Every AI Act conversation starts with documentation — and that is exactly the wrong place to begin. You cannot document systems you haven’t found yet, and our discovery surveys keep surfacing the same surprise: the average mid-size company uses three times more AI than its IT team can name.
Step one: find everything
Browser copilots, embedded vendor features, the support chatbot marketing bought last spring — all of it counts. A structured survey across departments takes about a week and typically doubles the known inventory. This is the unglamorous list everything else depends on.
Step two: classify with reasons
Only with the full list can you classify risk properly: prohibited, high-risk, limited or minimal — each with documented reasoning. Classification without inventory produces the worst outcome: confident paperwork about half your AI.
- Register every system with vendor, purpose and data involved.
- Classify risk class with reasoning on record, not just a label.
- Link each system to its data-protection record — one DPIA can cover both.
Step three: document once, reuse often
Technical files, transparency notices and oversight plans generate from the inventory — and stay linked to it. When a vendor ships a model update, the affected documents flag themselves for review instead of silently going stale.
The pattern that works
Discover, classify, document, monitor — in that order. Companies that follow it report the same relief: the AI Act stops feeling like a moving target and starts looking like any other managed register. That is precisely what our AI Flow encodes.