# AI tools register (template)

**How to use:** Make one row per AI tool or AI feature your organisation uses or sells. Update when you add, change, or retire a tool. Keep it somewhere your leadership can find (shared drive / wiki). Review quarterly.

**Disclaimer:** This template supports SMB orientation under the EU AI Act. It is **not legal advice** and does not certify compliance. Verify obligations for your facts; consult a lawyer when unsure.

**Organisation:** `[ORG NAME]`  
**Owner of register:** `[NAME / ROLE]`  
**Last reviewed:** `[YYYY-MM-DD]`  
**Next review:** `[YYYY-MM-DD]`

---

## Register

| ID | Tool / system name | Vendor / provider | What we use it for (intended purpose) | Our role (deployer / provider / both / other) | Customer-facing? (Y/N) | Personal data? (Y/N / types) | Risk flags (Art. 5 / HR / credit / biometrics / chatbot / other) | Live-now actions done | Prep deadline (if any) | Owner | Status (active / pilot / stopped) | Notes / link to DPIA or contracts |
|----|--------------------|-------------------|----------------------------------------|-----------------------------------------------|------------------------|------------------------------|----------------------------------------------------------------|----------------------|------------------------|-------|-----------------------------------|-----------------------------------|
| AI-001 | `[e.g. ChatGPT Business]` | `[OpenAI]` | `[Draft marketing copy; internal]` | `[deployer]` | `[N]` | `[Y — avoid client PII]` | `[none / internal assist]` | `[literacy 2026-09-01]` | `[—]` | `[Name]` | `[active]` | `[Acceptable use policy link]` |
| AI-002 | `[e.g. Website chatbot]` | `[Vendor]` | `[Customer support on website]` | `[deployer]` | `[Y]` | `[Y — chat logs]` | `[chatbot / Art. 50]` | `[notice live]` | `[—]` | `[Name]` | `[active]` | `[Art. 50 notice text]` |
| AI-003 | `[e.g. ATS AI rank]` | `[Vendor]` | `[Rank job candidates]` | `[deployer]` | `[N — candidates affected]` | `[Y — CVs]` | `[HR / Annex III prep]` | `[vendor DD sent]` | `[2027-12-02]` | `[Name]` | `[pilot]` | `[Human oversight rule]` |

---

## Instructions (short)

1. **ID** — stable code; don’t reuse after stop.  
2. **Intended purpose** — plain sentence; this drives AI Act duties more than the brand name.  
3. **Our role** — if you put your logo on it or change its purpose into hiring/credit/etc., you may be a **provider** (Art. 25).  
4. **Risk flags** — mark anything touching emotion at work, face scraping, HR decisions, credit, biometrics, or public chatbots.  
5. **Stopped tools** — keep the row; set status `stopped` and date in Notes (useful if authorities or customers ask).

## Related templates

- `ai-literacy-log.md` — who was trained  
- `art50-chatbot-notice.md` — disclosure text for bots  
- `vendor-due-diligence-questions.md` — questions for vendors  

