AI System Register (EU AI Act-Aligned)
Purpose: This register helps providers and deployers maintain structured records of AI systems used or placed on the market.
Legal references: Art. 6, Art. 9-15, Art. 17, Art. 26, Art. 49, Art. 60, Annex III, Annex VIII (EU AI Act 2024/1689).
Section A — Record Control
- Register entry ID: [REG-YYYY-###]
- Date created: [YYYY-MM-DD]
- Last updated: [YYYY-MM-DD]
- Record owner (name/role): [Name]
- Business unit: [Unit]
- Review frequency: [Monthly/Quarterly]
- Version history link: [URL or folder path]
Why this matters: Traceability and accountability are foundational across AI Act obligations.
Section B — System Identification
- AI system name: [Name]
- Internal code name: [Code]
- Model/system version: [vX.Y]
- Deployment status: [Design/Pilot/Production/Retired]
- Intended purpose: [Short statement]
- Primary use case: [Use case]
- Secondary use cases: [List]
- Geographic scope: [EU member states / global]
- User groups affected: [Customers/Employees/Candidates/etc.]
Example:
- AI system name: "TalentRank Assist"
- Intended purpose: "Support recruiter shortlisting for junior analyst roles"
- Status: "Production"
Section C — Role & Market Placement
- Role in this system: [Provider/Deployer/Importer/Distributor/Authorized Representative]
- If provider: legal entity name and EORI/VAT: [Details]
- If deployer: legal entity and responsible manager: [Details]
- Placed on market date (if applicable): [YYYY-MM-DD]
- Placed in service date: [YYYY-MM-DD]
- Trademark/branding owner: [Entity]
- Substantial modification performed? [Yes/No]
- If yes, modification summary: [Description]
Why this matters: Obligations differ heavily by role (not just by technology type).
Section D — Risk Classification
- Initial risk classification: [Minimal/Limited/High/Unacceptable candidate]
- Classification rationale: [Reasoning]
- Annex III category (if high-risk): [Category + point]
- Prohibited practice screening completed? [Yes/No]
- Prohibited practice result (Art. 5): [No hit / escalated]
- Date of latest classification review: [YYYY-MM-DD]
- Reviewer name/role: [Name]
Guidance note: Record both the category and the legal trigger, not just a color label.
Section E — Data & Inputs
- Input data types: [Text/Image/Biometric/Behavioral/etc.]
- Personal data involved? [Yes/No]
- Special category data involved? [Yes/No]
- Data source(s): [Internal/Vendor/Public]
- Training data provenance documented? [Yes/No/N/A]
- Validation/testing datasets documented? [Yes/No/N/A]
- Data quality controls in place? [List]
- Bias testing completed? [Yes/No]
- Data retention period: [Duration]
Related AI Act context: Art. 10 data governance and quality requirements for high-risk systems.
Section F — Human Oversight & Operations
- Human oversight owner: [Role]
- Human override mechanism available? [Yes/No]
- Escalation path defined? [Yes/No]
- Logging enabled? [Yes/No]
- Event log retention period: [Duration]
- Monitoring cadence: [Daily/Weekly/Monthly]
- Incident response owner: [Role]
- Serious incident threshold documented? [Yes/No]
Related AI Act context: Art. 12 logging, Art. 14 human oversight, Art. 62 incident reporting.
Section G — Transparency & Communication
- User-facing AI notice required? [Yes/No]
- Notice implemented? [Yes/No]
- Content labeling required? [Yes/No]
- Employee information obligations triggered? [Yes/No]
- Customer challenge/appeal channel: [Email/portal/process]
Related AI Act context: Art. 50-52 transparency obligations.
Section H — Documentation & Conformity
- Technical documentation status: [Not started/In progress/Complete]
- Risk management file status: [Not started/In progress/Complete]
- Post-market monitoring plan status: [Not started/In progress/Complete]
- Conformity assessment required? [Yes/No]
- Notified body involvement needed? [Yes/No]
- EU database registration required? [Yes/No]
- If required, EU database registration ID: [ID]
Related AI Act context: Art. 11, Art. 17, Art. 43, Art. 49, Art. 60.
Section I — Controls & Action Plan
- Open compliance gaps: [List]
- Risk severity per gap: [Low/Medium/High]
- Owner per gap: [Name/Role]
- Target completion dates: [Dates]
- Dependencies (legal/security/product): [List]
- Next governance review date: [YYYY-MM-DD]
- Executive sign-off required? [Yes/No]
- Sign-off status: [Pending/Approved]
Quick Validation Checklist
- [ ] Role is explicitly identified (provider/deployer/etc.)
- [ ] Risk classification includes legal rationale
- [ ] Prohibited practice screening is documented
- [ ] Oversight and incident owners are assigned
- [ ] Transparency obligations are assessed
- [ ] Action plan has owners and deadlines
Common Mistakes to Avoid
- Treating one tool as one use case (multiple uses can mean multiple risk profiles).
- Storing only technical details without legal rationale.
- Missing ownership fields (no accountable person).
- No timestamp/version history for auditability.
- Assuming deployers have no obligations.
Record Sign-Off
- Prepared by: [Name, Role, Date]
- Reviewed by: [Name, Role, Date]
- Approved by: [Name, Role, Date]