Everyone explains what an AI register is. Nobody shows you one. That's a problem, because the concept sounds like an enterprise platform with a six-figure price tag and a steering committee — when in reality it's a table with nine columns that somebody sensible maintains. The deeper definition of the inventory lives in our earlier guide; here we do something more useful. We show one, populated, for a realistic firm.

This matters because a register is the artefact the rest of the AI Act machine bolts onto. Risk classification, AI literacy records, logging, incident handling — every one of those obligations assumes you know which systems you have, and the register is where you prove it. It's also the first thing that gets requested when a client's procurement team or a regulator comes asking. For the wider picture, start with our full guide to the EU AI Act for UK and Irish businesses.

The worked example at a glance

The firm: "Northbridge Analytics" — 102 staff, UK HQ, small Dublin office, B2B data analytics.

The brief: build the AI register from a standing start. The MD's guess for company AI use: "four or five tools."

The result: 11 systems documented, 2 of them undeclared until survey week, 3 compliance gaps exposed on day one.

Elapsed: 9 working days.

Meet the company (a composite, deliberately)

Northbridge Analytics sells data dashboards and reporting services to mid-market clients in logistics, retail and financial services. 102 staff: engineering is the biggest team, then sales & marketing, finance, HR and support. UK headquarters, a Dublin office of nine — which matters, because Irish-establishment means the EU AI Act applies directly, and UK-side it applies through EU-market output anyway.

The starting condition will sound familiar. Nobody had a list of AI tools. Procurement had approved two. Engineering had opinions about three more. And when the MD was asked how many AI systems the company ran, he said "four or five" with the confidence of a man who had not yet seen the survey results.

The answer was eleven. Including two nobody had declared, one with no owner, and one that changed the company's entire compliance position on the afternoon it was found.

The register fields — and why each one earns its column

Nine fields. Not seventeen, not four. Each one exists because it answers a question a regulator, a client procurement team, or your own leadership will actually ask:

  1. System — name and vendor. You cannot govern what you cannot name.
  2. What it does — one line, plain English. If it takes a paragraph, you don't understand the tool yet.
  3. Provider or deployer — your role under the Act. Provider means you built or substantially modified the system; deployer means you operate someone else's. The duties differ enormously.
  4. Who owns it — a named person, not a team. Every line ends in a name or it isn't governance.
  5. Where it lives — SaaS, on-prem, or embedded in another platform. Determines who controls logging, retention and patching.
  6. Data it touches — client data, staff data, public data. This is where exposure actually lives.
  7. Risk class under the Act — prohibited, high-risk, limited (transparency), or minimal. Decides which obligations attach.
  8. Documentation held — DPA, terms, technical docs, or nothing. "Nothing" is a finding, not a blank.
  9. Status — approved, conditional, under review, retired, or shadow. Registers describe reality, not intentions.

No field survives without a reason, and no field is there for decoration. A regulator's information request, a client's due-diligence questionnaire and a new COO's first-week questions are all answered from these nine columns.

The register, populated

This is the centrepiece — the table as it stood at the end of the exercise. Scroll sideways on mobile; a register is wider than a phone and pretending otherwise helps nobody. Risk classes are shown as badges; rows with gaps carry a ⚠ marker.

System What it does Role Owner Where it lives Data it touches Risk class Docs held Status
Microsoft 365 Copilot Drafts documents, summarises email threads, meeting recaps Deployer IT lead SaaS, embedded in M365 tenancy Company + client email and files Minimal ⚠a Vendor DPA, enterprise terms Approved
ChatGPT Team Research, first drafts, internal Q&A Deployer Marketing lead SaaS Non-client content (policy enforced) Minimal ⚠a DPA, admin usage policy Approved
Claude API — "Insight Summary" feature AI-generated summaries and scoring factors inside the client-facing product Provider Head of Engineering SaaS API, integrated into product Client operational data, incl. financial indicators High-risk ⚠b ⚠c API terms only — no provider-grade documentation Under review
GitHub Copilot Code completion and review assistance Deployer Engineering manager SaaS Own codebase Minimal ⚠a Enterprise terms, usage policy Approved
CRM lead-scoring add-on Scores inbound leads for sales prioritisation Deployer Sales ops SaaS, embedded in CRM Contact and firmographic data Minimal ⚠a Vendor marketing page only Approved
Support bot (AI agent in helpdesk) Answers customer tickets from the knowledge base Deployer Support lead SaaS, embedded in helpdesk Support conversations, KB articles Limited ⚠b Vendor docs, DPA Approved — disclosure line added
Payroll platform embedded AI Flags timesheet and leave anomalies Deployer Finance — no named owner SaaS, embedded in payroll suite Employee payroll data Minimal ⚠c None — nobody knew it was there Undocumented
AI meeting notetaker Transcribes and summarises sales calls Deployer Sales ops SaaS Call recordings, incl. client participants Limited Tool policy, retention setting Conditional
Marketing copy tool Ad and email copy generation Deployer Marketing lead SaaS Brand assets only Minimal — Retired day one
Self-hosted LLM (open-source) Data transformation and scripting assistance on an internal box Provider + deployer Nobody — ops side-project On-prem Internal ops data Minimal ⚠c None Unowned — being assigned
Personal ChatGPT accounts ⚠ Undeclared individual use — including pasted client data Deployer (individual) None Free/personal SaaS Client data leaving the business Minimal ⚠c None Shadow — policy issued

⚠a No AI literacy records for any user of this system  ·  ⚠b Classified higher than assumed  ·  ⚠c No documentation held. Northbridge Analytics is a composite; details changed.

Three rows deserve the uncomfortable spotlight. Together they're the three gaps the register exposed on day one:

Gap 1 — No AI literacy records for anyone

AI literacy obligations have applied since February 2025, and Northbridge had no record of who had been trained, when, or to what depth — on any system. Six of the eleven rows carry the ⚠a flag. The fix is a training plan and records; the register turned an abstract obligation into a per-row to-do list.

Gap 2 — Two systems classed higher than assumed

The Insight Summary feature uses AI to generate scoring factors that feed client creditworthiness-adjacent assessments — that's Annex III territory, high-risk, and because Northbridge built the feature on a third-party API, they're the provider, not just a customer. The support bot talks to customers, which triggers transparency duties (disclose it's AI). Both had been filed mentally as "just tools we pay for."

Gap 3 — No documentation for the embedded AI

The payroll platform's anomaly flagging and the self-hosted LLM had no documentation trail whatsoever — nobody had read the payroll vendor's AI terms because nobody knew the feature existed. The shadow AI problem isn't only personal accounts; it's AI that arrives silently inside software you already pay for.

Notice what the register did to the personal-accounts row. "Minimal-risk" sits in the risk class column while the data column says client data is leaving the business — a reminder that risk class under the Act and actual exposure are related but not identical. The register's job is to make that visible, not to resolve it with a colour code.

What the register changed on day one

A register that changes nothing is paperwork. This one forced five decisions before the end of the first review meeting:

  • The marketing copy tool was retired. Redundant with ChatGPT Team, one more vendor, one more DPA, nothing gained. Cutting it took four minutes.
  • The Insight Summary feature went under review. Provider role, high-risk class, client financial data — that combination gets engineering, the MD and legal counsel in one room, with the technical documentation question on the agenda.
  • The payroll AI got documented or replaced. The vendor's AI terms were requested that afternoon; if they can't evidence the processing, finance migrates the function.
  • Literacy training was triggered. Every user of a flagged system goes on the Article 4 literacy plan — owned, dated, recorded, so ⚠a stops being a gap and starts being a schedule.
  • Two owners, one rhythm. Logging and retention expectations were set with the IT lead and the engineering manager, and the register itself went on a quarterly 30-minute review: new tools, retired tools, tier changes, new gaps.

That's the point most articles miss: the register isn't a compliance artefact you build and file. It's a management instrument. Nine columns, five decisions, one afternoon — and the company went from "we think four or five tools" to a defensible, owned, reviewable position.

Eleven systems. Three gaps. Nine working days. That's what the AI Readiness Diagnostic does for your business — register, classification and remediation plan in two weeks, fixed £3,500 / €4,000. See what's included, or skip straight to the conversation.

Book a 20-minute call

Could you build this yourself?

Honestly: yes. Two to three focused weeks — one to inventory systems via procurement records, SSO logs and an anonymous staff survey (the survey is where rows ten and eleven came from), one to two more to classify, document and gap-check. You'll need exec sponsorship, because the survey only works if people believe amnesty is real. And you'll need someone who understands the Act's classification tiers well enough to assign them honestly — the temptation to file everything as "minimal" is strong, and it's exactly the error an assessor looks for.

If you have that person and that sponsorship, build it in-house; the eight-field version is an afternoon. If you don't — or if you'd rather the first version be built by people who've done it before — we do it in two weeks, fixed fee. Want to see the process end to end first? The Diagnostic walkthrough covers both weeks in detail.

And if you're still at "does this even apply to us?" — take the AI Act quiz (2 min). If the result surprises you, this page is where you come back to.

Northbridge Analytics is a composite of real engagements; details changed. Practical guidance, not legal advice — we work alongside your legal counsel.