What Actually Goes in an AI Register, and Who Is Going to Read It?
Last updated 16 September 2026 · 7 min read
Direct Answer
An AI register is a plain inventory — usually one row per tool — recording, at minimum: the tool's name and vendor, what it's used for, who owns or approved it, what kind of data it can access, when it was approved, and when it was last reviewed. It's read by whoever a business needs to reassure that it knows what AI it's actually running: a customer's security questionnaire, an insurer, an auditor, or simply the owner trying to answer 'what are we actually using' without guessing. The single biggest obstacle to building one honestly is that most businesses don't yet know everything in use — building the register and finding out what's actually running are often the same first step, not two separate tasks.
Detailed Explanation
"AI register" gets used two ways online, and most of what's published assumes the wrong one for a small business. A lot of content describes it abstractly — "a documented inventory of AI systems" — without showing what a real one contains, and a lot more is written by vendors selling AI-discovery software, whose answer to "how do I build one" is unsurprisingly "buy our tool." Neither is much use to a 20 or 30-person Australian business that already knows, roughly, which handful of AI tools it uses and just needs a simple, honest record of them.
The register itself doesn't need to be complicated. What it needs is to be accurate, current, and to actually answer the questions someone will eventually ask it.
This general tool register is distinct from the narrower concept of an AI agent register — a record specifically of AI that can take actions on your systems rather than just produce answers a person acts on. See do you need a register of the AI agents running in your business if any of your AI tools write to systems, move files, or call other software on their own.
What a Real Register Looks Like
For a small or mid-sized business, a register is realistically a spreadsheet or simple table with one row per AI tool in use, and a small number of columns:
- Tool name and vendor (e.g. "Claude — Anthropic," "Copilot — Microsoft," "an AI summarisation feature inside [CRM name]").
- What it's used for, in one plain sentence — not a technical description, a business one.
- Who owns or approved it — the person or role responsible for that tool being on the approved list at all.
- What kind of data it can access — using the same simple categories a data-classification policy would use (general business information, customer personal data, financial records, and so on), not a technical data-flow diagram.
- When it was approved, and when it was last reviewed — the two dates that make the register something you can actually trust is current, rather than a list someone built once.
That's genuinely most of what's needed for a business without a dedicated compliance function. A larger or more heavily regulated business might add columns for the specific data-processing agreement on file, the tool's certifications, or a risk rating — but those are extensions of the same basic structure, not a different kind of document.
Who Actually Reads It
The register earns its keep at a small number of specific moments, not as a background compliance exercise:
- Answering a customer's security questionnaire. See how do you answer a customer's security questionnaire about AI for turning a register entry directly into a questionnaire answer — this is the single most common real-world trigger for someone actually opening the register.
- An insurer or auditor asking what AI the business runs. A clear, current register is a much stronger answer than reconstructing the list from memory under time pressure.
- The owner or a manager genuinely not knowing the answer. It's common for nobody inside a small business to be able to say, offhand and with confidence, every AI tool currently in use — the register exists partly to fix that for the business's own benefit, independent of any external question ever being asked.
- Onboarding a new hire or handing over a role. A register is one of the few documents that makes "here's what AI we use and why" something a new person can read rather than something they have to be told verbally and hope they remember.
The Real First Obstacle: You Don't Know What's Already in Use
Most businesses starting a register discover the harder problem isn't the format, it's the content — they genuinely don't know everything currently running. An AI feature embedded inside software the business already pays for (a summarisation button in a helpdesk tool, a drafting assistant inside a CRM) is easy to miss entirely, and a free-tier tool an individual employee adopted on their own initiative may never have been mentioned to anyone who'd think to register it. See how do you stop employees from using unauthorized AI tools for the practical discovery techniques — a short internal survey, reviewing expense-report line items, and checking admin consoles for connected apps — that usually need to happen before or alongside building the first version of the register, not as a separate later project.
Things to Consider
- A register with three tools honestly and completely listed beats one that claims comprehensiveness it can't back up. Publish what you actually know is in use, note explicitly that a discovery pass is ongoing if it is, and update the register as more is found — an incomplete-but-honest register is more defensible than a confident-looking one built on assumptions.
- This is a living document, not a one-time deliverable. A register built once and never revisited degrades the same way any inventory does — new tools get adopted, old ones get retired, and nobody updates the sheet unless someone owns that as an actual, recurring task.
- The register works better paired with an employee AI usage policy than alone. See what should an employee AI usage policy include — the policy sets the rules for what's allowed; the register records what's actually been approved and is currently running, which is a different, complementary function.
- Retention policy belongs alongside the register, not duplicated inside it. See how long should you keep records of AI tool conversations and outputs for the separate question of how long the AI-generated content itself is kept — the register tracks which tools exist; that page covers what happens to what they produce.
- Keep the language plain. A register written in compliance jargon is harder for the person actually maintaining it to keep updated, and harder for a customer or auditor reading it to trust as a genuine working document rather than a document produced to look compliant.
Common Mistakes
- Building the register from what should be approved, not what's actually in use. A register describing an idealised, fully-controlled AI environment that doesn't match reality is worse than no register, because it actively misrepresents the business's actual position if anyone relies on it.
- Treating the register as a one-off project with an end date. Without an owner and a review cadence, it's accurate on the day it's built and increasingly wrong after that.
- Missing embedded AI features because they don't look like a separate "AI tool." An AI summarisation or drafting feature bundled inside existing software is exactly the kind of entry that gets left off a first-pass register.
- Making the register too complex for a business its size. An elaborate risk-scoring framework with columns nobody fills in accurately is worse than a simple, complete table that's actually kept current.
- Not telling anyone the register exists. A well-built register nobody remembers to consult when a security questionnaire or an audit request arrives has produced none of its actual value.
Frequently Asked Questions
- Is an AI register the same thing as an AI agent register?
- No, and the distinction matters. An AI register (this page) covers every AI tool a business uses — Copilot, Claude, a transcription tool, an AI feature inside a CRM — regardless of how autonomously it acts. An AI agent register is a narrower, newer concept specifically covering AI agents that can take actions on a business's behalf (booking a job, sending an email, updating a record) — recent Australian Signals Directorate guidance recommends recording each agent's identity, owner, purpose, and what systems and data it can access, distinct from a general tool inventory. A business using both tool types and autonomous agents may eventually want both records, but most small businesses should start with the general tool register first, since it's the more immediately actionable of the two.
- Does building an AI register mean the business needs ISO 42001 certification?
- No — a register is a practical inventory a business can build and maintain on its own, with no certification requirement attached. ISO/IEC 42001 (an AI management system standard, with an identical Australian adoption as AS ISO/IEC 42001:2023) is a much larger, optional certification framework that a business might eventually pursue if a customer or contract specifically requires it; a register is one of many practical building blocks that would feed into a system like that, not a certification in itself.
- How often should the register be reviewed?
- A fixed cadence works better than an ad hoc one — quarterly is reasonable for most small businesses, with an additional check whenever a new AI tool is adopted or an existing one changes plan or vendor terms. The register loses its value the moment it goes stale, since a security questionnaire or audit answered from an out-of-date register is arguably worse than admitting no register exists at all.
Related Questions
How Do You Stop Employees From Using Unauthorized AI Tools?
Shadow AI — employees using AI tools nobody approved — is stopped by discovering current use, approving a fast alternative, and restricting the rest.
What Should an Employee AI Usage Policy Include?
An employee AI usage policy should cover approved tools, data classification, verification requirements, and incident reporting — what each section needs.
A Customer Sent You a Security Questionnaire With an AI Section — How Do You Answer It?
Most AI security questionnaires are written for tool builders. Here's how a business that uses AI tools rather than builds them can answer honestly.
How Long Should You Keep Records of AI Tool Conversations and Outputs?
Keeping AI records too briefly weakens dispute defense; too long adds Privacy Act and breach exposure. Here's how to set a practical retention period.
What Evidence Do You Actually Need to Show You're Governing AI?
A policy says what should happen with AI. Evidence proves it did. Here's the difference, and what a small business should actually be able to produce.
What Should You Log for Every AI-Assisted Task So You Can Explain It Later?
The fields worth recording every time AI touches a piece of work, so you can reconstruct exactly what happened on a specific run, months later.