Noxtrack

Practice · 3 min read

Building an AI register: what belongs in it and how to keep it current

First, something you won't read in most articles on this subject: for most companies an AI register is not a literal legal requirement. The AI Act prescribes one as such only for high-risk systems, and those obligations have just been postponed to December 2027.

Even so, more and more companies keep one, and not out of fear of a fine. It is because without a register you have no answer to questions that are already being asked.

The questions this is about

Your accountant asks at the annual accounts which AI sits in your processes. A customer sends a supplier questionnaire with ten questions about AI and data processing. An employee asks whether she can paste customer data into a chatbot. A supervisory authority asks how you meet article 4, the requirement that your people know what they are using.

The answer to all of those questions is the same list. If you don't have that list, you spend half a day asking around every single time.

What belongs in it

Per tool or model:

  • Name and supplier. Which tool, from whom, and which underlying model where that is known.
  • Where it runs. In which region the processing takes place. This is the question that comes up most often and can be answered least often.
  • Purpose. What it is used for, in one concrete sentence. Not "productivity" but "drafts for customer emails".
  • What data goes into it. And specifically: does that include personal data, or customer data.
  • Data processing agreement. Yes or no, and where it is filed.
  • Owner. One name. Not a department.
  • Risk assessment. Does this fall under prohibited practices, under high risk, or under neither. For most tools the answer is the last one, and you are allowed to write that down.
  • Transparency applies. Does this talk to customers, or does it produce published content. If so, has that been disclosed.
  • Last reviewed. Date. This field matters more than it looks.

The template

At the bottom of this page there is a fillable template with these columns, as a spreadsheet. Fill it in with what you know today and leave the gaps open. A register with blanks is usable; a register that doesn't exist is not.

Where it goes wrong after three months

Making the first version takes an afternoon. The problem is in what happens next.

Someone starts using a new tool on a trial account and doesn't report it. An existing supplier builds an AI feature into a product you have used for years, and nothing changes on the invoice. A developer switches models in the code, from one to another, and that is one line. An employee leaves and their personal API key stays active in a project.

None of those four events makes it into your register, because it is nobody's job. Six months later your list is wrong, and you find out at exactly the moment someone asks about it.

What does work

Three things, in increasing order of effort:

  1. One moment per quarter. Put it in the calendar, walk the list, ask two people whether anything has been added. Takes half an hour and is infinitely better than nothing.
  2. One entry point for new tools. Whoever wants to use something new reports it in one place. Only works if reporting takes less effort than working around it.
  3. Measuring instead of asking. Your company's AI traffic passes a point that records which models and tools go by. Then the list fills itself with what is actually happening.

The third is what we are building. You change one setting in your projects, after which the traffic runs through us and your register updates itself with what is really being used. Book an intro call if you want to try that.

Download

AI register template, as a spreadsheet. Leave your email address and you get it straight away.

AI register template

The fields you need to record your AI systems, as a spreadsheet with one filled-in example row. You get it straight away.

You get the template straight away. After that we send the occasional message about Noxtrack; you can unsubscribe from any email. See the privacy statement.

Read on