Does your company have to register its AI systems? The short answer is no (and the long one matters)
Equipo Tecnea
Tecnea

It is one of the most frequent questions we get since the AI Act started to apply: "do I have to register the artificial intelligence we use somewhere?". Behind it there is usually a reasonable fear of discovering an obligation with a fine attached too late.
The direct answer: if your company simply uses AI tools, you do not have to enter any public register. But it is worth understanding why, because the part that does affect you is constantly confused with this one.
There is a European register, but it is not for you
The EU Artificial Intelligence Act creates an EU database for high-risk AI systems (Articles 49 and 71). Who has to register:
- The provider of the high-risk system: whoever develops it and places it on the market under their name. They register themselves and the system before marketing it.
- The deployer that is a public authority or Union body: on top of using it, they register its use.
In other words: registration falls on whoever builds the high-risk system and on the public administration that uses it. A private company that buys or contracts an AI tool for its internal management is not on that list.
And there is a second reason not to panic about the calendar: the obligations attached to Annex III high-risk systems apply from 2 December 2027.
So what do you actually have to do?
Here is the confusion worth clearing up. There is no register to fill in, but there is something your company needs in writing, and which you will be asked for through other channels well before 2027: your large clients in their supplier audits, your insurer, your advisors, or yourself the day you want to know what is happening inside your organisation.
That something is an inventory of the AI systems your company uses. With three columns, not thirty:
- What the tool is and what it is used for. Including the ones nobody formally approved: the translator the sales department uses, the assistant someone connected to the mailbox. That is also AI in your company.
- What data goes into it. If personal data of clients or employees goes in, the GDPR already applied to you before the AI Act and still does.
- What risk level that specific use has. The Regulation classifies by use, not by tool: the same model can be minimal risk when drafting an email and high risk when deciding who gets hired.
What is already in force and many people do not know
While high-risk registration waits for 2027, there is an AI Act obligation that already applies: AI literacy (Article 4). Your company must ensure that whoever uses these systems has enough training to understand what they do and to spot their errors.
It does not require a certificate or an accredited course: it requires you to be able to show that your people know what they are handling. In an SME that is solved with one documented training session and written usage rules — not with a six-month consulting project.
The transparency obligation (Article 50) is also in force when a person interacts with an AI system instead of a human, or is given AI-generated content.
How to do it without turning it into a project
A normal SME's inventory fits in a spreadsheet and takes an afternoon. The order we recommend:
- Ask before auditing. Most of the AI in a company was brought in by a well-meaning employee, not by IT. If the conversation starts in inspection mode, the answer will be that nobody uses anything.
- Write down the use, not the brand name. "Summarising meeting minutes" says far more than "ChatGPT".
- Flag where there is personal data or decisions about people. That is where you need to look closely; the rest is probably minimal risk and only needs usage rules.
- Review it when the tools change, not on a calendar.
If in doing this you discover that half the AI in your company is personal accounts on free tools with internal documents going through them, the inventory has already paid for itself: that is exactly the problem the Regulation wants you to see.
Sources: Article 49 of Regulation (EU) 2024/1689 (registration of high-risk systems), Article 71 (EU database) and the Annex III application calendar.
This article is informational and does not replace legal advice. Tecnea builds AI applications and supports its clients with AI Act compliance, so we have an obvious commercial interest in this topic; we say so up front. The inventory we describe is something you can do yourself, and if it saves you from hiring anyone, it will have done its job.
¿Te ha resultado útil este artículo?
Publicamos análisis sobre IA y tecnología empresarial. Sin spam — solo cuando escribamos algo que valga la pena leer.
Did you like this article?
Tell us what you'd like to automate in your company and we'll tell you, with no strings attached, where to start.
