Building an AI Register: the Columns You Need

Building an AI register under the EU AI Act: the nine columns you need, whether it is mandatory, and the hidden AI that is usually missing.

Gepubliceerd door NordX Consulting — AI bureau voor enterprise bedrijven in Nederland.

Almost every article about the AI Act ends with the same advice: start with an AI register. It rarely says what should actually go in one. This is that detail — the columns you need, where the obligation comes from, and how to keep it current without it becoming a paper exercise.

What is an AI register?

An AI register is a single overview of every AI system your organisation uses or provides, listing per system its purpose, the vendor, the data involved, the risk classification, and who is accountable for it. It is the document every other compliance conversation rests on: without it, you do not know what the rules apply to.

It is not a legally prescribed form. It is the practical way to demonstrate that you know what you have.

Is an AI register mandatory?

With nuance: the EU AI Act — known in Dutch as the AI-verordening — nowhere literally instructs ordinary businesses to "keep an AI register". What the law does do:

For those last two you must be able to show which systems you use and who works with them. A register is not the only way to do that, but it is by far the simplest. For high-risk providers documentation is mandatory regardless — there the register is no longer a choice, only a format.

The columns your register needs

Keep it narrow enough to maintain and broad enough to answer a regulator's question.

ColumnWhy it is there
System nameRecognisable to colleagues, not just the vendor's product name
Purpose and useWhat it is actually used for — not what it was intended for
Vendor / built in-houseDetermines whether you are a provider or a deployer
Role under the AI ActProvider or deployer; this drives every obligation
Risk classificationProhibited, high-risk, transparency duty (Art. 50), or none of these
Data processedWhich categories, including personal data — the link to the GDPR
Accountable ownerOne name, not a department
Human oversightWho checks the output, and at what point
Date of last reviewWithout a date you cannot tell whether the register still holds

Two columns get forgotten most often: data processed and date of last review. The first is where your AI register meets your GDPR processing register. The second is the difference between a living document and a snapshot from 2025.

The AI you forget to include

The biggest mistake is recording only the obvious tools. AI now sits hidden inside software nobody labels as AI:

A short round of questions per team usually surfaces more than an audit of procurement records.

How to set it up in an afternoon

1. Ask each team which tools they use. Ask about tasks, not about "AI" — "what do you let software write, summarise, sort or predict for you?" surfaces more than "do you use AI?".

2. Put everything in one table. A spreadsheet is fine. The format matters less than its existence.

3. Classify each system. For most businesses nearly everything lands on "transparency duty" or "neither". High-risk concerns specific uses such as recruitment, credit scoring or critical infrastructure.

4. Assign one owner per system. Shared accountability is no accountability.

5. Put a recurring review in the calendar. Once a quarter is enough for most organisations, provided it actually happens.

6. Link it to your GDPR register. Where AI processes personal data, the two registers should reference each other. See GDPR and AI: privacy in AI automation for how the two relate.

Where it goes wrong

The register is treated as a one-off project. Someone fills it in and nobody looks at it again. Without an owner and a review date it is stale within a quarter.

Only purchased software is listed. Shadow AI is precisely the category carrying the most risk, because no vendor agreements sit underneath it.

The classification is set too heavy. Not every use of AI is high-risk. Labelling everything high-risk makes the register unusable and the work needlessly large.

It stands alone. An AI register that does not reference your GDPR register, your vendor agreements and your internal AI house rules covers only part of the story.

In short

An AI register is not a form you submit, but the overview that lets you answer every other AI Act question. For most businesses it is a nine-column table you can fill in an afternoon, provided you also capture the AI that is not called AI. The organisations setting this up now will not have to reconstruct it under time pressure later.

For the full overview of what applies when, see our AI Act compliance guide for Dutch businesses. For the duty most often overlooked, see AI literacy: what Article 4 requires.

Sources

Frequently asked questions

Is an AI register legally mandatory?

Not as a separately prescribed form for ordinary businesses. Providers of high-risk AI must maintain technical documentation (Article 11) and register in the EU database (Article 49). For the AI literacy and transparency duties you must be able to show which systems you use — a register is the simplest way to do that.

What must an AI register contain as a minimum?

Per system: the name, its actual purpose, the vendor or in-house build, your role under the AI Act (provider or deployer), the risk classification, which data is processed, one accountable owner, how human oversight is arranged, and the date of the last review.

Does shadow AI belong in the register?

Yes, and it is often the most important category. Tools staff adopted on their own sit outside any procurement process and therefore outside any vendor agreement. A short round of questions per team surfaces more than procurement records.

How does an AI register relate to the GDPR processing register?

They overlap where AI processes personal data, but do not replace one another. The GDPR register covers processing of personal data; the AI register covers AI systems and their risk classification. Have them reference each other.

Related articles

Meer weten? Bekijk onze andere artikelen op het NordX blog of neem contact op via nordx.ai.