AI Academy · Book
Executives & Directors · Module 07 · Chapter 008

AI Inventory and Risk Classification

You cannot govern AI you cannot see, and you cannot govern all of it at the same depth. The inventory gives visibility; classification decides how closely each use is governed. The law sets the first tiers, and no internal ladder can overrule it.

≈ 16 min read

After this chapter you can

  • Explain why an AI inventory records uses with owners, data and actions, not projects or models.
  • Describe how discovery finds AI that arrives outside the project portfolio.
  • Separate the EU AI Act's legal tiers from the organization's internal low, medium and high tiers.
  • Classify a use by impact, data, consequence, autonomy, reach and reversibility, before controls.
  • Test whether a classification actually changes the review a system receives.

In October 2024 the Netherlands Court of Audit published the first count of artificial intelligence in the Dutch central government. It asked 70 ministries and agencies a simple question: what AI do you use? Every one of them answered. Together they named 433 systems, of which 120 were in use, 167 were still experiments and 141 had already been switched off. Only 22 of the 433, about 5 percent, appeared in the government’s public Algorithm Register. For more than half of the systems, nobody had weighed the risks against the benefits, and there was no government-wide instrument for doing so1.

Dutch central government organizations named 433 AI systems; only 5 percent were in the public register and more than half had never been risk-assessed.433AI systems namedBy 70 centralgovernment organizations5%In the public register22 of the 433Over halfNever risk-assessedIncluding a third of thehigh-risk onesSource: Netherlands Court of Audit · 2024
Figure 7.8.1 A government that keeps a public algorithm register still found most of its AI missing from it.

The second finding is the sharper one. The organizations had sorted their current systems into the risk categories of the EU AI Act, and almost all of them came out at the bottom. The Court drew the obvious conclusion: organizations “have an incentive to downplay risks”, because a system that is not high-risk does not have to meet the Act’s strict requirements. It also found two reported systems, both retired, that would have been prohibited outright1.

Of 287 current and experimental systems, 155 were self-classified minimal risk, 60 limited, 30 high and 42 unknown.Minimal risk155Limited risk60High risk30Unknown42Source: Netherlands Court of Audit · 2024
Figure 7.8.2 How the organizations classified their 287 current and experimental systems. One in seven was not classified at all.

None of this is peculiar to the Netherlands. It is what an organization is likely to find when it looks properly for the first time. Some of its AI is not on any list, and the AI that is on the list has been graded by the people who would rather it passed. Two disciplines fix that: an inventory that shows what exists, and a classification that decides how closely each use is governed.

Visibility first, then routing

The argument fits in one line. You cannot govern what you cannot see, and you cannot govern everything at the same depth.

Governance runs from discovery to a record, a classification and a route, and the record is revisited when the use changes.DiscoverFind what isactually in useRecordOne entry peruse withan ownerClassifyLegal tier first,then internal tierRouteThe tier sets thedepth of reviewRevisit the record when the use changes
Figure 7.8.3 Visibility comes before routing. A classification of an incomplete list governs only the part you found.

Discovery and the record give visibility. Classification and routing turn visibility into proportionate governance. The order matters. Classifying an incomplete list produces a reassuring report about the part of the estate you happened to find. Recording everything without classifying it produces a long list that nobody acts on.

The major frameworks make the same point. The NIST AI Risk Management Framework asks that “mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities”23. ISO/IEC 42001, the certifiable standard for AI management systems, requires an organization to assess the impact of its AI systems, which it cannot do for systems it does not know it has4.

The AI Governance Operating Model showed why risk must decide how far a decision travels. What follows defines the tiers that make that routing work.

An inventory records uses, not projects

Many organizations think they already have an inventory, because they have a project portfolio. The two answer different questions. A project list says what is being built, by whom and by when. An inventory says what each system does, what it touches and who answers for it.

A project list records name, manager, date and status; an AI inventory also records purpose, owner, data, provider, users, actions, tiers, controls and review date.A project list recordsNameManagerDateStatusAn AI inventory also recordsBusiness purpose and ownerData usedModel and providerUsers and actionsLegal and internal tierControls and review date
Figure 7.8.4 The extra columns are the ones governance needs: purpose, owner, data, actions and tier.

The unit of record is the use, not the model. One model licensed once may sit behind a meeting summarizer, a contract reviewer and a customer chat agent, and those three uses carry very different risks. If the register has one line for the model, it cannot hold three different tiers. The reverse also applies. An approved general-purpose assistant used by thousands of employees for ordinary drafting needs one service-level record with its rules, not thousands of individual entries. Anything built on top of it that touches sensitive data or takes actions gets its own record.

Each record needs a named owner. Keeping the register is a service, usually run by the governance office; being accountable for a system is a business role, as AI Roles, Ownership and Accountability set out. The office keeps the record current. The owner keeps the system safe.

Finding what is not on the list

A register built from the project portfolio sees only the AI that went through a project gate. Much AI arrives by other doors.

AI enters through seven doors - built, bought, embedded in existing software, employee-built, agents, personal tools and acquisitions - and the register must cover all of them.AIone register forevery doorBuilt in-houseBoughtEmbeddedStaff-builtAgentsPersonal toolsAcquisitions
Figure 7.8.5 The doors most registers miss are the quiet ones: features switched on by an update, and tools staff build or bring.

Two of these doors have their own chapters. AI Is Already Inside Your Organization showed how AI arrives inside software you already pay for, often through a routine update. Privacy and Confidential Data covered shadow AI, the personal tools staff use outside any approval. Here the point is narrower: both must reach the register. One Dutch official put the first risk plainly: “There is a real risk you’ll be buying AI without knowing it”1.

No single channel finds everything, so discovery combines several. Procurement and contract records show what was bought. The application catalog and cloud bills show what is running. Security tools show which AI services staff reach from company devices. Business-unit declarations and a short, amnesty-style survey show what people built for themselves. The goal of the first pass is breadth, not depth. A thin record for everything, with an owner and a one-line purpose, is worth more than a perfect record for a tenth of the estate.

Before any internal tier, one question is not the organization’s to answer: what does the law already say about this use? In the European Union, the AI Act sets legal tiers, and they behave differently from a risk score.

Prohibited means stop. Practices such as social scoring, untargeted scraping of facial images and emotion recognition in workplaces and schools are banned. No control makes them acceptable, so they are never “approved with conditions”; they are retired. High-risk is set by law, not by appetite. Annex III lists the uses, among them remote biometric identification, safety components of critical infrastructure such as energy, water and traffic, recruitment and worker management, credit scoring and eligibility for essential public benefits5. There is a narrow exception for a listed system that only performs a procedural or preparatory task, but it must be documented before the system is placed on the market, and a listed system that profiles people is always high-risk6. That is a legal assessment, made with counsel, not an internal tier choice. Transparency duties require telling people when they deal with AI and labeling synthetic content. Everything else is minimal risk under the Act, which is where internal tiers do most of their work.

The Dutch count shows why the legal tier deserves its own step. When the same questionnaire decides both the legal category and the internal effort, the incentive runs one way. Keep the legal question separate, give it to legal specialists, and record the answer and the reasoning on the inventory.

Risk belongs to the use, not the model

Inside the legal floor, the organization sets its own tiers. A common shortcut is to classify the model or the vendor: this model is approved and low-risk, that one is not. The shortcut fails, because the same model can carry almost no risk in one use and serious risk in another.

The same model is low tier when it summarizes internal meetings and high tier when it changes customer accounts; six features of the use set the tier.One modelSummarizes internal meetingsLow tierChanges customer accountsHigh tierWHAT MOVES THE TIERImpactDataConsequenceAutonomyReachReversibility
Figure 7.8.7 Classify the use. The model is one input; what it is allowed to touch and do decides the tier.

A handful of questions move the tier. Impact: who could be harmed, and how badly, whether customers, employees, citizens or the public. Data: is it public, internal, personal or in a special category such as biometrics or health? Consequence: what happens when the output is wrong, from a few minutes of editing to a lost job, a refused loan or a wrongful accusation? Autonomy: does the system suggest, decide or act? Agentic AI and Autonomous Actions set out the autonomy ladder; for classification, a sensible default is that an agent able to act sits at least one tier above the same capability when it only drafts. Finally, the four multipliers from The AI Risk Landscape: can the harm be undone, how far does it reach, would anyone notice, and how fast does it spread?

The tier is assigned to the inherent risk of the use, before controls. Canada’s mandatory Algorithmic Impact Assessment for federal automated decision systems states that putting mitigations in place “does not alter the impact level”9. That separation stops a familiar trick: adding a control in order to downgrade a system, and then dropping the review the control was meant to support.

A ladder that changes the route

A classification is only useful if it changes what happens next. A simple internal ladder has three tiers. The table below is an illustrative design, not a standard: each organization sets its own thresholds, but the shape is common.

Low, medium and high internal tiers differ in typical use, who reviews, who approves and how closely the system is monitored.Internal tierTypical useReviewApprovalMonitoringLowInternal content, noactions, easy to undoOwner's short recordDelegated to ownerSampledMediumPersonal data orcustomer-facing adviceSpecialist reviewGovernance officeRegular checksHighMaterial decisions aboutpeople, or acts on its ownCross-functional reviewCommitteeContinuous
Figure 7.8.8 An illustrative ladder. If all three tiers follow the same process, the tier is a label, not a route.

Low does not mean no controls. A low-tier use still has an owner, a record, an approved tool and data rules; they are lighter and often standardized. Medium brings specialists in, typically privacy, security and the relevant business expert, and the governance office approves. High means a cross-functional review, approval by the committee described in AI Governance Committee and AI Governance Office, named human oversight and continuous monitoring.

Two rules connect the ladder to the law. A use the AI Act lists as high-risk can never sit below the internal high tier. A prohibited practice never enters the ladder at all, because there is nothing to approve.

The distribution of tiers is itself a health check. If almost everything is high, review becomes a bottleneck and teams learn to describe their systems as something else. If almost everything is low, as in the Dutch count, the questions were too easy or nobody challenged the answers. The fix in both cases is the same: an owner proposes the tier, the governance office confirms it, legal confirms any legal tier, and disagreements go to a named decision-maker, with the system following the higher tier until the question is settled.

A classification also has a shelf life. The tier is a field on the record, and it must be revisited when the use changes. AI Lifecycle Governance defines which changes count as material, and AI Evaluation and Approval Gates sets the written triggers that reopen each decision.

Story: the watchlist nobody classified

One of the best-documented cases of a use that was visible to its owner but never classified for what it was comes from an American pharmacy chain.

From 2012 to 2020, Rite Aid ran facial recognition in hundreds of its stores10. The system, supplied and operated by two vendors, compared the faces of shoppers with a watchlist of “persons of interest” and sent match alerts to store staff. Staff had been trained to “push for as many enrollments as possible”, and the database grew to at least tens of thousands of people, often from low-quality images taken from security cameras and phones. On an alert, employees followed shoppers, searched them, asked them to leave and sometimes called the police. In one five-day period, a single enrollment produced more than 900 alerts in more than 130 stores. Employees once stopped and searched an 11-year-old girl on a false match11.

The most telling document in the case is internal. A presentation arguing for expanding the program after its pilot named a single risk: “media attention and customer acceptance”. It did not mention false matches, wrongful accusation or bias. Rite Aid did not test the system’s accuracy before or after deployment, did not track false positives, and told employees not to reveal its use to customers or the media. It also never asked whether its store selection, which favored urban locations, would concentrate the harm. About 80 percent of its stores were in plurality-White areas, but about 60 percent of the stores using facial recognition were in plurality non-White areas11. The two figures have different bases: the first describes the whole chain, the second only the stores that ran the system. Put the same way round, roughly one store in five across the chain, but three in five of the system’s stores, sat in plurality non-White areas.

In December 2023 Rite Aid settled with the Federal Trade Commission, accepting a five-year ban on facial recognition for surveillance and an obligation to delete the images and any algorithms built from them. Before using any automated biometric system again, it must assess the risks, test accuracy, monitor false positives, train staff, tell customers, and stop if the risks cannot be controlled10. The allegations were settled without a trial.

A post-mortem of the watchlist - recorded as a security tool, classified by reputational risk, routed without testing and never monitored - against what a working register would have forced.StepWhat happenedWhat a working register would have forcedRecordRun by vendors as a loss-prevention toolOne entry: purpose, owner, biometric data, actionson peopleClassifyOne risk named: media and customer acceptanceImpact on shoppers, biometric data, accusation, hardto undoRouteNo accuracy test before or after launchTop-tier review, accuracy and bias testing,human checksMonitorFalse positives not trackedError rates by store and group, reported to the owner
Figure 7.8.9 The system was never hidden from its owner. It was classified by its risk to the company instead of its risk to people.

The lesson is precise. The failure was not that nobody knew the system existed. It was that the question “how much harm could this use do, and to whom?” was answered from the company’s point of view. Every dimension above pointed high: special-category data, consequences for individuals that are hard to undo, action taken on the output, reach across hundreds of stores and errors nobody counted. Were a retailer to run the same watchlist in the EU today, the AI Act would list it as remote biometric identification, a high-risk use, and GDPR would require a data protection impact assessment before it started, if data-protection law allowed it at all.

What this means for leaders

Leaders do not maintain the register, but they decide whether it tells the truth. Four habits make the difference. Ask for the discovery method before you trust the count, because a register built from the project portfolio will usually look small. Insist that the legal tier is decided separately from the internal tier, by people who gain nothing from a low answer. Ask to see the distribution of tiers, and treat a register that is nearly all low as a question, not a comfort. And check that the tier actually changes the route: a high-tier system should be visibly slower and more scrutinized than a low-tier one.

Check yourself

  1. An AI inventory is a list of the models and vendors the organization uses.
  2. The model determines the risk tier.
  3. A prohibited practice can be approved if the controls are strong enough.
  4. An organization can place an Annex III use in its internal low tier if its questionnaire scores it low.
  5. Adding mitigations should not lower a system’s assigned impact level.
  6. A register where nearly every system is rated low risk is a sign of good governance.

Reflection: find the system rated by the wrong risk

What comes next

The inventory shows what AI exists, and classification sets how closely each use is governed. But a classified system does not stand still. It is designed, tested, deployed, changed and eventually retired, and governance has to travel with it at every stage. The next chapter, AI Lifecycle Governance, follows a system from idea to retirement.

Laws referenced

EU AI Act · EU

Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744

Risk-based rules. Prohibited practices include social scoring, untargeted scraping of facial images, and emotion recognition in workplaces and schools (with narrow exceptions). High-risk systems (Annex III: biometrics, safety components of critical infrastructure such as energy, water and traffic, employment and worker management, credit, education, essential services, law enforcement, migration, justice) need risk management, data governance, documentation, logging, human oversight, human oversight that keeps people able to understand the system, notice automation bias (over-reliance on its output), override it or stop it (Art. 14(4)), appropriate accuracy, robustness and cybersecurity (Art. 15), automatic logging of events (Art. 12), a provider quality-management system (Art. 17) and conformity assessment. An Annex III system is not high-risk if it poses no significant risk of harm, for example a narrow procedural or preparatory task that does not replace human assessment; systems that profile people are always high-risk, and a provider relying on this exception must document it and register (Art. 6(3)). Deployers of high-risk AI must use it as instructed, assign competent human oversight, monitor its operation, keep logs for at least six months and report serious incidents (Art. 26); employers must inform workers' representatives (Art. 26(7)). Public bodies, private providers of public services, and deployers of credit-scoring or life and health insurance pricing systems must carry out a fundamental-rights impact assessment before first use (Art. 27). Providers must run post-market monitoring (Art. 72). A deployer that puts its name on a high-risk system, substantially modifies it, or changes its purpose so that it becomes high-risk takes on the provider's obligations (Art. 25(1)). A substantial modification (Art. 3(23)) of a high-risk system needs a new conformity assessment, unless the change was pre-determined and documented at the first assessment, as with planned continuous learning (Art. 43(4)). Providers of general-purpose AI models (from 2 Aug 2025) must keep technical documentation, have a policy to comply with EU copyright law including text-and-data-mining opt-outs, and publish a sufficiently detailed summary of training content (Art. 53). Research, testing and development before a system is placed on the market or put into service is outside the Act, except testing in real-world conditions (Art. 2(8)). Since the 2026 Omnibus, the Art. 4 AI-literacy duty is an obligation of effort (take measures to support literacy), not of result. Fines reach EUR 35 million or 7% of global turnover for prohibited practices.

  • 2024-08-01 — Entered into force
  • 2025-02-02 — Prohibited practices (Art. 5) and the AI-literacy duty (Art. 4) apply
  • 2026-07-27 — Omnibus softens Art. 4: providers and deployers must take measures to support AI literacy; no specific level must be guaranteed
  • 2025-08-02 — General-purpose AI model obligations apply; governance and penalties regime in place
  • 2026-08-02 — Transparency duties (Art. 50) apply: disclose AI interaction, label synthetic and deepfake content (marking for generative systems already on the market: 2 Dec 2026)
  • 2027-12-02 — High-risk obligations for Annex III systems (e.g. hiring, credit, education, essential services) - moved from 2 Aug 2026 by the 2026 Omnibus
  • 2028-08-02 — High-risk obligations for AI in products regulated under Annex I

Last verified 2026-10-06 · official text

General Data Protection Regulation · EU

Regulation (EU) 2016/679

Personal data is any information relating to an identified or identifiable person, directly or indirectly, including by an identifier such as an online ID (Art. 4(1)). Lawful basis and purpose limitation (Arts. 5-6); processing special-category data, including biometric data used to identify a person, health data and data revealing ethnicity, is prohibited unless a specific exception applies (Art. 9); data protection by design and by default (Art. 25); processors such as AI vendors may act only under a written contract with required terms and sufficient guarantees (Art. 28); transparency to data subjects (Arts. 13-14); right not to be subject to a decision based solely on automated processing with legal or similarly significant effects (Art. 22); breach notification to the supervisory authority within 72 hours (Art. 33) and to individuals without undue delay when the risk is high (Art. 34); data protection impact assessment for high-risk processing (Art. 35). Fines up to EUR 20 million or 4% of global turnover.

  • 2018-05-25 — Applies

Last verified 2026-10-08 · official text

References

  1. Netherlands Court of Audit (Algemene Rekenkamer). Focus on AI in the Dutch central government. Netherlands Court of Audit. 2024.
  2. National Institute of Standards and Technology. AI RMF Playbook: Govern. NIST Trustworthy and Responsible AI Resource Center. 2023.
  3. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. NIST. 2023.
  4. ISO/IEC. ISO/IEC 42001:2023 Information technology - Artificial intelligence - Management system. International Organization for Standardization. 2023.
  5. European Commission, AI Act Service Desk. AI Act, Annex III: High-risk AI systems referred to in Article 6(2). European Commission. 2024.
  6. European Commission, AI Act Service Desk. AI Act, Article 6: Classification rules for high-risk AI systems. European Commission. 2024.
  7. European Parliament and Council of the European Union. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Official Journal of the European Union. 2024.
  8. European Union. Regulation (EU) 2026/1744 (Digital Omnibus on AI) amending Regulation (EU) 2024/1689. Official Journal of the European Union. 2026.
  9. Treasury Board of Canada Secretariat. Algorithmic Impact Assessment tool. Government of Canada. 2026.
  10. U.S. Federal Trade Commission. Rite Aid Banned from Using AI Facial Recognition After FTC Says Retailer Deployed Technology without Reasonable Safeguards. Federal Trade Commission (press release). 2023.
  11. U.S. Federal Trade Commission. FTC v. Rite Aid Corporation, Complaint for Permanent Injunction and Other Relief, Case 2:23-cv-05023. U.S. District Court, Eastern District of Pennsylvania (filed by the FTC). 2023.

Further reading

Sources last verified 2026-10-08.