What should an AI use register contain?

Michał Rutkowski • for DPOs and compliance teams • published September 1, 2026 • updated September 12, 2026 • 9 min read

Let’s talk

Wondering how this plays out in your organisation? Get in touch — I answer personally.

Short answer

The AI Act does not require a register of AI use cases. What it does impose are three obligations for which a central inventory is a practical and evidentially strong tool. Those are the AI literacy duty in Article 4, the ban on prohibited practices in Article 5 and the transparency obligations in Article 50. Without it, demonstrating compliance is materially harder and riskier. The scope of the register therefore follows from those obligations rather than from a ready-made template. The same list will serve the obligations in Articles 25 and 26 once they start to bind in December 2027.

Why the question comes up at all

The record of processing activities has its basis in Article 30 GDPR and nobody asks whether to keep one. For artificial intelligence there is no such provision. The question about a register therefore looks like a question about good practice. It looks that way until the first time a client or an auditor asks where AI is at work in the organisation.

The second reason is organisational. Artificial intelligence entered the organisation by several routes at once. Some tools were bought deliberately. Some appeared as a new feature in software used for years, and some were built by teams on general-purpose models. None of those routes ends with an entry in any list.

The third reason concerns evidence. The regulation does not speak of a register. It does speak of informing, of oversight and of assessment. Each of those activities requires knowing what it applies to.

Remember

An organisation that does not know where it has AI will not perform any AI Act obligation in a way that can be checked.

What to establish before deciding

Three obligations that already bind

This is the core of the answer about scope. The register should hold exactly what makes it possible to perform the obligations that apply today.

AI literacy, Article 4, since 2 February 2025. Providers and deployers take measures supporting the development of AI literacy among their staff and other persons dealing with the operation and use of the systems on their behalf. The provision states expressly that the duty does not mean guaranteeing a particular level of AI literacy in individual people. It is therefore a duty of care rather than of result.

Performing it requires knowing who uses which tool and in what role. Without that knowledge, training reaches either everyone or nobody.

Prohibited practices, Article 5, since 2 February 2025. The prohibition does not depend on the risk classification or on the organisation’s role. It depends on what the system does. The register therefore has to describe the intended purpose and the manner of use precisely enough to be set against the list of prohibitions. Two new prohibitions take effect on 2 December 2026.

Transparency, Article 50, since 2 August 2026. The obligations divide according to role. The provider ensures that a system interacting directly with a person informs that person of the contact with AI. It is also responsible for marking synthetic content in a machine-readable format. The deployer informs people about emotion recognition and biometric categorisation, and discloses deep fakes and published text.

In the register this comes down to three questions for each use case. Does the system talk to people? Does it generate content? Does it process biometric data or recognise emotions?

What to add now, so the register is not built twice

The obligations in Articles 25 and 26 sit in Chapter III Section 3 and start to apply on 2 December 2027 for systems under Annex III and on 2 August 2028 for systems under Annex I. They do not bind yet.

That is not a reason to leave them out of the register. The fields they will call for are already known. Filling them in after the fact costs more than entering them straight away.

Article 25 calls for knowledge of three things. It has to be known whose name the system runs under, whether it has been modified and whether its intended purpose has changed. These answers have to be known at the moment of the change, not a year later.

Article 26 adds elements worth knowing well before December 2027.

  • Automatically generated logs kept for at least six months. The period follows from the intended purpose of the system and covers logs under the deployer’s control. The retention decision is made when the tool is configured, not when it is audited.
  • Informing workers before the system is used in the workplace. The employer informs workers’ representatives and the affected workers. This obligation surprises most often. It looks like a matter of employment law and it sits in a regulation on AI.
  • Human oversight assigned by name. The provision calls for people who have the necessary competence, training and authority, as well as the necessary support. An entry reading „oversight by the process owner” meets none of those conditions.
  • Information from the provider under Article 13. The deployer uses it for the data protection impact assessment. This is where the AI register connects with the GDPR documentation.

What does not belong in the register

The register does not replace the assessment. An entry reading „recruitment system, high risk” is a conclusion rather than a finding. Without a record of the reasoning it evidences nothing.

Nor is the register a list of tools. The unit of entry is the use case, meaning a specific use of a system in a specific process. The same tool used for drafting content and for initial screening of candidates produces two entries with different classifications.

Finally, fine levels and estimates of the likelihood of inspection do not belong there. The market surveillance authority in Poland is the Commission for the Development and Security of Artificial Intelligence. It was established by the Act on artificial intelligence systems. The obligations under the regulation bind regardless of how far that authority has been set up.

A checklist of register fields

The minimum set that serves the obligations applying today and prepares for those arriving in 2027.

  • Name of the use case and the process in which the system works.
  • Intended purpose, described precisely enough to be set against Article 5 and Article 6.
  • Role of the organisation towards that use case, with the date and basis of the finding.
  • Vendor of the tool, and whether the system runs under the organisation’s name.
  • Whether the system interacts with people, generates content, or recognises emotions or categorises biometrically.
  • The person exercising oversight, named, together with the scope of their authority.
  • People using the tool and the literacy measures assigned to them.
  • Personal data processed in the use case, linked to the record of processing and to the impact assessment.
  • Retention of logs and where they are kept.
  • Review date for the entry and the person responsible for keeping it current.

Conclusions and next steps

An AI use register is not a legal obligation, and presenting it to the board as one does not help. It is a precondition for performing the obligations that already bind. It is also the only material behind an answer given to a client or an auditor.

The order that produces a result fastest.

  1. Collect use cases from process owners rather than from IT. IT knows the tools; process owners know how they are used.
  2. For each use case answer the three Article 50 questions — interaction, synthetic content, biometrics and emotions.
  3. Set the intended purpose against the list of prohibited practices. This is the one part that does not tolerate delay.
  4. Assign the role of the organisation and record the reasoning, not just the outcome.
  5. Name the person responsible for keeping the entry current, and the review date.

The evidence that this work was done is a register in which every entry carries an author, a date and a reason for the classification. A register without those three is a list of tools, not documentation.

Related materials

Sources

  • Regulation (EU) 2024/1689 (AI Act), consolidated text as of 27 July 2026, Articles 4, 5, 25, 26, 50 and 113 — eur-lex.europa.eu (accessed: September 1, 2026).
  • Regulation (EU) 2026/1744 of 8 July 2026 amending Regulation (EU) 2024/1689 — OJ L 1744, 24 July 2026 (accessed: September 1, 2026).
  • Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) (in Polish) (accessed: September 1, 2026).

Find out where artificial intelligence is at work in your organisation today

A review of use cases ends with a list, a role assigned to each and a classification for each. A diagnostic conversation establishes how many such use cases there are and which one to start with.

Author

Michał Rutkowski — LabLogic. He combines the legal, organisational and technological perspective in his work with the boards of medium-sized and large organisations: support for and performance of the DPO role, preparation for NIS2 and the Polish KSC Act, incident response, audits and training. Contact: M.Rutkowski@LabLogic.pl · LinkedIn

This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.

Legal status: September 2026.

Scroll to Top