Discussion about this post

User's avatar
State of Play's avatar

Thanks for this. The enumeration-without-mandate framing is exactly right, and there’s a number behind it: the cross-org data I track puts the share of companies that can’t produce a full list of the AI systems they run at 83%. Atlas is the median case.

Your two failure modes may share one cause. The same edge configuration — system prompts, RAG, a repurposed use case — that trips your Article 25(1)(b) and (c) triggers is also structurally what happens outside procurement’s line of sight, so the systems most likely to have silently changed role are disproportionately the ones that never made it onto the register in the first place.

Mike Schlottman's avatar

Thank you for making the detection layer concrete. Self-reporting fails here for the same reason vendor security questionnaires fail: you are asking people to report legal events they never experienced as legal events. In third-party risk work, the honest witnesses were never the survey responses; they were the expense reports, the SSO logs, and the API keys, exactly as you lay out. My prediction is that the AI register converges with IT asset management within a few years, because the only inventories that stay true are the ones fed by systems that do not care how the answer looks.

2 more comments...

No posts

Ready for more?