Skip to content
Sections
All notes

All notes · Governance

The AI Register

A record of where AI is used and what decides what. Increasingly expected by regulators, and useful independently of that.

Governance · Procedure

General orientation, not legal advice; registration requirements are emerging and differ by jurisdiction and sector.

The controls in “The AI Register” only remain useful when someone owns the reviews, exceptions and follow-up work. An organisation evaluating remote work time tracking can attach time and responsibility to those recurring governance tasks, but the platform should support the policy rather than decide whether an AI use case is acceptable.

For an independent benchmark, compare the local approach with NIST AI RMF Playbook; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

An AI register records where the organisation uses these systems, for what, and with what oversight. It is a broader artefact than the shadow inventory and it answers different questions.

How it differs from the inventory

The inventory records tools in use, including shadow ones.

The register records uses: a system, a purpose, a decision it influences, an owner, an assessment.

One tool can appear as several register entries, because summarising internal documents and screening applications are different uses with different risk.

What each entry holds

The use, described in terms of what it does rather than what it is.

What decision it affects, and whether a person reviews.

Data categories involved.

Who owns it.

What assessment was done, and when.

And whether anybody outside the organisation is affected, which is the question regulators ask first.

Why uses rather than tools

Risk attaches to what the system decides, not to the technology.

A model drafting internal emails and the same model ranking job applicants are entirely different propositions.

A tool-based register obscures that, which is why it will not satisfy anybody asking a regulatory question.

The entries people forget

AI features inside approved software, used for substantive work.

Automations with a model step.

Anything a supplier does with AI on your behalf, which is a subprocessor question.

And decisions where a model's output is the main input even though a person signs it off.

Keeping it proportionate

For a small organisation this is a spreadsheet with a dozen rows.

Do not build a governance apparatus around it before there is anything to govern.

The value is in having thought about each entry, not in the format.

The high-risk entries

Anything affecting people outside the organisation: customers, applicants, patients.

These deserve a real assessment regardless of what any regulation requires, because they are where the visible failures occur.

Everything else can be a row with a sentence.

Keeping it current

New entry when a use starts, not when somebody remembers.

Review on the same cycle as the policy.

And fed by the exception route and the inventory, which is why those should be the same conversation rather than three separate processes.

What to check

Do you have a register, and does it record uses or tools?

Which entries affect people outside the organisation?

Who owns each one?

And when was it last updated?

The point

A register records uses, not tools.

Risk attaches to what the system decides, not to the technology behind it.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.