Question 1 of 53
How do we inventory and classify AI systems by risk level?
By Cody Maxwell · AI Governance Institute · January 2026 · Last verified September 13, 2026
Catalog your AI tools, including shadow AI. Assess each system’s data sensitivity, decision impact, and regulatory exposure.
▸Editorial status
- September 13, 2026 · Source update — The article already references the EU AI Act and its core risk tiers (unacceptable, high, limited, minimal) in the classification matrix section, and the EU AI Act is already listed in relatedFrameworks. The deferred Annex III deadline (December 2, 2027) and other timeline specifics are scheduling details that do not create a genuine gap or contradiction in an article focused on how to inventory and classify AI systems by risk level, not on compliance deadlines. (AI Governance Institute pipeline)
- September 13, 2026 · Substantive update — The NIST AI Documentation Guidance draft introduces a concrete requirement to document each AI system's purpose, intended use, performance characteristics, and known limitations using NIST-provided templates, and to maintain audit-ready records before deployment. An inventory and risk classification article is the natural home for guidance on what to record for each catalogued system, and this policy fills that gap with specific documentation obligations that readers relying on the article would need to act on. (AI Governance Institute pipeline)
If you only do 3 things, do this:
- 1.Run vendor contract reviews, employee surveys, and network scans together. Each finds AI use the others can miss.
- 2.Score data sensitivity, decision impact, and regulatory exposure. Use the results to prioritize oversight and check applicable legal classifications.
- 3.Give every system a named owner and review date. Assign responsibility for keeping its inventory record current.
The Situation
Who this is for: GRC teams, risk managers, or compliance leads launching an AI governance program
When you need this: Before any formal compliance work begins, or when a regulator asks what AI systems your organization operates
The Decision
Which AI systems need immediate governance attention, and what level of oversight does each one require?
The Steps
- 1Pull all vendor contracts and flag any that include AI features, model access, or "intelligent" functionality
- 2Send an employee survey offering amnesty for undisclosed tool use, with a clear path to get tools approved
- 3Ask IT security to monitor outbound traffic to known AI API endpoints (OpenAI, Anthropic, Google, Cohere)
- 4Consolidate results into a working inventory spreadsheet
- 5Score each system: 1-3 on data sensitivity, 1-3 on decision impact, 1-3 on regulatory exposure
- 6Assign a risk tier based on aggregate score, then assign a named owner and next review date to each row
The Artifacts
- —AI inventory spreadsheet template (fields: name, owner, vendor, use case, data processed, risk tier, regulatory frameworks, last reviewed)
- —Risk classification scoring matrix (data sensitivity × decision impact × regulatory exposure)
- —Employee survey template with amnesty language
- —Vendor AI capability checklist for procurement reviews
The Output
An AI inventory with a risk tier and named owner for every system. Schedule quarterly inventory reviews.
Find the systems already in use
Begin with the AI systems already in use. Include personal accounts, AI features inside vendor software, and departmental subscriptions that bypassed procurement. These tools can remain absent from an IT-approved software list.
Review vendor contracts for AI capabilities in existing software. Ask employees which AI tools they use in their workflows. Have IT audit network traffic for unauthorized calls to language model providers. Run these checks together; each covers gaps in the others.
Build a risk classification matrix
Apply a consistent risk classification to the inventory. A common summary of the EU AI Act distinguishes unacceptable, high, limited, and minimal risk. Prohibited uses require exclusion. High-risk uses face strict requirements, while certain other uses carry transparency duties. Minimal-risk uses generally have no specific AI Act obligations. Teams outside the Act’s scope can use this distinction as an organizing reference. Check statutory criteria before assigning a legal classification.
Assess data sensitivity first. Does the system process personal data, health information, financial records, or another regulated category? Then assess decision impact. Does it affect hiring, credit, benefits, or access to services? Finally, check regulatory exposure. Financial services, healthcare, and employment may have specific requirements.
Use these dimensions to assign an internal risk tier. High scores across all three call for rigorous oversight. Review classifications annually and whenever a system or its use changes. An internal score does not replace the legal classification required by an applicable regulation.
Maintain a living inventory
Assign an owner, record the risk tier, and schedule reviews for every system. Classify new deployments before launch. Add an AI capability check to procurement and vendor management so new tools enter the inventory.
Choose an inventory tool that filters by risk tier, business unit, data type, and regulatory framework. Keep records ready to explain which systems you operate and how you oversee them.
Record documentation for each inventoried system
NIST's draft guidance on public-facing AI documentation specifies that each system should be documented across several dimensions: its purpose, intended uses, performance characteristics, and known limitations. Using structured templates for these fields makes records consistent across your inventory and easier to compare during governance reviews. Documentation should be completed before deployment, not after.
The guidance also calls for audit-ready records that can substantiate claims during third-party or regulatory review, and for external-facing disclosures written in terms accessible to affected parties. Aligning your inventory records with NIST AI RMF categories, which the draft explicitly encourages, lets a single record serve both internal classification and external transparency purposes. Public comments on the draft are open until September 16, 2026, so practitioners should monitor the final version for changes to template requirements.
Governance Controls
Operational controls that implement the guidance in this playbook.
Related frameworks
Recent Coverage
News and developments relevant to this playbook topic.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →More guidance like this, every week
New playbook articles, governance controls, and the regulatory changes driving them. Every Thursday.
