Every AI Act conversation starts with documentation — and that is exactly the wrong place to begin. You cannot document systems you haven’t found yet, and our discovery surveys keep surfacing the same surprise: the average mid-size company uses three times more AI than its IT team can name.

Step one: find everything

Browser copilots, embedded vendor features, the support chatbot marketing bought last spring — all of it counts. A structured survey across departments takes about a week and typically doubles the known inventory. This is the unglamorous list everything else depends on.

Step two: classify with reasons

Only with the full list can you classify risk properly: prohibited, high-risk, limited or minimal — each with documented reasoning. Classification without inventory produces the worst outcome: confident paperwork about half your AI.

  • Register every system with vendor, purpose and data involved.
  • Classify risk class with reasoning on record, not just a label.
  • Link each system to its data-protection record — one DPIA can cover both.

Step three: document once, reuse often

Technical files, transparency notices and oversight plans generate from the inventory — and stay linked to it. When a vendor ships a model update, the affected documents flag themselves for review instead of silently going stale.

The pattern that works

Discover, classify, document, monitor — in that order. Companies that follow it report the same relief: the AI Act stops feeling like a moving target and starts looking like any other managed register. That is precisely what our AI Flow encodes.