Build and maintain your AI inventory.
Establish what AI your organisation actually uses, and keep that record current as systems are adopted, retired or change beneath you.
Why an AI inventory matters now
A board paper, a due diligence request, an insurance renewal questionnaire, an internal audit recommendation, or a cybersecurity review can all land in the same week. Each of them asks a version of the same question, which is "what AI is your organisation actually using." If the answer lives in people's heads, that is not an inventory.
An AI inventory you can stand behind is more than a list of system names. It captures the vendor, the data flows, the oversight model, the risk classification, the business owner, and the supporting documentation. It is a continuous record rather than a periodic snapshot, because AI use changes faster than that. Getting to the first credible version is the work this journey describes.
Seed the register with what you already know
You start with the systems you can name from your own knowledge of the business. Aicura ships with a prefill catalogue of well-known AI products, so for the systems on it you select from the catalogue rather than typing into a blank form. The metadata that comes with each catalogue entry gives you a head start on what the register needs to capture.
Surface the systems used outside your view
Most organisations have AI in places the governance lead does not see directly. You reach out to functional leads across the business and ask what AI tools their teams use. As replies come back, you check each one against the prefill catalogue. For systems that are not in the catalogue, the Helper PDF lets your technical teams capture the detail offline without having to learn the app, and the completed PDFs upload straight into the register.
Capture the detail per system
For each system in the register, the entry captures risk classification, oversight model, vendor, data flows, business owner, and the documents that support it. Artifacts such as specifications, security reports, model cards, and vendor confirmations attach to the system entry. Versioning kicks in whenever a material change happens, so you can see what the system looked like at any point in the past.
Keep the register current as things change
New AI systems get added when adopted, retired ones get marked retired, and material changes get versioned so the trail stays intact. Periodic sweeps with functional leads surface what has changed below the line. Filters by risk level, status or category let you see what is still missing at any moment.
After the first credible version of the register exists, the work is no longer a one-off project. The register is the artefact your team reaches for when the board asks, when the insurer's questionnaire arrives, when due diligence opens up, when audit scope is set. Keeping it current is structured rather than chaotic, with new systems registered when adopted, material changes versioned, and the inventory acting as the spine for everything else AI governance does.
Frequently asked questions
What is an AI system register, and do I need one?
An AI system register is a single record of every system in your organisation that uses AI or automation to make or support a decision. You need one because you cannot write an accurate ADM disclosure from memory, and the systems that make those decisions are spread across teams with some sitting inside tools a team adopted on its own. The register is how you find them and write them down before you draft the privacy policy.
What information goes in the register?
For each system you capture the same fixed set of fields, the system name, its purpose, its owner, the data it uses, whether it makes or supports decisions about people, the vendor and its lifecycle status. From those you flag the systems whose decisions significantly affect a person, because those are the ones the privacy policy has to disclose from 10 December 2026. You can start the register in a spreadsheet today.
How do I find the AI nobody registered?
You find shadow AI by checking vendor features, spreadsheet models, point solutions and recent procurements against your draft register, because the obligation does not stop at software you built. Cast wide on the first pass and record a system even when you are not sure it is in scope, since it is easier to drop one later than to miss one that should have been disclosed. The quiet systems, a tool that ranks applicants or a feature that sets a price, matter as much as the obvious ones.
Once the register exists, is the work finished?
No. The register reflects the systems you run at the moment you build it, and organisations add automated-decision systems, change how existing ones work and retire others. Each of those events can make your privacy policy wrong in a way that is quiet and easy to miss, so the register earns its place as the living record your disclosure stays true against, the one you build for December and keep for the systems that come after.
A register that stays current, not a snapshot
A register is only useful while it matches reality, and reality changes every time your organisation adds, retires or reconfigures a system. Aicura is the register, reconciled against the privacy policy as that happens, so what you disclose keeps matching what you run. A consultant produces a register that is accurate on the day it is handed over. Aicura keeps the record and the policy reconciled as the organisation changes. If you would rather see the work first, the guided tour walks through the register, the policy review and what it surfaces without asking for an account.