DISCOVER: Recording AI Systems
DISCOVER: how to build an AI recording process that works
In the last article I showed why a one-off AI inventory is not enough. Today I show you the solution: a continuous recording process that fits your company.
No enterprise software. No external consultants. A pragmatic approach for SMEs.
DISCOVER: the first phase in the compliance lifecycle
In my 5-phase framework NADOVO for EU AI Act compliance, DISCOVER is the starting point. Before you can assess risks, implement measures or run training, you have to know what you actually have.
DISCOVER means: establishing complete visibility over all AI systems in your organization.
That sounds simple. But it is not. Because AI systems hide everywhere, in SaaS tools, browser extensions, embedded features. And they multiply faster than you can maintain lists.
What you have to record
An AI inventory is more than a list of tool names. For each entry you need information in five categories.
The first category is master data. Name of the AI system, vendor, version, licence type. For SaaS tools: contract term and notice periods. For open source: source and community status.
The second category is technical information. Where does the system run, locally, cloud, hybrid? Which data is processed? Are there interfaces to other systems? Is data used for training?
The third category is the application context. Which department uses the system? For what specific purpose? Who are the users? Which decisions are supported or automated?
The fourth category is the role determination. Are you a provider or a deployer for this system? Providers develop or substantially modify AI systems. Deployers use ready-made systems under their own responsibility. Most SMEs are deployers, but the distinction matters because different obligations apply.
The fifth category is the compliance status. Is there an official approval? Has a risk assessment been carried out? Is training documented? Is there a data processing agreement under the GDPR?
Provider or deployer: why the distinction matters
The EU AI Act distinguishes clearly between providers and deployers. Providers have comprehensive obligations: conformity assessment, CE marking, technical documentation under Article 11, a quality management system.
Deployers have different but also significant obligations: risk assessment under Article 26, training of employees under Article 26(5), ongoing monitoring under Article 26(6), reporting of serious incidents under Article 73.
The good news for SMEs: if you use SaaS tools like ChatGPT, Microsoft Copilot or Salesforce Einstein, you are generally a deployer. The provider obligations lie with the vendor.
But be careful: if you substantially modify an AI system, for example through extensive fine-tuning or integration into your own products, you can become a provider. With all the consequences.
The recording process in four steps
A working recording process needs four elements: initial recording, reporting channels, approval and regular review.
The first step is the initial recording. Start with a systematic inventory. Check your software asset management, analyse SaaS subscriptions, survey department heads. Run an anonymous employee survey: which AI tools do you use for your work? Expect surprises.
The second step is clear reporting channels. Define how new AI systems are reported. That can be a simple form, an email to a central point or a ticket in a ticketing system. What matters: the channel must be known and easy. If employees have to fill in three approval forms, they will not do it.
The third step is an approval process. Not every AI tool needs a board decision. But every tool needs a conscious decision. Define criteria: which data is processed? Is there a data processing agreement? Is the vendor GDPR-compliant? Does the use case fall under Annex III? A simple decision tree with five questions is enough for most cases.
The fourth step is regular review. Once a quarter: go through the inventory, survey departments, identify new tools. Once a year: a complete review of all entries. Have use cases changed? Are there new versions with new features? Are tools no longer in use?
Setting responsibilities
A process without clear responsibilities is not a process. You need answers to three questions.
Who is responsible for the overall inventory? In larger companies: the AI compliance officer or IT manager. In smaller SMEs: often the managing director or data protection officer. This person maintains the central register and coordinates the reviews.
Who reports new systems? Every employee who wants to introduce a new AI tool. That has to be communicated and trained. No exceptions for executives.
Who approves? Depending on the risk level. MINIMAL RISK: IT manager or department head. Potential HIGH-RISK cases: management or the compliance officer.
Practical implementation for SMEs
You do not need expensive governance software. To start, a structured spreadsheet with the following columns is enough: ID, system name, vendor, department, purpose of use, data types, provider/deployer, approved (yes/no), approval date, risk assessment (pending/completed), responsible person, last review, notes.
Store the spreadsheet in a central location with access control. Keep a change log. Make backups.
If you grow and manage more than 20 AI systems, you can think about specialized tools. But start simple.
The connection to the next phase
DISCOVER is the first step, not the last. Each recorded AI system has to be linked to specific use cases in the next phase, DEFINE.
Because: it is not the system itself that determines the risk class, but the purpose of use. ChatGPT for marketing texts is MINIMAL RISK. ChatGPT to support personnel decisions is HIGH-RISK.
This linking of asset and area of application into an AI process is the core of my framework. But without clean recording in DISCOVER, you have nothing to link.
The quick start for this week
You do not need a perfect process tomorrow. But you can start today.
This week: create the spreadsheet. Record the five most important AI systems you know of. In your next team meeting, ask: which AI tools do you use?
Next week: extend the list. Check your SaaS subscriptions. Send a short survey to all employees.
In four weeks: you have a first inventory and a rough process. Not perfect, but a start. From there you can iterate and improve.
Conclusion
DISCOVER is not a one-off action. It is the cornerstone for everything that follows: process definition, risk assessment, implementation of measures, monitoring.
An AI system you do not know about, you cannot assess. A risk you do not see, you cannot manage. An obligation you do not know about, you cannot meet.
The EU AI Act requires control. Control begins with visibility. Visibility begins with DISCOVER.
Start this week. The deadline does not wait.
About the author
Jochen Stier is co-founder of NADOVO with over 20 years of experience in process management and IT service management. He helps German SMEs implement the requirements of the EU AI Act systematically and pragmatically. His 5-phase framework NADOVO combines regulatory requirements with practical feasibility, without enterprise budgets or complex tools.
More articles
AI Technology Website Migration and SEO Ranking
Many fear a website migration destroys the Google ranking. That is true - if you do it wrong. What really happens and what matters.
read more ...
AI Technology Maintaining a Website Without an Agency
If you have a business website, you should be able to maintain it yourself. Why that does not work for most people - and how it can be done differently.
read more ...
AI Compliance Why I Built NADOVO
Why a process consultant with 20 years of experience builds his own AI compliance framework and his own platform - and what that has to do with the EU AI Act.
read more ...