can complete a task fastest.
The purchasing contract covers the extension as a single item.
The inventory creates three use records.
The spare-parts feature uses approved catalogue content and requires editorial review.
Supplier recommendations need a review of commercial criteria and data completeness.
The employee prediction requires a separate assessment of purpose, inputs and implications before use.
This is not a legal classification of those fictional features.
It demonstrates why procurement packaging is an unreliable unit of governance.
The group can make progress on a bounded use while investigating another, and the relevant business owner can explain exactly what is permitted in each workflow.
Date the assessment, not just the spreadsheet
[2] Different provisions and transitional situations require separate attention.
Store the source and date behind a timing assumption.
A field that merely says AI Act ready becomes meaningless when the use changes or official guidance is updated.
Record which issue was assessed and which requirement the conclusion concerns.
Separate timing from operational readiness.
A future application date does not prove that current data access is appropriate, employee implications have been addressed or outputs are reliable.
Conversely, a useful internal control need not be presented as legally mandatory to justify implementing it for an important business process.
Make inventory maintenance part of ordinary work
A new connector, expanded user group or action permission should prompt the owner to check the relevant record.
Relying on an annual survey alone allows consequential changes to disappear between review dates.
Retire entries properly.
Note what happened to the data, integrations and access when a tool was withdrawn.
Keeping an abandoned account active can preserve exposure even when nobody considers the system part of current operations.
Begin by reconciling a small set of known tools with the tasks people actually perform.
Ask process owners to demonstrate a typical use.
The inventory should support an immediate decision, such as narrowing access or assigning an owner.
A lengthy catalogue that changes nothing about business operations has limited value.
What this page cannot conclude
- 01The inventory does not itself determine legal risk categories or conformity obligations.
- 02The AI timetable is attributed to the current Commission service desk, not independently reconstructed from every amending provision.
- 03This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Sources
- 01AI Act risk levelsBundesnetzagentur · accessed Sep 15, 2026
- 02Timeline for the Implementation of the EU AI ActEuropean Commission AI Act Service Desk · accessed Sep 15, 2026
This article was researched and drafted with AI assistance. Sources and limitations are provided for scrutiny; it is not an independent professional review or a compliance certification.
Our editorial standard · Found an error? Send a correction with its source.
/ CITE OR SHARE THIS GUIDE
Make the evidence easy to verify.
When you reference this guide, link to its canonical URL. That gives readers one stable place for the evidence, limitations and future updates.
dotSuper Research Desk. (September 15, 2026). Build an AI Inventory That Changes Decisions. dotSuper. https://dotsuper.net/feeds/applied-systems/germany-ai-systems-inventory-decisions