Short answer: An AI use register is a single record of every AI tool in your business — what it is, who uses it, for what purpose, on what data, under what contract, and at what risk classification. It's the document that answers almost every compliance question you'll be asked, and it takes about a day to build for a small business.
Every other AI obligation depends on knowing what you're using. You can't classify risk without an inventory. You can't check transparency obligations without knowing which tools face customers. You can't complete a data protection record without knowing which process personal data. And you can't answer a client's due diligence questionnaire without it.
Most businesses discover something surprising while building one — usually a tool nobody approved, processing data nobody considered.
Twelve fields. A spreadsheet or an Airtable table handles it comfortably.
The register is only as good as its completeness, and shadow AI is the norm rather than the exception. Four methods, in order of effectiveness:
Work through in order:
Detailed enough to answer a due diligence questionnaire without further research. That's the practical bar.
With your other compliance records, accessible to whoever handles data protection. Not in one person's local files.
If you use AI at all, yes. It's the cheapest compliance artefact available and the one everything else is built from.
We inventory every AI tool genuinely in use — including the ones nobody approved. See what we check.