| System identity | Name, supplier, version, business owner, lifecycle stage and whether the system is built, bought or embedded in SaaS. | Annex IV technical documentation | One early-access register entry per AI system, joined to the relevant supplier, system and owner records. |
|---|
| Operator role | Provider, deployer, importer, distributor or product manufacturer status, because obligations change by role. | Article 26 deployer duties | Role assessment is drafted for review and written only from the human-approved assessment. |
|---|
| Purpose and use context | Business process, user group, affected persons, geography and how the output is used in decisions. | Annex VIII registration information | Assessment answers and knowledge-base evidence remain traceable to the reviewer and source record. |
|---|
| Risk classification | Risk tier, Annex III category, Article 6(3) reasoning and GPAI flag, with the reason preserved. | Article 6 / Annex III | Four classification fields copy deterministically from the human-approved assessment; no language model writes them directly. |
|---|
| Technical documentation | Design, intended purpose, data, performance, limitations and conformity evidence for high-risk systems. | Article 11 / Annex IV | Conformity templates are available on opt-in (early access), with source evidence and review history attached. |
|---|
| EU-database registration status | Whether Article 49 applies, the EU-database URL or reference, and the reason no registration is required if it does not apply. | Article 49 / Article 71 | Acompli records registration status and URL; it does not submit entries to the EU database. |
|---|
| FRIA and affected groups | Whether Article 27 applies, affected groups, specific fundamental-rights risks, oversight and mitigation measures. | Article 27 FRIA | A FRIA can reuse DPIA evidence where the facts overlap. |
|---|
| Transparency scenario | Whether the system interacts with people, generates or manipulates content, or performs emotion recognition or biometric categorisation. | Article 50 transparency | Code Scan AI Governance mode can flag chatbots, generative-content libraries and biometric or emotion-classification SDKs for review. |
|---|
| GDPR evidence link | Article 30 RoPA activity, DPIA status, lawful basis, personal-data categories, transfers and supplier records. | Article 30 RoPA / Article 35 DPIA | The register is designed to sit on the existing GDPR evidence spine instead of duplicating it in a separate AI silo. |
|---|
| Monitoring, logs and review | Human oversight, log retention, incidents, substantial changes, next review date and approval history. | Article 12 logs / Article 9 risk management | Each reviewed decision keeps owner, status, approval history and evidence; operational monitoring remains the organisation's responsibility. |
|---|