As AI becomes core to your business, TruePrivacy helps you govern it responsibly — mapping AI systems, assessing privacy risks, and documenting compliance for regulators.
AI system inventory with risk classifications

In this section

AI System Inventory

Register AI systems and models with ownership, purpose, and the personal data each one uses.

EU AI Act Risk Classification

Classify systems into risk tiers via a guided questionnaire and track obligations and conformity documentation.

AI system inventory

Maintain a structured registry of every AI and ML model in your organization. Each entry captures:
  • Training data sources and their provenance — the consents or legal bases the data was collected under
  • Data subjects affected and the personal data categories processed
  • Decision outputs and the business process the model supports
  • Model cards — standardized documentation for each system

EU AI Act risk classification

Map each AI system to the EU AI Act’s risk categories and track the conformity obligations that apply:
CategoryExamplesWhat TruePrivacy does
ProhibitedSocial scoring, manipulative systemsFlags for immediate escalation
High-riskEmployment screening, credit scoring, biometricsTracks conformity obligations as compliance tasks with deadlines
Limited riskChatbots, content generationTracks transparency obligations (disclosure to users)
Minimal riskSpam filters, recommendation tuningInventoried, no active obligations

Model assessments

1

Register the system

Add the model to the inventory — or let discovery flag AI services detected among your connected systems.
2

Classify

Answer a guided classification questionnaire; TruePrivacy assigns the AI Act risk category and the applicable obligations.
3

Assess

High-risk AI processing automatically triggers a DPIA workflow, pre-populated with the system’s data inputs, processing logic, and likely impacts.
4

Monitor

Bias and fairness checks flag systems that may produce discriminatory outputs from personal data processing; findings feed the organizational risk register.

Regulatory reporting

Generate documentation packages per AI system — inventory record, classification rationale, assessment results, and mitigations — ready for EU AI Act conformity documentation and DPA inquiries.
AI governance builds on the same foundations as the rest of the platform: training data sources link to your data map, and third-party AI vendors are assessed through Vendor Risk.