Governance framework & guidance

What is an AI Register?

An AI Register is a structured record of how artificial intelligence is being used across an organisation. It helps answer where AI is being used, what it is being used for, which products and suppliers are involved, who is accountable, what has been assessed and approved, and what still requires attention.

Without this visibility, an organisation can have policies and governance processes while still not knowing whether those processes apply to every real AI use. The Register provides the foundation from which individual AI uses can be assessed, controlled, approved, monitored and reviewed.

Why an AI Register matters

AI can enter an organisation through major technology projects, existing software products adding AI features, employees adopting online tools, suppliers using AI to deliver services, or teams experimenting with new capabilities. Good AI governance therefore starts with visibility.

Australian responsible-AI guidance emphasises accountability, understanding impacts, managing AI-specific risks, transparency, monitoring and meaningful human control. Maintaining a current inventory is a practical way to turn those principles into an ongoing organisational process. An AI Register is not itself a risk assessment and appearing in the Register does not mean an AI use is unsafe.

AI Product and AI Use are different

An AI Product is the technology, product or service being used. An AI Use describes what your organisation is actually doing with it. One product can support several organisational uses and those uses may have very different purposes, information, consequences and governance risks.

Swell therefore connects multiple AI Uses to the same Product while assessing each use in context. Governance depends not only on what the technology is, but on how your organisation uses it.

What belongs in the AI Register?

The Register should capture identifiable organisational uses of AI, including generative assistants, automated decision support, predictive tools, AI-enabled customer services and AI capabilities embedded inside software the organisation already uses.

You do not need to create a record for every prompt. The useful unit is the organisational use. A materially different purpose may warrant a separate AI Use even when the underlying product is the same.

Using Swell AI

Where the AI Register fits in Swell

Swell uses the governance lifecycle Register → Assess → Control → Approve → Monitor → Review. Registration establishes an identifiable organisational AI Use and the information needed to determine what should happen next.

The same record remains connected to assessment, risks, controls, approvals, monitoring and reviews. The Register is therefore intended to be the organisation’s current view of AI use rather than a spreadsheet updated once a year.

Disclosure first, assessment second

You do not need to be an AI specialist to disclose an AI use in Swell. Contributors are asked about the business activity and information they can reasonably know. Technical, privacy, security, legal or supplier questions can be confirmed later by an appropriate reviewer.

The objective is to make disclosure easy enough that people actually tell the organisation about AI use. An incomplete but accurate disclosure is more useful than a confident guess.

Disclosing an AI use in Swell

  • Start a new AI Use disclosure from the AI Register.
  • Describe the business use in ordinary language rather than simply naming the tool.
  • Identify the business area and accountable owner where known.
  • Link the AI Product where known. Do not guess if you are unsure.
  • Answer the factual questions about the activity and information involved.
  • Use “I don’t know” or “Needs confirmation” when specialist information is unavailable.
  • Review the disclosure and submit it so the appropriate governance process can continue.

What happens next?

Registration does not automatically mean an AI Use is approved. Depending on the circumstances, Swell may require additional assessment, specialist confirmation, risk identification, controls, actions, approval, monitoring or review.

The original disclosure remains connected to that governance history so the organisation can understand what was known, what was decided and what changed.

Common questions

Is an AI Register required by Australian law?
There is no single general law requiring every organisation to maintain a register, but an inventory is a practical governance mechanism that supports Australian responsible-AI guidance.
Is an AI Register the same as an AI Risk Register?
No. The AI Register records AI Uses; the Risk Register records identified AI-related risks requiring management.
Does registering an AI Use mean it is approved?
No. Registration, assessment and approval are separate governance activities.
What if I do not know the technical details?
Answer what you reasonably know and identify what needs confirmation.