An inventory should support a decision, not just a count
This article revisits 2025 from a 2026 perspective. The decisions and scenario are illustrative and do not claim any CYTIZEN client result. In 2025, many organisations asked how many artificial intelligence tools they used. A more useful question was which uses could influence a decision, disclose information or act on a system, and who could answer for them. A supplier list cannot provide that assessment.
The same tool may help draft an email, retrieve an internal procedure and prioritise job applicants. Sharing a model does not make those uses equivalent. Purpose, affected people, data, autonomy and connection to decisions matter more than the commercial product name. An operational inventory should describe a particular use and connect it to an owner, an assessment and an action.
Illustrative scenario: one subscription hides four uses
Claire, the AI programme lead, receives a spreadsheet containing eight subscriptions. Legal asks which systems should be reviewed first. Procurement suggests ranking suppliers by spending. Malik, the HR director, adds that his team does not own an AI tool: it only uses a feature included in its recruitment software.
A forty-minute workshop identifies four uses of the same subscription: email correction, internal document search, applicant ranking and preparation of meeting minutes. The first two have different owners; the third has no recorded approval; the fourth sometimes processes sensitive information. Claire stops asking whether people have AI and instead asks what output they use, at which stage and with what consequence.
The eight-licence spreadsheet becomes a register of twelve uses. Three require detailed assessment, two are paused because no owner has been identified and seven continue through a proportionate review. Those numbers illustrate a governance exercise rather than a prediction about a typical organisation. Pausing a use is not a declaration that it is unlawful: it prevents operation without a known accountable owner.
One completed record is worth more than twenty empty fields
Give each use a stable identifier and a description that the business can understand. Supplier and model are attributes, not the identity of the case. If the model changes while the journey remains identical, update its version. If purpose or autonomy changes, reassess the use before treating it as an ordinary technical upgrade.
| Field | Completed example | Decision enabled |
|---|---|---|
| Identifier and purpose | HR-04: propose an order for reviewing applications | Separate writing assistance from selection |
| Affected people | External applicants; recruiter uses the output | Examine consequences and challenges |
| Data and output | CVs, job requirements, explained ranking | Assess relevance, access and retention |
| Autonomy | No automatic notification; recruiter examines every application | Check that oversight actually happens |
| Responsibilities | HR owner; applications team for integration; legal for classification | Identify who authorises operation |
| Version and next review | Configuration V3; review before adding automatic rejection | Trigger reassessment when the use changes |
This record does not decide the final regulatory classification in advance. It makes that discussion possible and preserves evidence of what was examined. Link contracts, provider documentation and relevant tests instead of copying lengthy descriptions that will soon diverge. Keep a date and named reviewer alongside the classification so a future owner can distinguish a current decision from an inherited assumption.
Determine the organisation's role before ticking a category
The team must establish who provides the system, who deploys it and whether a modification changes the organisation's role in the value chain. Buying a product does not by itself establish that the business remains only a customer in every situation. Integration, a change of purpose or a substantial modification may need separate analysis. Competent reviewers make that assessment using the technical and contractual facts of the case.
The business describes the journey and its consequence. IT describes permissions, interfaces and possible actions. The supplier explains behaviour, limitations and commitments. Security examines exposure and misuse. The data protection officer contributes when personal-data processing warrants it. Legal identifies applicable obligations. The use owner brings these views together and owns operating decisions without pretending to become an expert in every discipline.
Having a person read the output does not automatically remove its consequence. If ranking determines the only applications actually reviewed, supervision may exist in name only. Observe a working session using prepared cases. How many suggestions can the recruiter challenge? Does the reviewer have the underlying information and time to examine them? A checkbox stating that a human is involved answers none of those questions.
Separate the historical year from the current position
To understand 2025, distinguish the regulation's entry into force in 2024 from obligations becoming applicable in stages. Prohibited practices and AI literacy obligations began in February 2025; governance rules and certain general-purpose model obligations followed in August 2025. Treating 2025 as a period without obligations would therefore be misleading.
As of 4 October 2026, the Commission describes general application from August 2026 with exceptions and the AI Omnibus changes: certain high-risk uses now have December 2027 dates and certain product-integrated systems have August 2028 dates. The register needs the text, organisational role and deadline specific to each case, rather than one organisation-wide date. This is a documentary reference point, not an individual legal classification.
Prioritise using three observable questions
First, can the output affect an important decision about a person, a sensitive process or product safety? Second, can the use disclose data, contact a third party or execute an action? Third, who detects a wrong output and can stop its use? Answers determine the order of examination without replacing legal categories.
In the example, a simple internal triage score awards two points for consequences affecting a person, one for an external action and two when a stopping mechanism or owner has not been demonstrated. The maximum is five. Uses scoring four or five receive priority review; the others follow the ordinary process. A suspected prohibited practice never waits in this queue: isolate it for immediate examination. This teaching score must not be marketed as a compliance calculation.
For each record, state an action with a verb and evidence: demonstrate access restrictions, document the recruiter's role, limit admitted documents or suspend automatic sending. Awareness training may be necessary, but it does not demonstrate lower exposure. Closing an action should reference a test, configuration or decision rather than merely meeting minutes.
The review should also distinguish a vendor promise from an effective control. A supplier may describe a setting that the organisation has not enabled, or one that applies only to a different subscription tier. Record the configuration inspected, account type and test result. If the information cannot be verified, mark the uncertainty explicitly and restrict the use accordingly instead of treating a marketing description as evidence.
Measure the register's quality and plan for change
A useful completeness measure divides active uses with a current owner, purpose, consequence, data description and decision by all active uses recorded. Do not silently mix exploratory ideas into that denominator. With twelve active uses and nine actionable records, completeness is 75%. Prioritise the three missing records by exposure instead of adding thirty more fields to the form.
A change of purpose, a new data source, a connected tool or increased autonomy triggers review. The owner informs the register before activation. The team then samples actual configurations to check whether declared uses match reality. A quarterly review may suit a stable portfolio; a system changed every week requires a version-triggered process rather than waiting for the next calendar review.
Preserve successive decisions to show why a use was allowed, restricted or stopped. Procurement passes on provider announcements affecting the service. Employee departures and reorganisations transfer ownership. Otherwise the register becomes obsolete even when the technology itself remains unchanged. If a business area cannot identify its successor owner, mark that as an operational issue requiring resolution, rather than leaving the former employee's name in place.
What changes with the business journey
In HR, document the consequence for applicants or employees, how oversight works in practice and the available challenge process. Drafting a job advertisement and ranking candidates need separate records even within the same software. The review should understand whether all files remain visible and whether staff can reconsider a suggested ranking.
In industrial quality, separate retrieval of an approved procedure from generation of an instruction to execute. State the document version, validated scope and person authorised to approve a change. The register must not turn a plausible answer into a controlled instruction. If an assistant cannot identify the approved source, its result cannot silently replace the governing document.
For a sales assistant, identify admitted customer data, possible recipients and sending actions. Preparing a reviewed reply and automatically transmitting a contractual commitment have different consequences. The commercial owner approves limits on promises and IT verifies that those limits are enforced. A statement in an operating policy should be supported by the actual tool permissions.
Sources, method and limitations
Primary sources consulted on 4 October 2026: European Commission, AI Act framework and timeline; Commission, AI Omnibus entry into force; NIST AI Risk Management Framework. The NIST framework is a voluntary risk-management reference and does not establish European compliance.
The proposed method organises assessment work: describe, assign, examine, decide and maintain. Fields and thresholds are illustrative design choices. Exact obligations require examination of the system, its purpose, the organisation's role and current legislation. This article is neither a certified legal opinion nor a declaration that a product complies. It provides a practical record that enables competent people to make and revisit those decisions.