Re-triage, linkage, and the end of life
Lesson 5 of 5 in AI Inventory, Use-Case Intake, and Risk Triage.
A triage decision describes a system as submitted. Systems do not stay as submitted. The tier assigned to a chatbot that answers FAQs is void the day someone connects it to the refunds API — and unless something forces a re-look, the registry will keep asserting the old truth while the new system runs.
That something is the re-triage trigger list, written into policy and wired into pipelines where possible: a major version or model swap (the vendor moves your copilot to a new underlying model); new data (a feature added, a data source joined); a new population (the UK model now scoring EU applicants — jurisdiction flags change); repurposing (the collections model now used for marketing eligibility — purpose is the axis GDPR cares about most); expanded autonomy (draft-only becomes auto-send); and any serious incident. Each trigger reopens triage, not necessarily full review — proportionality applies to change too. The EU AI Act sharpens the stakes: under Article 25, substantially modifying a high-risk system (or rebranding one, or repurposing a system into high risk) can convert a deployer into a provider, inheriting the full provider duty set. The value-chain module covers that mechanics; your registry’s job is to notice the change early enough for the legal question to be asked before the duties are already owed.
Key terms: substantial modification, decommissioning, orphaned model, provider, deployer
The registry also has to connect, because a record that links to nothing answers nothing. Each entry should point at its assessments (the impact-assessments module picks up there), its documentation artifacts, its monitoring dashboard, its incident history, and its vendor contract. The payoff is speed in both directions: when an incident fires, responders pull owner, tier, dependencies, and vendor SLA in one query; when a regulator or auditor asks "show me your high-risk systems and their evidence", the answer is a filtered view, not a three-week scramble. This linkage is also what makes the registry the natural spine for regulator-facing transparency — the same structure US federal agencies publish as their public use-case inventories.
Retiring an entry — more than flipping a status field
A retirement checklist per system: dependent systems notified and migrated, endpoints actually switched off (a "retired" model still serving traffic is the worst of both worlds — live risk, zero monitoring), user communications, and a defined data disposition: what happens to the training data, the outputs, the logs.
Archive before you delete
Retention obligations outlive the system. EU AI Act documentation duties run for 10 years after a high-risk system is placed on the market; litigation holds and sectoral record rules (credit, health, employment) add their own clocks. Archive the model version, documentation, validation results, and decision logs as of retirement — when a claim arrives four years later about a decision the dead system made, its archived record is the defence.
Orphaned models — ownership churn is the killer
The most common registry pathology is not missing systems but missing owners: the data scientist left, the reorg dissolved the team, and a production model now belongs to nobody. Controls: ownership transfer as a mandatory offboarding step, attestation cycles that bounce on unanswered records, and a standing rule that an unowned high-tier system is an incident, not a housekeeping item.
Registry hygiene as a metric
Track staleness like you track coverage: % of records attested in-cycle, % with a reachable owner, median age of tier rationale, count of "retired" entries with live endpoints. These are the KRIs that tell the board whether the inventory is an asset or an artifact.
Tool: EU AI Act Risk Classifier — Take the triage desk for a shift: classify a queue of real-shaped use cases into tiers and regimes, with instant feedback on every call.
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.