Found this helpful? Share it with peers.
Introduction
Artificial Intelligence is rapidly becoming part of everyday business operations. Organizations deploy AI assistants, AI agents, copilots, and generative AI capabilities across customer service, software development, HR, finance, and countless other business functions. While technical discovery sources can identify AI-related components, organizations are now facing a different challenge: governing them.
The EU AI Act introduces new obligations for organizations that develop or use AI systems. To comply, organizations need an inventory that explains what the AI does, why it exists, where it is used, who is responsible, and which business data and processes are affected.
This article presents an ArchiMate-based pattern for building such an AI system repository.
Why Every Organization Needs an AI Inventory
Ask a typical organization how many AI agents they currently operate, and the answer is often uncertain. Questions quickly arise:
- Which AI agents are used across the enterprise?
- Which business processes rely on AI?
- Which applications embed AI capabilities?
- Which AI models are being used?
- Who owns each AI agent?
- Which data does it process?
- Which AI systems are considered High-Risk under the EU AI Act?
Organizations can leverage multiple discovery sources, including Microsoft Entra, Azure AI Foundry, Microsoft Defender, cloud platforms, and CI/CD pipelines, to identify AI-related components. While these sources provide valuable evidence that AI exists, they do not explain why it exists, how it is used by the business, or who is responsible for it.
The EU AI Act therefore creates the need for an enterprise-wide AI inventory rather than simply another list of technical assets.
What the EU AI Act Requires
The EU AI Act follows a risk-based approach. While obligations differ depending on the AI system’s classification, organizations generally need to maintain information such as:
- AI system or AI agent
- Intended purpose
- Provider
- Deployer
- Business owner
- Risk classification
- Business context
- Data being processed
- Human oversight
- Applicable governance and regulatory constraints
For High-Risk AI systems, additional requirements such as technical documentation, logging, risk management, and human oversight become particularly important.
The regulation does not simply require organizations to know that an AI system exists. It requires them to demonstrate how that system is governed throughout its lifecycle.
Modelling an AI Repository with ArchiMate
Technical discovery provides valuable evidence that AI-related components exist within an organization’s IT landscape. However, achieving compliance with the EU AI Act requires this technical information to be placed into its business and architectural context.
This is where Enterprise Architecture comes in.
Enterprise Architecture links AI capabilities to the business processes they support, the applications implementing them, the data they process, the people responsible for them, and the governance requirements they must satisfy. Rather than maintaining disconnected inventories, it provides a single repository that connects business, application, data, and governance perspectives.
ArchiMate is particularly well suited for this task because it already provides the concepts needed to model these relationships.
ArchiMate pattern for documenting AI Agents
In this pattern, an AI Agent is modelled as a specialization of an Application Service. The AI Agent is linked to the Business Processes and Business Roles that use it, the Application Component implementing it, the Foundation Model (LLM) providing its AI features, and the Data Objects it processes. Applicable Constraints capture regulatory obligations such as the EU AI Act or internal governance policies. In addition, Artifacts discovered through automated monitoring can be linked to the AI Agent, providing evidence of its existence and helping identify undocumented AI capabilities.
Besides these relationships, the AI Agent itself stores important governance information as properties, including its purpose, business owner, risk classification, High-Risk status, version, lifecycle status, and criticality. Together, these relationships and properties provide a comprehensive inventory of AI capabilities from both a business and governance perspective.
Putting the Pattern into Action with ADOIT
The ArchiMate pattern provides the foundation for practical AI governance. ADOIT operationalizes this pattern by supporting the complete lifecycle of AI inventory management:
Forms – Capture and maintain AI agents, their business context, ownership, risk classification, and governance information in a structured way.
ADOIT Forms for registering AI agents
Reports – Generate AI inventories, compliance reports, ownership overviews, and other documentation required for governance, audits, and regulatory reporting.
Reporting on AI agents in ADOIT
AI-Assisted Risk Classification – Analyze documented AI agents and automatically propose an EU AI Act risk classification based on their metadata. The AI Assistant explains its assessment, identifies missing information, and supports transparent, human-reviewed compliance decisions.
AI-assisted risk classification in ADOIT
Dashboards – Visualize AI inventories, documentation coverage, High-Risk AI systems, governance status, and discovered artifacts requiring review.
Dashboard visualization of AI inventory in ADOIT
Integrations – Connect to discovery sources such as Microsoft Entra, Azure AI Foundry, ServiceNow, or other enterprise systems to identify AI-related artifacts and support continuous synchronization between technical discovery and the architecture repository.
Connector configuration in ADOIT
Summary
The biggest challenge introduced by the EU AI Act is not discovering AI. It is governing it.
Technical discovery sources can identify AI-related components, but they cannot explain why an AI agent exists, who owns it, which business processes depend on it, or which regulatory obligations apply.
Enterprise Architecture fills this gap by providing the business context that technical discovery alone cannot deliver.
Using ArchiMate as the modeling language allows organizations to build a vendor-independent AI repository that connects business, applications, data, governance, and monitoring evidence into a single architecture model. This creates a solid foundation for AI governance, compliance with the EU AI Act, and informed decision-making as AI adoption continues to grow.
By combining automated discovery with EA, organizations can move beyond simple asset inventories toward a living AI repository that supports transparency, governance, and continuous compliance.











