The National AI Centre recommends that organisations create and maintain an AI register covering systems they build, procure and encounter as features inside other products. The challenge is turning that inventory into a management tool rather than a static list.

Register the use, not only the product

A supplier and product record answers what the technology is. A use-case record answers what the organisation is doing with it. Both matter.

The same product might draft internal communications, summarise sensitive client notes and shortlist job candidates. Those uses have different purposes, data, affected people, owners, expected value and consequences. Each materially different purpose should have its own record, linked back to the relevant supplier and product.

A practical naming pattern

Use a plain-language action and context, such as “Summarise client case notes for the service team”, rather than a broad label such as “Copilot” or “AI project”.

Discovery needs more than one source

No single team sees every AI use. A useful discovery process combines:

  • structured business-unit responses;
  • simple staff disclosure for current and proposed uses;
  • software, procurement and supplier records;
  • project, innovation and transformation portfolios;
  • security and privacy reviews;
  • expense and corporate-card data where appropriate;
  • known AI features added to products already in use.

Track response coverage so leaders know which business units have participated and where follow-up remains. Discovery should improve visibility without claiming perfect completeness.

Capture the information management will use

A minimum useful record usually includes:

  • plain-language purpose and expected outcome;
  • business unit, lifecycle status and planned scale;
  • accountable business owner and relevant technical owner;
  • supplier, product, model or embedded AI feature;
  • people affected and decisions influenced;
  • personal, sensitive or confidential information involved;
  • level of autonomy and human oversight;
  • strategic objective or roadmap initiative supported;
  • assessment, testing and approval status;
  • material findings, controls, evidence and open actions;
  • review date, incidents and material changes;
  • cost, value and benefit measures where reliable data exists.

Treat unknown information as work

Teams will not know every data flow, model detail or supplier control when the register is first created. Keep “Unknown” as a visible answer. It should lead to a named evidence task and due date. For a higher-impact use, the missing information may need resolution before approval.

This avoids a common failure in spreadsheets, where a blank cell quietly appears harmless even when nobody has investigated it.

Use duplicate detection carefully

Normalised supplier, product, purpose and business-unit information can flag possible duplicates. The system should not silently merge them. A reviewer may discover that two disclosures describe the same use, or that the same product supports different uses that must remain separate.

Connect the register to the lifecycle

The register becomes credible when it changes with the organisation. New supplier terms, changed data, wider deployment, new affected groups, incidents, poor performance and expired conditions should return the use to review. Each active record needs a review date and accountable owner.

The AICD and HTI also recommend that boards understand where AI is already used, including features in third-party products. A maintained register is the practical source for that visibility and for reporting on alignment with strategy and risk appetite.

Quality checks for the register

  • Each record describes one distinct organisational use.
  • An accountable business owner is named.
  • The product and use-case assessments remain separate.
  • Risk and approval status can be traced to supporting evidence.
  • Proposed, pilot, production, paused and retired uses are distinguishable.
  • Unknown information and overdue work remain visible.
  • Material changes return the use to review.
  • Management reporting is generated from the current record.

Sources and further reading

This article provides general governance guidance. The fields and review process should be adapted to the organisation's sector, operating model and risk profile.