Important: This is practical information for Irish SMEs, not legal advice. The relevant obligations depend on your role, the system, how it is used and whether personal data is involved.
What an AI systems inventory is
An AI systems inventory is a working list of the ways your business uses AI. It is not a catalogue of software licences. One product can support several different uses, and each use can create different risks. For example, an AI feature that drafts an internal meeting summary is not the same use as one that ranks job applicants.
The aim is simple: give a named person a reliable picture of the tool, its purpose, the people affected, the data involved, the supplier and the controls. It should include stand-alone tools such as ChatGPT and Copilot, but also AI features inside your CRM, accounting, meeting, email, recruitment and customer-support software.
Legal duty or good practice?
Good practice: the EU AI Act does not impose a single, universal obligation for every Irish SME to maintain an “AI inventory”. Keeping one is nevertheless a practical way to find use cases and assign decisions before they become harder to explain.
Legal duties may sit behind individual rows. The AI Act requires providers and deployers to support appropriate AI literacy for people operating or using AI on their behalf. For a high-risk AI system, deployers have more specific duties, including following the instructions for use, assigning competent human oversight and monitoring the system. A usable inventory helps identify whether those duties could apply; it does not classify a system by itself.
GDPR can require a record. Where an AI use processes personal data, it may need to appear in the organisation’s Record of Processing Activities (RoPA). GDPR Article 30 specifies information such as purposes, data subjects and data categories, recipients, transfers, retention and security measures. The small-organisation exemption is limited, so do not assume that having fewer than 250 staff removes the need to keep records. The Irish Data Protection Commission (DPC) provides guidance and a template.
Use one row for each real use case
Start with a spreadsheet or register that people can update. Do not wait for perfect information. Mark gaps as “unknown” and give them an owner and review date.
- Tool and supplier: product name, AI feature, supplier, plan/account type and business owner.
- Actual purpose: what it does in the workflow—not just “marketing” or “AI assistant”.
- Users and affected people: which team uses it and whether it affects customers, staff, applicants, children or the public.
- Inputs and outputs: categories of personal, confidential or special-category data; where the information comes from; and what the system produces.
- Data and vendor position: link to the relevant RoPA entry, data-processing terms, hosting or transfer information, retention settings and privacy notice where applicable.
- Risk screen: whether the use needs a GDPR/DPIA review, an AI Act prohibited-practice, high-risk or transparency assessment, or specialist advice.
- Controls and evidence: approved settings, human review, staff guidance, access control, testing, incident route, decision owner and next review date.
How to find the AI you already have
Most SMEs do not discover every use by sending one email. Ask each function to walk through its work: sales, marketing, HR, finance, operations, IT and customer service. Ask what is used to draft, summarise, transcribe, score, recommend, search, forecast or make decisions.
Then check practical evidence: software subscriptions and expense claims; purchase orders; browser or password-manager entries shown voluntarily by staff; corporate app catalogues; meeting tools; CRM and help-desk release notes; and vendor renewal records. The result is often a mix of approved tools, switched-on features and informal “shadow AI”. Record all three. Discovery is not a disciplinary exercise; people are more likely to disclose a tool if they know the goal is to make the safe route clear.
Screen first, then prioritise
Do not try to finish a legal assessment for every row on day one. Apply a short triage and escalate what needs more work:
- Personal or sensitive data? Link the use to the RoPA and check lawful basis, transparency, processor terms, security, retention, transfers and whether a DPIA could be needed.
- Important decisions about people? Flag uses in employment, education, credit, insurance, essential services, law enforcement or other sensitive contexts for specialist AI Act and data-protection review. Product branding alone cannot decide the classification.
- Public-facing or synthetic content? Check whether AI Act transparency duties could apply to the particular output or interaction.
- Low-impact internal assistance? Record basic boundaries, approval, output checking and staff guidance. Revisit if the purpose, model, data or integration changes.
Connect the inventory to GDPR records
An AI inventory and a RoPA have different jobs. The inventory is operational: it tells you what the business is using and who owns it. The RoPA is the GDPR record of processing activities. Link the two with a common reference number rather than duplicating data in both places.
The DPC says organisations considering AI should recognise the risks of personal-data processing before deciding whether the chosen product is appropriate. That is why an inventory row should not simply say “uses customer data”. It should point to the purpose, data categories, supplier arrangement, safeguards and the decision about whether further assessment is needed.
Good practice: run a simple review cycle
Set a review date for every active use, and trigger an earlier review when the supplier changes its terms, model, training setting, hosting, integrations, retention or intended purpose. Make a new-use-case approval step part of procurement and change management. A modest register that is updated is more useful than an elaborate one that is abandoned after launch.
Plain-English takeaway
You cannot govern AI you have not found.
Build one practical list of real use cases, connect personal-data uses to your RoPA, and send higher-impact decisions for the right review.
What to do this week
- Name an accountable owner for the inventory and agree where it will live.
- Ask each department to list its AI tools and AI-enabled features.
- Create one row per use case, including data, affected people, vendor and business purpose.
- Link personal-data rows to your RoPA and flag any possible DPIA question.
- Prioritise the unknown, public-facing and people-affecting uses for review.
Use the AI compliance readiness checklist to structure the first screen, then see how to retain the supporting decisions in the AI compliance evidence guide. If staff use generative-AI tools, the ChatGPT and GDPR guide covers the specific data-protection questions.
Official sources: EU AI Act (consolidated text), including Articles 3, 4 and 26 ↗ · GDPR, including Articles 5, 25, 30 and 35 ↗ · Irish DPC: Records of Processing guidance ↗ · Irish DPC: AI, LLMs and data protection ↗