Skip to content

The EU AI Act for mid-market companies: why an AI inventory comes first

If you run AI in your company, the first step is a clean AI inventory: use cases, data flows, owners, control level, evidence. A small internal mini app makes it auditable in 14 days — whichever EU AI Act deadline comes next.

Attila Arndt
Attila Arndt

Triple A Digital, Cologne · · 4 min read

Updated

Who it's for
Owners, IT and data protection in mid-sized companies who need to know which AI is in use.
What you'll be able to do
Set up an AI inventory with the fields from checklist 1 and reach your first controlled use case in 14 days.
As of
September 2026
TL;DR

The highest-leverage AI Act move for most teams is not legal deep-dives. It’s: knowing what AI you actually run (use cases, data, tools, owners, control level). Without an AI inventory you won’t “become compliant later”. You’ll drown in unknowns.

Primary sources: when does what apply?

Regulation (EU) 2024/1689 applies from 2 August 2026, with earlier phases — among them 2 February 2025 and 2 August 2025. You can read it up in the EUR‑Lex summary of the regulation and in Article 113, explained by the AI Act Service Desk.

Update of 12 September 2026: the timeline has shifted

This post was published in March 2026. Since then the legal situation has changed in three places, and in favour of companies:

The obligations for high-risk systems apply later. Amending Regulation (EU) 2026/1744 (the “Digital Omnibus on AI”, in force since 27 July 2026) moved them to 2 December 2027 — and for AI in regulated products under Annex I even to 2 August 2028. At the same time, the definition of high-risk has been narrowed.

The transparency obligations, by contrast, have applied since 2 August 2026 as planned. Anyone running a chatbot or publishing AI-generated images and videos has to say so — that also affects companies which merely use AI rather than build it.

In Germany the Bundesnetzagentur is in charge. The AI market surveillance and innovation act (KI‑MIG) came into force on 29 July 2026. The authority runs a service desk, an online tool for a first assessment of the risk class and an AI regulatory sandbox. Small and mid-sized companies are explicitly the target group.

What that means for this project: nothing. An AI inventory is not worth having because a deadline is looming, but because nobody can steer a process they cannot see. The postponed deadline buys you time — it does not take the work off your desk.

Sources: Bundesnetzagentur on the KI‑MIG · KI‑MIG full text · overview of the changes

Not legal advice. This is implementation/process guidance.

In 2026 nobody asks “do you use AI?” — they ask “where exactly, and how do you control it?”

In real mid-market setups it often looks like this: AI sits inside SaaS tools, browser extensions, “test accounts” and automations. The data for it flows through email, CRM, tickets and files — sometimes with personal data in the mix. And decisions are semi-automated in practice: AI drafts, and the human still clicks send fast.

The risk isn’t the model. The risk is missing visibility + missing evidence that you’re in control.

What happens today — and what the inventory records
Tools
Today in the businessAI sits inside SaaS tools, browser extensions, test accounts and automations.
In the AI inventoryTool, provider and hosting per use case — including whatever is in unofficial circulation.
Data
Today in the businessThe data flows through email, CRM, tickets and files, sometimes with personal data in the mix.
In the AI inventoryData sources and data types: public, internal, confidential, personal.
Decisions
Today in the businessSemi-automated in practice: AI drafts, and the human still clicks send fast.
In the AI inventoryControl level from assistance to critical — and the point at which a human approves.
Evidence
Today in the businessWhat is missing is the evidence that you are in control.
In the AI inventoryLogging, retention and evidence as links or files.
Every detail in the right-hand column is part of checklist 1 further down.

The 80/20 system: an AI inventory as a small internal mini app

An AI inventory is not a spreadsheet that dies after two weeks. It’s a small internal app with three jobs.

Three jobs of the mini app
  1. 01
    CaptureWhich AI use cases exist at all — inside SaaS tools, browser extensions, test accounts and automations.
  2. 02
    ClassifyEvery use case by control level and risk flags.
  3. 03
    ProveWith evidence and an audit trail: who approved what when.
The list below shows which details per use case are enough for this.

The data model behind it can stay pragmatic. These details per use case are enough:

  • use case name + goal (one sentence)
  • owner (business) + reviewers (IT/security/DPO)
  • input data types (public/internal/confidential/PII)
  • tool/provider + hosting/region (if known)
  • output type (internal/external) + impact if wrong
  • control level (draft/assist → partial automation → critical)
  • logging/retention (what is stored for how long?)
  • evidence links/uploads (DPA, DPIA artefacts, approvals)

What you do NOT need (and what you do)

To start, you don’t need perfect legal classification on day 1, you don’t need 60-page policies, and you don’t need a “Center of Excellence” that exists as an org chart in a slide deck.

What you do need is one front door where all AI use cases land. Then ownership: who is accountable, and who reviews. Gates where someone decides whether a pilot may start or not. And evidence that shows why you approved it.

Checklist 1: AI inventory fields (copy/paste)

AI inventory: minimum dataset per use case
  • Use case name + goal (one sentence)
  • Owner (business) + backup
  • User group (who uses it?)
  • Tool/provider/model (if known)
  • Input sources (email/CRM/files/DB/API)
  • Data types: public / internal / confidential / PII
  • Output: internal vs external (customer/partner)
  • Human-in-the-loop (where must a human approve?)
  • Automation level (assist / partial process / decision)
  • Logging: what’s logged? (inputs/outputs/prompts/IDs)
  • Retention: how long? who can access?
  • Risk flags (e.g., people impact, PII, external)
  • Evidence: links/files (DPA, DPIA, approvals)

Checklist 2: “AI Act ready” in 14 days (realistic)

14-day plan: inventory + governance MVP
  • Days 1–2: collect 15–30 use cases (workshop + ask for shadow AI)
  • Days 3–4: lock the data model + roles (owner/reviewer)
  • Days 5–7: build the review flow (submitted → review → pilot → approved/rejected)
  • Days 8–9: evidence vault + audit trail (who approved what when)
  • Days 10–11: triage wizard (risk flags + default control levels)
  • Days 12–14: pilot playbook (do/don’t, data rules, logging) + team briefing

Getting the AI inventory mini app built

If you don’t want to run blind into 2026

Send me:

  • your top 10 processes where AI is “somehow” used
  • the tools currently in the wild (including unofficial)
  • who performs IT/security/DPO reviews

I deliver in 7–14 days an internal AI inventory mini app, together with the review flow and its audit trail, plus templates for typical mid-market use cases: email assist, support drafts, document workflows.

Questions

Answered in brief

Isn’t a spreadsheet enough for an AI inventory?

An AI inventory is not a spreadsheet that dies after two weeks. It’s a small internal app with three jobs: capture, classify, prove — with an audit trail that records who approved what when.

What details does a use case need as a minimum?

Name and goal in one sentence, the owner and the reviewers, the input data types, tool and provider including hosting, the output type, the control level, plus logging and retention — and the evidence as links or uploads.

Is there anything left to do now that the deadlines have moved?

For the inventory the postponement changes nothing: it buys you time, it does not take the work off your desk. Nobody can steer a process they cannot see. Which obligation applies when is in the update above, with sources.

Related

What I do in this area


Keep reading

Attila Arndt

Attila Arndt · Triple A Digital, Cologne

Is there a process like this in your company?

Pick a time that suits you. In the intro call, we'll work out which process is worth tackling first — and whether I'm the right person for it.

Free intro call (opens in a new tab)

Or email me directly: hello@tripleadigital.de · I reply within 48 hours.