DE | EN

DISCOVER: Recording AI Systems

DISCOVER: how to build an AI recording process that works

In the last article I showed why a one-off AI inventory is not enough. Today I show you the solution: a continuous recording process that fits your company.

No enterprise software. No external consultants. A pragmatic approach for SMEs.

DISCOVER: the first phase in the compliance lifecycle

In my 5-phase framework NADOVO for EU AI Act compliance, DISCOVER is the starting point. Before you can assess risks, implement measures or run training, you have to know what you actually have.

DISCOVER means: establishing complete visibility over all AI systems in your organization.

That sounds simple. But it is not. Because AI systems hide everywhere, in SaaS tools, browser extensions, embedded features. And they multiply faster than you can maintain lists.

What you have to record

An AI inventory is more than a list of tool names. For each entry you need information in five categories.

The first category is master data. Name of the AI system, vendor, version, licence type. For SaaS tools: contract term and notice periods. For open source: source and community status.

The second category is technical information. Where does the system run, locally, cloud, hybrid? Which data is processed? Are there interfaces to other systems? Is data used for training?

The third category is the application context. Which department uses the system? For what specific purpose? Who are the users? Which decisions are supported or automated?

The fourth category is the role determination. Are you a provider or a deployer for this system? Providers develop or substantially modify AI systems. Deployers use ready-made systems under their own responsibility. Most SMEs are deployers, but the distinction matters because different obligations apply.

The fifth category is the compliance status. Is there an official approval? Has a risk assessment been carried out? Is training documented? Is there a data processing agreement under the GDPR?

Provider or deployer: why the distinction matters

The EU AI Act distinguishes clearly between providers and deployers. Providers have comprehensive obligations: conformity assessment, CE marking, technical documentation under Article 11, a quality management system.

Deployers have different but also significant obligations: risk assessment under Article 26, training of employees under Article 26(5), ongoing monitoring under Article 26(6), reporting of serious incidents under Article 73.

The good news for SMEs: if you use SaaS tools like ChatGPT, Microsoft Copilot or Salesforce Einstein, you are generally a deployer. The provider obligations lie with the vendor.

But be careful: if you substantially modify an AI system, for example through extensive fine-tuning or integration into your own products, you can become a provider. With all the consequences.

The recording process in four steps

A working recording process needs four elements: initial recording, reporting channels, approval and regular review.

The first step is the initial recording. Start with a systematic inventory. Check your software asset management, analyse SaaS subscriptions, survey department heads. Run an anonymous employee survey: which AI tools do you use for your work? Expect surprises.

The second step is clear reporting channels. Define how new AI systems are reported. That can be a simple form, an email to a central point or a ticket in a ticketing system. What matters: the channel must be known and easy. If employees have to fill in three approval forms, they will not do it.

The third step is an approval process. Not every AI tool needs a board decision. But every tool needs a conscious decision. Define criteria: which data is processed? Is there a data processing agreement? Is the vendor GDPR-compliant? Does the use case fall under Annex III? A simple decision tree with five questions is enough for most cases.

The fourth step is regular review. Once a quarter: go through the inventory, survey departments, identify new tools. Once a year: a complete review of all entries. Have use cases changed? Are there new versions with new features? Are tools no longer in use?

Setting responsibilities

A process without clear responsibilities is not a process. You need answers to three questions.

Who is responsible for the overall inventory? In larger companies: the AI compliance officer or IT manager. In smaller SMEs: often the managing director or data protection officer. This person maintains the central register and coordinates the reviews.

Who reports new systems? Every employee who wants to introduce a new AI tool. That has to be communicated and trained. No exceptions for executives.

Who approves? Depending on the risk level. MINIMAL RISK: IT manager or department head. Potential HIGH-RISK cases: management or the compliance officer.

Practical implementation for SMEs

You do not need expensive governance software. To start, a structured spreadsheet with the following columns is enough: ID, system name, vendor, department, purpose of use, data types, provider/deployer, approved (yes/no), approval date, risk assessment (pending/completed), responsible person, last review, notes.

Store the spreadsheet in a central location with access control. Keep a change log. Make backups.

If you grow and manage more than 20 AI systems, you can think about specialized tools. But start simple.

The connection to the next phase

DISCOVER is the first step, not the last. Each recorded AI system has to be linked to specific use cases in the next phase, DEFINE.

Because: it is not the system itself that determines the risk class, but the purpose of use. ChatGPT for marketing texts is MINIMAL RISK. ChatGPT to support personnel decisions is HIGH-RISK.

This linking of asset and area of application into an AI process is the core of my framework. But without clean recording in DISCOVER, you have nothing to link.

The quick start for this week

You do not need a perfect process tomorrow. But you can start today.

This week: create the spreadsheet. Record the five most important AI systems you know of. In your next team meeting, ask: which AI tools do you use?

Next week: extend the list. Check your SaaS subscriptions. Send a short survey to all employees.

In four weeks: you have a first inventory and a rough process. Not perfect, but a start. From there you can iterate and improve.

Conclusion

DISCOVER is not a one-off action. It is the cornerstone for everything that follows: process definition, risk assessment, implementation of measures, monitoring.

An AI system you do not know about, you cannot assess. A risk you do not see, you cannot manage. An obligation you do not know about, you cannot meet.

The EU AI Act requires control. Control begins with visibility. Visibility begins with DISCOVER.

Start this week. The deadline does not wait.


About the author

Jochen Stier is co-founder of NADOVO with over 20 years of experience in process management and IT service management. He helps German SMEs implement the requirements of the EU AI Act systematically and pragmatically. His 5-phase framework NADOVO combines regulatory requirements with practical feasibility, without enterprise budgets or complex tools.

© 2026 Jochen Stier / contoro.solutions