Skip to main content

Challenge 01: EU Regulator Wants Your AI Inventory in 30 Days

Scenario Brief

Industry: Enterprise (any) | Regulatory Context: EU AI Act Art. 51, GDPR Art. 35
Time Estimate: 90 minutes | Azure Cost: ~$0–5 (Purview licensing required)


What's at Stake​

Europax Manufacturing operates across 7 EU member states. A national competent authority has issued a formal inquiry:

"Under Article 51 of Regulation (EU) 2024/1689, you are required to provide a complete register of all high-risk AI systems in use within 30 days, including technical documentation as specified in Article 11."

Their IT team estimates they have "about 15 AI systems" but has no formal inventory. You have 30 days to discover, classify, document, and respond.


Skills Practiced​

  • Using Microsoft Purview AI Hub to auto-discover AI activity across the tenant
  • Applying the EU AI Act risk classification framework (unacceptable, high, limited, minimal)
  • Building a compliant technical documentation package per Art. 11
  • Implementing Microsoft RAI Standard v2 impact assessment
  • Understanding EU AI Act registration requirements for high-risk systems

EU AI Act Risk Classification​

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ EU AI Act Risk Pyramid β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ UNACCEPTABLE RISK β€” BANNED as of Feb 2, 2025 β”‚
β”‚ β€’ Social scoring by public authorities β”‚
β”‚ β€’ Real-time remote biometric surveillance in public spaces β”‚
β”‚ β€’ Subliminal manipulation β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ HIGH RISK β€” Annex III list (must comply by Aug 2, 2026) β”‚
β”‚ β€’ Hiring & HR decisions β€’ Credit scoring β”‚
β”‚ β€’ Medical devices β€’ Insurance risk assessment β”‚
β”‚ β€’ Critical infrastructure β€’ Educational assessment β”‚
β”‚ β€’ Law enforcement β€’ Migration & border control β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LIMITED RISK β€” Transparency obligations only β”‚
β”‚ β€’ Chatbots (must disclose it's AI) β”‚
β”‚ β€’ Deepfake content (must label) β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ MINIMAL RISK β€” No obligations (but document anyway) β”‚
β”‚ β€’ Spam filters, recommendation engines, AI in games β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

🧰 Before You Start β€” Environment Setup​

This is a governance discovery exercise, so most of your setup is access and permissions, not code. The goal: be able to see all AI activity in your tenant, then classify and document it.

Prerequisites​

RequirementWhy you need itHow to check
Microsoft 365 E5 or a Purview compliance licenseUnlocks Microsoft Purview AI Hub (AI activity discovery + DSPM for AI)Purview portal β†’ Data Security β†’ AI Hub
Purview / compliance admin roleRun activity reports and author DLP policiesMicrosoft 365 admin center β†’ Roles
PowerShell + Exchange Online Management moduleExport AI activity via Connect-IPPSSessionGet-Module -ListAvailable ExchangeOnlineManagement
A spreadsheet / Microsoft Lists or Dataverse tableHold your AI system inventory + risk classificationMicrosoft 365

Step 0 β€” Confirm you can actually see AI activity (10 min) β€” the "where do I go"​

This exercise depends on Microsoft Purview DSPM for AI. Before anything else, prove you can reach it and that data is flowing β€” otherwise Task 1 discovery returns empty and you'll think you have no shadow AI when you just have no visibility.

  1. Go to purview.microsoft.com and sign in with an account that has the Purview / compliance admin role.
  2. In the left nav, open DSPM for AI (Data Security Posture Management for AI). If you don't see it, your tenant is missing the M365 E5 or Purview compliance license β€” see the official DSPM for AI get-started guide.
  3. On the Overview page, confirm Activity tiles show data. If they're empty, turn on the one-time setup options (audit + Copilot/AI analytics) β€” DSPM for AI prompts you; allow up to 24–48h for first data.
  4. Verify the PowerShell path you'll use to export activity:
Install-Module ExchangeOnlineManagement -Scope CurrentUser # if not already installed
Connect-IPPSSession # opens sign-in; this is your compliance/eDiscovery endpoint

βœ… Done when DSPM for AI shows activity tiles and Connect-IPPSSession connects without error.

Step 1 β€” Create your inventory as a governed list, not a spreadsheet (10 min)​

Your inventory is a regulated artifact, so give it ownership, history, and access control from the start. Create a Microsoft List (or a Dataverse table) with these exact columns:

System name | Owner | Data touched | EU AI Act risk tier | Art. 11 doc? | Registered? | Last reviewed

To create it: Microsoft Lists β†’ + New list β†’ Blank list β†’ add the columns above (use a Choice column for risk tier: Prohibited / High / Limited / Minimal).

βœ… Done when the list exists with all 7 columns and at least you as owner.

🟦 Microsoft-first note: this challenge is already Microsoft-native β€” Purview DSPM for AI does the discovery, Purview DLP enforces the guardrails, and your inventory belongs in Microsoft Lists or Dataverse (not a loose spreadsheet) so it has ownership, history, and access control.

Common fixes: DSPM for AI not visible β†’ missing E5/Purview license or compliance-admin role. Activity empty β†’ enable auditing under DSPM for AI one-time setup and wait for data to accrue.

The path through this challenge​

  1. Task 1 β€” discover AI activity with Purview AI Hub (expect shadow AI).
  2. Task 2 β€” classify every system by EU AI Act risk tier.
  3. Task 3 β€” complete Article 11 technical documentation for high-risk systems.
  4. Task 4 β€” stand up a Purview DLP policy blocking sensitive data to external AI.
  5. Success Criteria β€” a complete, defensible inventory + regulator response.
  6. Adapt to Your Business β€” run this discovery on your org.

⏱️ Time budget: ~90 minutes. Discovery (Task 1) usually surprises people β€” budget extra for shadow-AI findings.


Your Tasks​

Task 1: Discover AI Activity with Microsoft Purview AI Hub​

# Purview AI Hub requires Microsoft 365 E3/E5 or Purview compliance license
# Access via: https://purview.microsoft.com β†’ Data Security β†’ AI Hub

# PowerShell: Export Purview AI activity report
Connect-IPPSSession

# Get AI interactions report (last 30 days)
Get-AIActivityReport -StartDate (Get-Date).AddDays(-30) -EndDate (Get-Date) |
Export-Csv -Path "ai_activity_report.csv" -NoTypeInformation

# Get list of AI applications detected
Get-AISiteActivityReport |
Select-Object ApplicationName, UserCount, InteractionCount, DataSensitivity |
Sort-Object InteractionCount -Descending |
Format-Table

Task 2: Classify Each AI System​

For each discovered system, apply this classification matrix:

from enum import Enum
from dataclasses import dataclass
from typing import Optional

class EUAIActRisk(Enum):
UNACCEPTABLE = "Unacceptable" # BANNED
HIGH = "High" # Art. 6 + Annex III
LIMITED = "Limited" # Art. 52 transparency
MINIMAL = "Minimal" # Recommended practice

@dataclass
class AISystemRecord:
name: str
description: str
vendor: str
deployment_date: str
data_processed: list[str]
eu_act_risk: EUAIActRisk
annex_iii_category: Optional[str]
article_11_docs_complete: bool
human_oversight_mechanism: str
registration_required: bool
notes: str

# Example classification
systems = [
AISystemRecord(
name="HR Candidate Screening Tool",
description="AI-powered resume screening that ranks candidates",
vendor="Internal (Azure OpenAI)",
deployment_date="2024-03-15",
data_processed=["CV/Resume", "Work history", "Education", "Name", "Location"],
eu_act_risk=EUAIActRisk.HIGH,
annex_iii_category="Section 4 β€” Employment and workers management (HR decisions)",
article_11_docs_complete=False, # MUST complete before Aug 2026
human_oversight_mechanism="HR manager reviews all ranked candidates before outreach",
registration_required=True, # Must register in EU AI database
notes="URGENT: Must implement Art. 14 oversight + Art. 11 documentation"
),
AISystemRecord(
name="Customer Service Chatbot",
description="AI chatbot answering product FAQs on website",
vendor="Azure OpenAI + Custom Agent",
deployment_date="2024-09-01",
data_processed=["Chat messages", "Session ID"],
eu_act_risk=EUAIActRisk.LIMITED,
annex_iii_category=None,
article_11_docs_complete=True,
human_oversight_mechanism="Escalation to human agent available at all times",
registration_required=False,
notes="Must disclose AI to users per Art. 52. DONE: disclosure message in chat header."
),
]

# Generate compliance status report
for sys in systems:
status = "⚠️ ACTION REQUIRED" if not sys.article_11_docs_complete else "βœ… Compliant"
print(f"{status} | {sys.eu_act_risk.value} | {sys.name}")
if sys.registration_required:
print(f" β†’ Must register in EU AI database before Aug 2, 2026")

Task 3: Build Article 11 Technical Documentation​

For each High-Risk system, Article 11 requires documentation of:

## Article 11 Technical Documentation β€” [System Name]

### 1. General Description
- System name, version, purpose
- Intended use case and geographic deployment
- Intended users (deployers, end users)

### 2. Development Information
- Training data description and governance
- Model architecture and validation approach
- Performance metrics on validation datasets

### 3. Risk Management System (Art. 9)
- Identified risks and their severity
- Mitigation measures implemented
- Residual risks and acceptance rationale

### 4. Human Oversight Measures (Art. 14)
- How human oversight is implemented
- What decisions require human review
- How humans can intervene or override

### 5. Data Governance (Art. 10)
- Data sources and lineage
- Data quality measures
- Bias testing results

### 6. Monitoring (Art. 17)
- How the system is monitored post-deployment
- Key performance indicators and thresholds
- Incident reporting procedure

Task 4: Set Up Purview Policies to Control Shadow AI​

# In Microsoft Purview, create an AI Interaction Protection policy
# This prevents sensitive data from being sent to external AI tools

# PowerShell: Create AI Interaction Protection policy
New-DlpCompliancePolicy -Name "Block-Sensitive-Data-To-AI" `
-Mode Enable `
-Comment "Prevent PII and confidential data from being sent to AI tools"

New-DlpComplianceRule -Name "Block-AI-PII-Transfer" `
-Policy "Block-Sensitive-Data-To-AI" `
-ContentContainsSensitiveInformation @{Name="EU Social Security Numbers"; minCount=1} `
-BlockAccess $true `
-GenerateAlert $true

Success Criteria​

  • Purview AI Hub shows discovered AI applications and interaction counts
  • All AI systems classified with EU AI Act risk levels
  • High-risk systems have Article 11 documentation template completed
  • Registration requirement identified for each high-risk system
  • Purview policy blocking sensitive data to external AI tools is active
  • 30-day response to regulator is drafted with complete system inventory

πŸ” Adapt This to Your Own Business​

The scenario is an EU regulator inquiry, but every organization needs an AI inventory β€” for the EU AI Act, ISO 42001, NIST AI RMF, internal audit, or simply knowing what's running. The discovery-classify-document loop is universal.

Step 1 β€” Find your "what AI is even running here?" moment​

Organization typeThe triggerWhat you'll discover
Multinational enterpriseEU AI Act / cross-border auditHigh-risk HR, credit, or biometric systems
Regulated financeModel risk management (SR 11-7)Undocumented scoring / pricing models
HealthcareFDA SaMD / HIPAA reviewClinical-decision tools without oversight docs
Public sectorTransparency / FOIA obligationsCitizen-facing AI needing disclosure
Any companyCopilot / GenAI rolloutShadow AI: staff pasting data into public tools

Step 2 β€” Map the building blocks to your stack (Microsoft-first)​

In this challengeIn your project β€” use
Purview AI Hub discoveryMicrosoft Purview AI Hub / DSPM for AI β€” tenant-wide AI activity
Risk classificationMicrosoft RAI Standard v2 + EU AI Act Annex III tiers
Article 11 documentationA Transparency Note / Dataverse record per system
Inventory registerMicrosoft Lists or Dataverse (owned, audited)
Blocking sensitive dataPurview DLP policy for generative-AI apps
Ongoing monitoringPurview Compliance Manager + Azure Monitor

Step 3 β€” The 5-question implementation checklist​

  1. Can you see AI usage you didn't approve? If not β†’ turn on Purview AI Hub / DSPM for AI first.
  2. Does every AI system have a named owner? If not β†’ assign one before classifying.
  3. Do you know which systems are "high-risk"? If not β†’ apply Annex III + RAI Standard v2.
  4. Is sensitive data leaving to public AI tools? If unknown β†’ a DLP policy answers this fast.
  5. Could you produce this inventory in 30 days under audit? If not β†’ this challenge is your fire drill.

Step 4 β€” A 1-week rollout plan​

DayActionOwner
Day 1Enable Purview AI Hub / DSPM for AI; run a 30-day activity reportCompliance admin
Day 2Build the inventory register in Microsoft Lists / DataverseGovernance lead
Day 3Classify each system by EU AI Act tier + RAI StandardRisk + eng
Day 4Draft Art. 11 / Transparency Notes for high-risk systemsProduct owner
Day 5Deploy a Purview DLP policy for external AI toolsSecurity

Step 5 β€” Prove the ROI​

  • Inventory completeness β€” % of AI systems in a governed register (target: 100%).
  • Shadow-AI reduction β€” unapproved AI tools blocked or sanctioned (track month over month).
  • Audit readiness β€” days to produce a full inventory (target: well under 30).

πŸ’‘ Rule of thumb: you cannot govern what you cannot see. Turn on discovery before you write a single policy β€” the surprises are the whole point.

Doing this solo (no team, portfolio-first)​

No team, no budget? An AI governance inventory needs zero code and proves you can operationalize the EU AI Act β€” a skill in huge demand. Run the week solo:

  • Mon–Tue β€” list every AI system you can find (start with your own tenant's Copilot/GenAI use) into a Microsoft List/Excel register, each with a named owner.
  • Wed–Thu β€” classify each by EU AI Act tier + RAI Standard; draft a Transparency Note for the highest-risk one.
  • Fri β€” time yourself producing the full inventory β€” that's your audit-readiness number.

πŸ“¦ Ship this artifact: a completed RAI inventory register + one Transparency Note. Resume bullet: "Stood up an EU AI Act-ready AI inventory β€” 100% of systems governed with named owners, risk tier, and transparency documentation."

πŸ†“ Free-tier path: Microsoft Lists / Excel + the public RAI Standard template β€” this one is genuinely $0.


πŸ“‹ Regulatory mapping β€” EU AI Act articles & deadlines
RequirementArticleDeadlineStatus Check
Register high-risk AI systemsArt. 51Aug 2, 2026Is each high-risk system registered?
Technical documentationArt. 11Before deploymentIs Art. 11 doc complete for each system?
Human oversightArt. 14Before deploymentIs oversight mechanism documented?
Risk management systemArt. 9Before deploymentIs risk register maintained?
Post-market monitoringArt. 72OngoingAre KPIs being tracked?
Transparency disclosureArt. 52ImmediateAre chatbots disclosing AI to users?

πŸ’‘ Hints
  1. Shadow AI is the real challenge: Purview AI Hub often discovers 3–5x more AI tools than IT knows about. Budget time for surprise discoveries (Grammarly, Notion AI, Midjourney on personal devices connecting to corporate network).
  2. High-risk β‰  bad: Being classified as High-Risk means the system is significant β€” not that it's inherently problematic. The law just requires more documentation and oversight.
  3. The registration deadline is August 2, 2026 for Annex III systems already deployed. New high-risk systems deployed after August 2, 2026 must register before deployment.
  4. Art. 52 is immediate: If you're running a chatbot today in the EU without disclosing it's AI, you're already non-compliant. Add "This conversation is with an AI assistant" to the chat interface immediately.

Knowledge Check​

  1. Under the EU AI Act, which risk category requires registration in the EU AI database?
  2. What is the difference between a "provider" and a "deployer" of AI systems under the EU AI Act?
  3. Why might a recommendation engine be classified as Minimal Risk while a credit scoring tool is High Risk?
  4. What does Microsoft Purview AI Hub discover that traditional IT asset management tools miss?

Cleanup​

No Azure resources created β€” Purview is a SaaS service. Delete any exported CSV files with sensitive data.