The risk tier is derived, never chosen
A register where somebody picks "low" from a dropdown tells you what that person felt that morning. Ours computes the tier from what the system actually does — and it moves by itself when the answers change.
Platform capability
Ask any organisation to list the AI it runs and you will get the two or three systems somebody bought on purpose. The rest arrived inside products you already pay for, and nobody decided anything about it.
Every compliance vendor now sells AI governance, and for most of them it is a policy template and a questionnaire. Both are useful. Neither answers the question an incident will ask first, which is simply: what AI do we run, what does it touch, and who said that was acceptable?
The awkward part is that the majority of an organisation's AI exposure is not the model somebody procured. It is the summarisation feature in the helpdesk, the drafting assistant in the CRM, the code completion in the IDE, the meeting transcription nobody switched off. Each one reads real data, most were enabled by default, and almost none went through a review — because nobody thinks of a product they already bought as an AI system.
So this is a register, and it is deliberately the unglamorous half. It records what is in use, what data reaches it, how much it does without a person, who owns it, and where it sits under the EU AI Act. Then it computes the risk rather than asking somebody to feel it.
Coverage
The inputs are facts about the system. The risk tier is a consequence.
A register where somebody picks "low" from a dropdown tells you what that person felt that morning. Ours computes the tier from what the system actually does — and it moves by itself when the answers change.
Personal, sensitive, health, financial, credentials, source code, customer content. The single largest factor, and the one people have not thought about when a tool was enabled by default.
Assistive, automated or agentic. An agent that chooses its own steps and calls tools can do damage an assistant cannot, and the tier reflects that.
Hiring, credit, pricing, access, moderation, a medical or legal suggestion. This is the factor regulators care about most, and it is a question most registers never ask.
Human oversight lowers the tier — but never far enough to make an agentic system handling sensitive data look safe, because oversight after the fact is not the same as a person deciding.
An unbounded disclosure of whatever you send. Weighted against what that actually is: public marketing copy is a nuisance, customer content is a contractual problem.
Role — provider, deployer or both — and risk class, with the reasoning recorded. Most organisations are deployers of far more AI than they provide, and the deployer obligations are the ones almost nobody has read.
The register connects to the AI assurance clauses you actually track — ISO 42001, the NIST AI RMF and the EU AI Act are all in the control library — so it is a programme rather than a list.
Approach
Start with what you already pay for.
Go through the SaaS you already buy and record the AI features in each. This is the pass that finds the entries nobody expected, and it takes an afternoon.
What data reaches it, how autonomously it acts, whether output affects anybody, whether a person can intervene. The tier computes itself as you go.
Work through the EU AI Act position for anything with an EU nexus, and record the reasoning. A documented determination that a system is not high-risk is itself something you have to keep.
Every entry gets a named owner and an approval. Approved systems come back for review annually, because what they are connected to changes faster than the approval does.
Deliverables
The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.
Every AI system with its owner, its data, its classification and its approval on record.
Computed from what each system does, and re-computed whenever that changes.
Agentic with nobody watching, personal data to a third party with no DPA, in use with no approval, overdue its review — flagged without being asked.
The ISO 42001, NIST AI RMF and EU AI Act clauses you track, with their current state.
Is this for you?
If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.
Book a scoping callHow we work
The same engagement model applies to every piece of work we take on, so you always know what happens next.
A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.
Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.
Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.
One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.
A walkthrough call with your engineers. We answer questions on the fix, not just the finding.
A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.
Questions
The questions clients actually ask during scoping. If yours is not here, ask it directly.
No, and we are explicit about that rather than implying otherwise. This is a register: it records what has been declared. Automatic discovery — from OAuth grants and endpoint inventory — is a separate piece of work, and shipping a half-built discovery alongside the register would make the register's numbers untrustworthy from day one. What the register does do is make the declaring cheap enough that it actually happens.
Because a tier somebody typed is a tier somebody typed. It records a judgement made on one day, by one person, and it does not change when the system does. A tier computed from the data, the autonomy, the human impact and the oversight tells you something — and when a team switches a tool from assistive to agentic, the register notices without anybody remembering to update it.
Different question entirely. AI red teaming asks whether a specific system can be made to misbehave — prompt injection, agent abuse, retrieval leakage — and it is an engagement. The register asks what you run, what it touches and who owns it, and it is a module. Most organisations need the register first, because you cannot test what you have not listed.
No. The register records your position and the reasoning behind it so the determination exists and can be produced. It will tell you when a combination looks worth a proper look — high-risk with no human oversight recorded, say — but the classification is yours to make, with advice from someone qualified to give it.
The register will not let you approve it into use. That is the one place this module refuses rather than warns: there is no compliance route for a prohibited practice, so it is not something to control, it is something to stop. If the classification is wrong, correct it first.
Next step
A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.