Almost every AI Act question that reaches us stalls at the same point. Not on the legal interpretation, but on which AI systems are actually in use and who is responsible for them. Without that view every next step is guesswork: you cannot classify what you cannot see, and you cannot justify a measure for a system you do not know is running.
This is a practical approach to building that register in four weeks. No software selection, no months-long implementation programme. A workable overview you can extend later.
Why the register comes first
The AI Act ties nearly every obligation to two variables: what the system does and which role you hold. The transparency duties under Article 50, which have applied since 2 August 2026, land differently for a provider than for a deployer. The heavier obligations for Annex III systems apply from 2 December 2027, but preparing for them starts with the same inventory.
That makes the register a working instrument rather than an administrative end product. It answers the question a supervisor, a client or your own board asks first: which AI do you use, and how do you know it is used responsibly.
Week 1: collect what is running
Start broad and filter later. Most organisations underestimate how much AI is already in use, because AI functionality increasingly sits inside software nobody thinks of as an AI tool.
Ask three things per department. Which tools do you use that predict, generate, score, summarise or recommend. Which suppliers added AI features to existing software in the past year. And which tools do staff use themselves, outside official procurement.
That last category produces the biggest surprise almost every time. Staff use generative tools because the work goes faster, not because there is a policy for it. That is not a reproach but a fact your register has to account for.
Week 2: determine your role per system
This is the step most often skipped and the one that makes the most difference. The AI Act places obligations on different parties, and which duty is yours depends on your position.
A provider develops the system or places it on the market under its own name or trademark. A deployer uses a system under its own authority. Most organisations are the deployer for purchased software and the provider for what they build themselves or offer under their own name.
Watch the tipping point in Article 25: substantially modifying a system, placing it on the market under your own name, or changing its intended purpose can move you from deployer to provider. That happens more often than expected, for example when a standard model is fine-tuned on your own data and then offered as your own service.
Week 3: classify on what the system does
The risk category follows from the task, not from the technology. A language model is not high risk in itself; a language model that shortlists job applicants is, because recruitment and selection sit in Annex III.
Run this order per system:
- Does it fall under a prohibited practice in Article 5? Then it stops there and the use has to end.
- Does it perform a task listed in Annex III, such as recruitment, credit assessment, access to essential services, education or law enforcement? Then it is high risk, unless the Article 6(3) exception applies.
- Does it interact directly with people, generate synthetic content, or infer emotions or biometric characteristics? Then the Article 50 transparency duties apply, which have been in force since 2 August 2026.
- Otherwise the baseline regime applies, including the Article 4 duty to take measures that support the AI literacy of the people working with it.
Document why you reached each conclusion. The classification itself is a snapshot; the reasoning is what a supervisor can assess and what you will still understand a year from now.
Week 4: make it maintainable
A register filled in once ages within a quarter. Three arrangements keep it alive.
Assign an owner per system, someone who knows when the system changes. Connect the register to your procurement process, so a new tool does not arrive unseen. And record what triggers a reassessment: a new system, a changed purpose, a supplier switching model, or an incident.
For most organisations this fits in a spreadsheet with ten to fifteen columns. Software helps once you have dozens of systems and several people updating at the same time. Do not start with the tool, start with the content.
What takes the most time
Three things overrun in practice. Finding out which AI features your existing suppliers have switched on, because that is often absent from the product documentation and you have to ask. Determining the role for systems you have modified, because Article 25 draws a line that is not always sharp. And recording the reasoning for borderline cases, because that is the step everyone wants to skip and the one that turns out to be worth the most later.
Expect four weeks of lead time for an organisation up to roughly 250 staff, provided you have one contact per department and the board has given the assignment. Without that mandate it becomes a round of emails that takes months.
How Embed AI works on this
We start this kind of engagement with the AI governance scan at 2,950 euro, creditable against a follow-up engagement. It delivers the register, the role determination and the classification, plus the first priorities. To move straight on to policy, documentation and a working governance structure, the AI Act Readiness Sprint at 9,900 euro is the route.
If the organisation needs temporary senior ownership across departments rather than a fixed sprint, an interim AI governance lead can own the decisions, evidence and implementation until the permanent structure is in place.
The legal reasoning behind the classification sits on the Praxikon, where the Annex III domains are worked out per category. For the people who work with the systems, LearnWize provides role-based training with a record per employee.
Closing
The register is not a compliance document you file away. It is the answer to the question of which AI your organisation uses and why that is responsible. Organisations with that answer ready can hang every next AI Act obligation on information they already have. Organisations without a register start from scratch with every new question.

