Short answer: An AI use register is a single record of every AI tool in your business — what it is, who uses it, for what purpose, on what data, under what contract, and at what risk classification. It's the document that answers almost every compliance question you'll be asked, and it takes about a day to build for a small business.
Why it's the first thing to build
Every other AI obligation depends on knowing what you're using. You can't classify risk without an inventory. You can't check transparency obligations without knowing which tools face customers. You can't complete a data protection record without knowing which process personal data. And you can't answer a client's due diligence questionnaire without it.
Most businesses discover something surprising while building one — usually a tool nobody approved, processing data nobody considered.
What to record for each tool
- Tool name and vendor.
- Purpose — the specific business use, not "productivity". "Drafting client proposal first drafts" is useful; "AI assistance" isn't.
- Owner — the named person responsible.
- Users — individuals or roles.
- Data processed — personal data yes or no; if yes, which categories; special category data flagged separately.
- Provider or deployer — your role under the AI Act for this system.
- Risk classification — prohibited, high-risk, limited-risk (transparency), or minimal.
- Customer-facing — yes or no, which drives Article 50 analysis.
- Contract tier and DPA status — consumer or business; DPA signed or not.
- Processing location — and transfer mechanism if outside the UK.
- Human review — what checking applies to the output.
- Date added and last reviewed.
Twelve fields. A spreadsheet or an Airtable table handles it comfortably.
How to find the tools you don't know about
The register is only as good as its completeness, and shadow AI is the norm rather than the exception. Four methods, in order of effectiveness:
- Ask, without consequences attached. Say plainly that you're building a register, that nobody is in trouble, and that you need the honest list. This surfaces most of it.
- Check expenses and card statements for subscriptions.
- Review browser extensions and connected apps in your Google Workspace or Microsoft tenancy. Third-party apps with access to company data are visible in admin settings and frequently forgotten.
- Check the AI features inside tools you already own. Your CRM, your email client and your design software have all shipped AI features. Some are on by default, and they belong in the register.
Classifying each entry
Work through in order:
- Is it a prohibited practice? Rare, but check — workplace emotion inference catches some monitoring and HR tools.
- Is it high-risk? Only if used in a listed domain: recruitment and worker management decisions, credit, education access, essential services, and similar. Most SME tools aren't.
- Does it trigger transparency obligations? Customer-facing conversational systems, synthetic content generation, emotion recognition.
- Otherwise, minimal risk. Which will be most entries, and that's a legitimate finding to record.
Keeping it current
- Make adding a new AI tool a defined process that includes register entry.
- Review quarterly for the first year, then twice yearly.
- Re-check when a vendor changes terms — AI vendors change data handling terms frequently.
- Include it in your onboarding and offboarding checklists.
Frequently asked questions
How detailed does it need to be?
Detailed enough to answer a due diligence questionnaire without further research. That's the practical bar.
Where should it live?
With your other compliance records, accessible to whoever handles data protection. Not in one person's local files.
Does a small business really need one?
If you use AI at all, yes. It's the cheapest compliance artefact available and the one everything else is built from.
We inventory every AI tool genuinely in use — including the ones nobody approved. See what we check.
