Mapping your AI systems means listing, in a single table, every artificial intelligence tool in use across the company, with its vendor, its purpose, the data it processes and the person accountable for it. In a company of 30 to 100 employees, that work takes half a day to two days, not six weeks.
Read the full guide
EU AI Act 2026: The Complete Compliance Guide for SMEs and Nonprofits
Answer a few questions and get a personalized assessment with recommendations tailored to your industry.
Assess my AI maturityRelated articles
Dive deeper with these complementary articles.
The EU AI Act (Regulation 2024/1689) applies to your SME or nonprofit as soon as you use an AI tool, even a simple ChatGPT subscription. Since February 2025 you must train your teams; on 2 August 2026 the transparency obligations and the penalty regime take effect.
Mapping your AI systems means listing, in a single table, every artificial intelligence tool in use across the company, with its vendor, its purpose, the data it processes and the person accountable for it. In a company of 30 to 100 employees, that work takes half a day to two days, not six weeks. It is the mandatory starting point for any compliance effort, and it is also what stops you paying for the same subscription three times over.
Most of the content available on this topic will steer you towards an AI governance platform priced at 2,000 to 15,000 € per year. For a company running ChatGPT, Copilot, an AI writing assistant and a meeting transcription tool, that is out of proportion. A well built spreadsheet does the job, provided you know what to put in it and where to look. This article covers both. It complements the AI Act compliance guide for SMEs and nonprofits, which sets out the wider regulatory framework.
Under Regulation (EU) 2024/1689, an AI system is an automated system that infers, from the input it receives, outputs such as predictions, content, recommendations or decisions. The definition is deliberately broad. It captures far more than most executives assume at first glance.
In practice, the following fall inside the scope:
Purely deterministic software stays outside: an Excel macro, a fixed business rules engine, a classic list-based spam filter. The boundary is sometimes blurred. When in doubt, add the row to the table marked "to be qualified" rather than leaving it out. A row too many costs five minutes; a missing row costs you a blind spot.
Mapping serves compliance, but its immediate payback is time and budget.
On the regulatory side, no text literally requires every company to keep "a register of AI systems". Several obligations do, however, become impossible to meet without a prior inventory: identifying whether you operate a system classified as high risk under Article 6, checking that no use case falls under the prohibited practices in Article 5, knowing who should receive an AI information notice. On the GDPR side, the record of processing activities is genuinely mandatory, and every AI tool touching personal data belongs in it. How the two registers overlap is covered in AI Act vs GDPR.
Financially, the effect is immediate and routinely underestimated. In the mapping exercises we run, it is common to uncover two to four duplicate subscriptions: a ChatGPT Plus plan on the founder's card alongside Team licences bought by a department, or a transcription tool duplicating a feature already bundled in the office suite.
Operationally, the inventory shows who uses what. That is the basis for targeting training. Training the 8 people who actually use an assistant every day produces more than training 60 people for half a day.
Software bought by IT or management takes twenty minutes to list. Undeclared usage, shadow AI, is where the real work sits.
An employee pasting a contract excerpt into a free assistant does not think of themselves as deploying an AI system. They are saving time. They will not report it spontaneously, least of all if the question is asked in the tone of an audit.
Four sources let you reconstruct what declarations miss:
That last point is not window dressing. If the first mapping ends in a blanket ban, the second one will surface nothing at all and usage will simply move out of sight.
A 30-person company completes its first mapping in half a day by working through sources rather than departments.
Pass 1, purchasing: pull 12 months of software subscriptions from the accounts and sort by description. Allow 45 minutes.
Pass 2, SSO and licences: export the list of connected applications and active licences per user. Allow 30 minutes.
Pass 3, AI features in existing software: go back through your business applications and check, vendor by vendor, which AI features are switched on. This is the most frequently skipped pass and often the most productive: your recruitment tool or your CRM has probably enabled automatic suggestions without anyone making an explicit decision. Allow 1 hour.
Pass 4, interviews: 15 minutes per department head, with the question phrased as above. For five departments, allow 1.5 hours.
Pass 5, qualification: for each row, fill in the role and the risk level, then flag the rows that need a decision. Allow 1 hour.
Above 150 employees, or where systems have been developed in-house, the timeline stretches considerably, up to several weeks. The logic stays the same.
Twelve columns are enough. Beyond that, the table will not be kept up to date.
| Column | What goes in it | Why |
|---|---|---|
| Tool name | ChatGPT Team, Copilot 365, Fireflies | Identification |
| Vendor | Publisher and country of establishment | Chain of accountability |
| Purpose | One sentence, in business language | Basis for all qualification |
| User department | Sales, HR, management | Training target |
| Number of users | Actual headcount, not licences bought | Duplicate detection |
| Data types processed | Public, internal, personal, sensitive | Link to the GDPR record |
| Hosting | EU, outside EU, undocumented | Transfers and contractual clauses |
| Your role | Provider, deployer, distributor, importer | Determines your obligations |
Two columns deserve a comment. "Your role" is decisive: in the vast majority of SMEs you are a deployer (you use a tool designed by someone else), not a provider. The heavy obligations in the regulation fall first on the provider. The exact scope is set out in who the AI Act applies to.
"Automated decision" is the best warning indicator available to a non-lawyer. A tool producing a draft reviewed by a human almost never carries the same risk profile as one that screens applications or rejects a file without human involvement.
Plenty of articles still date the high-risk rules to 2 August 2026. That is no longer accurate.
The package known as the Digital Omnibus pushed the application of obligations for standalone high-risk systems under Annex III to 2 December 2027, and to August 2028 for systems embedded in regulated products under Annex I. The Article 5 prohibitions have applied since February 2025, and the Article 50 transparency obligations since 2 August 2026. The full picture is in the AI Act timeline, and the amounts at stake in AI Act sanctions.
That postponement has a direct practical consequence for your mapping: the urgency is not documenting a hypothetical high-risk system, it is checking three far more mundane things. No use case falls under the prohibited practices. Tools that interact with your customers or generate published content meet the transparency obligations. Personal data flowing through those tools is covered by your GDPR record and by a proper processing agreement.
The same reform softened Article 4 on AI literacy: what was an obligation on companies became an incentive, with the Commission and member states taking the lead on promoting literacy. A competence requirement nonetheless remains for deployers of high-risk systems, through the effective human oversight duty. We unpack that nuance in Article 4 AI Act: is AI training mandatory. Put plainly: train your teams because your tools are being used badly, not because an inspector is coming.
A mapping that is not maintained goes stale within four months, because vendors switch on AI features without asking you.
Three rules are enough to maintain it.
A quarterly 30-minute review, attached to a management meeting that already exists. It covers three questions: what is new, what has been dropped, which row changed status.
Three triggers that force an update outside that cycle: a new tool arriving, a major update to existing software (the most frequent and the quietest case), and any change in the scope of data processed.
A named owner. In an SME this is rarely a dedicated role: the finance controller, the office manager or the founder. What matters is that the "internal owner" column never holds a department name. The mapping then connects naturally to a formal AI policy, which sets the usage rules the inventory has made necessary.
Is mapping AI systems mandatory? Not as such for most companies. No article of Regulation (EU) 2024/1689 imposes a general AI register comparable to the GDPR record of processing activities. It becomes indispensable in practice, since the obligations that actually apply to you cannot be identified without it.
Is a spreadsheet enough, or do I need dedicated software? A spreadsheet holds up to roughly thirty rows and a single site. AI governance platforms become relevant beyond that, when you need approval workflows, several legal entities or an auditable change history. Starting with a spreadsheet does not lock you in: the columns are the same either way.
Should tools used by external providers be listed? Yes, whenever they process your data or produce deliverables on your behalf. That covers the communications agency generating visuals for you, or the accounting firm using invoice recognition software. Add an "internal / provider" column if the volume justifies it.
How do I know whether a tool is high risk? Look at the purpose first, not the technology. Annex III targets specific uses: recruitment and worker management, access to education, creditworthiness assessment, essential public services, law enforcement, among others. An internal writing assistant does not qualify. A tool that shortlists CVs does. See Article 6 AI Act.
How much time does it genuinely take? Half a day for a 30-person company following the five passes above. Two to three days if you have several sites, in-house development or a loosely structured software purchasing history. The six-week timelines quoted by some providers apply to organisations of several hundred people.
What should I do about tools the mapping flags as non-compliant? In order: stop anything falling under a prohibited practice, which is rare; issue written instructions for anything processing personal data without a contractual basis, pending proper documentation; leave the rest running and document it. A general, immediate ban mostly produces workarounds.
Should the mapping be shared with staff? It is not an obligation in itself, but it is strongly advisable. Usage surfaces far better on the second pass when teams have seen what the first one produced, and that it led to no sanctions.
We run the mapping with you rather than for you, for a simple reason: the table has to remain workable by your team once we step away. The AI audit we run covers the five passes described here, delivers the twelve-column table filled in, and flags the rows that call for a decision on your side.
What follows depends on what the inventory shows. If it mostly reveals unmanaged usage and scattered subscriptions, the answer is operational AI training aimed at the people who actually use the tools. If it reveals regulatory exposure, the answer is documentation and compliance work, starting again from the AI Act guide for SMEs. Either way, the mapping stays the reference document.
GrowthPerf is a Qualiopi-certified training provider, which opens up OPCO funding on the training side for French companies.
To review your current AI usage, book a free 30-minute audit at cal.com/growthperf/audit-gratuit.
| Automated decision | Yes, no, human-assisted | Primary risk signal |
| Presumed risk level | Prohibited, high risk, transparency, minimal | Prioritisation |
| Internal owner | A name, not a department | Without a name, nothing moves |
| Status | Approved, to qualify, to stop | Steering |