Record an AI system in the inventory
How to create a system with AI components in the AI systems module, determine its protection requirements and lay the basis for risk classification under the AI Regulation.
A complete register of all systems containing AI components is the prerequisite for reliably determining the risk class and the required measures under the AI Regulation. In this guide you record an AI system in the “AI systems” module, determine its protection requirements and link the relevant measures.
Prerequisites
- Your team has a licence for the “AI Regulation”.
- You have permission to view AI systems (
ai-systems); to create, edit or release entries you also need the corresponding permission. - You have access to the organization the system is to be assigned to.
Step by step
- Switch the toggle at the top of the Main navigation to “ISMS”. The toggle only appears if your team is licensed for both privacy and information security.
- In the left-hand menu, click the “AI Regulation” category and then the “AI systems” entry. The overview shows only those systems in your team that contain AI components.
- Click “New” at the top right and select “Create AI system”. For a proven sample system, choose “Load from sample documents” instead; for a derived entry, choose “Create linked document”.
- Fill in at least the “Designation” field and select at least one “Organization” under “Association”, or activate “All organisations”. Without an assignment, the note “Organisations must be filled in.” appears.
- Click “Create”. The AI system is created and automatically marked as a system with AI components; its detail view opens with the breadcrumb “AI Regulation › AI systems › [Designation]”.
- In the “Contents” tab, complete the “General”, “Settings” and “Protective measures” sections as well as the “Data fields”, “Users”, “Roles” and “Clients” subordinate lists. Use the “Categorisation” to classify the system, for example as “Artificial intelligence”.
- Switch to the “Protection requirements” tab and determine the protection requirements for “Confidentiality”, “Integrity” and “Availability”. As long as no classification has been made, the tab shows “Not rated”; the determined level then appears in the overview as the “Protection requirements” column and filter.
- Link the system via “AI technical and organisational measures” to the AI-specific protective and governance measures that apply to its operation.
- Release the entry with “Release”. The status changes to “Released” and a revision is created. To release several entries at once, select them in the table and choose the “Release” action under “Actions” at the top right.
Risk classification under the AI Regulation
The risk classification is not stored on the system record itself: the AI systems recorded here are the reference object for the “AI compliance checks” in the same “AI Regulation” category, where the risk class and the operator obligations are documented. The protection requirements remain the benchmark for risk assessment and for selecting appropriate measures in the ISMS.
Practical tips
- Maintain the system register completely before documenting risk classification and measures — the other modules in the “AI Regulation” category build on it.
- You only record the system once: it also becomes part of the overall “Assets” set and can additionally be marked as “relevant to data protection” so that it also appears under “Data processing systems”.
- The quickest way to review nested system landscapes is the “Tree” toggle at the top right, which displays the “Parent asset” and “Subordinate assets” relationships.
Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.