Back to the kit

Evidence Kit · Samples

Full samples, nothing held back

These are complete documents, generated for a fictional company — Northwind Talent, a recruiter whose CV-ranking tool lands in Annex III point 4. Nothing is truncated and nothing is watermarked. If they are not worth paying for, you will know before you pay.

Placeholders marked [to be completed] are deliberate: they are the points where only you can supply the fact, and a blank invites the conversation that a confident guess would skip.

Sample. Fictional organisation and system. Do not use this as your own record — the reasoning in it belongs to a company that does not exist.

AI system inventory register

Northwind Talent GmbH, HRB 998877, Berlin

For the compliance owner, and the first document to hand to an auditor, acquirer or authority.

1. What this register is for

Art. 26; Art. 49; Art. 72

No AI Act provision says "keep an inventory" in those words. Every provision that matters assumes you have one. You cannot classify what you have not listed, cannot register under Article 49 what you have not classified, cannot assign oversight under Article 26 without knowing who owns what, and cannot answer a market surveillance authority's first question without this table.

It is also the document an acquirer, an insurer or an enterprise customer asks for. Treat it as the index to everything else in this kit.

Organisation
Northwind Talent GmbH, HRB 998877, Berlin
Country
Germany
Register owner
Jana Novak — Head of People Operations, acting AI compliance owner
Created
2026-09-11
Review cycle
Quarterly, and on any change of intended purpose

2. The register

SystemVendor / built byIntended purposeOur roleClassificationAnnex III pointPersonal data?DPIA / FRIAOwnerHuman oversightLogs keptDeadlineEvidenceReviewed
CandidateRank (version 2.4)In-house, built on a third-party general-purpose model via APIRanks inbound job applications by fit against the role description in order to produce a shortlist, which a recruiter reviews before any interview or rejection decision is taken.Provider and deployerHigh-risk — Annex III use case + Transparency obligations — live now4 (employment)YesDPIA: [to be completed]Jana Novak[to be completed][to be completed]2 December 2027Classification memorandum dated 2026-09-112026-09-11
ChatGPTChatGPT[to be completed]deployer[to be completed][to be completed][to be completed]Jana Novak[to be completed][to be completed][to be completed][to be completed][to be completed]
Microsoft CopilotMicrosoft Copilot[to be completed]deployer[to be completed][to be completed][to be completed]Jana Novak[to be completed][to be completed][to be completed][to be completed][to be completed]
DeepLDeepL[to be completed]deployer[to be completed][to be completed][to be completed]Jana Novak[to be completed][to be completed][to be completed][to be completed][to be completed]
The first row is built from the system you assessed. The remaining rows are the tools you told us are in use — they are listed so they cannot be forgotten, not because they are necessarily in scope. Classify each one, even if the answer is "minimal risk, no obligations": a documented nil return is worth having.

3. How to fill each column

ColumnWhat goes in itWhy
SystemThe name people here actually useYou need to be able to talk about it
Vendor / built byIn-house, or the supplier's legal nameDecides whether you are provider, deployer or both
Intended purposeOne sentence, what it is forClassification turns on this and nothing else
Our roleProvider, deployer, or both (Art. 3(3), 3(4))Selects which obligations apply
ClassificationProhibited / high-risk Annex I / high-risk Annex III / not high-risk via Art. 6(3) / transparency only / GPAI / minimalThe whole point of the register
Annex III pointThe specific point, e.g. 4 for employmentAuthorities ask which point, not whether
Personal data?Yes / no / unsureTriggers the parallel GDPR analysis
DPIA / FRIALink or reference, or why not requiredArt. 27 FRIA and GDPR Art. 35 DPIA; they may be combined under Art. 27(4)
OwnerA named person, not a teamRegulators want a name
Human oversightWho can override or stop it, and howArt. 14 design and Art. 26(2) assignment
Logs keptWhere, and for how longArt. 26(6) requires at least six months for deployers
DeadlineThe date Chapter III bites, or "applies now"2 December 2027 Annex III; 2 August 2028 Annex I; Art. 50 already live
EvidenceLinks to the memo, disclosures, training recordsTurns a claim into a record
ReviewedDate of last reviewShows the register is alive

4. Finding the systems you have missed

Most organisations undercount their AI systems by a wide margin. The gaps are almost always in the same places:

  • AI features switched on inside software you already licence — the CRM, the HR suite, the helpdesk, the office suite. You did not buy "an AI system", so nobody logged one.
  • Tools individuals signed up for themselves, often on a free tier, frequently the most sensitive use of all.
  • Recruitment and assessment tools operated by an agency on your behalf, where you may still be the deployer.
  • Anything with "assistant", "copilot", "smart", "automatic" or "predictive" in the marketing.
  • Models your engineers call by API inside your own product — which may make you a provider under Article 25 rather than a deployer.

Practical sweep: ask finance for every software subscription, ask IT for the SSO and browser-extension list, and ask each team lead the single question "what do you use AI for?" — that last one finds more than the first two.

Register owner

Reviewed by

Date

What a lawyer should check

Hand this list to counsel with the document. It is short on purpose — these are the points where a generated record most often diverges from the facts of a real organisation.

  1. Whether any row classified as minimal risk or Article 6(3) deserves a second look — those are the entries that later turn out to be wrong.
  2. Whether an agency, payroll provider or outsourced recruiter is operating a high-risk system on your behalf, and which of you is the deployer.
  3. Whether any in-product model call makes you a provider under Article 25 rather than a deployer.
  4. Whether the register should be disclosable to customers or investors, and what that implies for how candidly it is written.
  5. This document is a structured record of an assessment you made, drafted for your review. It is not legal advice and it does not bind any authority.
  6. It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force 27 July 2026. The Commission's guidelines on high-risk classification under Article 6(5) were due on 2 February 2026 and remain in draft (version of 19 May 2026), so classification positions that depend on them may change.
  7. No harmonised standard has yet been cited in the Official Journal, so the presumption of conformity in Article 40 is not available to anyone.
Generated by euai-act.com — a documented self-assessment, not legal advice.

Generate these for your own system

Run the free Navigator to classify your system, then the kit fills these documents in from your answers.