Saltar al contenido principal
Back to blog
AI ActAI Governance

Quick inventory to comply with the AI Act in 30 days

August 3, 20265 min readOptimTech
Share:

Why prioritize an inventory in 30 days

The EU AI Regulation (AI Act) is already an operational reality for public administrations: it requires identifying high-risk systems, applying risk management measures, and ensuring transparency and documentation requirements. Before designing controls or contracting vendors, an urgent and achievable task is to create a reliable inventory of AI systems. In 30 days you can obtain an initial classification that allows you to prioritize compliance and mitigation.

Below is a practical plan, templates and concrete actions designed for municipal teams, IT directors and legal offices.

Goal of the 30-day sprint

Deliverables after 30 days:

  • Minimal viable inventory of all systems that use AI or ML.
  • Preliminary classification by risk level (Annex III / high risk, limited risk, minimal).
  • Prioritized list of 10 immediate actions (mitigations, owners, deadlines).
  • "System record" template suitable for audits and procurement.

Roles and participants (day 0)

  • Political sponsor / unit head (decisions and resources).
  • Data owner / DPO (GDPR).
  • IT director / project manager.
  • Legal lead (contracts and liabilities).
  • Key user per service (e.g., Planning Office, Traffic).
  • (Optional) vendor or technical partner to support the inventory.

Week 1: Rapid collection (days 1–7)

Objective: create an initial list with sources and owners.

Actions:

  • Gather sources: application catalog, SaaS contracts, server inventory, citizen service forms, back-office processes.
  • Send a simple template by email to area managers asking them to confirm use of AI (5-day deadline).
  • Collect minimal metadata: system name, vendor, internal owner, data locations, whether it processes personal data.

Minimum template (system record — required fields):

  • System name
  • Brief description of AI use
  • Internal owner (person and unit)
  • Vendor / service (SaaS / on-prem)
  • Data processed (personal / non-personal)
  • End users
  • Production deployment date
  • Contractual evidence (yes / no)

Week 2: Preliminary risk classification (days 8–14)

Objective: assign a risk category according to AI Act criteria.

Actions:

  • Review each record and apply a risk checklist:
    • Do automated decisions affect fundamental rights, access to essential services, employment, justice, migration, or public safety?
    • Does it include remote biometric identification or recognition of people in public spaces?
    • Is it used for selection or classification in regulated areas (education, employment, credit, health)?
  • Classify: High risk / Limited risk / Minimal risk / Prohibited (if applicable).

Practical notes:

  • If in doubt, classify as "prima facie high risk" to prioritize.
  • Document the reason for the classification in the record.

Week 3: Quick compliance assessment and mitigations (days 15–21)

Objective: detect critical gaps and define immediate mitigations.

Actions:

  • For systems classified as high risk, check whether there is:
    • A model risk management system (documented procedures).
    • Training records and data quality logs.
    • Technical documentation and operational logs.
    • Human oversight mechanisms and escalation procedures.
  • For SaaS, review contracts: responsibilities for compliance, access to records and subcontracting.
  • Define immediate mitigations (examples):
    • Restrict operational use until a conformity assessment is completed.
    • Activate enhanced human oversight for sensitive decisions.
    • Add transparency notices in citizen procedures.

Deliverable: prioritized action list with owners and deadlines (30/60/90 days).

Week 4: Communication and plan for the next phase (days 22–30)

Objective: ensure governance and a multi-month plan.

Actions:

  • Prepare an executive report for municipal leadership with:
    • Number of systems inventoried and classified.
    • List of high-risk systems and immediate mitigations.
    • Recommendations for conformity assessment and audit.
  • Publish an internal registry (and, where appropriate, a public transparency note) indicating AI systems used in citizen services.
  • Plan next phases:
    • Detailed technical assessments for high-risk systems.
    • Integration with ENS and GDPR (joint assessment).
    • Definition of standard contract clauses and SLAs.

Practical recommendations and useful templates

  • Use simple formats: CSV for the inventory, one editable record per system.
  • Prioritize production systems that affect rights or essential services.
  • Require vendors to provide technical documentation and access to logs for auditing.
  • Coordinate with the Data Protection Officer: the AI Act and GDPR should be assessed together.
  • Integrate this inventory with the services catalog and the local AI Governance Committee.

Risks and limits of the sprint

  • This is not a final conformity assessment: the inventory provides prioritization, not certification.
  • It requires commitment from units to collect information.
  • Some classifications may change after in-depth technical evaluations.

Takeaway / Immediate action

Start today: send the system record template to all area owners with a 7-day deadline. With that information you will be able, in 30 days, to have the visibility needed to prioritize AI Act compliance and protect critical services. OptimGov and local partners can provide templates and technical support for the inventory if help is needed in the collection and classification phase.