Technology · AI and automation · Component

AI use-case register

Every place AI or automation is used, with its task, owner, provider, level of autonomy and risk classification.

The deliverable

What it is

The register is the starting point in both the NIST AI Risk Management Framework and ISO/IEC 42001, for the plain reason that uses nobody has listed cannot be overseen. It includes informal uses — staff drafting with a public assistant, a team scripting its own workflow — since those are often the majority.

Each entry refers to the system landscape for the underlying system and to Data Core for the data it draws on. The register adds what is specific to AI: what task is delegated, how much autonomy is given, which model it depends on, and how the use is classified.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Use-case description

    The task being done or supported, the decision it feeds, and what a good outcome looks like.

    4 attributes: Task · Good outcome · Owner · Underlying system

    Learn
  2. Autonomy level

    Whether the system suggests, drafts for approval, acts with review afterwards, or acts alone.

    3 attributes: Autonomy · Why this level · Agreed by

    Learn
  3. Risk classification

    The internal risk grade and, where relevant, the EU AI Act category the use appears to fall under.

    4 attributes: Internal risk grade · AI Act category · Compliance entry · Assessed

    Learn
  4. Provider and model

    Which provider and model version the use depends on, since behaviour can change when either does.

    3 attributes: Provider · Model version · Last changed

    Learn

Ask teams what they use, not what they have approved. The informal uses are where the register earns its keep.