Skip to main content
AI Act Delay: Build Your High-Risk System Inventory NowPrivacy Regulations
5 min readFor Data Governance Teams

AI Act Delay: Build Your High-Risk System Inventory Now

The European Commission's proposed delay in regulating high-risk AI systems under the EU AI Act offers a crucial opportunity. For your data governance team, this isn't a chance to relax. It's a deadline extension that should be treated as a compliance sprint.

If your AI systems process personal data at scale, you likely have high-risk systems in production. You just haven't classified them yet. The proposed delay gives you time to address this gap before enforcement begins.

Identify Which Systems Will Be Regulated

Many organizations can't answer a basic question: Which of our AI systems will fall under high-risk classification when the AI Act takes effect?

The AI Act defines high-risk systems in Annex III. These include AI used for biometric identification, critical infrastructure management, employment decisions, credit scoring, law enforcement, and migration control. If your system makes or significantly influences decisions in these areas, it's likely high-risk.

Your GDPR compliance work probably didn't map AI systems by risk tier. Your data processing records document lawful basis and retention periods, not whether the underlying system uses machine learning for employment recommendations or credit decisions.

The proposed delay means you won't face immediate enforcement. But you still need to build a complete inventory of AI systems, classified by risk level, with documented Technical and Organisational Measures for each high-risk deployment.

Gather Essential Resources

Before building your high-risk AI inventory, gather these resources:

Documentation access. Ensure you have read access to your data processing records (Article 30 records under GDPR), vendor contracts for third-party AI tools, and system architecture documentation for internally developed models.

Cross-functional stakeholders. Identify owners for each business unit deploying AI. You'll need input from HR (recruitment tools, performance systems), finance (credit models, fraud detection), IT (infrastructure automation), and legal (contract review tools).

The AI Act text. Download Annex III and the conformity assessment requirements in Chapter III. You'll reference these repeatedly during classification.

A classification framework. Create a simple decision tree: Does this system process personal data? Does it make or influence decisions in Annex III domains? Is human oversight meaningful or cosmetic?

You don't need a specialized tool yet. A structured spreadsheet works for initial inventory. You'll need a governance platform later, but start with clear data.

Step-by-Step Implementation

Step 1: Enumerate All AI Systems (Week 1-2)

Start with systems that process personal data. Query your Article 30 register for any processing activity that mentions "automated decision-making," "profiling," "algorithmic," "machine learning," or "AI."

Then expand beyond GDPR records. Survey each business unit:

  • What tools use predictive models or automated scoring?
  • Which vendors provide "intelligent" features or recommendations?
  • What internal systems use training data to improve decisions over time?

Document each system with: system name, business owner, vendor or internal, data types processed, decision type (fully automated, human-in-loop, advisory only), and deployment date.

Step 2: Classify by Risk Tier (Week 3-4)

For each system, apply the Annex III test. High-risk systems fall into eight categories. Focus on these common enterprise use cases:

Employment and worker management. Recruitment screening tools, resume parsers that rank candidates, performance monitoring systems, and shift scheduling algorithms are all high-risk if they significantly influence hiring, promotion, or termination decisions.

Credit and insurance. Credit scoring models, loan approval systems, and insurance underwriting tools are high-risk. This includes vendor-provided scores you consume via API.

Biometric systems. Any real-time remote biometric identification is prohibited in public spaces (with narrow exceptions). Biometric categorization systems are high-risk.

For each high-risk system, document the specific Annex III category and the decision impact. "Significantly influences" means a human reviewer typically accepts the system's output without independent verification.

Step 3: Document Technical Measures (Week 5-8)

For each confirmed high-risk system, document existing controls:

Training data governance. Where did training data originate? How was it labeled? What bias testing was performed? If you're using a vendor model, request their data governance documentation.

Accuracy metrics. What is the system's error rate? How is accuracy measured and monitored? The AI Act requires ongoing performance monitoring, so establish baseline metrics now.

Human oversight. Who can override the system? How often do they exercise that override? If overrides are rare (less than 5% of decisions), your human oversight may not satisfy the "meaningful" standard.

Logging and traceability. Can you reconstruct why the system made a specific decision? High-risk systems must maintain logs sufficient for post-hoc review.

If you discover gaps, document them. You're not fixing everything this quarter. You're creating a remediation roadmap.

Step 4: Map to GDPR Obligations (Week 9-10)

High-risk AI systems that process personal data trigger specific GDPR requirements you may not have addressed:

Article 22 compliance. If the system makes solely automated decisions with legal or similarly significant effects, you need Informed Consent, contractual necessity, or legal authorization. Verify your lawful basis.

Rights related to automated decision-making. Data subjects can request human review of automated decisions. Document your review process.

Data Protection Impact Assessment updates. High-risk AI processing likely requires a DPIA under Article 35. If you completed a DPIA before deploying the AI system, update it to address AI-specific risks. If you didn't, create one now.

Cross-reference your AI inventory with your Article 30 register. Every high-risk AI system should have a corresponding processing activity with documented lawful basis, retention period, and technical measures.

Validation: How to Verify It Works

Your inventory is complete when you can answer these questions for every AI system:

  • Is this system high-risk under Annex III? (Yes/No/Uncertain)
  • What personal data does it process, and under what lawful basis?
  • What is the current accuracy rate, and how is it monitored?
  • Can a human meaningfully override the system's output?
  • Can we reconstruct individual decisions for audit purposes?

Test your inventory with a sample audit. Select three high-risk systems and attempt to produce:

  • Complete training data lineage
  • Six months of accuracy metrics
  • Evidence of human override in at least 10 recent decisions
  • Logs sufficient to explain one specific decision

If you can't produce these artifacts, your technical measures need work.

Maintenance and Ongoing Tasks

Quarterly inventory updates. New AI deployments happen continuously. Review procurement and IT deployment logs quarterly to catch new systems.

Annual risk reclassification. The AI Act's high-risk categories may expand through delegated acts. Review Annex III annually and reclassify systems as needed.

Vendor due diligence. When evaluating new AI vendors, require documentation of their conformity assessment approach. If they can't articulate how they'll meet AI Act requirements, they're not ready.

Monitor guidance from supervisory authorities. The European Data Protection Board and national supervisory authorities will issue guidance on AI Act and GDPR intersection. Subscribe to official channels and update your framework accordingly.

The proposed delay isn't a reprieve. It's a window to build the governance infrastructure you'll need when high-risk AI regulation takes effect. Start your inventory now, before the deadline pressure begins.

You Might Also Like